Commit Graph

342 Commits

Author SHA1 Message Date
staticsafe
dd4d335302 make ipset.service import even if ipset already exists and then reload in main.yml 2020-04-15 10:24:02 -04:00
staticsafe
05176fb83e don't destroy ipset in main.yml 2020-04-15 10:15:37 -04:00
staticsafe
3fb3507d40 make some more explicit requirements in ipset.service 2020-04-15 10:14:05 -04:00
staticsafe
8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe
a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe
358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe
14c62687a7 ipset service stop destroy 2020-04-14 22:16:02 -04:00
staticsafe
53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe
377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe
58c0b0e2c1 always reload systemd 2020-04-14 22:09:46 -04:00
staticsafe
3abbcbbd9e use flush instead of destroy in ipset everywhere 2020-04-14 22:07:16 -04:00
staticsafe
92f286bbd6 should be src for ipset based rule 2020-04-14 22:03:31 -04:00
staticsafe
c267ec243f use ipset instead of a bunch of INPUTs 2020-04-14 22:02:50 -04:00
staticsafe
0d7df674ec dont use handler 2020-04-14 21:56:14 -04:00
staticsafe
02a376b367 restart ipset service instead of start and use handler 2020-04-14 21:52:51 -04:00
staticsafe
1430497f5c move order of ipset destroy up 2020-04-14 21:47:16 -04:00
staticsafe
696bf3348f fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml 2020-04-14 21:44:55 -04:00
staticsafe
ce39f769a2 add ipset-deploy role 2020-04-14 21:42:03 -04:00
staticsafe
835384a24d add rulesets for uriel.asininetech.net. 2020-04-04 19:19:53 -04:00
staticsafe
66eebc37d3 add moz.com crawler to firewall block list on web servers 2020-03-28 23:10:00 -04:00
staticsafe
99137e82f1 Merge branch 'nextgen' of github.com:staticsafe/ansible-playbooks into nextgen 2020-03-27 13:08:19 -04:00
staticsafe
07cf97fa21 add rpcbind to list of packages we remove on setup 2020-03-27 13:08:12 -04:00
Sadiq Saif
57a0f65ffd
Update README.md to say 18.04 2020-03-24 11:43:02 -04:00
staticsafe
114970ec4b Use a more generic sshd_config with our options. 2020-03-24 11:15:43 -04:00
staticsafe
1f1bf5147b common role is now copying over a sshd_config 2020-03-24 10:27:23 -04:00
staticsafe
1de56b96b9 remove grevane.asininetech.net.rules.*, not needed anymore 2020-03-23 11:26:08 -04:00
staticsafe
c1b3d2a171 clean up nginx_remove_sites 2020-03-09 20:38:56 -04:00
staticsafe
6613d75162 remove sadiqsaif.ca and staticsafe.ca vhosts 2020-03-09 19:26:22 -04:00
staticsafe
7fb64da246 no need for 127/8 rules in demonreach.asininetech.net.rules.v4 2020-03-08 22:56:18 -04:00
staticsafe
10c45c850b DNS resolving issues in demonreach.asininetech.net.rules.v4? 2020-03-08 15:58:13 -04:00
staticsafe
f9e74ee5aa allow TCP DNS as well for VPN subnet 2020-03-04 17:50:43 -05:00
staticsafe
13f9b1575c add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6 2020-03-04 17:16:48 -05:00
staticsafe
a0d1c0598d remove port 1723 from demonreach.asininetech.net.rules.v4 2020-03-04 13:49:55 -05:00
staticsafe
12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe
907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe
e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe
db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe
c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe
9766d2ced5 Add vhost for ultonomy.com. 2020-01-22 10:46:15 -05:00
staticsafe
2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe
bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe
a4c0bcde30 min heap size 4g 2020-01-18 18:56:24 -05:00
staticsafe
42bf05965b increase min heap size to 2g 2020-01-18 18:54:41 -05:00
staticsafe
2c83554698 elasticsearch_version should be 6.x 2020-01-18 18:49:03 -05:00
staticsafe
869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe
201f4a35ca min heap size to 1g? 2020-01-18 17:39:47 -05:00
staticsafe
6f0febf806 needs min heap size? 2020-01-18 17:36:56 -05:00
staticsafe
d810ba667e let's try again? 2020-01-18 17:34:00 -05:00
staticsafe
d0976ca7fb fix formatting on namshiel-elasticsearch.asininetech.net.yml? 2020-01-18 17:33:01 -05:00
staticsafe
e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00