当前位置:网站首页>Ansible firewall firewalld setting
Ansible firewall firewalld setting
2022-07-03 05:37:00 【Shuibutian】
ansible A firewall firewalld Set up
background
A firewall By organically combining all kinds of software and hardware equipment for safety management and screening , Help the computer network in it 、 Build a relatively isolated protective barrier between the external networks , A technology to protect user data and information security .
As far as computers are concerned, firewalls are divided into hardware and software , This article starts from the firewall of software , Introduce the firewall technology of the operating system .
Firewall setting is one of the common operations in the process of program deployment . This article ansible Introduction to the carrier , Traditional firewall settings reference 《centos7 Firewall settings 》
demand
Switch the firewall for the assigned server 、 Port policy and service settings .
operation
ansible Operation firewall involves three parts in this chapter
- Switch of firewall
- Firewall port policy
- Firewall service policy
Switch of firewall
The switch of firewall uses ansible Medium service service
open
# Turn on firewalld service
- hosts: middleware
# Remote task execution user
remote_user: root
# Task list
tasks:
# Get service information in the system
- name: checking service
ansible.builtin.service_facts:
# Statement
- name: Turn on firewalld A firewall
service:
name: firewalld
state: started
enabled: yes
when: ansible_facts.services['firewalld.service'] is defined
If you need to turn off the firewall state The status is set to stopped
verification
$ ansible middleware -a 'systemctl status firewalld' -i hosts
Firewall port policy
open
# Set up firewalld Port policy
- hosts: middleware
# Remote task execution user
remote_user: root
# Task list
tasks:
# Statement
- name: Set up firewalld Port policy
firewalld:
port: 8848/tcp
state: enabled
permanent: yes
immediate: yes
verification
$ ansible middleware -m shell -a 'firewall-cmd --lists-ports' -i hosts
Firewall service policy
open
# Set up firewalld Service strategy
- hosts: middleware
# Remote task execution user
remote_user: root
# Task list
tasks:
# Statement
- name: Set up firewalld Service strategy
firewalld:
service: http
state: enabled
permanent: yes
immediate: yes
verification
$ ansible middleware -m shell -a 'firewall-cmd --lists-services' -i hosts
边栏推荐
- Go practice -- generate and read QR codes in golang (skip2 / go QRcode and boombuilder / barcode)
- AtCoder Beginner Contest 258(A-D)
- Jetson AgX Orin platform porting ar0233 gw5200 max9295 camera driver
- Covering Safari and edge, almost all mainstream browsers have realized webgl 2.0 support
- AtCoder Beginner Contest 258(A-D)
- @Autowired 导致空指针报错 解决方式
- Disassembly and installation of Lenovo r7000 graphics card
- Pessimistic lock and optimistic lock of multithreading
- Jetson AGX Orin 平台移植ar0233-gw5200-max9295相机驱动
- 6.23星期四库作业
猜你喜欢
"250000 a year is just the price of cabbage" has become a thing of the past. The annual salary of AI posts has decreased by 8.9%, and the latest salary report has been released
Differences among bio, NiO and AIO
mapbox尝鲜值之云图动画
Brief introduction of realsense d435i imaging principle
大学校园IP网络广播-厂家基于校园局域网的大学校园IP广播方案设计指南
Mapbox tasting value cloud animation
Redis使用Lua脚本简介
Common interview questions of microservice
Export the altaro event log to a text file
kubernetes资源对象介绍及常用命令(五)-(ConfigMap)
随机推荐
redis 遇到 NOAUTH Authentication required
Go practice -- use redis in golang (redis and go redis / redis)
Go practice -- design patterns in golang's singleton
NG Textarea-auto-resize
Go practice -- gorilla/rpc (gorilla/rpc/json) used by gorilla web Toolkit
Today, many CTOs were killed because they didn't achieve business
2022.DAY592
Redis使用Lua脚本简介
Training method of grasping angle in grasping detection
2022.7.2day594
@Autowired 导致空指针报错 解决方式
BTC-密码学原理
32GB Jetson Orin SOM 不能刷机问题排查
Learn libcef together -- set cookies for your browser
(subplots用法)matplotlib如何绘制多个子图(轴域)
(subplots usage) Matplotlib how to draw multiple subgraphs (axis field)
[untitled]
College campus IP network broadcasting - manufacturer's design guide for college campus IP broadcasting scheme based on campus LAN
Final review (Day5)
ES 2022 正式发布!有哪些新特性?