TripleO Ansible project repository. Contains playbooks for use with TripleO OpenStack deployments.
# All variables intended for modification should be placed in this file.
# All variables within this role should have a prefix of "tripleo_firewall"
# Example rule definition
# '003 accept ssh from all':
# proto: 'tcp'
# dport: 22
# '002 remove ssh from all':
# proto: 'tcp'
# dport: 22
# extras:
# ensure: 'absent'
tripleo_firewall_rules: {}
'000 accept related established rules':
proto: all
'001 accept all icmp':
ipversion: ipv4
proto: icmp
'001 accept all ipv6-icmp':
ipversion: ipv6
proto: ipv6-icmp
'002 accept all to lo interface':
proto: all
interface: lo
'004 accept ipv6 dhcpv6':
ipversion: ipv6
dport: 546
proto: udp
destination: 'fe80::/64'
'998 log all':
proto: all
jump: LOG
limit: 20/min
limit_burst: 15
'999 drop all':
proto: all
action: drop