diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples/zone-policy | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'examples/zone-policy')
| -rw-r--r-- | examples/zone-policy/group_vars/firewall.yml | 80 | ||||
| -rw-r--r-- | examples/zone-policy/inventory.yml | 13 | ||||
| -rw-r--r-- | examples/zone-policy/site.yml | 12 | ||||
| -rw-r--r-- | examples/zone-policy/topology.clab.yml | 40 | ||||
| -rw-r--r-- | examples/zone-policy/verify.yml | 9 |
5 files changed, 154 insertions, 0 deletions
diff --git a/examples/zone-policy/group_vars/firewall.yml b/examples/zone-policy/group_vars/firewall.yml new file mode 100644 index 0000000..13c0188 --- /dev/null +++ b/examples/zone-policy/group_vars/firewall.yml @@ -0,0 +1,80 @@ +--- +# Router on a stick, as on the docs page. The page trunks VLANs 10/20/30 on +# eth0; this example uses eth1 because containerlab reserves eth0 for +# management. +base_interfaces: + - {name: eth1, description: trunk} + - {name: eth1.10, description: WAN, addresses: [172.16.10.1/24, "2001:db8:0:9999::1/64"]} + - {name: eth1.20, description: LAN, addresses: [192.168.100.1/24, "2001:db8:0:aaaa::1/64"]} + - {name: eth1.30, description: DMZ, addresses: [192.168.200.1/24, "2001:db8:0:bbbb::1/64"]} + +zone_firewall_zones: + # mgmt exists only so Ansible keeps its SSH session in containerlab. On a real + # router follow the page: the admin console (192.168.100.10) reaches the router + # through the lan-local rule 800, so make sure that rule is in place first. + - {name: mgmt, interfaces: [eth0]} + - {name: wan, interfaces: [eth1.10]} + - {name: lan, interfaces: [eth1.20]} + - {name: dmz, interfaces: [eth1.30]} + - {name: local, local: true} + +zone_firewall_policies: + - {from: mgmt, to: local, default_action: accept} + - from: wan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}} + - {number: 200, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "80,443"}} + - {number: 500, protocol: tcp, destination: {address: 192.168.200.200, port: "25"}} + - {number: 500, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "25"}} + - {number: 600, protocol: tcp, destination: {address: 192.168.200.200, port: "53"}} + - {number: 600, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "53"}} + - from: dmz + to: local + rules: + - {number: 400, protocol: tcp, destination: {port: "123"}} + - {number: 600, protocol: tcp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: lan + to: local + rules: + - {number: 400, protocol: tcp, destination: {port: "123"}} + - {number: 600, protocol: tcp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {port: "22"}} + - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {port: "22"}} + - from: lan + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - {number: 800, protocol: tcp, destination: {port: "22"}} + - from: dmz + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - {number: 600, protocol: tcp_udp, destination: {port: "53"}} + - {number: 800, protocol: tcp, destination: {port: "22"}} + - from: local + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - from: local + to: dmz + rules: + - {number: 500, protocol: tcp, destination: {port: "25"}} + - {number: 600, protocol: tcp_udp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: local + to: lan + rules: + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: lan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {address: 192.168.200.200, port: "22"}} + - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {address: "2001:db8:0:bbbb::200", port: "22"}} + - {number: 900, protocol: tcp, destination: {port: "993"}} diff --git a/examples/zone-policy/inventory.yml b/examples/zone-policy/inventory.yml new file mode 100644 index 0000000..206412d --- /dev/null +++ b/examples/zone-policy/inventory.yml @@ -0,0 +1,13 @@ +--- +# docs.vyos.io/en/1.5/configexamples/zone-policy.html +all: + children: + firewall: + hosts: + fw1: + ansible_host: clab-zone-policy-fw1 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/zone-policy/site.yml b/examples/zone-policy/site.yml new file mode 100644 index 0000000..4d82cdf --- /dev/null +++ b/examples/zone-policy/site.yml @@ -0,0 +1,12 @@ +--- +- name: Zone-based firewall + hosts: firewall + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.zone_firewall + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/zone-policy/topology.clab.yml b/examples/zone-policy/topology.clab.yml new file mode 100644 index 0000000..63080d2 --- /dev/null +++ b/examples/zone-policy/topology.clab.yml @@ -0,0 +1,40 @@ +name: zone-policy +topology: + nodes: + fw1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + # one host per network on its own VLAN, behind a VLAN-aware bridge + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge vlan_filtering 1 + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set eth3 master br0 + - ip link set eth4 master br0 + - bridge vlan add dev eth1 vid 10 + - bridge vlan add dev eth1 vid 20 + - bridge vlan add dev eth1 vid 30 + - bridge vlan add dev eth2 vid 10 pvid untagged + - bridge vlan add dev eth3 vid 20 pvid untagged + - bridge vlan add dev eth4 vid 30 pvid untagged + - ip link set br0 up + wan: + kind: linux + image: alpine:3 + exec: ["ip addr add 172.16.10.100/24 dev eth1", "ip route replace default via 172.16.10.1"] + lan: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.100.10/24 dev eth1", "ip route replace default via 192.168.100.1"] + dmz: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.200.200/24 dev eth1", "ip route replace default via 192.168.200.1"] + links: + - endpoints: ["fw1:eth1", "sw:eth1"] + - endpoints: ["sw:eth2", "wan:eth1"] + - endpoints: ["sw:eth3", "lan:eth1"] + - endpoints: ["sw:eth4", "dmz:eth1"] diff --git a/examples/zone-policy/verify.yml b/examples/zone-policy/verify.yml new file mode 100644 index 0000000..3132524 --- /dev/null +++ b/examples/zone-policy/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the zone firewall + hosts: firewall + gather_facts: false + tasks: + - name: Zone checks + ansible.builtin.include_role: + name: vyos.blueprints.zone_firewall + tasks_from: verify |
