Skip to content
Snippets Groups Projects
Commit 4c572e27 authored by void's avatar void
Browse files

ldap ports auf 0.0.0.0 binden und per iptables blocken

parent b50043cb
No related branches found
No related tags found
No related merge requests found
...@@ -50,8 +50,8 @@ ...@@ -50,8 +50,8 @@
LDAP_READONLY_USER_USERNAME: readonly LDAP_READONLY_USER_USERNAME: readonly
LDAP_READONLY_USER_PASSWORD: "{{ ldap_readonly_pass }}" LDAP_READONLY_USER_PASSWORD: "{{ ldap_readonly_pass }}"
ports: ports:
- 127.0.0.1:389:389 - 0.0.0.0:389:389
- 127.0.0.1:636:636 - 0.0.0.0:636:636
- name: start phpldapadmin docker - name: start phpldapadmin docker
docker_container: docker_container:
......
- name: Konfiguration erstellen
template: src=rc.local dest=/etc/rc.local mode=o+x
#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will "exit 0" on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.
iptables -I FORWARD -p tcp -m tcp --dport 389 -j REJECT --reject-with icmp-port-unreachable
iptables -I FORWARD -p tcp -m tcp --dport 636 -j REJECT --reject-with icmp-port-unreachable
iptables -I FORWARD -s 127.0.0.0/8 -p tcp -m tcp --dport 636 -j ACCEPT
iptables -I FORWARD -s 192.168.0.0/24 -p tcp -m tcp --dport 636 -j ACCEPT
iptables -I FORWARD -s 172.17.0.0/24 -p tcp -m tcp --dport 636 -j ACCEPT
iptables -I FORWARD -s 192.168.0.0/24 -p tcp -m tcp --dport 389 -j ACCEPT
iptables -I FORWARD -s 127.0.0.0/8 -p tcp -m tcp --dport 389 -j ACCEPT
iptables -I FORWARD -s 172.17.0.0/24 -p tcp -m tcp --dport 389 -j ACCEPT
exit 0
...@@ -3,6 +3,7 @@ ...@@ -3,6 +3,7 @@
- hosts: webserver - hosts: webserver
remote_user: root remote_user: root
roles: roles:
- { role: iptables, tags: iptables }
- { role: nginx, tags: nginx } - { role: nginx, tags: nginx }
- { role: openvpn, tags: openvpn } - { role: openvpn, tags: openvpn }
- { role: docker, tags: docker } - { role: docker, tags: docker }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment