From 5a964c9cbd3c83d1dcfe50ce99e9dcd0a8120c9a Mon Sep 17 00:00:00 2001
From: Jason DeTiberus <jdetiber@redhat.com>
Date: Tue, 5 Jan 2016 16:10:32 -0500
Subject: Add ability to disable os_firewall

---
 roles/os_firewall/defaults/main.yml | 1 +
 roles/os_firewall/tasks/main.yml    | 4 ++--
 2 files changed, 3 insertions(+), 2 deletions(-)

(limited to 'roles/os_firewall')

diff --git a/roles/os_firewall/defaults/main.yml b/roles/os_firewall/defaults/main.yml
index bcf1d9a34..e3176e611 100644
--- a/roles/os_firewall/defaults/main.yml
+++ b/roles/os_firewall/defaults/main.yml
@@ -1,2 +1,3 @@
 ---
+os_firewall_enabled: True
 os_firewall_use_firewalld: True
diff --git a/roles/os_firewall/tasks/main.yml b/roles/os_firewall/tasks/main.yml
index ad89ef97c..076e5e311 100644
--- a/roles/os_firewall/tasks/main.yml
+++ b/roles/os_firewall/tasks/main.yml
@@ -1,6 +1,6 @@
 ---
 - include: firewall/firewalld.yml
-  when: os_firewall_use_firewalld
+  when: os_firewall_enabled | bool and os_firewall_use_firewalld | bool
 
 - include: firewall/iptables.yml
-  when: not os_firewall_use_firewalld
+  when: os_firewall_enabled | bool and not os_firewall_use_firewalld | bool
-- 
cgit v1.2.3