commit
7aa93d44bc
@ -1,5 +1,5 @@
|
|||||||
terraform {
|
terraform {
|
||||||
required_version = ">=0.15.0"
|
required_version = ">=1.0"
|
||||||
|
|
||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
terraform {
|
terraform {
|
||||||
required_version = ">=0.15.0"
|
required_version = ">=1.0"
|
||||||
|
|
||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
terraform {
|
terraform {
|
||||||
required_version = ">=0.15.0"
|
required_version = ">=1.0"
|
||||||
|
|
||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
|
@ -112,7 +112,7 @@ resource "azurerm_firewall_policy_rule_collection_group" "azure_firewall_rules_c
|
|||||||
firewall_policy_id = azurerm_firewall_policy.base_policy.id
|
firewall_policy_id = azurerm_firewall_policy.base_policy.id
|
||||||
priority = 100
|
priority = 100
|
||||||
|
|
||||||
application_rule_collection {
|
application_rule_collection {
|
||||||
name = "afwp-base-app-rule-collection"
|
name = "afwp-base-app-rule-collection"
|
||||||
priority = 200
|
priority = 200
|
||||||
action = "Allow"
|
action = "Allow"
|
||||||
@ -125,7 +125,7 @@ application_rule_collection {
|
|||||||
}
|
}
|
||||||
protocols {
|
protocols {
|
||||||
type = "Http"
|
type = "Http"
|
||||||
port= 80
|
port = 80
|
||||||
}
|
}
|
||||||
source_ip_groups = [azurerm_ip_group.ip_group_dsvm_subnet.id]
|
source_ip_groups = [azurerm_ip_group.ip_group_dsvm_subnet.id]
|
||||||
destination_fqdns = ["*"]
|
destination_fqdns = ["*"]
|
||||||
@ -148,7 +148,7 @@ application_rule_collection {
|
|||||||
port = 443
|
port = 443
|
||||||
}
|
}
|
||||||
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id]
|
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id]
|
||||||
destination_fqdns = ["api.snapcraft.io","motd.ubuntu.com",]
|
destination_fqdns = ["api.snapcraft.io", "motd.ubuntu.com", ]
|
||||||
}
|
}
|
||||||
|
|
||||||
rule {
|
rule {
|
||||||
@ -398,8 +398,8 @@ application_rule_collection {
|
|||||||
rule {
|
rule {
|
||||||
name = "hub-to-spoke-rule"
|
name = "hub-to-spoke-rule"
|
||||||
protocols = ["Any"]
|
protocols = ["Any"]
|
||||||
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id,azurerm_ip_group.ip_group_hub.id]
|
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id, azurerm_ip_group.ip_group_hub.id]
|
||||||
destination_ip_groups = [azurerm_ip_group.ip_group_hub.id,azurerm_ip_group.ip_group_spoke.id]
|
destination_ip_groups = [azurerm_ip_group.ip_group_hub.id, azurerm_ip_group.ip_group_spoke.id]
|
||||||
destination_ports = ["*"]
|
destination_ports = ["*"]
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -455,7 +455,7 @@ application_rule_collection {
|
|||||||
name = "Azure-Front-Door-Frontend"
|
name = "Azure-Front-Door-Frontend"
|
||||||
protocols = ["TCP"]
|
protocols = ["TCP"]
|
||||||
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id]
|
source_ip_groups = [azurerm_ip_group.ip_group_spoke.id]
|
||||||
destination_addresses = ["AzureFrontDoor.Frontend","AzureFrontDoor.FirstParty"]
|
destination_addresses = ["AzureFrontDoor.Frontend", "AzureFrontDoor.FirstParty"]
|
||||||
destination_ports = ["443"]
|
destination_ports = ["443"]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -51,7 +51,7 @@ resource "azurerm_network_security_group" "bastion_nsg" {
|
|||||||
access = "Allow"
|
access = "Allow"
|
||||||
protocol = "*"
|
protocol = "*"
|
||||||
source_port_range = "*"
|
source_port_range = "*"
|
||||||
destination_port_ranges = ["5701","8080"]
|
destination_port_ranges = ["5701", "8080"]
|
||||||
source_address_prefix = "VirtualNetwork"
|
source_address_prefix = "VirtualNetwork"
|
||||||
destination_address_prefix = "VirtualNetwork"
|
destination_address_prefix = "VirtualNetwork"
|
||||||
}
|
}
|
||||||
@ -98,7 +98,7 @@ resource "azurerm_network_security_group" "bastion_nsg" {
|
|||||||
destination_port_ranges = ["80"]
|
destination_port_ranges = ["80"]
|
||||||
source_address_prefix = "*"
|
source_address_prefix = "*"
|
||||||
destination_address_prefix = "Internet"
|
destination_address_prefix = "Internet"
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
terraform {
|
terraform {
|
||||||
required_version = ">=0.15.0"
|
required_version = ">=1.0"
|
||||||
|
|
||||||
required_providers {
|
required_providers {
|
||||||
azurerm = {
|
azurerm = {
|
||||||
|
Loading…
x
Reference in New Issue
Block a user