Skip to content

Commit

Permalink
fix(agent): enable rich rule properly (#19)
Browse files Browse the repository at this point in the history
  • Loading branch information
hairmare authored Mar 2, 2024
1 parent 4b85bc4 commit 9f2d953
Showing 1 changed file with 3 additions and 11 deletions.
14 changes: 3 additions & 11 deletions roles/agent/tasks/main.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -61,17 +61,9 @@
name: "{{ _radiorabe_zabbix_agent_firewall_rolename }}"
vars:
firewall:
- ipset: hgrp_zabbix_servers
ipset_type: "hash:ip"
short: Zabbix Servers
description: set of of all zabbix servers and proxies
ipset_entries:
- "{{ lookup('dig', radiorabe_zabbix_agent_server) }}"
state: present
permanent: true
- rich_rule: 'rule family="ipv4" source ipset="hgrp_zabbix_servers" service name="zabbix-agent" accept'
state: present
permanent: true
- rich_rule: ['rule family="ipv4" source address="{{ lookup("dig", radiorabe_zabbix_agent_server) }}" service name="zabbix-agent" accept']
zone: service
state: enabled
tags:
- role::rabe_zabbix.agent
- role::rabe_zabbix.agent.firewall

0 comments on commit 9f2d953

Please sign in to comment.