Compare commits
4 Commits
v0.0.4j-ak
...
v0.0.4p-jc
Author | SHA1 | Date | |
---|---|---|---|
8b59a5553f | |||
5f1b04fd96 | |||
3b88857c0b | |||
72c5498e64 |
@ -4,7 +4,6 @@
|
|||||||
|
|
||||||
@def $DEV_PRIVATE = enp0s8;
|
@def $DEV_PRIVATE = enp0s8;
|
||||||
@def $DEV_WORLD = enp0s9;
|
@def $DEV_WORLD = enp0s9;
|
||||||
@def $DEV_WORLD = enp0s9;
|
|
||||||
@def $DEV_VPN= wg0;
|
@def $DEV_VPN= wg0;
|
||||||
@def $NET_PRIVATE = 172.16.0.0/24;
|
@def $NET_PRIVATE = 172.16.0.0/24;
|
||||||
|
|
||||||
@ -32,7 +31,7 @@ table filter {
|
|||||||
# well-known internet hosts
|
# well-known internet hosts
|
||||||
saddr ($NET_PRIVATE) proto tcp dport ssh ACCEPT;
|
saddr ($NET_PRIVATE) proto tcp dport ssh ACCEPT;
|
||||||
|
|
||||||
# we provide DNS and SMTP services for the internal net
|
# we provide DNS services for the internal net
|
||||||
interface $DEV_PRIVATE saddr $NET_PRIVATE {
|
interface $DEV_PRIVATE saddr $NET_PRIVATE {
|
||||||
proto (udp tcp) dport domain ACCEPT;
|
proto (udp tcp) dport domain ACCEPT;
|
||||||
proto udp dport bootps ACCEPT;
|
proto udp dport bootps ACCEPT;
|
||||||
|
@ -29,7 +29,7 @@ table filter {
|
|||||||
# well-known internet hosts
|
# well-known internet hosts
|
||||||
saddr ($NET_PRIVATE) proto tcp dport ssh ACCEPT;
|
saddr ($NET_PRIVATE) proto tcp dport ssh ACCEPT;
|
||||||
|
|
||||||
# we provide DNS and SMTP services for the internal net
|
# we provide DNS services for the internal net
|
||||||
interface $DEV_PRIVATE saddr $NET_PRIVATE {
|
interface $DEV_PRIVATE saddr $NET_PRIVATE {
|
||||||
proto (udp tcp) dport domain ACCEPT;
|
proto (udp tcp) dport domain ACCEPT;
|
||||||
proto udp dport bootps ACCEPT;
|
proto udp dport bootps ACCEPT;
|
||||||
|
@ -69,8 +69,13 @@
|
|||||||
args:
|
args:
|
||||||
chdir: /root/nxc
|
chdir: /root/nxc
|
||||||
|
|
||||||
- name: Creation reseau docker proxy
|
- name: vérification si le réseau proxy existe
|
||||||
|
command: docker network ls --filter name=proxy
|
||||||
|
register: net_proxy
|
||||||
|
|
||||||
|
- name: création du réseau proxy
|
||||||
command: docker network create proxy
|
command: docker network create proxy
|
||||||
|
when: net_proxy.stdout.find('proxy') == -1
|
||||||
|
|
||||||
#- name: Démarrage du docker-compose...
|
#- name: Démarrage du docker-compose...
|
||||||
#command: /bin/bash docker-compose up -d
|
#command: /bin/bash docker-compose up -d
|
||||||
|
@ -7,15 +7,15 @@ iface lo inet loopback
|
|||||||
# carte n-adm
|
# carte n-adm
|
||||||
allow-hotplug enp0s3
|
allow-hotplug enp0s3
|
||||||
iface enp0s3 inet static
|
iface enp0s3 inet static
|
||||||
address 192.168.99.101/24
|
address 192.168.99.102/24
|
||||||
|
|
||||||
# Réseau n-dmz-lb
|
# Réseau n-dmz-lb
|
||||||
allow-hotplug enp0s8
|
allow-hotplug enp0s8
|
||||||
iface enp0s8 inet static
|
iface enp0s8 inet static
|
||||||
address 192.168.101.1/24
|
address 192.168.101.2/24
|
||||||
|
|
||||||
# réseau n-dmz-db
|
# réseau n-dmz-db
|
||||||
allow-hotplug enp0s9
|
allow-hotplug enp0s9
|
||||||
iface enp0s9 inet static
|
iface enp0s9 inet static
|
||||||
address 192.168.102.1/24
|
address 192.168.102.2/24
|
||||||
post-up mount -o rw 192.168.102.253:/home/wordpress /var/www/html
|
post-up mount -o rw 192.168.102.253:/home/wordpress /var/www/html
|
||||||
|
@ -34,3 +34,10 @@
|
|||||||
- { regexp: '^(ServerActive\s*=\s*).*$', replace: 'ServerActive = 192.168.99.8' }
|
- { regexp: '^(ServerActive\s*=\s*).*$', replace: 'ServerActive = 192.168.99.8' }
|
||||||
- { regexp: '^(Hostname\s*=\s*).*$', replace: 'Hostname = {{ ansible_hostname }}' }
|
- { regexp: '^(Hostname\s*=\s*).*$', replace: 'Hostname = {{ ansible_hostname }}' }
|
||||||
- { regexp: '^(Include\s*=\s*).*$', replace: 'Include = /etc/zabbix/zabbix_agentd.d/*.conf' }
|
- { regexp: '^(Include\s*=\s*).*$', replace: 'Include = /etc/zabbix/zabbix_agentd.d/*.conf' }
|
||||||
|
|
||||||
|
- name: Enable Zabbix agent service
|
||||||
|
service:
|
||||||
|
name: zabbix-agent
|
||||||
|
state: restarted
|
||||||
|
enabled: yes
|
||||||
|
|
||||||
|
@ -18,4 +18,4 @@ echo ping r-vp2 interface interface interne
|
|||||||
ping -c3 172.16.128.254
|
ping -c3 172.16.128.254
|
||||||
|
|
||||||
echo ping s-agence
|
echo ping s-agence
|
||||||
ping -c3 172.16.128.11
|
ping -c3 172.16.128.10
|
||||||
|
Reference in New Issue
Block a user