diff options
Diffstat (limited to 'roles/gateway/tasks/main.yml')
| -rw-r--r-- | roles/gateway/tasks/main.yml | 112 |
1 files changed, 0 insertions, 112 deletions
diff --git a/roles/gateway/tasks/main.yml b/roles/gateway/tasks/main.yml deleted file mode 100644 index f9ccd4cb..00000000 --- a/roles/gateway/tasks/main.yml +++ /dev/null @@ -1,112 +0,0 @@ ---- -- name: "Ensure iptables are installed" - become: true - ansible.builtin.package: - name: "iptables" - state: "present" - -- name: "Configure IP forwarding" - become: true - ansible.builtin.blockinfile: - path: "/etc/sysctl.conf" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - prepend_newline: true - append_newline: true - marker: "# ==== {mark} ANSIBLE GATEWAY CONFIG" - create: true - mode: "0644" - block: | - net.ipv4.ip_forward=1 - net.ipv6.conf.all.forwarding=1 - notify: "Reload sysctl" - -# IPv4 iptables rules -- name: "Add IPv4 NAT masquerading for traffic through internet" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" - out_interface: "{{ ansible_default_ipv4.interface }}" - jump: "MASQUERADE" - comment: "NAT local subnet traffic through internet" - state: "present" - -- name: "Add IPv4 NAT masquerading for traffic through VPN" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" - out_interface: "{{ item }}" - jump: "MASQUERADE" - comment: "NAT local subnet traffic through VPN" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - with_items: "{{ wireguard_connections }}" - -- name: "Add IPv4 FORWARD rule to accept traffic from local subnet" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24" - jump: "ACCEPT" - comment: "Allow forwarding from local subnet" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - -- name: "Add IPv4 FORWARD rule to accept established connections" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - match: "conntrack" - ctstate: "RELATED,ESTABLISHED" - jump: "ACCEPT" - comment: "Allow established connections" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - -# IPv6 iptables rules -- name: "Add IPv6 NAT masquerading for traffic through internet" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" - out_interface: "{{ ansible_default_ipv6.interface }}" - jump: "MASQUERADE" - comment: "NAT IPv6 local subnet traffic through internet" - ip_version: "ipv6" - state: "present" - when: ansible_default_ipv6.address is defined - -- name: "Add IPv6 NAT masquerading for traffic through VPN" - become: true - ansible.builtin.iptables: - table: "nat" - chain: "POSTROUTING" - source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" - out_interface: "{{ item }}" - jump: "MASQUERADE" - comment: "NAT IPv6 local subnet traffic through VPN" - ip_version: "ipv6" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - with_items: "{{ wireguard_connections }}" - -- name: "Add IPv6 FORWARD rule to accept traffic from local subnet" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}" - jump: "ACCEPT" - comment: "Allow IPv6 forwarding from local subnet" - ip_version: "ipv6" - state: "{{ 'present' if gateway_enabled else 'absent' }}" - -- name: "Add IPv6 FORWARD rule to accept established connections" - become: true - ansible.builtin.iptables: - chain: "FORWARD" - match: "conntrack" - ctstate: "RELATED,ESTABLISHED" - jump: "ACCEPT" - comment: "Allow IPv6 established connections" - ip_version: "ipv6" - state: "{{ 'present' if gateway_enabled else 'absent' }}" |
