Skip to content

Ansible playbooks

ansible windows firewall block all except

To block all Windows firewall traffic except specific exceptions using Ansible, you must add allow rules first before setting the default inbound and outbound actions to block. This order is critical because Windows firewall deny rules take precedence, but if the default action is set to block before allow rules are added, the connection may be lost or the allow rules may not apply as intended.

You can use the community.windows.win_firewall module to set the default action and the community.windows.win_firewall_rule module to create specific exceptions.

1. Enable Firewall and Set Default Block Action🔗

Use community.windows.win_firewall to ensure the firewall is enabled and set the default action for inbound and/or outbound traffic to block. Note that the inbound_action and outbound_action parameters were added in version 1.1.0 of the community.windows collection.

- name: Set Windows Firewall default action to block
  community.windows.win_firewall:
    state: enabled
    profiles:
      - Domain
      - Private
      - Public
    inbound_action: block
    outbound_action: block

2. Create Allow Rules for Exceptions🔗

Use community.windows.win_firewall_rule to create specific allow rules for the traffic you want to permit (e.g., SSH/RDP, HTTP). These rules should be defined before or in a separate play that runs before the default block is applied, or ensure the module handles idempotency correctly by allowing existing rules to persist.

- name: Allow RDP from specific IP
  community.windows.win_firewall_rule:
    name: "Allow RDP from Management"
    localport: 3389
    action: allow
    direction: in
    protocol: tcp
    remoteip: "10.0.100.50" # Replace with your management IP
    state: present
    enabled: yes
    profiles:
      - Domain
      - Private
      - Public

- name: Allow HTTP from anywhere
  community.windows.win_firewall_rule:
    name: "Allow HTTP"
    localport: 80
    action: allow
    direction: in
    protocol: tcp
    state: present
    enabled: yes
    profiles:
      - Domain
      - Private
      - Public

Important Considerations🔗

  • Idempotency and Order: If you are connecting remotely (e.g., via WinRM), setting the default action to block without prior allow rules for your management port will disconnect you. Always ensure the allow rule for your management port (e.g., WinRM port 5985/5986) is applied before blocking inbound traffic.
  • Module Collection: The community.windows.win_firewall module is part of the community.windows collection. Ensure it is installed (ansible-galaxy collection install community.windows).
  • Profiles: Specify the correct profiles (Domain, Private, Public) to ensure the rules apply to the correct network context.
  • GPO Conflicts: If Group Policy Objects (GPOs) are managing the firewall, Ansible settings might be overwritten on reboot. Use not_configured for actions if managing via GPO, or ensure Ansible runs after GPO application.