diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples/vrf-firewall/topology.clab.yml | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'examples/vrf-firewall/topology.clab.yml')
| -rw-r--r-- | examples/vrf-firewall/topology.clab.yml | 43 |
1 files changed, 43 insertions, 0 deletions
diff --git a/examples/vrf-firewall/topology.clab.yml b/examples/vrf-firewall/topology.clab.yml new file mode 100644 index 0000000..0612a1f --- /dev/null +++ b/examples/vrf-firewall/topology.clab.yml @@ -0,0 +1,43 @@ +name: vrf-firewall +topology: + nodes: + r1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + mgmt: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.100.100.10/24 dev eth1", "ip route replace default via 10.100.100.1"] + # VLAN-aware bridge for the eth2 trunk (vif 150 = LAN, vif 3500 = PROD) + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge vlan_filtering 1 + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set eth3 master br0 + - bridge vlan add dev eth1 vid 150 + - bridge vlan add dev eth1 vid 3500 + - bridge vlan add dev eth2 vid 150 pvid untagged + - bridge vlan add dev eth3 vid 3500 pvid untagged + - ip link set br0 up + lan: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.150.150.10/24 dev eth1", "ip route replace default via 10.150.150.1"] + prod: + kind: linux + image: alpine:3 + exec: ["ip addr add 172.16.20.10/24 dev eth1", "ip route replace default via 172.16.20.1"] + # stands in for the page's PPPoE uplink + wan: + kind: linux + image: alpine:3 + exec: ["ip addr add 203.0.113.100/24 dev eth1", "ip route replace default via 203.0.113.1"] + links: + - endpoints: ["r1:eth1", "mgmt:eth1"] + - endpoints: ["r1:eth2", "sw:eth1"] + - endpoints: ["sw:eth2", "lan:eth1"] + - endpoints: ["sw:eth3", "prod:eth1"] + - endpoints: ["r1:eth3", "wan:eth1"] |
