This Ansible role enables IP forwarding and configures NAT using iptables.
- An Ubuntu-based system (tested on Ubuntu).
- Ansible installed.
vpc_network_prefixesvariable defined with one or more VPC network addresses.
vpc_network_prefixes: A list of VPC network addresses to NAT (e.g.,["10.0.0.0/24"]). The role configures a masquerade rule for each entry.
This role has no dependencies.
- hosts: your_hosts
become: true
vars:
vpc_network_prefixes: # replace with your VPC network(s)
- "10.0.0.0/24"
roles:
- brett-buskirk.ip_forwardingYou can install this role using Ansible Galaxy:
ansible-galaxy install brett-buskirk.ip_forwardingOr you can include it in your requirements.yml file:
---
roles:
- name: brett-buskirk.ip_forwarding
src: https://github.com/brett-buskirk/ansible-role-ip_forwarding
version: main # or a specific tagThen install it using:
ansible-galaxy install -r requirements.ymlThis role performs the following tasks:
- Install
iptables-persistent: Installs theiptables-persistentpackage to save iptables rules across reboots. - Enable IP Forwarding: Enables IP forwarding by setting
net.ipv4.ip_forwardto 1 insysctl. - Persist IP Forwarding: Uncomment the
net.ipv4.ip_forwardline in/etc/sysctl.confto make the IP forwarding change permanent. - Configure NAT (Network Address Translation): Configures iptables to perform NAT for traffic originating from the specified VPC networks (
vpc_network_prefixes) to the public interface (eth0). - Persist NAT Configuration: Saves the iptables rules to
/etc/iptables/rules.v4to ensure the NAT configuration persists across reboots.
Include the role in your playbook as shown in the "Example Playbook" section. The role will automatically install the necessary packages on the target host.
MIT
This role was created by Brett Buskirk.
networking, iptables, nat, ip_forwarding