Skip to content

Commit e475e9e

Browse files
committed
Firewall instructions
1 parent e21f771 commit e475e9e

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

README.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,15 @@ ansible-playbook -i hosts -b -K <name of playbook>.yml
6464
Before you run any of the commands below, make sure that you updated the file `group_vars/all.yml`
6565
and include the new/extra URLs of any server you want to change/add (e.g. add your Stratum 1).
6666

67+
### Firewalls
68+
To make all communication between the CVMFS services possible, some ports have to be opened on the Stratum 0 (default: port 80),
69+
Stratum 1 (default: port 80 and 8000), and local proxy (default: port 3128).
70+
These default port numbers are listed in `roles/cvmfs/defaults/main.yml`,but can be overridden elsewhere.
71+
72+
The Ansible playbook can update your firewall rules automatically (firewalld on Redhat systems, ufw on Debian systems),
73+
but by default it will not do this. If you want to enable this functionality, set `cvmfs_manage_firewall` to `true`.
74+
This can be done in either `group_vars/all.yml`, or in a vars section in your hosts or playbook file, or by passing
75+
`-e cvmfs_manage_firewall=true` to the `ansible-playbook` command.
6776

6877
### Stratum 0
6978
First install the Stratum 0 server:

0 commit comments

Comments
 (0)