Re: How to manage a firewall script with minor tweaks for different machines?

2021-06-19 Thread Anssi Saari
Andy Smith writes: > Ansible can be very simple and quick to learn and everything you've > mentioned in your post can easily be done with it. Thanks, I'd heard of Ansible before and I tried it and cdist and decided to do this with Ansible. Mostly because I couldn't get anywhere with cdist. Ansi

Re: How to manage a firewall script with minor tweaks for different machines?

2021-06-12 Thread Anssi Saari
john doe writes: > You could have one common file that includes a custum file (1). > You would have one custum file per host (custum-cups, custum-smb ...). Right, thanks. I missed the whole include ability in nftables.

Re: How to manage a firewall script with minor tweaks for different machines?

2021-06-12 Thread Andy Smith
Hello, On Sat, Jun 12, 2021 at 07:02:50PM +0300, Anssi Saari wrote: > But then... One machine has a radius server that needs UDP port 1812 > open. And another is a print server with CUPS and SMB which apparently > need at least TCP ports 631 and 137 open. It sounds like you need configuration man

Re: How to manage a firewall script with minor tweaks for different machines?

2021-06-12 Thread john doe
On 6/12/2021 6:02 PM, Anssi Saari wrote: I've recently setup nftables firewalls on the machines of my little home network. I was a little optimistic and thought I could get by with a simple one that only allows ssh and nfs in i.e. two TCP ports and mDNS with its slightly more complex rules. But

Re: How to manage a firewall script with minor tweaks for different machines?

2021-06-12 Thread deloptes
Anssi Saari wrote: > I also need some way of pushing these firewall scripts and other config > stuff over to the machines too. It's not a huge network but manually > logging into each machine, overwriting /etc/nftables.conf and restarting > nftables.service is a pain. cdist looks interesting and s

How to manage a firewall script with minor tweaks for different machines?

2021-06-12 Thread Anssi Saari
I've recently setup nftables firewalls on the machines of my little home network. I was a little optimistic and thought I could get by with a simple one that only allows ssh and nfs in i.e. two TCP ports and mDNS with its slightly more complex rules. But then... One machine has a radius server t