staticsafe
|
4f7b399783
|
add another adsbot IP to ipset list
|
2020-09-09 09:27:07 -04:00 |
|
staticsafe
|
10ba23f5d6
|
add another Adsbot IP to the nasties ipset
|
2020-09-07 12:40:23 -04:00 |
|
staticsafe
|
4d0660e162
|
quotes needed
|
2020-08-22 19:03:10 -04:00 |
|
staticsafe
|
1bd0269944
|
make sure to set hostname on new nodes and turn off motd news on focal
|
2020-08-22 19:00:56 -04:00 |
|
staticsafe
|
2d45e87d98
|
remove sshd_config copy in common role
its in ssh-enforcement now
|
2020-08-22 18:43:35 -04:00 |
|
staticsafe
|
2bfed5b9ed
|
add ssh-enforcement playbook
|
2020-08-22 15:47:23 -04:00 |
|
Sadiq Saif
|
b6946a3e26
|
Update pgbackrest version to 2.28
|
2020-08-18 08:40:19 -04:00 |
|
staticsafe
|
d2b0e47564
|
add Adsbot IPs to webserver ipsets
|
2020-07-29 08:46:33 -04:00 |
|
staticsafe
|
4ea258d17b
|
add 149.248.4.242 to deirdre.asininetech.net.ipset
|
2020-07-05 14:34:47 -04:00 |
|
staticsafe
|
71fc82ed22
|
remove namshiel.asininetech.net.rules.*
|
2020-07-05 14:33:29 -04:00 |
|
staticsafe
|
f5f09ebc58
|
add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre
|
2020-07-05 14:31:44 -04:00 |
|
staticsafe
|
7426c88be2
|
add 75.64.236.168/32 to deirdre and waldo ipset
|
2020-06-27 17:31:15 -04:00 |
|
staticsafe
|
f091373a1b
|
add yet another pimeyes.com crawler IP to ipset
|
2020-06-01 23:31:36 -04:00 |
|
staticsafe
|
07badc1ff1
|
add another pimeyes crawler IP to ipset
|
2020-06-01 23:17:07 -04:00 |
|
staticsafe
|
c69b2dda9a
|
add another pimeyes.com crawler IP
|
2020-05-27 21:05:14 -04:00 |
|
staticsafe
|
146fd41a7f
|
add pimeeyes.com crawler IP to nasties ipset
|
2020-05-27 21:01:18 -04:00 |
|
staticsafe
|
e1c36822fa
|
add a centurybot IP to nasties ipset
|
2020-05-27 13:44:27 -04:00 |
|
staticsafe
|
4fbedfec4e
|
add Aspiegel bot range to nasties ipset
|
2020-05-19 13:24:00 -04:00 |
|
staticsafe
|
4c573cb5a0
|
remove python-pip and python-dev from common role
|
2020-04-23 16:55:18 -04:00 |
|
staticsafe
|
27b9e93b0d
|
reference nasties ipset for erlking and waldo
|
2020-04-15 10:54:52 -04:00 |
|
staticsafe
|
fd475f98cb
|
add some more ipsets for erlking and waldo
|
2020-04-15 10:52:33 -04:00 |
|
staticsafe
|
d8f5681c52
|
fix typo in ipset.service
|
2020-04-15 10:26:29 -04:00 |
|
staticsafe
|
dd4d335302
|
make ipset.service import even if ipset already exists and then reload in main.yml
|
2020-04-15 10:24:02 -04:00 |
|
staticsafe
|
05176fb83e
|
don't destroy ipset in main.yml
|
2020-04-15 10:15:37 -04:00 |
|
staticsafe
|
3fb3507d40
|
make some more explicit requirements in ipset.service
|
2020-04-15 10:14:05 -04:00 |
|
staticsafe
|
8aa1d869ba
|
clean up unnecessary comments in firewall rulesets
|
2020-04-14 22:41:05 -04:00 |
|
staticsafe
|
a7888e95bf
|
set FLUSH_ON_STOP to 0
|
2020-04-14 22:36:13 -04:00 |
|
staticsafe
|
358b88ea60
|
we use a default file for netfilter-persistent
|
2020-04-14 22:29:56 -04:00 |
|
staticsafe
|
14c62687a7
|
ipset service stop destroy
|
2020-04-14 22:16:02 -04:00 |
|
staticsafe
|
53d62d54f5
|
let's try this again with destroy
|
2020-04-14 22:15:06 -04:00 |
|
staticsafe
|
377a5bcebf
|
temporarily comment out firewall rule
|
2020-04-14 22:12:03 -04:00 |
|
staticsafe
|
58c0b0e2c1
|
always reload systemd
|
2020-04-14 22:09:46 -04:00 |
|
staticsafe
|
3abbcbbd9e
|
use flush instead of destroy in ipset everywhere
|
2020-04-14 22:07:16 -04:00 |
|
staticsafe
|
92f286bbd6
|
should be src for ipset based rule
|
2020-04-14 22:03:31 -04:00 |
|
staticsafe
|
c267ec243f
|
use ipset instead of a bunch of INPUTs
|
2020-04-14 22:02:50 -04:00 |
|
staticsafe
|
0d7df674ec
|
dont use handler
|
2020-04-14 21:56:14 -04:00 |
|
staticsafe
|
02a376b367
|
restart ipset service instead of start and use handler
|
2020-04-14 21:52:51 -04:00 |
|
staticsafe
|
1430497f5c
|
move order of ipset destroy up
|
2020-04-14 21:47:16 -04:00 |
|
staticsafe
|
696bf3348f
|
fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml
|
2020-04-14 21:44:55 -04:00 |
|
staticsafe
|
ce39f769a2
|
add ipset-deploy role
|
2020-04-14 21:42:03 -04:00 |
|
staticsafe
|
835384a24d
|
add rulesets for uriel.asininetech.net.
|
2020-04-04 19:19:53 -04:00 |
|
staticsafe
|
66eebc37d3
|
add moz.com crawler to firewall block list on web servers
|
2020-03-28 23:10:00 -04:00 |
|
staticsafe
|
07cf97fa21
|
add rpcbind to list of packages we remove on setup
|
2020-03-27 13:08:12 -04:00 |
|
staticsafe
|
114970ec4b
|
Use a more generic sshd_config with our options.
|
2020-03-24 11:15:43 -04:00 |
|
staticsafe
|
1f1bf5147b
|
common role is now copying over a sshd_config
|
2020-03-24 10:27:23 -04:00 |
|
staticsafe
|
1de56b96b9
|
remove grevane.asininetech.net.rules.*, not needed anymore
|
2020-03-23 11:26:08 -04:00 |
|
staticsafe
|
7fb64da246
|
no need for 127/8 rules in demonreach.asininetech.net.rules.v4
|
2020-03-08 22:56:18 -04:00 |
|
staticsafe
|
10c45c850b
|
DNS resolving issues in demonreach.asininetech.net.rules.v4?
|
2020-03-08 15:58:13 -04:00 |
|
staticsafe
|
f9e74ee5aa
|
allow TCP DNS as well for VPN subnet
|
2020-03-04 17:50:43 -05:00 |
|
staticsafe
|
13f9b1575c
|
add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6
|
2020-03-04 17:16:48 -05:00 |
|