old_version_cleanup_iptables.yml 1.1 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. ---
  2. - name: Old version cleanup | Delete old forward [in] iptables rules
  3. iptables:
  4. state: absent
  5. chain: FORWARD
  6. in_interface: "{{ item }}"
  7. jump: ACCEPT
  8. comment: "{{ item }} FORWARD input"
  9. with_items:
  10. - contivh0
  11. - contivh1
  12. notify: Save iptables rules
  13. - name: Old version cleanup | Delete old forward [out] iptables rules
  14. iptables:
  15. state: absent
  16. chain: FORWARD
  17. out_interface: "{{ item }}"
  18. jump: ACCEPT
  19. comment: "{{ item }} FORWARD output"
  20. with_items:
  21. - contivh0
  22. - contivh1
  23. notify: Save iptables rules
  24. - name: Old version cleanup | Delete old input iptables rules
  25. iptables:
  26. state: absent
  27. chain: INPUT
  28. protocol: "{{ item.split('/')[1] }}"
  29. match: "{{ item.split('/')[1] }}"
  30. destination_port: "{{ item.split('/')[0] }}"
  31. comment: "{{ item.split('/')[2] }}"
  32. jump: ACCEPT
  33. with_items:
  34. - "53/udp/contiv dns"
  35. - "4789/udp/netplugin vxlan 4789"
  36. - "8472/udp/netplugin vxlan 8472"
  37. - "9003/tcp/contiv"
  38. - "9002/tcp/contiv"
  39. - "9001/tcp/contiv"
  40. - "9999/tcp/contiv"
  41. - "10000/tcp/Contiv auth proxy service (10000)"
  42. notify: Save iptables rules