diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples/policy-ipsec-firewall | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'examples/policy-ipsec-firewall')
| -rw-r--r-- | examples/policy-ipsec-firewall/group_vars/sites.yml | 5 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/host_vars/left.yml | 98 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/host_vars/right.yml | 23 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/inventory.yml | 15 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/site.yml | 15 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/topology.clab.yml | 51 | ||||
| -rw-r--r-- | examples/policy-ipsec-firewall/verify.yml | 22 |
7 files changed, 229 insertions, 0 deletions
diff --git a/examples/policy-ipsec-firewall/group_vars/sites.yml b/examples/policy-ipsec-firewall/group_vars/sites.yml new file mode 100644 index 0000000..72cb49a --- /dev/null +++ b/examples/policy-ipsec-firewall/group_vars/sites.yml @@ -0,0 +1,5 @@ +--- +# IPsec settings shared by both routers, as on the page +ipsec_policy_based_ike_group: {name: IKE-GROUP, key_exchange: ikev2, proposal_id: 1, dh_group: 14, encryption: aes256, hash: sha256} +ipsec_policy_based_esp_group: {name: ESP-GROUP, mode: tunnel, proposal_id: 1, encryption: aes256, hash: sha256} +ipsec_policy_based_interfaces: [eth3] diff --git a/examples/policy-ipsec-firewall/host_vars/left.yml b/examples/policy-ipsec-firewall/host_vars/left.yml new file mode 100644 index 0000000..e6fe1ee --- /dev/null +++ b/examples/policy-ipsec-firewall/host_vars/left.yml @@ -0,0 +1,98 @@ +--- +# WAN is eth3 here, eth0 on the page (containerlab uses eth0 for management). +# Input rule 5 keeps containerlab management reachable - drop it on a real router +# and make sure your management source is allowed (rule 20, TRUSTED) instead. +ipsec_policy_based_peers: + - name: RIGHT + psk_name: RIGHT + psk: p4ssw0rd # use ansible-vault for real devices + authentication_ids: false + local_address: 198.51.100.14 + remote_address: 192.0.2.130 + connection_type: initiate + tunnels: + - {id: 0, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.21.0/24} + - {id: 1, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.22.0/24} + - {id: 2, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.21.0/24} + - {id: 3, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.22.0/24} +ipsec_policy_based_default_gateway: 198.51.100.13 +firewall_groups: + network: + - name: LOCAL-NETS + networks: [10.1.11.0/24, 10.1.12.0/24] + - name: REMOTE-NETS + networks: [10.2.21.0/24, 10.2.22.0/24] + - name: TRUSTED + networks: [198.51.100.125/32, 203.0.113.0/24, 10.1.11.0/24, 192.168.70.0/24] +firewall_ipv4: + forward: + default_action: drop + rules: + - number: 1 + action: accept + state: {established: true, related: true} + - number: 2 + action: drop + state: {invalid: true} + - number: 10 + action: accept + source: + group: {network_group: LOCAL-NETS} + - number: 20 + action: accept + source: + group: {network_group: REMOTE-NETS} + destination: + group: {network_group: LOCAL-NETS} + input: + default_action: drop + rules: + - number: 1 + action: accept + state: {established: true, related: true} + - number: 2 + action: drop + state: {invalid: true} + - number: 5 + action: accept + description: containerlab management + inbound_interface: {name: eth0} + - number: 10 + action: accept + protocol: udp + destination: {port: '500,4500'} + inbound_interface: {name: eth3} + - number: 15 + action: accept + protocol: esp + inbound_interface: {name: eth3} + - number: 20 + action: accept + protocol: tcp + destination: {port: '22'} + source: + group: {network_group: TRUSTED} + - number: 25 + action: accept + protocol: udp + destination: {port: '53'} + source: + group: {network_group: LOCAL-NETS} + - {number: 30, action: accept, protocol: icmp} +nat_source_rules: + - id: 10 + exclude: true + outbound_interface: {name: eth3} + source: {network_group: LOCAL-NETS} + destination: {network_group: REMOTE-NETS} + - id: 20 + outbound_interface: {name: eth3} + source: {network_group: LOCAL-NETS} + translation: {address: masquerade} +base_interfaces: + - name: eth3 + addresses: [198.51.100.14/30] + - name: eth1.111 + addresses: [10.1.11.1/24] + - name: eth2.112 + addresses: [10.1.12.1/24] diff --git a/examples/policy-ipsec-firewall/host_vars/right.yml b/examples/policy-ipsec-firewall/host_vars/right.yml new file mode 100644 index 0000000..ab629da --- /dev/null +++ b/examples/policy-ipsec-firewall/host_vars/right.yml @@ -0,0 +1,23 @@ +--- +# The page sets no default route on RIGHT; it needs one to reach LEFT. +ipsec_policy_based_peers: + - name: LEFT + psk_name: LEFT + psk: p4ssw0rd # use ansible-vault for real devices + authentication_ids: false + local_address: 192.0.2.130 + remote_address: 198.51.100.14 + connection_type: none + tunnels: + - {id: 0, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.11.0/24} + - {id: 1, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.11.0/24} + - {id: 2, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.12.0/24} + - {id: 3, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.12.0/24} +base_interfaces: + - name: eth3 + addresses: [192.0.2.130/30] + - name: eth1.221 + addresses: [10.2.21.1/24] + - name: eth2.222 + addresses: [10.2.22.1/24] +ipsec_policy_based_default_gateway: 192.0.2.129 diff --git a/examples/policy-ipsec-firewall/inventory.yml b/examples/policy-ipsec-firewall/inventory.yml new file mode 100644 index 0000000..95eeddb --- /dev/null +++ b/examples/policy-ipsec-firewall/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html +all: + children: + sites: + hosts: + left: + ansible_host: clab-policy-ipsec-firewall-left # your router's address + right: + ansible_host: clab-policy-ipsec-firewall-right + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/policy-ipsec-firewall/site.yml b/examples/policy-ipsec-firewall/site.yml new file mode 100644 index 0000000..87ea9a5 --- /dev/null +++ b/examples/policy-ipsec-firewall/site.yml @@ -0,0 +1,15 @@ +--- +- name: Policy-based IPsec with firewall and NAT + hosts: sites + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ipsec_policy_based + # firewall and nat only have inputs on LEFT, as on the page; on RIGHT they do nothing + - vyos.blueprints.firewall + - vyos.blueprints.nat + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/policy-ipsec-firewall/topology.clab.yml b/examples/policy-ipsec-firewall/topology.clab.yml new file mode 100644 index 0000000..e512c9c --- /dev/null +++ b/examples/policy-ipsec-firewall/topology.clab.yml @@ -0,0 +1,51 @@ +name: policy-ipsec-firewall +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + left: + kind: vyosnetworks_vyos + right: + kind: vyosnetworks_vyos + isp: + kind: linux + image: alpine:3 + exec: + - sysctl -w net.ipv4.ip_forward=1 + - ip addr add 198.51.100.13/30 dev eth1 + - ip addr add 192.0.2.129/30 dev eth2 + - ip addr add 203.0.113.1/24 dev eth3 + internet: + kind: linux + image: alpine:3 + exec: ["ip addr add 203.0.113.10/24 dev eth1", "ip route replace default via 203.0.113.1"] + l11: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.111 type vlan id 111", "ip link set eth1.111 up", + "ip addr add 10.1.11.10/24 dev eth1.111", "ip route replace default via 10.1.11.1"] + l12: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.112 type vlan id 112", "ip link set eth1.112 up", + "ip addr add 10.1.12.10/24 dev eth1.112", "ip route replace default via 10.1.12.1"] + r21: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.221 type vlan id 221", "ip link set eth1.221 up", + "ip addr add 10.2.21.10/24 dev eth1.221", "ip route replace default via 10.2.21.1"] + r22: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.222 type vlan id 222", "ip link set eth1.222 up", + "ip addr add 10.2.22.10/24 dev eth1.222", "ip route replace default via 10.2.22.1"] + links: + # WAN is eth3 here (eth0 on the page; eth0 is containerlab management) + - endpoints: ["left:eth3", "isp:eth1"] + - endpoints: ["right:eth3", "isp:eth2"] + - endpoints: ["isp:eth3", "internet:eth1"] + - endpoints: ["left:eth1", "l11:eth1"] + - endpoints: ["left:eth2", "l12:eth1"] + - endpoints: ["right:eth1", "r21:eth1"] + - endpoints: ["right:eth2", "r22:eth1"] diff --git a/examples/policy-ipsec-firewall/verify.yml b/examples/policy-ipsec-firewall/verify.yml new file mode 100644 index 0000000..d1006cf --- /dev/null +++ b/examples/policy-ipsec-firewall/verify.yml @@ -0,0 +1,22 @@ +--- +- name: Check both sites + hosts: sites + gather_facts: false + tasks: + - name: IPsec checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_policy_based + tasks_from: verify + +- name: Check firewall and NAT on LEFT + hosts: left + gather_facts: false + tasks: + - name: Firewall checks + ansible.builtin.include_role: + name: vyos.blueprints.firewall + tasks_from: verify + - name: NAT checks + ansible.builtin.include_role: + name: vyos.blueprints.nat + tasks_from: verify |
