diff --git a/README.md b/README.md index 45280cb..134f74b 100644 --- a/README.md +++ b/README.md @@ -13,7 +13,9 @@ Role Variables Set the default policy: - ufw_default_policy: deny + ufw_default_policy: + - { direction: "incoming", policy: "deny" } + Add or remove rules: diff --git a/defaults/main.yml b/defaults/main.yml index 7a5ea9e..5398cfe 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -3,4 +3,6 @@ ufw_rules_to_create: [] ufw_rules_to_delete: [] -ufw_default_policy: deny +ufw_default_policy: + - { direction: "incoming", policy: "deny" } + diff --git a/tasks/main.yml b/tasks/main.yml index c579d67..6896fda 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -32,7 +32,9 @@ - name: set default policy ufw: - policy: "{{ ufw_default_policy }}" + policy: "{{ item.policy }}" + direction: "{{ item.direction }}" + with_items: "{{ ufw_default_policy }}" - name: enable and start ufw ufw: