infra-v1/applications/roles/authsec.pihole/tasks/firewall-iptables.yml

41 lines
698 B
YAML

- name: Allow ping
iptables:
chain: INPUT
jump: ACCEPT
protocol: icmp
- name: Allow DHCP
iptables:
chain: INPUT
protocol: udp
destination_port: "67"
jump: ACCEPT
when: riv_pihole_dhcp_active|bool
- name: Allow HTTP
iptables:
chain: INPUT
protocol: tcp
destination_port: "80"
jump: ACCEPT
- name: Allow HTTPS
iptables:
chain: INPUT
protocol: tcp
destination_port: "443"
jump: ACCEPT
- name: Allow UDP DNS queries
iptables:
chain: INPUT
protocol: udp
destination_port: "53"
jump: ACCEPT
- name: Allow TCP DNS queries
iptables:
chain: INPUT
protocol: tcp
destination_port: "53"
jump: ACCEPT