diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'examples')
56 files changed, 1220 insertions, 1 deletions
diff --git a/examples/README.md b/examples/README.md index 449efe4..8c149d5 100644 --- a/examples/README.md +++ b/examples/README.md @@ -6,8 +6,19 @@ Each directory is a complete, runnable Ansible project: |---|---|---| | `single-edge/` | `base`, `edge_nat` | – (small-office internet edge) | | `ha-pair/` | `base`, `ha_vrrp` | [High Availability Walkthrough](https://docs.vyos.io/en/1.5/configexamples/ha.html) | +| `ospf-unnumbered/` | `base`, `ospf_unnumbered` | [OSPF unnumbered with ECMP](https://docs.vyos.io/en/1.5/configexamples/ospf-unnumbered.html) | +| `bgp-unnumbered/` | `bgp_unnumbered` | [BGP IPv6 unnumbered with extended nexthop](https://docs.vyos.io/en/1.5/configexamples/bgp-ipv6-unnumbered.html) | +| `zone-policy/` | `base`, `zone_firewall` | [Zone-Policy example](https://docs.vyos.io/en/1.5/configexamples/zone-policy.html) | +| `vrf-firewall/` | `base`, `vrf_firewall` | [VRF and firewall example](https://docs.vyos.io/en/1.5/configexamples/fwall-and-vrf.html) | +| `bridge-firewall/` | `base`, `bridge_firewall` | [Bridge and firewall example](https://docs.vyos.io/en/1.5/configexamples/fwall-and-bridge.html) | +| `ipsec-route-based/` | `base`, `ipsec_route_based` | [Route-based ... VyOS and Cisco](https://docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html); for [Route-based ... VyOS and Palo Alto](https://docs.vyos.io/en/1.5/configexamples/ipsec-pa-route-based.html) rename the peer `CISCO` to `PA` - the VyOS side is otherwise identical | +| `ipsec-policy-based/` | `base`, `ipsec_policy_based` | [Policy-based Site-to-Site VPN IPsec between VyOS and Cisco](https://docs.vyos.io/en/1.5/configexamples/ipsec-cisco-policy-based.html) | +| `policy-ipsec-firewall/` | `base`, `ipsec_policy_based`, `firewall`, `nat` | [Policy-Based Site-to-Site VPN and Firewall Configuration](https://docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html) | +| `flexvpn-cisco/` | `gre_tunnel`, `ipsec_policy_based` | [Site-to-Site IPSec VPN to Cisco using FlexVPN](https://docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html) (no containerlab topology: needs a Cisco FlexVPN hub) | +| `azure-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html) (no containerlab topology: the far end is Azure) | +| `azure-vpn-dual-bgp/` | `ipsec_route_based` | [Route-Based Redundant Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html) (no containerlab topology: the far end is Azure) | -Every example ships a `topology.clab.yml`, so you can try it against +Most examples ship a `topology.clab.yml`, so you can try them against containerized VyOS before pointing it at real routers: ```bash diff --git a/examples/azure-vpn-bgp/group_vars/onprem.yml b/examples/azure-vpn-bgp/group_vars/onprem.yml new file mode 100644 index 0000000..fdada7a --- /dev/null +++ b/examples/azure-vpn-bgp/group_vars/onprem.yml @@ -0,0 +1,45 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html +ipsec_route_based_peers: + - name: 203.0.113.2 + description: AZURE PRIMARY TUNNEL + psk_name: azure + psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices + local_address: 10.10.0.5 # private IP; the device is behind NAT + local_id: 198.51.100.3 # public IP + remote_address: 203.0.113.2 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Tunnel, adjust_mss: "1350"} +ipsec_route_based_ike_group: + name: AZURE + key_exchange: ikev2 + ikev2_reauth: true + lifetime: 28800 + proposal_id: 1 + dh_group: 2 + encryption: aes256 + hash: sha1 + dead_peer_detection: {action: restart, interval: 15, timeout: 30} +ipsec_route_based_esp_group: + name: AZURE + lifetime: 3600 + mode: tunnel + pfs: dh-group2 + proposal_id: 1 + encryption: aes256 + hash: sha1 +ipsec_route_based_interfaces: [eth0] +ipsec_route_based_disable_route_autoinstall: false # the page does not set it +ipsec_route_based_interface_routes: + - {dest: 10.0.0.4/32, interface: vti1} +ipsec_route_based_bgp: + asn: 64499 + neighbors: + - address: 10.0.0.4 + remote_as: 65540 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true diff --git a/examples/azure-vpn-bgp/inventory.yml b/examples/azure-vpn-bgp/inventory.yml new file mode 100644 index 0000000..787a66e --- /dev/null +++ b/examples/azure-vpn-bgp/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html +# Only the VyOS side is configured here; the Azure VNet gateway, local network +# gateway and connection are created in Azure as the page's prerequisites describe. +all: + children: + onprem: + hosts: + vyos: + ansible_host: 192.0.2.10 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/azure-vpn-bgp/site.yml b/examples/azure-vpn-bgp/site.yml new file mode 100644 index 0000000..8d27036 --- /dev/null +++ b/examples/azure-vpn-bgp/site.yml @@ -0,0 +1,11 @@ +--- +- name: Route-based VPN to Azure with BGP + hosts: onprem + gather_facts: false + roles: + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/azure-vpn-bgp/verify.yml b/examples/azure-vpn-bgp/verify.yml new file mode 100644 index 0000000..fb4e633 --- /dev/null +++ b/examples/azure-vpn-bgp/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the Azure VPN + hosts: onprem + gather_facts: false + tasks: + - name: IPsec and BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify diff --git a/examples/azure-vpn-dual-bgp/group_vars/onprem.yml b/examples/azure-vpn-dual-bgp/group_vars/onprem.yml new file mode 100644 index 0000000..7f0f1ba --- /dev/null +++ b/examples/azure-vpn-dual-bgp/group_vars/onprem.yml @@ -0,0 +1,64 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html +# Both peers share the PSK entry "azure" (one entry, three ids), as on the page. +ipsec_route_based_peers: + - name: azure-primary + description: AZURE PRIMARY TUNNEL + psk_name: azure + psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices + local_address: 10.10.0.5 # private IP; the device is behind NAT + local_id: 198.51.100.3 # public IP + remote_address: 203.0.113.2 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Primary Tunnel, adjust_mss: "1350"} + - name: azure-secondary + description: AZURE secondary TUNNEL + psk_name: azure + psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices + local_address: 10.10.0.5 + local_id: 198.51.100.3 + remote_address: 203.0.113.3 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti2, address: 10.10.1.6/32, description: Azure Secondary Tunnel, adjust_mss: "1350"} +ipsec_route_based_ike_group: + name: AZURE + key_exchange: ikev2 + ikev2_reauth: true + lifetime: 28800 + proposal_id: 1 + dh_group: 2 + encryption: aes256 + hash: sha1 + dead_peer_detection: {action: restart, interval: 15, timeout: 30} +ipsec_route_based_esp_group: + name: AZURE + lifetime: 3600 + mode: tunnel + pfs: dh-group2 + proposal_id: 1 + encryption: aes256 + hash: sha1 +ipsec_route_based_interfaces: [eth0] +ipsec_route_based_disable_route_autoinstall: false # the page does not set it +ipsec_route_based_interface_routes: + - {dest: 10.0.0.4/32, interface: vti1} + - {dest: 10.0.0.5/32, interface: vti2} +ipsec_route_based_bgp: + asn: 64499 + neighbors: + - address: 10.0.0.4 + remote_as: 65540 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true + - address: 10.0.0.5 + remote_as: 65540 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true diff --git a/examples/azure-vpn-dual-bgp/inventory.yml b/examples/azure-vpn-dual-bgp/inventory.yml new file mode 100644 index 0000000..1d4f699 --- /dev/null +++ b/examples/azure-vpn-dual-bgp/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html +# Only the VyOS side is configured here; the Azure VNet gateway, local network +# gateway and connection are created in Azure as the page's prerequisites describe. +all: + children: + onprem: + hosts: + vyos: + ansible_host: 192.0.2.10 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/azure-vpn-dual-bgp/site.yml b/examples/azure-vpn-dual-bgp/site.yml new file mode 100644 index 0000000..651bf93 --- /dev/null +++ b/examples/azure-vpn-dual-bgp/site.yml @@ -0,0 +1,11 @@ +--- +- name: Redundant route-based VPN to Azure with BGP + hosts: onprem + gather_facts: false + roles: + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/azure-vpn-dual-bgp/verify.yml b/examples/azure-vpn-dual-bgp/verify.yml new file mode 100644 index 0000000..ef02155 --- /dev/null +++ b/examples/azure-vpn-dual-bgp/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check both Azure tunnels + hosts: onprem + gather_facts: false + tasks: + - name: IPsec and BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify diff --git a/examples/bgp-unnumbered/group_vars/fabric.yml b/examples/bgp-unnumbered/group_vars/fabric.yml new file mode 100644 index 0000000..34617ff --- /dev/null +++ b/examples/bgp-unnumbered/group_vars/fabric.yml @@ -0,0 +1,3 @@ +--- +bgp_unnumbered_interfaces: [eth1, eth2] +bgp_unnumbered_group: fabric diff --git a/examples/bgp-unnumbered/host_vars/routerA.yml b/examples/bgp-unnumbered/host_vars/routerA.yml new file mode 100644 index 0000000..e538109 --- /dev/null +++ b/examples/bgp-unnumbered/host_vars/routerA.yml @@ -0,0 +1,3 @@ +--- +bgp_unnumbered_asn: 64496 +bgp_unnumbered_router_id: 192.168.0.1 diff --git a/examples/bgp-unnumbered/host_vars/routerB.yml b/examples/bgp-unnumbered/host_vars/routerB.yml new file mode 100644 index 0000000..e9e9e62 --- /dev/null +++ b/examples/bgp-unnumbered/host_vars/routerB.yml @@ -0,0 +1,3 @@ +--- +bgp_unnumbered_asn: 64499 +bgp_unnumbered_router_id: 192.168.0.2 diff --git a/examples/bgp-unnumbered/inventory.yml b/examples/bgp-unnumbered/inventory.yml new file mode 100644 index 0000000..30bdaba --- /dev/null +++ b/examples/bgp-unnumbered/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/bgp-ipv6-unnumbered.html +all: + children: + fabric: + hosts: + routerA: + ansible_host: clab-bgp-unnumbered-routerA # your router's address + routerB: + ansible_host: clab-bgp-unnumbered-routerB + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/bgp-unnumbered/site.yml b/examples/bgp-unnumbered/site.yml new file mode 100644 index 0000000..a314bc9 --- /dev/null +++ b/examples/bgp-unnumbered/site.yml @@ -0,0 +1,11 @@ +--- +- name: BGP IPv6 unnumbered with extended next-hop + hosts: fabric + gather_facts: false + roles: + - vyos.blueprints.bgp_unnumbered + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/bgp-unnumbered/topology.clab.yml b/examples/bgp-unnumbered/topology.clab.yml new file mode 100644 index 0000000..004cd54 --- /dev/null +++ b/examples/bgp-unnumbered/topology.clab.yml @@ -0,0 +1,13 @@ +name: bgp-unnumbered +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + routerA: + kind: vyosnetworks_vyos + routerB: + kind: vyosnetworks_vyos + links: + - endpoints: ["routerA:eth1", "routerB:eth1"] + - endpoints: ["routerA:eth2", "routerB:eth2"] diff --git a/examples/bgp-unnumbered/verify.yml b/examples/bgp-unnumbered/verify.yml new file mode 100644 index 0000000..07004ac --- /dev/null +++ b/examples/bgp-unnumbered/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the BGP fabric + hosts: fabric + gather_facts: false + tasks: + - name: BGP checks (all routers in one play for the route checks) + ansible.builtin.include_role: + name: vyos.blueprints.bgp_unnumbered + tasks_from: verify diff --git a/examples/bridge-firewall/group_vars/bridge.yml b/examples/bridge-firewall/group_vars/bridge.yml new file mode 100644 index 0000000..a72e386 --- /dev/null +++ b/examples/bridge-firewall/group_vars/bridge.yml @@ -0,0 +1,85 @@ +--- +# The page's internet uplink is eth0; this example uses eth8 because +# containerlab reserves eth0 for management. Use eth0 on a real router. +base_interfaces: + - {name: eth8, addresses: [203.0.113.1/24]} + +bridge_firewall_bridges: + - name: br0 + description: Isolated L2 bridge + members: + - {interface: eth1, description: br0} + - {interface: eth2, description: br0} + prerouting: + default_action: drop + rules: + - {number: 10, description: Accept IPv6 traffic, ethernet_type: ipv6} + forward: + default_action: accept + + - name: br1 + description: L3 bridge br1 + addresses: [10.1.1.1/24] + members: + - {interface: eth3, description: br1} + - {interface: eth4, description: br1} + prerouting: + default_action: accept + rules: + - number: 10 + description: Drop DHCP discover + action: drop + protocol: udp + source: {port: "68"} + destination: {port: "67", mac_address: "ff:ff:ff:ff:ff:ff"} + log: true + - {number: 20, description: Drop IPv6 traffic, action: drop, ethernet_type: ipv6} + forward: + default_action: drop + rules: + - {number: 10, description: Accept ARP, ethernet_type: arp} + - {number: 20, description: Accept ipv4 from host, source: {address: 10.1.1.102}, state: [new]} + ip_forward: + rules: + - {number: 10, description: br1 - allow internet access, outbound_interface: eth8} + router_access: accept + + - name: br2 + description: L3 bridge br2 + addresses: [10.2.2.1/24] + members: + - {interface: eth5, description: br2 - Host} + - {interface: eth6, description: br2 - Trusted DHCP Server} + - {interface: eth7, description: br2} + prerouting: + default_action: accept + rules: + - {number: 10, description: Drop IPv6 traffic, action: drop, ethernet_type: ipv6} + forward: + default_action: drop + rules: + - number: 10 + description: Accept DHCP discover + protocol: udp + source: {port: "68"} + destination: {port: "67", mac_address: "ff:ff:ff:ff:ff:ff"} + - number: 20 + description: Accept DHCP offers from trusted interface + protocol: udp + source: {port: "67"} + destination: {port: "68"} + inbound_interface: eth6 + - number: 22 + description: Drop all other DHCP offers + action: drop + protocol: udp + source: {port: "67"} + destination: {port: "68"} + log: true + - {number: 30, description: Accept ARP, ethernet_type: arp} + - {number: 40, description: Accept ipv4, ethernet_type: ipv4} + ip_forward: + rules: + - {number: 10, description: br2 - allow internet access, outbound_interface: eth8} + - {number: 20, description: br2 - allow access to br1, outbound_bridge: br1} + router_access: drop diff --git a/examples/bridge-firewall/inventory.yml b/examples/bridge-firewall/inventory.yml new file mode 100644 index 0000000..3d882a0 --- /dev/null +++ b/examples/bridge-firewall/inventory.yml @@ -0,0 +1,13 @@ +--- +# docs.vyos.io/en/1.5/configexamples/fwall-and-bridge.html +all: + children: + bridge: + hosts: + r1: + ansible_host: clab-bridge-firewall-r1 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/bridge-firewall/site.yml b/examples/bridge-firewall/site.yml new file mode 100644 index 0000000..c8ac898 --- /dev/null +++ b/examples/bridge-firewall/site.yml @@ -0,0 +1,12 @@ +--- +- name: Bridges and firewall + hosts: bridge + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.bridge_firewall + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/bridge-firewall/topology.clab.yml b/examples/bridge-firewall/topology.clab.yml new file mode 100644 index 0000000..14b9b55 --- /dev/null +++ b/examples/bridge-firewall/topology.clab.yml @@ -0,0 +1,63 @@ +name: bridge-firewall +topology: + nodes: + r1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + h1: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.0.1/24 dev eth1 + - ip -6 addr add fd00:b0::1/64 dev eth1 + h2: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.0.2/24 dev eth1 + - ip -6 addr add fd00:b0::2/64 dev eth1 + h3: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.1.1.102/24 dev eth1 + - ip route replace default via 10.1.1.1 + h4: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.1.1.103/24 dev eth1 + - ip route replace default via 10.1.1.1 + h5: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.2.2.5/24 dev eth1 + - ip route replace default via 10.2.2.1 + h6: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.2.2.6/24 dev eth1 + - ip route replace default via 10.2.2.1 + h7: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.2.2.7/24 dev eth1 + - ip route replace default via 10.2.2.1 + wan: + kind: linux + image: alpine:3 + exec: + - ip addr add 203.0.113.100/24 dev eth1 + - ip route replace default via 203.0.113.1 + links: + - endpoints: ["r1:eth1", "h1:eth1"] + - endpoints: ["r1:eth2", "h2:eth1"] + - endpoints: ["r1:eth3", "h3:eth1"] + - endpoints: ["r1:eth4", "h4:eth1"] + - endpoints: ["r1:eth5", "h5:eth1"] + - endpoints: ["r1:eth6", "h6:eth1"] + - endpoints: ["r1:eth7", "h7:eth1"] + - endpoints: ["r1:eth8", "wan:eth1"] diff --git a/examples/bridge-firewall/verify.yml b/examples/bridge-firewall/verify.yml new file mode 100644 index 0000000..1af9772 --- /dev/null +++ b/examples/bridge-firewall/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the bridges + hosts: bridge + gather_facts: false + tasks: + - name: Bridge checks + ansible.builtin.include_role: + name: vyos.blueprints.bridge_firewall + tasks_from: verify diff --git a/examples/flexvpn-cisco/group_vars/spoke.yml b/examples/flexvpn-cisco/group_vars/spoke.yml new file mode 100644 index 0000000..c0c5dd0 --- /dev/null +++ b/examples/flexvpn-cisco/group_vars/spoke.yml @@ -0,0 +1,44 @@ +--- +# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html - VyOS side +gre_tunnel_interfaces: + - name: tun1 + encapsulation: gre + adjust_mss: "1336" + mtu: 1376 + remote: 10.1.1.6 + source_address: 198.51.100.1 + +ipsec_policy_based_peers: + - name: cisco_hub + psk_name: vyos_cisco_l + psk: secret # use ansible-vault for real devices + local_address: 198.51.100.1 + remote_address: 10.1.1.6 + local_id: vyos.net + remote_id: cisco.hub.net + connection_type: initiate + virtual_address: 0.0.0.0 + tunnels: + - {id: 1, local_prefix: 198.51.100.1/32, remote_prefix: 10.1.1.6/32, protocol: gre} +ipsec_policy_based_ike_group: + name: i1 + key_exchange: ikev2 + lifetime: 28800 + proposal_id: 1 + dh_group: 5 + encryption: aes256 + hash: sha256 +ipsec_policy_based_esp_group: + name: e1 + lifetime: 3600 + mode: tunnel + pfs: disable + proposal_id: 1 + encryption: aes128 + hash: sha256 +ipsec_policy_based_interfaces: [eth2] # WAN interface (198.51.100.1/24 on the page) +ipsec_policy_based_options: + disable_route_autoinstall: true + flexvpn: true + interface: tun1 + virtual_ip: true diff --git a/examples/flexvpn-cisco/inventory.yml b/examples/flexvpn-cisco/inventory.yml new file mode 100644 index 0000000..9368dca --- /dev/null +++ b/examples/flexvpn-cisco/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html +# Only the VyOS spoke is configured here; the Cisco FlexVPN hub is configured +# as shown on the page (there is no lab stand-in: VyOS cannot act as a FlexVPN hub). +all: + children: + spoke: + hosts: + vyos: + ansible_host: 192.0.2.10 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/flexvpn-cisco/site.yml b/examples/flexvpn-cisco/site.yml new file mode 100644 index 0000000..6204e3f --- /dev/null +++ b/examples/flexvpn-cisco/site.yml @@ -0,0 +1,12 @@ +--- +- name: FlexVPN spoke - GRE over IPsec to a Cisco hub + hosts: spoke + gather_facts: false + roles: + - vyos.blueprints.gre_tunnel + - vyos.blueprints.ipsec_policy_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/flexvpn-cisco/verify.yml b/examples/flexvpn-cisco/verify.yml new file mode 100644 index 0000000..e637db8 --- /dev/null +++ b/examples/flexvpn-cisco/verify.yml @@ -0,0 +1,13 @@ +--- +- name: Check the FlexVPN spoke + hosts: spoke + gather_facts: false + tasks: + - name: Tunnel interface checks + ansible.builtin.include_role: + name: vyos.blueprints.gre_tunnel + tasks_from: verify + - name: IPsec checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_policy_based + tasks_from: verify diff --git a/examples/ipsec-route-based/group_vars/vpn.yml b/examples/ipsec-route-based/group_vars/vpn.yml new file mode 100644 index 0000000..092d64b --- /dev/null +++ b/examples/ipsec-route-based/group_vars/vpn.yml @@ -0,0 +1,17 @@ +--- +# IKE and IPsec parameters from the page's tables +ipsec_route_based_ike_group: + name: IKE-GROUP + key_exchange: ikev1 + lifetime: 28800 + dh_group: 14 + encryption: aes128 + hash: sha1 + close_action: start + dead_peer_detection: {action: restart, interval: 10, timeout: 30} +ipsec_route_based_esp_group: + name: ESP-GROUP + lifetime: 3600 + pfs: disable + encryption: aes256 + hash: sha256 diff --git a/examples/ipsec-route-based/host_vars/cisco.yml b/examples/ipsec-route-based/host_vars/cisco.yml new file mode 100644 index 0000000..f536639 --- /dev/null +++ b/examples/ipsec-route-based/host_vars/cisco.yml @@ -0,0 +1,20 @@ +--- +# Lab stand-in for the page's Cisco router, using the page's Cisco values +base_interfaces: + - {name: eth1, addresses: [10.0.2.2/30]} + - {name: eth2, addresses: [192.168.10.1/24]} + - {name: eth3, addresses: [192.168.11.1/24]} +ipsec_route_based_peers: + - name: VYOS + local_address: 10.0.2.2 + remote_address: 10.0.1.2 + psk: dGVzdA== + psk_type: base64 + psk_name: AUTH-PSK + connection_type: none + vti: {interface: vti1, address: 10.100.100.2/30, mtu: 1438} +ipsec_route_based_ospf: + router_id: 1.1.1.1 + networks: [10.100.100.0/30, 192.168.10.0/24, 192.168.11.0/24] + passive_interfaces: [eth2, eth3] +ipsec_route_based_default_gateway: 10.0.2.1 diff --git a/examples/ipsec-route-based/host_vars/vyos.yml b/examples/ipsec-route-based/host_vars/vyos.yml new file mode 100644 index 0000000..8674a81 --- /dev/null +++ b/examples/ipsec-route-based/host_vars/vyos.yml @@ -0,0 +1,20 @@ +--- +# WAN is eth1 here, eth0 on the page (containerlab uses eth0 for management) +base_interfaces: + - {name: eth1, addresses: [10.0.1.2/30]} + - {name: eth2, addresses: [192.168.0.1/24]} + - {name: eth3, addresses: [192.168.1.1/24]} +ipsec_route_based_peers: + - name: CISCO + local_address: 10.0.1.2 + remote_address: 10.0.2.2 + psk: dGVzdA== # use ansible-vault for real devices + psk_type: base64 + psk_name: AUTH-PSK + connection_type: initiate + vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438} +ipsec_route_based_ospf: + router_id: 2.2.2.2 + networks: [10.100.100.0/30, 192.168.0.0/24, 192.168.1.0/24] + passive_interfaces: [eth2, eth3] +ipsec_route_based_default_gateway: 10.0.1.1 diff --git a/examples/ipsec-route-based/inventory.yml b/examples/ipsec-route-based/inventory.yml new file mode 100644 index 0000000..4d42e0d --- /dev/null +++ b/examples/ipsec-route-based/inventory.yml @@ -0,0 +1,18 @@ +--- +# docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html +# "vyos" is the router this collection configures. "cisco" is a second VyOS in +# the lab standing in for the page's Cisco router; on a real network, configure +# the Cisco side as shown on the page and remove it from this inventory. +all: + children: + vpn: + hosts: + vyos: + ansible_host: clab-ipsec-route-based-vyos # your router's address + cisco: + ansible_host: clab-ipsec-route-based-cisco + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/ipsec-route-based/site.yml b/examples/ipsec-route-based/site.yml new file mode 100644 index 0000000..db7d07b --- /dev/null +++ b/examples/ipsec-route-based/site.yml @@ -0,0 +1,12 @@ +--- +- name: Route-based site-to-site IPsec + hosts: vpn + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/ipsec-route-based/topology.clab.yml b/examples/ipsec-route-based/topology.clab.yml new file mode 100644 index 0000000..23e49ac --- /dev/null +++ b/examples/ipsec-route-based/topology.clab.yml @@ -0,0 +1,25 @@ +name: ipsec-route-based +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + vyos: + kind: vyosnetworks_vyos + cisco: + kind: vyosnetworks_vyos + isp: + kind: linux + image: alpine:3 + exec: ["sysctl -w net.ipv4.ip_forward=1", "ip addr add 10.0.1.1/30 dev eth1", "ip addr add 10.0.2.1/30 dev eth2"] + pc1: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.0.2/24 dev eth1", "ip route replace default via 192.168.0.1"]} + pc2: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.1.2/24 dev eth1", "ip route replace default via 192.168.1.1"]} + pc3: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.10.2/24 dev eth1", "ip route replace default via 192.168.10.1"]} + pc4: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.11.2/24 dev eth1", "ip route replace default via 192.168.11.1"]} + links: + - endpoints: ["vyos:eth1", "isp:eth1"] + - endpoints: ["cisco:eth1", "isp:eth2"] + - endpoints: ["vyos:eth2", "pc1:eth1"] + - endpoints: ["vyos:eth3", "pc2:eth1"] + - endpoints: ["cisco:eth2", "pc3:eth1"] + - endpoints: ["cisco:eth3", "pc4:eth1"] diff --git a/examples/ipsec-route-based/verify.yml b/examples/ipsec-route-based/verify.yml new file mode 100644 index 0000000..268ff9c --- /dev/null +++ b/examples/ipsec-route-based/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the VPN + hosts: vpn + gather_facts: false + tasks: + - name: IPsec and OSPF checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify diff --git a/examples/ospf-unnumbered/group_vars/fabric.yml b/examples/ospf-unnumbered/group_vars/fabric.yml new file mode 100644 index 0000000..9fa7a6c --- /dev/null +++ b/examples/ospf-unnumbered/group_vars/fabric.yml @@ -0,0 +1,4 @@ +--- +ospf_unnumbered_interfaces: [eth1, eth2] +ospf_unnumbered_md5_key: yourpassword # use ansible-vault for real devices +ospf_unnumbered_group: fabric diff --git a/examples/ospf-unnumbered/host_vars/routerA.yml b/examples/ospf-unnumbered/host_vars/routerA.yml new file mode 100644 index 0000000..e3803e6 --- /dev/null +++ b/examples/ospf-unnumbered/host_vars/routerA.yml @@ -0,0 +1,5 @@ +--- +ospf_unnumbered_router_id: 192.168.0.1 +# LAN address; eth0 on the docs page, eth3 here because containerlab uses eth0 for management +base_interfaces: + - {name: eth3, addresses: [10.0.0.1/24]} diff --git a/examples/ospf-unnumbered/host_vars/routerB.yml b/examples/ospf-unnumbered/host_vars/routerB.yml new file mode 100644 index 0000000..b2aac66 --- /dev/null +++ b/examples/ospf-unnumbered/host_vars/routerB.yml @@ -0,0 +1,4 @@ +--- +ospf_unnumbered_router_id: 192.168.0.2 +base_interfaces: + - {name: eth3, addresses: [10.0.0.2/24]} diff --git a/examples/ospf-unnumbered/inventory.yml b/examples/ospf-unnumbered/inventory.yml new file mode 100644 index 0000000..97bc8d4 --- /dev/null +++ b/examples/ospf-unnumbered/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/ospf-unnumbered.html +all: + children: + fabric: + hosts: + routerA: + ansible_host: clab-ospf-unnumbered-routerA # your router's address + routerB: + ansible_host: clab-ospf-unnumbered-routerB + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/ospf-unnumbered/site.yml b/examples/ospf-unnumbered/site.yml new file mode 100644 index 0000000..ad9bd0a --- /dev/null +++ b/examples/ospf-unnumbered/site.yml @@ -0,0 +1,12 @@ +--- +- name: OSPF unnumbered with ECMP + hosts: fabric + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ospf_unnumbered + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/ospf-unnumbered/topology.clab.yml b/examples/ospf-unnumbered/topology.clab.yml new file mode 100644 index 0000000..4b2ae23 --- /dev/null +++ b/examples/ospf-unnumbered/topology.clab.yml @@ -0,0 +1,25 @@ +name: ospf-unnumbered +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + routerA: + kind: vyosnetworks_vyos + routerB: + kind: vyosnetworks_vyos + # shared 10.0.0.0/24 LAN, as on the docs page: a Linux bridge plus a test host + lan: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set br0 up + - ip addr add 10.0.0.10/24 dev br0 + links: + - endpoints: ["routerA:eth1", "routerB:eth1"] + - endpoints: ["routerA:eth2", "routerB:eth2"] + - endpoints: ["routerA:eth3", "lan:eth1"] + - endpoints: ["routerB:eth3", "lan:eth2"] diff --git a/examples/ospf-unnumbered/verify.yml b/examples/ospf-unnumbered/verify.yml new file mode 100644 index 0000000..f5b7b6f --- /dev/null +++ b/examples/ospf-unnumbered/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the OSPF fabric + hosts: fabric + gather_facts: false + tasks: + - name: OSPF checks (all routers in one play for the route checks) + ansible.builtin.include_role: + name: vyos.blueprints.ospf_unnumbered + tasks_from: verify diff --git a/examples/policy-ipsec-firewall/group_vars/sites.yml b/examples/policy-ipsec-firewall/group_vars/sites.yml new file mode 100644 index 0000000..72cb49a --- /dev/null +++ b/examples/policy-ipsec-firewall/group_vars/sites.yml @@ -0,0 +1,5 @@ +--- +# IPsec settings shared by both routers, as on the page +ipsec_policy_based_ike_group: {name: IKE-GROUP, key_exchange: ikev2, proposal_id: 1, dh_group: 14, encryption: aes256, hash: sha256} +ipsec_policy_based_esp_group: {name: ESP-GROUP, mode: tunnel, proposal_id: 1, encryption: aes256, hash: sha256} +ipsec_policy_based_interfaces: [eth3] diff --git a/examples/policy-ipsec-firewall/host_vars/left.yml b/examples/policy-ipsec-firewall/host_vars/left.yml new file mode 100644 index 0000000..e6fe1ee --- /dev/null +++ b/examples/policy-ipsec-firewall/host_vars/left.yml @@ -0,0 +1,98 @@ +--- +# WAN is eth3 here, eth0 on the page (containerlab uses eth0 for management). +# Input rule 5 keeps containerlab management reachable - drop it on a real router +# and make sure your management source is allowed (rule 20, TRUSTED) instead. +ipsec_policy_based_peers: + - name: RIGHT + psk_name: RIGHT + psk: p4ssw0rd # use ansible-vault for real devices + authentication_ids: false + local_address: 198.51.100.14 + remote_address: 192.0.2.130 + connection_type: initiate + tunnels: + - {id: 0, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.21.0/24} + - {id: 1, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.22.0/24} + - {id: 2, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.21.0/24} + - {id: 3, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.22.0/24} +ipsec_policy_based_default_gateway: 198.51.100.13 +firewall_groups: + network: + - name: LOCAL-NETS + networks: [10.1.11.0/24, 10.1.12.0/24] + - name: REMOTE-NETS + networks: [10.2.21.0/24, 10.2.22.0/24] + - name: TRUSTED + networks: [198.51.100.125/32, 203.0.113.0/24, 10.1.11.0/24, 192.168.70.0/24] +firewall_ipv4: + forward: + default_action: drop + rules: + - number: 1 + action: accept + state: {established: true, related: true} + - number: 2 + action: drop + state: {invalid: true} + - number: 10 + action: accept + source: + group: {network_group: LOCAL-NETS} + - number: 20 + action: accept + source: + group: {network_group: REMOTE-NETS} + destination: + group: {network_group: LOCAL-NETS} + input: + default_action: drop + rules: + - number: 1 + action: accept + state: {established: true, related: true} + - number: 2 + action: drop + state: {invalid: true} + - number: 5 + action: accept + description: containerlab management + inbound_interface: {name: eth0} + - number: 10 + action: accept + protocol: udp + destination: {port: '500,4500'} + inbound_interface: {name: eth3} + - number: 15 + action: accept + protocol: esp + inbound_interface: {name: eth3} + - number: 20 + action: accept + protocol: tcp + destination: {port: '22'} + source: + group: {network_group: TRUSTED} + - number: 25 + action: accept + protocol: udp + destination: {port: '53'} + source: + group: {network_group: LOCAL-NETS} + - {number: 30, action: accept, protocol: icmp} +nat_source_rules: + - id: 10 + exclude: true + outbound_interface: {name: eth3} + source: {network_group: LOCAL-NETS} + destination: {network_group: REMOTE-NETS} + - id: 20 + outbound_interface: {name: eth3} + source: {network_group: LOCAL-NETS} + translation: {address: masquerade} +base_interfaces: + - name: eth3 + addresses: [198.51.100.14/30] + - name: eth1.111 + addresses: [10.1.11.1/24] + - name: eth2.112 + addresses: [10.1.12.1/24] diff --git a/examples/policy-ipsec-firewall/host_vars/right.yml b/examples/policy-ipsec-firewall/host_vars/right.yml new file mode 100644 index 0000000..ab629da --- /dev/null +++ b/examples/policy-ipsec-firewall/host_vars/right.yml @@ -0,0 +1,23 @@ +--- +# The page sets no default route on RIGHT; it needs one to reach LEFT. +ipsec_policy_based_peers: + - name: LEFT + psk_name: LEFT + psk: p4ssw0rd # use ansible-vault for real devices + authentication_ids: false + local_address: 192.0.2.130 + remote_address: 198.51.100.14 + connection_type: none + tunnels: + - {id: 0, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.11.0/24} + - {id: 1, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.11.0/24} + - {id: 2, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.12.0/24} + - {id: 3, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.12.0/24} +base_interfaces: + - name: eth3 + addresses: [192.0.2.130/30] + - name: eth1.221 + addresses: [10.2.21.1/24] + - name: eth2.222 + addresses: [10.2.22.1/24] +ipsec_policy_based_default_gateway: 192.0.2.129 diff --git a/examples/policy-ipsec-firewall/inventory.yml b/examples/policy-ipsec-firewall/inventory.yml new file mode 100644 index 0000000..95eeddb --- /dev/null +++ b/examples/policy-ipsec-firewall/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html +all: + children: + sites: + hosts: + left: + ansible_host: clab-policy-ipsec-firewall-left # your router's address + right: + ansible_host: clab-policy-ipsec-firewall-right + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/policy-ipsec-firewall/site.yml b/examples/policy-ipsec-firewall/site.yml new file mode 100644 index 0000000..87ea9a5 --- /dev/null +++ b/examples/policy-ipsec-firewall/site.yml @@ -0,0 +1,15 @@ +--- +- name: Policy-based IPsec with firewall and NAT + hosts: sites + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ipsec_policy_based + # firewall and nat only have inputs on LEFT, as on the page; on RIGHT they do nothing + - vyos.blueprints.firewall + - vyos.blueprints.nat + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/policy-ipsec-firewall/topology.clab.yml b/examples/policy-ipsec-firewall/topology.clab.yml new file mode 100644 index 0000000..e512c9c --- /dev/null +++ b/examples/policy-ipsec-firewall/topology.clab.yml @@ -0,0 +1,51 @@ +name: policy-ipsec-firewall +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + left: + kind: vyosnetworks_vyos + right: + kind: vyosnetworks_vyos + isp: + kind: linux + image: alpine:3 + exec: + - sysctl -w net.ipv4.ip_forward=1 + - ip addr add 198.51.100.13/30 dev eth1 + - ip addr add 192.0.2.129/30 dev eth2 + - ip addr add 203.0.113.1/24 dev eth3 + internet: + kind: linux + image: alpine:3 + exec: ["ip addr add 203.0.113.10/24 dev eth1", "ip route replace default via 203.0.113.1"] + l11: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.111 type vlan id 111", "ip link set eth1.111 up", + "ip addr add 10.1.11.10/24 dev eth1.111", "ip route replace default via 10.1.11.1"] + l12: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.112 type vlan id 112", "ip link set eth1.112 up", + "ip addr add 10.1.12.10/24 dev eth1.112", "ip route replace default via 10.1.12.1"] + r21: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.221 type vlan id 221", "ip link set eth1.221 up", + "ip addr add 10.2.21.10/24 dev eth1.221", "ip route replace default via 10.2.21.1"] + r22: + kind: linux + image: alpine:3 + exec: ["ip link add link eth1 name eth1.222 type vlan id 222", "ip link set eth1.222 up", + "ip addr add 10.2.22.10/24 dev eth1.222", "ip route replace default via 10.2.22.1"] + links: + # WAN is eth3 here (eth0 on the page; eth0 is containerlab management) + - endpoints: ["left:eth3", "isp:eth1"] + - endpoints: ["right:eth3", "isp:eth2"] + - endpoints: ["isp:eth3", "internet:eth1"] + - endpoints: ["left:eth1", "l11:eth1"] + - endpoints: ["left:eth2", "l12:eth1"] + - endpoints: ["right:eth1", "r21:eth1"] + - endpoints: ["right:eth2", "r22:eth1"] diff --git a/examples/policy-ipsec-firewall/verify.yml b/examples/policy-ipsec-firewall/verify.yml new file mode 100644 index 0000000..d1006cf --- /dev/null +++ b/examples/policy-ipsec-firewall/verify.yml @@ -0,0 +1,22 @@ +--- +- name: Check both sites + hosts: sites + gather_facts: false + tasks: + - name: IPsec checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_policy_based + tasks_from: verify + +- name: Check firewall and NAT on LEFT + hosts: left + gather_facts: false + tasks: + - name: Firewall checks + ansible.builtin.include_role: + name: vyos.blueprints.firewall + tasks_from: verify + - name: NAT checks + ansible.builtin.include_role: + name: vyos.blueprints.nat + tasks_from: verify diff --git a/examples/vrf-firewall/group_vars/router.yml b/examples/vrf-firewall/group_vars/router.yml new file mode 100644 index 0000000..3045bce --- /dev/null +++ b/examples/vrf-firewall/group_vars/router.yml @@ -0,0 +1,51 @@ +--- +# The page's WAN is PPPoE (pppoe0); this example uses eth3 instead, because +# PPPoE needs an access concentrator. Swap eth3 back to pppoe0 on a real router. +base_interfaces: + - {name: eth1, addresses: [10.100.100.1/24]} + - {name: eth2} + - {name: eth2.150, addresses: [10.150.150.1/24]} + - {name: eth2.160, addresses: [10.160.160.1/24]} + - {name: eth2.3500, addresses: [172.16.20.1/24]} + - {name: eth3, addresses: [203.0.113.1/24]} +vrf_firewall_vrfs: + - name: MGMT + table: 102 + interfaces: [eth1] + routes: + - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN} + - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN} + - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD} + - name: WAN + table: 101 + interfaces: [eth3] + routes: + - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN} + - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN} + - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD} + - name: LAN + table: 103 + interfaces: [eth2.150, eth2.160] + routes: + - {dest: 0.0.0.0/0, interface: eth3, vrf: WAN} + - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT} + - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD} + - name: PROD + table: 104 + interfaces: [eth2.3500] + routes: + - {dest: 0.0.0.0/0, interface: eth3, vrf: WAN} + - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT} + - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN} + - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN} + +vrf_firewall_forward_rules: + - {number: 10, description: MGMT - Allow to LAN and PROD, inbound_interface: MGMT, outbound_interface: eth2*} + - {number: 99, action: drop, description: MGMT - Drop all going to mgmt, outbound_interface: eth1} + - {number: 120, description: LAN - Allow to PROD, inbound_interface: LAN, outbound_interface: eth2.3500} + - {number: 130, description: LAN - Allow internet, inbound_interface: LAN, outbound_interface: eth3} + +vrf_firewall_input_rules: + # containerlab management only - on a real router the page allows input from MGMT only + - {number: 5, description: containerlab management, inbound_interface: eth0} + - {number: 10, description: MGMT - Allow input, inbound_interface: MGMT} diff --git a/examples/vrf-firewall/inventory.yml b/examples/vrf-firewall/inventory.yml new file mode 100644 index 0000000..f3e6b10 --- /dev/null +++ b/examples/vrf-firewall/inventory.yml @@ -0,0 +1,13 @@ +--- +# docs.vyos.io/en/1.5/configexamples/fwall-and-vrf.html +all: + children: + router: + hosts: + r1: + ansible_host: clab-vrf-firewall-r1 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/vrf-firewall/site.yml b/examples/vrf-firewall/site.yml new file mode 100644 index 0000000..0f0b66a --- /dev/null +++ b/examples/vrf-firewall/site.yml @@ -0,0 +1,12 @@ +--- +- name: VRFs and firewall + hosts: router + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.vrf_firewall + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/vrf-firewall/topology.clab.yml b/examples/vrf-firewall/topology.clab.yml new file mode 100644 index 0000000..0612a1f --- /dev/null +++ b/examples/vrf-firewall/topology.clab.yml @@ -0,0 +1,43 @@ +name: vrf-firewall +topology: + nodes: + r1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + mgmt: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.100.100.10/24 dev eth1", "ip route replace default via 10.100.100.1"] + # VLAN-aware bridge for the eth2 trunk (vif 150 = LAN, vif 3500 = PROD) + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge vlan_filtering 1 + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set eth3 master br0 + - bridge vlan add dev eth1 vid 150 + - bridge vlan add dev eth1 vid 3500 + - bridge vlan add dev eth2 vid 150 pvid untagged + - bridge vlan add dev eth3 vid 3500 pvid untagged + - ip link set br0 up + lan: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.150.150.10/24 dev eth1", "ip route replace default via 10.150.150.1"] + prod: + kind: linux + image: alpine:3 + exec: ["ip addr add 172.16.20.10/24 dev eth1", "ip route replace default via 172.16.20.1"] + # stands in for the page's PPPoE uplink + wan: + kind: linux + image: alpine:3 + exec: ["ip addr add 203.0.113.100/24 dev eth1", "ip route replace default via 203.0.113.1"] + links: + - endpoints: ["r1:eth1", "mgmt:eth1"] + - endpoints: ["r1:eth2", "sw:eth1"] + - endpoints: ["sw:eth2", "lan:eth1"] + - endpoints: ["sw:eth3", "prod:eth1"] + - endpoints: ["r1:eth3", "wan:eth1"] diff --git a/examples/vrf-firewall/verify.yml b/examples/vrf-firewall/verify.yml new file mode 100644 index 0000000..6a66c8f --- /dev/null +++ b/examples/vrf-firewall/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the VRFs + hosts: router + gather_facts: false + tasks: + - name: VRF checks + ansible.builtin.include_role: + name: vyos.blueprints.vrf_firewall + tasks_from: verify diff --git a/examples/zone-policy/group_vars/firewall.yml b/examples/zone-policy/group_vars/firewall.yml new file mode 100644 index 0000000..13c0188 --- /dev/null +++ b/examples/zone-policy/group_vars/firewall.yml @@ -0,0 +1,80 @@ +--- +# Router on a stick, as on the docs page. The page trunks VLANs 10/20/30 on +# eth0; this example uses eth1 because containerlab reserves eth0 for +# management. +base_interfaces: + - {name: eth1, description: trunk} + - {name: eth1.10, description: WAN, addresses: [172.16.10.1/24, "2001:db8:0:9999::1/64"]} + - {name: eth1.20, description: LAN, addresses: [192.168.100.1/24, "2001:db8:0:aaaa::1/64"]} + - {name: eth1.30, description: DMZ, addresses: [192.168.200.1/24, "2001:db8:0:bbbb::1/64"]} + +zone_firewall_zones: + # mgmt exists only so Ansible keeps its SSH session in containerlab. On a real + # router follow the page: the admin console (192.168.100.10) reaches the router + # through the lan-local rule 800, so make sure that rule is in place first. + - {name: mgmt, interfaces: [eth0]} + - {name: wan, interfaces: [eth1.10]} + - {name: lan, interfaces: [eth1.20]} + - {name: dmz, interfaces: [eth1.30]} + - {name: local, local: true} + +zone_firewall_policies: + - {from: mgmt, to: local, default_action: accept} + - from: wan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}} + - {number: 200, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "80,443"}} + - {number: 500, protocol: tcp, destination: {address: 192.168.200.200, port: "25"}} + - {number: 500, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "25"}} + - {number: 600, protocol: tcp, destination: {address: 192.168.200.200, port: "53"}} + - {number: 600, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "53"}} + - from: dmz + to: local + rules: + - {number: 400, protocol: tcp, destination: {port: "123"}} + - {number: 600, protocol: tcp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: lan + to: local + rules: + - {number: 400, protocol: tcp, destination: {port: "123"}} + - {number: 600, protocol: tcp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {port: "22"}} + - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {port: "22"}} + - from: lan + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - {number: 800, protocol: tcp, destination: {port: "22"}} + - from: dmz + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - {number: 600, protocol: tcp_udp, destination: {port: "53"}} + - {number: 800, protocol: tcp, destination: {port: "22"}} + - from: local + to: wan + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 300, protocol: tcp, destination: {port: "20,21"}} + - from: local + to: dmz + rules: + - {number: 500, protocol: tcp, destination: {port: "25"}} + - {number: 600, protocol: tcp_udp, destination: {port: "53"}} + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: local + to: lan + rules: + - {number: 700, protocol: tcp, destination: {port: "67,68"}} + - from: lan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} + - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {address: 192.168.200.200, port: "22"}} + - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {address: "2001:db8:0:bbbb::200", port: "22"}} + - {number: 900, protocol: tcp, destination: {port: "993"}} diff --git a/examples/zone-policy/inventory.yml b/examples/zone-policy/inventory.yml new file mode 100644 index 0000000..206412d --- /dev/null +++ b/examples/zone-policy/inventory.yml @@ -0,0 +1,13 @@ +--- +# docs.vyos.io/en/1.5/configexamples/zone-policy.html +all: + children: + firewall: + hosts: + fw1: + ansible_host: clab-zone-policy-fw1 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/zone-policy/site.yml b/examples/zone-policy/site.yml new file mode 100644 index 0000000..4d82cdf --- /dev/null +++ b/examples/zone-policy/site.yml @@ -0,0 +1,12 @@ +--- +- name: Zone-based firewall + hosts: firewall + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.zone_firewall + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/zone-policy/topology.clab.yml b/examples/zone-policy/topology.clab.yml new file mode 100644 index 0000000..63080d2 --- /dev/null +++ b/examples/zone-policy/topology.clab.yml @@ -0,0 +1,40 @@ +name: zone-policy +topology: + nodes: + fw1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + # one host per network on its own VLAN, behind a VLAN-aware bridge + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge vlan_filtering 1 + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set eth3 master br0 + - ip link set eth4 master br0 + - bridge vlan add dev eth1 vid 10 + - bridge vlan add dev eth1 vid 20 + - bridge vlan add dev eth1 vid 30 + - bridge vlan add dev eth2 vid 10 pvid untagged + - bridge vlan add dev eth3 vid 20 pvid untagged + - bridge vlan add dev eth4 vid 30 pvid untagged + - ip link set br0 up + wan: + kind: linux + image: alpine:3 + exec: ["ip addr add 172.16.10.100/24 dev eth1", "ip route replace default via 172.16.10.1"] + lan: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.100.10/24 dev eth1", "ip route replace default via 192.168.100.1"] + dmz: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.200.200/24 dev eth1", "ip route replace default via 192.168.200.1"] + links: + - endpoints: ["fw1:eth1", "sw:eth1"] + - endpoints: ["sw:eth2", "wan:eth1"] + - endpoints: ["sw:eth3", "lan:eth1"] + - endpoints: ["sw:eth4", "dmz:eth1"] diff --git a/examples/zone-policy/verify.yml b/examples/zone-policy/verify.yml new file mode 100644 index 0000000..3132524 --- /dev/null +++ b/examples/zone-policy/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the zone firewall + hosts: firewall + gather_facts: false + tasks: + - name: Zone checks + ansible.builtin.include_role: + name: vyos.blueprints.zone_firewall + tasks_from: verify |
