1 - name: Install fail2ban and nftables
6 name: ['fail2ban', 'nftables']
9 notify: Restart firewall
11 - name: "Change /etc/fail2ban/jail.conf (iptables -> nftables)"
14 path: /etc/fail2ban/jail.conf
15 regexp: '^banaction = iptables-multiport$'
16 line: 'banaction = nftables-multiport'
17 notify: Restart firewall
20 path: /etc/fail2ban/jail.conf
21 regexp: '^banaction = iptables-multiport-log$'
22 line: 'banaction = nftables-multiport'
23 notify: Restart firewall
26 path: /etc/fail2ban/jail.conf
27 regexp: '^banaction_allports = iptables-allports$'
28 line: 'banaction_allports = nftables-allports'
29 notify: Restart firewall
31 - name: Configure Debian firewall
38 directory_mode: '0750'
41 notify: Restart firewall
43 - name: Fix permissions for /etc/network/functions
46 path: /etc/network/functions.phd
48 notify: Restart firewall
50 - name: Remove iptables leftovers
53 path: /etc/init.d/iptables.sh