--- - name: Handle DRBD ports iptables_raw: name: drbd_ports state: "{{ (drbd_src_ip | length > 0) | ternary('present','absent') }}" rules: "-A INPUT -m state --state NEW -p tcp --dport 7000:8000 -s {{ drbd_src_ip | join(',') }} -j ACCEPT" tags: firewall,drbd