summaryrefslogtreecommitdiffstats
path: root/roles/gateway/tasks/main.yml
diff options
context:
space:
mode:
Diffstat (limited to 'roles/gateway/tasks/main.yml')
-rw-r--r--roles/gateway/tasks/main.yml112
1 files changed, 0 insertions, 112 deletions
diff --git a/roles/gateway/tasks/main.yml b/roles/gateway/tasks/main.yml
deleted file mode 100644
index f9ccd4cb..00000000
--- a/roles/gateway/tasks/main.yml
+++ /dev/null
@@ -1,112 +0,0 @@
----
-- name: "Ensure iptables are installed"
- become: true
- ansible.builtin.package:
- name: "iptables"
- state: "present"
-
-- name: "Configure IP forwarding"
- become: true
- ansible.builtin.blockinfile:
- path: "/etc/sysctl.conf"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
- prepend_newline: true
- append_newline: true
- marker: "# ==== {mark} ANSIBLE GATEWAY CONFIG"
- create: true
- mode: "0644"
- block: |
- net.ipv4.ip_forward=1
- net.ipv6.conf.all.forwarding=1
- notify: "Reload sysctl"
-
-# IPv4 iptables rules
-- name: "Add IPv4 NAT masquerading for traffic through internet"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- out_interface: "{{ ansible_default_ipv4.interface }}"
- jump: "MASQUERADE"
- comment: "NAT local subnet traffic through internet"
- state: "present"
-
-- name: "Add IPv4 NAT masquerading for traffic through VPN"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- out_interface: "{{ item }}"
- jump: "MASQUERADE"
- comment: "NAT local subnet traffic through VPN"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
- with_items: "{{ wireguard_connections }}"
-
-- name: "Add IPv4 FORWARD rule to accept traffic from local subnet"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- source: "{{ (ansible_default_ipv4.address.split('.')[0:3] | join('.')) }}.0/24"
- jump: "ACCEPT"
- comment: "Allow forwarding from local subnet"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
-
-- name: "Add IPv4 FORWARD rule to accept established connections"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- match: "conntrack"
- ctstate: "RELATED,ESTABLISHED"
- jump: "ACCEPT"
- comment: "Allow established connections"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
-
-# IPv6 iptables rules
-- name: "Add IPv6 NAT masquerading for traffic through internet"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- out_interface: "{{ ansible_default_ipv6.interface }}"
- jump: "MASQUERADE"
- comment: "NAT IPv6 local subnet traffic through internet"
- ip_version: "ipv6"
- state: "present"
- when: ansible_default_ipv6.address is defined
-
-- name: "Add IPv6 NAT masquerading for traffic through VPN"
- become: true
- ansible.builtin.iptables:
- table: "nat"
- chain: "POSTROUTING"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- out_interface: "{{ item }}"
- jump: "MASQUERADE"
- comment: "NAT IPv6 local subnet traffic through VPN"
- ip_version: "ipv6"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
- with_items: "{{ wireguard_connections }}"
-
-- name: "Add IPv6 FORWARD rule to accept traffic from local subnet"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- source: "{{ (ansible_default_ipv6.address.split(':')[:4] | join(':')) + '::/64' }}"
- jump: "ACCEPT"
- comment: "Allow IPv6 forwarding from local subnet"
- ip_version: "ipv6"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"
-
-- name: "Add IPv6 FORWARD rule to accept established connections"
- become: true
- ansible.builtin.iptables:
- chain: "FORWARD"
- match: "conntrack"
- ctstate: "RELATED,ESTABLISHED"
- jump: "ACCEPT"
- comment: "Allow IPv6 established connections"
- ip_version: "ipv6"
- state: "{{ 'present' if gateway_enabled else 'absent' }}"