Skip to content
Toggle navigation
Projects
Groups
Snippets
Help
ansible
/
common-playbook
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Settings
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit e1be87dd
authored
Nov 24, 2017
by
ansible
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
edit syntax
1 parent
75a6cc4e
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
5 additions
and
5 deletions
hardening.yml
hardening.yml
View file @
e1be87d
...
@@ -2,7 +2,7 @@
...
@@ -2,7 +2,7 @@
-
hosts
:
new-host
-
hosts
:
new-host
become
:
true
become
:
true
tasks
:
tasks
:
-
name
:
Hardening Ubuntu OS
:
Disable IPv6
-
name
:
Hardening Ubuntu OS Disable IPv6
sysctl
:
sysctl
:
name
:
"
{{
item.parameter
}}"
name
:
"
{{
item.parameter
}}"
state
:
present
state
:
present
...
@@ -12,7 +12,7 @@
...
@@ -12,7 +12,7 @@
-
{
parameter
:
net.ipv6.conf.default.disable_ipv6
,
value
:
1
}
-
{
parameter
:
net.ipv6.conf.default.disable_ipv6
,
value
:
1
}
-
{
parameter
:
net.ipv6.conf.lo.disable_ipv6
,
value
:
1
}
-
{
parameter
:
net.ipv6.conf.lo.disable_ipv6
,
value
:
1
}
-
name
:
Hardening Ubuntu OS
:
IP Spoofing protection
-
name
:
Hardening Ubuntu OS IP Spoofing protection
sysctl
:
sysctl
:
name
:
"
{{
item.parameter
}}"
name
:
"
{{
item.parameter
}}"
state
:
present
state
:
present
...
@@ -21,7 +21,7 @@
...
@@ -21,7 +21,7 @@
-
{
parameter
:
net.ipv4.conf.all.rp_filter
,
value
:
1
}
-
{
parameter
:
net.ipv4.conf.all.rp_filter
,
value
:
1
}
-
{
parameter
:
net.ipv4.conf.default.rp_filter
,
value
:
1
}
-
{
parameter
:
net.ipv4.conf.default.rp_filter
,
value
:
1
}
-
name
:
Hardening Ubuntu OS
:
Block SYN attacks
-
name
:
Hardening Ubuntu OS Block SYN attacks
sysctl
:
sysctl
:
name
:
"
{{
item.parameter
}}"
name
:
"
{{
item.parameter
}}"
state
:
present
state
:
present
...
@@ -32,7 +32,7 @@
...
@@ -32,7 +32,7 @@
-
{
parameter
:
net.ipv4.tcp_synack_retries
,
value
:
2
}
-
{
parameter
:
net.ipv4.tcp_synack_retries
,
value
:
2
}
-
{
parameter
:
net.ipv4.tcp_syn_retries
,
value
:
5
}
-
{
parameter
:
net.ipv4.tcp_syn_retries
,
value
:
5
}
-
name
:
Hardening Ubuntu OS
:
Ignore send redirects
-
name
:
Hardening Ubuntu OS Ignore send redirects
sysctl
:
sysctl
:
name
:
"
{{
item.parameter
}}"
name
:
"
{{
item.parameter
}}"
state
:
present
state
:
present
...
@@ -41,7 +41,7 @@
...
@@ -41,7 +41,7 @@
-
{
parameter
:
net.ipv4.conf.all.send_redirects
,
value
:
0
}
-
{
parameter
:
net.ipv4.conf.all.send_redirects
,
value
:
0
}
-
{
parameter
:
net.ipv4.conf.default.send_redirects
,
value
:
0
}
-
{
parameter
:
net.ipv4.conf.default.send_redirects
,
value
:
0
}
-
name
:
Hardening Ubuntu OS
:
Log Martians
-
name
:
Hardening Ubuntu OS Log Martians
sysctl
:
sysctl
:
name
:
"
{{
item.parameter
}}"
name
:
"
{{
item.parameter
}}"
state
:
present
state
:
present
...
...
Write
Preview
Markdown
is supported
Attach a file
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to post a comment