- name: Gather the package facts
package_facts:
manager: auto
tags:
- PCI-DSSv4-1.2
- PCI-DSSv4-1.2.1 - disable_strategy
- low_complexity
- low_disruption
- medium_severity
- no_reboot_needed
- service_nftables_disabled
- name: Verify nftables Service is Disabled - Collect systemd Services Present in
the System
ansible.builtin.command: systemctl -q list-unit-files --type service
register: service_exists
changed_when: false
failed_when: service_exists.rc not in [0, 1]
check_mode: false
when: ( "firewalld" in ansible_facts.packages and "nftables" in ansible_facts.packages
and "kernel" in ansible_facts.packages )
tags:
- PCI-DSSv4-1.2
- PCI-DSSv4-1.2.1
- disable_strategy
- low_complexity
- low_disruption
- medium_severity
- no_reboot_needed
- service_nftables_disabled
- name: Verify nftables Service is Disabled - Ensure nftables.service is Masked
ansible.builtin.systemd:
name: nftables.service
state: stopped
enabled: false
masked: true
when:
- ( "firewalld" in ansible_facts.packages and "nftables" in ansible_facts.packages
and "kernel" in ansible_facts.packages )
- service_exists.stdout_lines is search("nftables.service", multiline=True)
tags:
- PCI-DSSv4-1.2
- PCI-DSSv4-1.2.1
- disable_strategy
- low_complexity
- low_disruption
- medium_severity
- no_reboot_needed
- service_nftables_disabled
- name: Unit Socket Exists - nftables.socket
ansible.builtin.command: systemctl -q list-unit-files nftables.socket
register: socket_file_exists
changed_when: false
failed_when: socket_file_exists.rc not in [0, 1]
check_mode: false
when: ( "firewalld" in ansible_facts.packages and "nftables" in ansible_facts.packages
and "kernel" in ansible_facts.packages )
tags:
- PCI-DSSv4-1.2
- PCI-DSSv4-1.2.1
- disable_strategy
- low_complexity
- low_disruption
- medium_severity
- no_reboot_needed
- service_nftables_disabled
- name: Verify nftables Service is Disabled - Disable Socket nftables
ansible.builtin.systemd:
name: nftables.socket
enabled: false
state: stopped
masked: true
when:
- ( "firewalld" in ansible_facts.packages and "nftables" in ansible_facts.packages
and "kernel" in ansible_facts.packages )
- socket_file_exists.stdout_lines is search("nftables.socket", multiline=True)
tags:
- PCI-DSSv4-1.2
- PCI-DSSv4-1.2.1
- disable_strategy
- low_complexity
- low_disruption
- medium_severity
- no_reboot_needed
- service_nftables_disabled
Show more