- additional AP config - fw rules

This commit is contained in:
Pi
2019-08-08 10:36:06 -04:00
parent 81592c1288
commit a7eaa63577
3 changed files with 28 additions and 32 deletions

View File

@@ -1,7 +1,7 @@
interface=wlan0 interface=wlan0
dhcp-range=10.250.250.2,10.250.250.6,255.255.255.248,24h dhcp-range=10.250.250.2,10.250.250.6,255.255.255.248,24h
listen-address=10.250.250.1 listen-address=10.250.250.1
bind-interfaces #bind-interfaces
server=8.8.8.8 server=8.8.8.8
bogus-priv bogus-priv
domain=demo.dsfinancial.com domain=demo.dsfinancial.com

View File

@@ -65,32 +65,28 @@
masked: no masked: no
state: restarted state: restarted
tags: wireless_ap tags: wireless_ap
- name: enable ipv4.forwarding - name: lan to wlan
become: true iptables:
sysctl: chain: FORWARD
name: net.ipv4.ip_forward ctstate: ESTABLISHED,RELATED
value: 1 jump: ACCEPT
sysctl_set: yes in_interface: eth0
state: present out_interface: wlan0
reload: yes become: yes
tags: wireless_ap - name: wlan to lan
- name: copy fw config iptables:
become: true chain: FORWARD
copy: jump: ACCEPT
src: "{{ role_path }}/files/iptables.ipv4.nat" in_interface: wlan0
dest: "/etc/iptables.ipv4.nat" out_interface: eth0
backup: yes become: yes
owner: root - name: forwarding
group: root iptables:
tags: wireless_ap chain: POSTROUTING
- name: iptables-restore to rc.local out_interface: eth0
lineinfile: table: nat
path: "/etc/rc.local" jump: MASQUERADE
state: present become: yes
insertbefore: "exit 0"
line: "iptables-restore < /etc/iptables.ipv4.nat"
become: true
tags: wireless_ap
- name: restart dhcpcd - name: restart dhcpcd
become: true become: true
systemd: systemd:

View File

@@ -1,6 +1,6 @@
#!/bin/bash #!/bin/bash
/usr/bin/killall chromium-browser sudo /usr/bin/killall chromium-browser
/usr/bin/killall chromium-browser sudo /usr/bin/killall chromium-browser
/usr/bin/killall chromium-browser sudo /usr/bin/killall chromium-browser
systemctl restart ntopng sudo systemctl restart ntopng