[ntp_server] Update adm restriction for Cachan
Signed-off-by: Yohann D'ANELLO <ynerant@crans.org>certbot_on_virtu
							parent
							
								
									fee42cd5ea
								
							
						
					
					
						commit
						f6b2ff4804
					
				| 
						 | 
				
			
			@ -0,0 +1,4 @@
 | 
			
		|||
---
 | 
			
		||||
glob_ntp_server:
 | 
			
		||||
  adm_network: '172.16.10.0'
 | 
			
		||||
  adm_mask: '255.255.255.0'
 | 
			
		||||
| 
						 | 
				
			
			@ -4,6 +4,9 @@ interfaces:
 | 
			
		|||
  cachan_srv: eth1.2
 | 
			
		||||
  infra: eth0.111
 | 
			
		||||
 | 
			
		||||
loc_ntp_server:
 | 
			
		||||
  adm_network: '172.17.10.0'
 | 
			
		||||
 | 
			
		||||
loc_vsftpd:
 | 
			
		||||
  root: /pool/mirror/pub
 | 
			
		||||
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -3,5 +3,7 @@
 | 
			
		|||
# NTP client is in utilities.yml
 | 
			
		||||
 | 
			
		||||
- hosts: ntp_server
 | 
			
		||||
  vars:
 | 
			
		||||
    ntp_server: "{{ glob_ntp_server | default({}) | combine(loc_ntp_server | default({})) }}"
 | 
			
		||||
  roles:
 | 
			
		||||
    - ntp-server
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -44,7 +44,7 @@ restrict ::1
 | 
			
		|||
restrict source notrap nomodify noquery
 | 
			
		||||
 | 
			
		||||
# Server on adm can sync
 | 
			
		||||
restrict 172.16.10.0 mask 255.255.255.0 notrap nomodify
 | 
			
		||||
restrict {{ ntp_server.adm_network }} mask {{ ntp_server.adm_mask }} notrap nomodify
 | 
			
		||||
 | 
			
		||||
# Clients from this (example!) subnet have unlimited access, but only if
 | 
			
		||||
# cryptographically authenticated.
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue