Ansible Pilot

Open firewall ports in RedHat-like systems - Ansible module firewalld

How to open HTTP and HTTPS firewall ports in RedHat-like systems with Ansible. I’m going to show you a live demo and some simple Ansible code: RedHat Enterprise Linux, CentOS, CentOS Stream, Fedora, ClearOS, Oracle Linux, EuroLinux, Fermi Linux, EulerOS, ROSA Linux, Springdale Linux, Asianux

September 2, 2021
Access the Complete Video Course and Learn Quick Ansible by 200+ Practical Lessons

How to open firewall ports in RedHat-like systems with Ansible?

I’m going to show you a live demo and some simple Ansible code. I’m Luca Berton and welcome to today’s episode of Ansible Pilot.

Ansible open firewall ports in RedHat-like systems

Today we’re talking about the Ansible module firewalld. The full name is ansible.posix.firewalld, which means that is part of the collection targeting POSIX platforms. This module requires Ansible 2.9+. It works in RedHat-like systems with firewalld >= 0.2.11 and python firewalld bindings. It manages arbitrary ports/services with firewalld.

Parameters

The parameter list is pretty wide but these are the most important options for our use case to open firewall ports. The “state” parameter is mandatory and specifies to enable or disable a setting. The options “enabled” accept and “disabled” reject connections for ports. The options “present” and “absent” are for zone-level operations. The “service” parameter specifies the name of a service to add/remove to/from firewalld. For the full list please use “firewall-cmd - get-services”. The “port” parameter specifies the name of a port or port range to add/remove to/from firewalld. The format is PORT/PROTOCOL so for example 80/TCP for HTTP connections. You could also specify a range with PORT-PORT/PROTOCOL. The “permanent” parameter defines if the configuration should persist across reboots. Note that if “permanent” is no, “immediate” is assumed yes. The “immediate” parameter applies immediately to the configuration of the system.

The Best Resources For Ansible

Certifications

Video Course

Printed Book

eBooks

demo

Let’s jump in a real-life demo about how to open firewall ports in RedHat-like systems with Ansible Playbook.

# firewall-cmd --state
# systemctrl status firewalld
# firewall-cmd --list-all
# firewall-cmd --list-services
# dnf info nginx
---
- name: firewalld module demo
  hosts: all
  become: true
  tasks:
- name: nginx installed
      ansible.builtin.yum:
        name: nginx
        state: present
- name: firewalld rules
      ansible.posix.firewalld:
        service: "{{ item }}"
        state: enabled
        permanent: true
        immediate: true
      with_items:
        - http
        - https

code with ❤️ in GitHub

Recap

Now you know how to open firewall ports in RedHat-like systems with Ansible. Subscribe to the YouTube channel, Medium, and Website, X (formerly Twitter) to not miss the next episode of the Ansible Pilot.

Academy

Learn the Ansible automation technology with some real-life examples in my

My book Ansible By Examples: 200+ Automation Examples For Linux and Windows System Administrator and DevOps

BUY the Complete PDF BOOK to easily Copy and Paste the 250+ Ansible code

Want to keep this project going? Please donate

Access the Complete Video Course and Learn Quick Ansible by 200+ Practical Lessons
Follow me

Subscribe not to miss any new releases