Ansible playbooks
ansible windows firewall block all except
To block all Windows firewall traffic except specific exceptions using Ansible, you must add allow rules first before setting the default inbound and outbound actions to block. This order is critical because Windows firewall deny rules take precedence, but if the default action is set to block before allow rules are added, the connection may be lost or the allow rules may not apply as intended.
You can use the community.windows.win_firewall module to set the default action and the community.windows.win_firewall_rule module to create specific exceptions.
1. Enable Firewall and Set Default Block Action🔗
Use community.windows.win_firewall to ensure the firewall is enabled and set the default action for inbound and/or outbound traffic to block. Note that the inbound_action and outbound_action parameters were added in version 1.1.0 of the community.windows collection.
- name: Set Windows Firewall default action to block
community.windows.win_firewall:
state: enabled
profiles:
- Domain
- Private
- Public
inbound_action: block
outbound_action: block
2. Create Allow Rules for Exceptions🔗
Use community.windows.win_firewall_rule to create specific allow rules for the traffic you want to permit (e.g., SSH/RDP, HTTP). These rules should be defined before or in a separate play that runs before the default block is applied, or ensure the module handles idempotency correctly by allowing existing rules to persist.
- name: Allow RDP from specific IP
community.windows.win_firewall_rule:
name: "Allow RDP from Management"
localport: 3389
action: allow
direction: in
protocol: tcp
remoteip: "10.0.100.50" # Replace with your management IP
state: present
enabled: yes
profiles:
- Domain
- Private
- Public
- name: Allow HTTP from anywhere
community.windows.win_firewall_rule:
name: "Allow HTTP"
localport: 80
action: allow
direction: in
protocol: tcp
state: present
enabled: yes
profiles:
- Domain
- Private
- Public
Important Considerations🔗
- Idempotency and Order: If you are connecting remotely (e.g., via WinRM), setting the default action to block without prior allow rules for your management port will disconnect you. Always ensure the allow rule for your management port (e.g., WinRM port 5985/5986) is applied before blocking inbound traffic.
- Module Collection: The
community.windows.win_firewallmodule is part of thecommunity.windowscollection. Ensure it is installed (ansible-galaxy collection install community.windows). - Profiles: Specify the correct profiles (
Domain,Private,Public) to ensure the rules apply to the correct network context. - GPO Conflicts: If Group Policy Objects (GPOs) are managing the firewall, Ansible settings might be overwritten on reboot. Use
not_configuredfor actions if managing via GPO, or ensure Ansible runs after GPO application.