summaryrefslogtreecommitdiff
path: root/examples/flexvpn-cisco
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples/flexvpn-cisco
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'examples/flexvpn-cisco')
-rw-r--r--examples/flexvpn-cisco/group_vars/spoke.yml44
-rw-r--r--examples/flexvpn-cisco/inventory.yml15
-rw-r--r--examples/flexvpn-cisco/site.yml12
-rw-r--r--examples/flexvpn-cisco/verify.yml13
4 files changed, 84 insertions, 0 deletions
diff --git a/examples/flexvpn-cisco/group_vars/spoke.yml b/examples/flexvpn-cisco/group_vars/spoke.yml
new file mode 100644
index 0000000..c0c5dd0
--- /dev/null
+++ b/examples/flexvpn-cisco/group_vars/spoke.yml
@@ -0,0 +1,44 @@
+---
+# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html - VyOS side
+gre_tunnel_interfaces:
+ - name: tun1
+ encapsulation: gre
+ adjust_mss: "1336"
+ mtu: 1376
+ remote: 10.1.1.6
+ source_address: 198.51.100.1
+
+ipsec_policy_based_peers:
+ - name: cisco_hub
+ psk_name: vyos_cisco_l
+ psk: secret # use ansible-vault for real devices
+ local_address: 198.51.100.1
+ remote_address: 10.1.1.6
+ local_id: vyos.net
+ remote_id: cisco.hub.net
+ connection_type: initiate
+ virtual_address: 0.0.0.0
+ tunnels:
+ - {id: 1, local_prefix: 198.51.100.1/32, remote_prefix: 10.1.1.6/32, protocol: gre}
+ipsec_policy_based_ike_group:
+ name: i1
+ key_exchange: ikev2
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 5
+ encryption: aes256
+ hash: sha256
+ipsec_policy_based_esp_group:
+ name: e1
+ lifetime: 3600
+ mode: tunnel
+ pfs: disable
+ proposal_id: 1
+ encryption: aes128
+ hash: sha256
+ipsec_policy_based_interfaces: [eth2] # WAN interface (198.51.100.1/24 on the page)
+ipsec_policy_based_options:
+ disable_route_autoinstall: true
+ flexvpn: true
+ interface: tun1
+ virtual_ip: true
diff --git a/examples/flexvpn-cisco/inventory.yml b/examples/flexvpn-cisco/inventory.yml
new file mode 100644
index 0000000..9368dca
--- /dev/null
+++ b/examples/flexvpn-cisco/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html
+# Only the VyOS spoke is configured here; the Cisco FlexVPN hub is configured
+# as shown on the page (there is no lab stand-in: VyOS cannot act as a FlexVPN hub).
+all:
+ children:
+ spoke:
+ hosts:
+ vyos:
+ ansible_host: 192.0.2.10 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/flexvpn-cisco/site.yml b/examples/flexvpn-cisco/site.yml
new file mode 100644
index 0000000..6204e3f
--- /dev/null
+++ b/examples/flexvpn-cisco/site.yml
@@ -0,0 +1,12 @@
+---
+- name: FlexVPN spoke - GRE over IPsec to a Cisco hub
+ hosts: spoke
+ gather_facts: false
+ roles:
+ - vyos.blueprints.gre_tunnel
+ - vyos.blueprints.ipsec_policy_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/flexvpn-cisco/verify.yml b/examples/flexvpn-cisco/verify.yml
new file mode 100644
index 0000000..e637db8
--- /dev/null
+++ b/examples/flexvpn-cisco/verify.yml
@@ -0,0 +1,13 @@
+---
+- name: Check the FlexVPN spoke
+ hosts: spoke
+ gather_facts: false
+ tasks:
+ - name: Tunnel interface checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.gre_tunnel
+ tasks_from: verify
+ - name: IPsec checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_policy_based
+ tasks_from: verify