Parcourir la source

disable ip forwarding not over egress

Blaine Story il y a 1 an
Parent
commit
4877f59aa4
1 fichiers modifiés avec 7 ajouts et 0 suppressions
  1. 7 0
      roles/router/tasks/main.yml

+ 7 - 0
roles/router/tasks/main.yml

@@ -35,6 +35,13 @@
   notify: Save iptables rules
 
 
+- name: Drop traffic not going over egress interface
+  ansible.builtin.iptables:
+    chain: FORWARD
+    jump: DROP
+  notify: Save iptables rules
+
+
 - name: Enable IP forwarding
   ansible.posix.sysctl:
     name: net.ipv4.ip_forward