summaryrefslogtreecommitdiff
path: root/examples
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /examples
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'examples')
-rw-r--r--examples/README.md13
-rw-r--r--examples/azure-vpn-bgp/group_vars/onprem.yml45
-rw-r--r--examples/azure-vpn-bgp/inventory.yml15
-rw-r--r--examples/azure-vpn-bgp/site.yml11
-rw-r--r--examples/azure-vpn-bgp/verify.yml9
-rw-r--r--examples/azure-vpn-dual-bgp/group_vars/onprem.yml64
-rw-r--r--examples/azure-vpn-dual-bgp/inventory.yml15
-rw-r--r--examples/azure-vpn-dual-bgp/site.yml11
-rw-r--r--examples/azure-vpn-dual-bgp/verify.yml9
-rw-r--r--examples/bgp-unnumbered/group_vars/fabric.yml3
-rw-r--r--examples/bgp-unnumbered/host_vars/routerA.yml3
-rw-r--r--examples/bgp-unnumbered/host_vars/routerB.yml3
-rw-r--r--examples/bgp-unnumbered/inventory.yml15
-rw-r--r--examples/bgp-unnumbered/site.yml11
-rw-r--r--examples/bgp-unnumbered/topology.clab.yml13
-rw-r--r--examples/bgp-unnumbered/verify.yml9
-rw-r--r--examples/bridge-firewall/group_vars/bridge.yml85
-rw-r--r--examples/bridge-firewall/inventory.yml13
-rw-r--r--examples/bridge-firewall/site.yml12
-rw-r--r--examples/bridge-firewall/topology.clab.yml63
-rw-r--r--examples/bridge-firewall/verify.yml9
-rw-r--r--examples/flexvpn-cisco/group_vars/spoke.yml44
-rw-r--r--examples/flexvpn-cisco/inventory.yml15
-rw-r--r--examples/flexvpn-cisco/site.yml12
-rw-r--r--examples/flexvpn-cisco/verify.yml13
-rw-r--r--examples/ipsec-route-based/group_vars/vpn.yml17
-rw-r--r--examples/ipsec-route-based/host_vars/cisco.yml20
-rw-r--r--examples/ipsec-route-based/host_vars/vyos.yml20
-rw-r--r--examples/ipsec-route-based/inventory.yml18
-rw-r--r--examples/ipsec-route-based/site.yml12
-rw-r--r--examples/ipsec-route-based/topology.clab.yml25
-rw-r--r--examples/ipsec-route-based/verify.yml9
-rw-r--r--examples/ospf-unnumbered/group_vars/fabric.yml4
-rw-r--r--examples/ospf-unnumbered/host_vars/routerA.yml5
-rw-r--r--examples/ospf-unnumbered/host_vars/routerB.yml4
-rw-r--r--examples/ospf-unnumbered/inventory.yml15
-rw-r--r--examples/ospf-unnumbered/site.yml12
-rw-r--r--examples/ospf-unnumbered/topology.clab.yml25
-rw-r--r--examples/ospf-unnumbered/verify.yml9
-rw-r--r--examples/policy-ipsec-firewall/group_vars/sites.yml5
-rw-r--r--examples/policy-ipsec-firewall/host_vars/left.yml98
-rw-r--r--examples/policy-ipsec-firewall/host_vars/right.yml23
-rw-r--r--examples/policy-ipsec-firewall/inventory.yml15
-rw-r--r--examples/policy-ipsec-firewall/site.yml15
-rw-r--r--examples/policy-ipsec-firewall/topology.clab.yml51
-rw-r--r--examples/policy-ipsec-firewall/verify.yml22
-rw-r--r--examples/vrf-firewall/group_vars/router.yml51
-rw-r--r--examples/vrf-firewall/inventory.yml13
-rw-r--r--examples/vrf-firewall/site.yml12
-rw-r--r--examples/vrf-firewall/topology.clab.yml43
-rw-r--r--examples/vrf-firewall/verify.yml9
-rw-r--r--examples/zone-policy/group_vars/firewall.yml80
-rw-r--r--examples/zone-policy/inventory.yml13
-rw-r--r--examples/zone-policy/site.yml12
-rw-r--r--examples/zone-policy/topology.clab.yml40
-rw-r--r--examples/zone-policy/verify.yml9
56 files changed, 1220 insertions, 1 deletions
diff --git a/examples/README.md b/examples/README.md
index 449efe4..8c149d5 100644
--- a/examples/README.md
+++ b/examples/README.md
@@ -6,8 +6,19 @@ Each directory is a complete, runnable Ansible project:
|---|---|---|
| `single-edge/` | `base`, `edge_nat` | – (small-office internet edge) |
| `ha-pair/` | `base`, `ha_vrrp` | [High Availability Walkthrough](https://docs.vyos.io/en/1.5/configexamples/ha.html) |
+| `ospf-unnumbered/` | `base`, `ospf_unnumbered` | [OSPF unnumbered with ECMP](https://docs.vyos.io/en/1.5/configexamples/ospf-unnumbered.html) |
+| `bgp-unnumbered/` | `bgp_unnumbered` | [BGP IPv6 unnumbered with extended nexthop](https://docs.vyos.io/en/1.5/configexamples/bgp-ipv6-unnumbered.html) |
+| `zone-policy/` | `base`, `zone_firewall` | [Zone-Policy example](https://docs.vyos.io/en/1.5/configexamples/zone-policy.html) |
+| `vrf-firewall/` | `base`, `vrf_firewall` | [VRF and firewall example](https://docs.vyos.io/en/1.5/configexamples/fwall-and-vrf.html) |
+| `bridge-firewall/` | `base`, `bridge_firewall` | [Bridge and firewall example](https://docs.vyos.io/en/1.5/configexamples/fwall-and-bridge.html) |
+| `ipsec-route-based/` | `base`, `ipsec_route_based` | [Route-based ... VyOS and Cisco](https://docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html); for [Route-based ... VyOS and Palo Alto](https://docs.vyos.io/en/1.5/configexamples/ipsec-pa-route-based.html) rename the peer `CISCO` to `PA` - the VyOS side is otherwise identical |
+| `ipsec-policy-based/` | `base`, `ipsec_policy_based` | [Policy-based Site-to-Site VPN IPsec between VyOS and Cisco](https://docs.vyos.io/en/1.5/configexamples/ipsec-cisco-policy-based.html) |
+| `policy-ipsec-firewall/` | `base`, `ipsec_policy_based`, `firewall`, `nat` | [Policy-Based Site-to-Site VPN and Firewall Configuration](https://docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html) |
+| `flexvpn-cisco/` | `gre_tunnel`, `ipsec_policy_based` | [Site-to-Site IPSec VPN to Cisco using FlexVPN](https://docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html) (no containerlab topology: needs a Cisco FlexVPN hub) |
+| `azure-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html) (no containerlab topology: the far end is Azure) |
+| `azure-vpn-dual-bgp/` | `ipsec_route_based` | [Route-Based Redundant Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html) (no containerlab topology: the far end is Azure) |
-Every example ships a `topology.clab.yml`, so you can try it against
+Most examples ship a `topology.clab.yml`, so you can try them against
containerized VyOS before pointing it at real routers:
```bash
diff --git a/examples/azure-vpn-bgp/group_vars/onprem.yml b/examples/azure-vpn-bgp/group_vars/onprem.yml
new file mode 100644
index 0000000..fdada7a
--- /dev/null
+++ b/examples/azure-vpn-bgp/group_vars/onprem.yml
@@ -0,0 +1,45 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html
+ipsec_route_based_peers:
+ - name: 203.0.113.2
+ description: AZURE PRIMARY TUNNEL
+ psk_name: azure
+ psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices
+ local_address: 10.10.0.5 # private IP; the device is behind NAT
+ local_id: 198.51.100.3 # public IP
+ remote_address: 203.0.113.2
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Tunnel, adjust_mss: "1350"}
+ipsec_route_based_ike_group:
+ name: AZURE
+ key_exchange: ikev2
+ ikev2_reauth: true
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 2
+ encryption: aes256
+ hash: sha1
+ dead_peer_detection: {action: restart, interval: 15, timeout: 30}
+ipsec_route_based_esp_group:
+ name: AZURE
+ lifetime: 3600
+ mode: tunnel
+ pfs: dh-group2
+ proposal_id: 1
+ encryption: aes256
+ hash: sha1
+ipsec_route_based_interfaces: [eth0]
+ipsec_route_based_disable_route_autoinstall: false # the page does not set it
+ipsec_route_based_interface_routes:
+ - {dest: 10.0.0.4/32, interface: vti1}
+ipsec_route_based_bgp:
+ asn: 64499
+ neighbors:
+ - address: 10.0.0.4
+ remote_as: 65540
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
diff --git a/examples/azure-vpn-bgp/inventory.yml b/examples/azure-vpn-bgp/inventory.yml
new file mode 100644
index 0000000..787a66e
--- /dev/null
+++ b/examples/azure-vpn-bgp/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html
+# Only the VyOS side is configured here; the Azure VNet gateway, local network
+# gateway and connection are created in Azure as the page's prerequisites describe.
+all:
+ children:
+ onprem:
+ hosts:
+ vyos:
+ ansible_host: 192.0.2.10 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/azure-vpn-bgp/site.yml b/examples/azure-vpn-bgp/site.yml
new file mode 100644
index 0000000..8d27036
--- /dev/null
+++ b/examples/azure-vpn-bgp/site.yml
@@ -0,0 +1,11 @@
+---
+- name: Route-based VPN to Azure with BGP
+ hosts: onprem
+ gather_facts: false
+ roles:
+ - vyos.blueprints.ipsec_route_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/azure-vpn-bgp/verify.yml b/examples/azure-vpn-bgp/verify.yml
new file mode 100644
index 0000000..fb4e633
--- /dev/null
+++ b/examples/azure-vpn-bgp/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the Azure VPN
+ hosts: onprem
+ gather_facts: false
+ tasks:
+ - name: IPsec and BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
diff --git a/examples/azure-vpn-dual-bgp/group_vars/onprem.yml b/examples/azure-vpn-dual-bgp/group_vars/onprem.yml
new file mode 100644
index 0000000..7f0f1ba
--- /dev/null
+++ b/examples/azure-vpn-dual-bgp/group_vars/onprem.yml
@@ -0,0 +1,64 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html
+# Both peers share the PSK entry "azure" (one entry, three ids), as on the page.
+ipsec_route_based_peers:
+ - name: azure-primary
+ description: AZURE PRIMARY TUNNEL
+ psk_name: azure
+ psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices
+ local_address: 10.10.0.5 # private IP; the device is behind NAT
+ local_id: 198.51.100.3 # public IP
+ remote_address: 203.0.113.2
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Primary Tunnel, adjust_mss: "1350"}
+ - name: azure-secondary
+ description: AZURE secondary TUNNEL
+ psk_name: azure
+ psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices
+ local_address: 10.10.0.5
+ local_id: 198.51.100.3
+ remote_address: 203.0.113.3
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti2, address: 10.10.1.6/32, description: Azure Secondary Tunnel, adjust_mss: "1350"}
+ipsec_route_based_ike_group:
+ name: AZURE
+ key_exchange: ikev2
+ ikev2_reauth: true
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 2
+ encryption: aes256
+ hash: sha1
+ dead_peer_detection: {action: restart, interval: 15, timeout: 30}
+ipsec_route_based_esp_group:
+ name: AZURE
+ lifetime: 3600
+ mode: tunnel
+ pfs: dh-group2
+ proposal_id: 1
+ encryption: aes256
+ hash: sha1
+ipsec_route_based_interfaces: [eth0]
+ipsec_route_based_disable_route_autoinstall: false # the page does not set it
+ipsec_route_based_interface_routes:
+ - {dest: 10.0.0.4/32, interface: vti1}
+ - {dest: 10.0.0.5/32, interface: vti2}
+ipsec_route_based_bgp:
+ asn: 64499
+ neighbors:
+ - address: 10.0.0.4
+ remote_as: 65540
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
+ - address: 10.0.0.5
+ remote_as: 65540
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
diff --git a/examples/azure-vpn-dual-bgp/inventory.yml b/examples/azure-vpn-dual-bgp/inventory.yml
new file mode 100644
index 0000000..1d4f699
--- /dev/null
+++ b/examples/azure-vpn-dual-bgp/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html
+# Only the VyOS side is configured here; the Azure VNet gateway, local network
+# gateway and connection are created in Azure as the page's prerequisites describe.
+all:
+ children:
+ onprem:
+ hosts:
+ vyos:
+ ansible_host: 192.0.2.10 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/azure-vpn-dual-bgp/site.yml b/examples/azure-vpn-dual-bgp/site.yml
new file mode 100644
index 0000000..651bf93
--- /dev/null
+++ b/examples/azure-vpn-dual-bgp/site.yml
@@ -0,0 +1,11 @@
+---
+- name: Redundant route-based VPN to Azure with BGP
+ hosts: onprem
+ gather_facts: false
+ roles:
+ - vyos.blueprints.ipsec_route_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/azure-vpn-dual-bgp/verify.yml b/examples/azure-vpn-dual-bgp/verify.yml
new file mode 100644
index 0000000..ef02155
--- /dev/null
+++ b/examples/azure-vpn-dual-bgp/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check both Azure tunnels
+ hosts: onprem
+ gather_facts: false
+ tasks:
+ - name: IPsec and BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
diff --git a/examples/bgp-unnumbered/group_vars/fabric.yml b/examples/bgp-unnumbered/group_vars/fabric.yml
new file mode 100644
index 0000000..34617ff
--- /dev/null
+++ b/examples/bgp-unnumbered/group_vars/fabric.yml
@@ -0,0 +1,3 @@
+---
+bgp_unnumbered_interfaces: [eth1, eth2]
+bgp_unnumbered_group: fabric
diff --git a/examples/bgp-unnumbered/host_vars/routerA.yml b/examples/bgp-unnumbered/host_vars/routerA.yml
new file mode 100644
index 0000000..e538109
--- /dev/null
+++ b/examples/bgp-unnumbered/host_vars/routerA.yml
@@ -0,0 +1,3 @@
+---
+bgp_unnumbered_asn: 64496
+bgp_unnumbered_router_id: 192.168.0.1
diff --git a/examples/bgp-unnumbered/host_vars/routerB.yml b/examples/bgp-unnumbered/host_vars/routerB.yml
new file mode 100644
index 0000000..e9e9e62
--- /dev/null
+++ b/examples/bgp-unnumbered/host_vars/routerB.yml
@@ -0,0 +1,3 @@
+---
+bgp_unnumbered_asn: 64499
+bgp_unnumbered_router_id: 192.168.0.2
diff --git a/examples/bgp-unnumbered/inventory.yml b/examples/bgp-unnumbered/inventory.yml
new file mode 100644
index 0000000..30bdaba
--- /dev/null
+++ b/examples/bgp-unnumbered/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/bgp-ipv6-unnumbered.html
+all:
+ children:
+ fabric:
+ hosts:
+ routerA:
+ ansible_host: clab-bgp-unnumbered-routerA # your router's address
+ routerB:
+ ansible_host: clab-bgp-unnumbered-routerB
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/bgp-unnumbered/site.yml b/examples/bgp-unnumbered/site.yml
new file mode 100644
index 0000000..a314bc9
--- /dev/null
+++ b/examples/bgp-unnumbered/site.yml
@@ -0,0 +1,11 @@
+---
+- name: BGP IPv6 unnumbered with extended next-hop
+ hosts: fabric
+ gather_facts: false
+ roles:
+ - vyos.blueprints.bgp_unnumbered
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/bgp-unnumbered/topology.clab.yml b/examples/bgp-unnumbered/topology.clab.yml
new file mode 100644
index 0000000..004cd54
--- /dev/null
+++ b/examples/bgp-unnumbered/topology.clab.yml
@@ -0,0 +1,13 @@
+name: bgp-unnumbered
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ routerA:
+ kind: vyosnetworks_vyos
+ routerB:
+ kind: vyosnetworks_vyos
+ links:
+ - endpoints: ["routerA:eth1", "routerB:eth1"]
+ - endpoints: ["routerA:eth2", "routerB:eth2"]
diff --git a/examples/bgp-unnumbered/verify.yml b/examples/bgp-unnumbered/verify.yml
new file mode 100644
index 0000000..07004ac
--- /dev/null
+++ b/examples/bgp-unnumbered/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the BGP fabric
+ hosts: fabric
+ gather_facts: false
+ tasks:
+ - name: BGP checks (all routers in one play for the route checks)
+ ansible.builtin.include_role:
+ name: vyos.blueprints.bgp_unnumbered
+ tasks_from: verify
diff --git a/examples/bridge-firewall/group_vars/bridge.yml b/examples/bridge-firewall/group_vars/bridge.yml
new file mode 100644
index 0000000..a72e386
--- /dev/null
+++ b/examples/bridge-firewall/group_vars/bridge.yml
@@ -0,0 +1,85 @@
+---
+# The page's internet uplink is eth0; this example uses eth8 because
+# containerlab reserves eth0 for management. Use eth0 on a real router.
+base_interfaces:
+ - {name: eth8, addresses: [203.0.113.1/24]}
+
+bridge_firewall_bridges:
+ - name: br0
+ description: Isolated L2 bridge
+ members:
+ - {interface: eth1, description: br0}
+ - {interface: eth2, description: br0}
+ prerouting:
+ default_action: drop
+ rules:
+ - {number: 10, description: Accept IPv6 traffic, ethernet_type: ipv6}
+ forward:
+ default_action: accept
+
+ - name: br1
+ description: L3 bridge br1
+ addresses: [10.1.1.1/24]
+ members:
+ - {interface: eth3, description: br1}
+ - {interface: eth4, description: br1}
+ prerouting:
+ default_action: accept
+ rules:
+ - number: 10
+ description: Drop DHCP discover
+ action: drop
+ protocol: udp
+ source: {port: "68"}
+ destination: {port: "67", mac_address: "ff:ff:ff:ff:ff:ff"}
+ log: true
+ - {number: 20, description: Drop IPv6 traffic, action: drop, ethernet_type: ipv6}
+ forward:
+ default_action: drop
+ rules:
+ - {number: 10, description: Accept ARP, ethernet_type: arp}
+ - {number: 20, description: Accept ipv4 from host, source: {address: 10.1.1.102}, state: [new]}
+ ip_forward:
+ rules:
+ - {number: 10, description: br1 - allow internet access, outbound_interface: eth8}
+ router_access: accept
+
+ - name: br2
+ description: L3 bridge br2
+ addresses: [10.2.2.1/24]
+ members:
+ - {interface: eth5, description: br2 - Host}
+ - {interface: eth6, description: br2 - Trusted DHCP Server}
+ - {interface: eth7, description: br2}
+ prerouting:
+ default_action: accept
+ rules:
+ - {number: 10, description: Drop IPv6 traffic, action: drop, ethernet_type: ipv6}
+ forward:
+ default_action: drop
+ rules:
+ - number: 10
+ description: Accept DHCP discover
+ protocol: udp
+ source: {port: "68"}
+ destination: {port: "67", mac_address: "ff:ff:ff:ff:ff:ff"}
+ - number: 20
+ description: Accept DHCP offers from trusted interface
+ protocol: udp
+ source: {port: "67"}
+ destination: {port: "68"}
+ inbound_interface: eth6
+ - number: 22
+ description: Drop all other DHCP offers
+ action: drop
+ protocol: udp
+ source: {port: "67"}
+ destination: {port: "68"}
+ log: true
+ - {number: 30, description: Accept ARP, ethernet_type: arp}
+ - {number: 40, description: Accept ipv4, ethernet_type: ipv4}
+ ip_forward:
+ rules:
+ - {number: 10, description: br2 - allow internet access, outbound_interface: eth8}
+ - {number: 20, description: br2 - allow access to br1, outbound_bridge: br1}
+ router_access: drop
diff --git a/examples/bridge-firewall/inventory.yml b/examples/bridge-firewall/inventory.yml
new file mode 100644
index 0000000..3d882a0
--- /dev/null
+++ b/examples/bridge-firewall/inventory.yml
@@ -0,0 +1,13 @@
+---
+# docs.vyos.io/en/1.5/configexamples/fwall-and-bridge.html
+all:
+ children:
+ bridge:
+ hosts:
+ r1:
+ ansible_host: clab-bridge-firewall-r1 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/bridge-firewall/site.yml b/examples/bridge-firewall/site.yml
new file mode 100644
index 0000000..c8ac898
--- /dev/null
+++ b/examples/bridge-firewall/site.yml
@@ -0,0 +1,12 @@
+---
+- name: Bridges and firewall
+ hosts: bridge
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.bridge_firewall
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/bridge-firewall/topology.clab.yml b/examples/bridge-firewall/topology.clab.yml
new file mode 100644
index 0000000..14b9b55
--- /dev/null
+++ b/examples/bridge-firewall/topology.clab.yml
@@ -0,0 +1,63 @@
+name: bridge-firewall
+topology:
+ nodes:
+ r1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ h1:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.0.1/24 dev eth1
+ - ip -6 addr add fd00:b0::1/64 dev eth1
+ h2:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.0.2/24 dev eth1
+ - ip -6 addr add fd00:b0::2/64 dev eth1
+ h3:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.1.1.102/24 dev eth1
+ - ip route replace default via 10.1.1.1
+ h4:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.1.1.103/24 dev eth1
+ - ip route replace default via 10.1.1.1
+ h5:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.2.2.5/24 dev eth1
+ - ip route replace default via 10.2.2.1
+ h6:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.2.2.6/24 dev eth1
+ - ip route replace default via 10.2.2.1
+ h7:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.2.2.7/24 dev eth1
+ - ip route replace default via 10.2.2.1
+ wan:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 203.0.113.100/24 dev eth1
+ - ip route replace default via 203.0.113.1
+ links:
+ - endpoints: ["r1:eth1", "h1:eth1"]
+ - endpoints: ["r1:eth2", "h2:eth1"]
+ - endpoints: ["r1:eth3", "h3:eth1"]
+ - endpoints: ["r1:eth4", "h4:eth1"]
+ - endpoints: ["r1:eth5", "h5:eth1"]
+ - endpoints: ["r1:eth6", "h6:eth1"]
+ - endpoints: ["r1:eth7", "h7:eth1"]
+ - endpoints: ["r1:eth8", "wan:eth1"]
diff --git a/examples/bridge-firewall/verify.yml b/examples/bridge-firewall/verify.yml
new file mode 100644
index 0000000..1af9772
--- /dev/null
+++ b/examples/bridge-firewall/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the bridges
+ hosts: bridge
+ gather_facts: false
+ tasks:
+ - name: Bridge checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.bridge_firewall
+ tasks_from: verify
diff --git a/examples/flexvpn-cisco/group_vars/spoke.yml b/examples/flexvpn-cisco/group_vars/spoke.yml
new file mode 100644
index 0000000..c0c5dd0
--- /dev/null
+++ b/examples/flexvpn-cisco/group_vars/spoke.yml
@@ -0,0 +1,44 @@
+---
+# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html - VyOS side
+gre_tunnel_interfaces:
+ - name: tun1
+ encapsulation: gre
+ adjust_mss: "1336"
+ mtu: 1376
+ remote: 10.1.1.6
+ source_address: 198.51.100.1
+
+ipsec_policy_based_peers:
+ - name: cisco_hub
+ psk_name: vyos_cisco_l
+ psk: secret # use ansible-vault for real devices
+ local_address: 198.51.100.1
+ remote_address: 10.1.1.6
+ local_id: vyos.net
+ remote_id: cisco.hub.net
+ connection_type: initiate
+ virtual_address: 0.0.0.0
+ tunnels:
+ - {id: 1, local_prefix: 198.51.100.1/32, remote_prefix: 10.1.1.6/32, protocol: gre}
+ipsec_policy_based_ike_group:
+ name: i1
+ key_exchange: ikev2
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 5
+ encryption: aes256
+ hash: sha256
+ipsec_policy_based_esp_group:
+ name: e1
+ lifetime: 3600
+ mode: tunnel
+ pfs: disable
+ proposal_id: 1
+ encryption: aes128
+ hash: sha256
+ipsec_policy_based_interfaces: [eth2] # WAN interface (198.51.100.1/24 on the page)
+ipsec_policy_based_options:
+ disable_route_autoinstall: true
+ flexvpn: true
+ interface: tun1
+ virtual_ip: true
diff --git a/examples/flexvpn-cisco/inventory.yml b/examples/flexvpn-cisco/inventory.yml
new file mode 100644
index 0000000..9368dca
--- /dev/null
+++ b/examples/flexvpn-cisco/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html
+# Only the VyOS spoke is configured here; the Cisco FlexVPN hub is configured
+# as shown on the page (there is no lab stand-in: VyOS cannot act as a FlexVPN hub).
+all:
+ children:
+ spoke:
+ hosts:
+ vyos:
+ ansible_host: 192.0.2.10 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/flexvpn-cisco/site.yml b/examples/flexvpn-cisco/site.yml
new file mode 100644
index 0000000..6204e3f
--- /dev/null
+++ b/examples/flexvpn-cisco/site.yml
@@ -0,0 +1,12 @@
+---
+- name: FlexVPN spoke - GRE over IPsec to a Cisco hub
+ hosts: spoke
+ gather_facts: false
+ roles:
+ - vyos.blueprints.gre_tunnel
+ - vyos.blueprints.ipsec_policy_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/flexvpn-cisco/verify.yml b/examples/flexvpn-cisco/verify.yml
new file mode 100644
index 0000000..e637db8
--- /dev/null
+++ b/examples/flexvpn-cisco/verify.yml
@@ -0,0 +1,13 @@
+---
+- name: Check the FlexVPN spoke
+ hosts: spoke
+ gather_facts: false
+ tasks:
+ - name: Tunnel interface checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.gre_tunnel
+ tasks_from: verify
+ - name: IPsec checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_policy_based
+ tasks_from: verify
diff --git a/examples/ipsec-route-based/group_vars/vpn.yml b/examples/ipsec-route-based/group_vars/vpn.yml
new file mode 100644
index 0000000..092d64b
--- /dev/null
+++ b/examples/ipsec-route-based/group_vars/vpn.yml
@@ -0,0 +1,17 @@
+---
+# IKE and IPsec parameters from the page's tables
+ipsec_route_based_ike_group:
+ name: IKE-GROUP
+ key_exchange: ikev1
+ lifetime: 28800
+ dh_group: 14
+ encryption: aes128
+ hash: sha1
+ close_action: start
+ dead_peer_detection: {action: restart, interval: 10, timeout: 30}
+ipsec_route_based_esp_group:
+ name: ESP-GROUP
+ lifetime: 3600
+ pfs: disable
+ encryption: aes256
+ hash: sha256
diff --git a/examples/ipsec-route-based/host_vars/cisco.yml b/examples/ipsec-route-based/host_vars/cisco.yml
new file mode 100644
index 0000000..f536639
--- /dev/null
+++ b/examples/ipsec-route-based/host_vars/cisco.yml
@@ -0,0 +1,20 @@
+---
+# Lab stand-in for the page's Cisco router, using the page's Cisco values
+base_interfaces:
+ - {name: eth1, addresses: [10.0.2.2/30]}
+ - {name: eth2, addresses: [192.168.10.1/24]}
+ - {name: eth3, addresses: [192.168.11.1/24]}
+ipsec_route_based_peers:
+ - name: VYOS
+ local_address: 10.0.2.2
+ remote_address: 10.0.1.2
+ psk: dGVzdA==
+ psk_type: base64
+ psk_name: AUTH-PSK
+ connection_type: none
+ vti: {interface: vti1, address: 10.100.100.2/30, mtu: 1438}
+ipsec_route_based_ospf:
+ router_id: 1.1.1.1
+ networks: [10.100.100.0/30, 192.168.10.0/24, 192.168.11.0/24]
+ passive_interfaces: [eth2, eth3]
+ipsec_route_based_default_gateway: 10.0.2.1
diff --git a/examples/ipsec-route-based/host_vars/vyos.yml b/examples/ipsec-route-based/host_vars/vyos.yml
new file mode 100644
index 0000000..8674a81
--- /dev/null
+++ b/examples/ipsec-route-based/host_vars/vyos.yml
@@ -0,0 +1,20 @@
+---
+# WAN is eth1 here, eth0 on the page (containerlab uses eth0 for management)
+base_interfaces:
+ - {name: eth1, addresses: [10.0.1.2/30]}
+ - {name: eth2, addresses: [192.168.0.1/24]}
+ - {name: eth3, addresses: [192.168.1.1/24]}
+ipsec_route_based_peers:
+ - name: CISCO
+ local_address: 10.0.1.2
+ remote_address: 10.0.2.2
+ psk: dGVzdA== # use ansible-vault for real devices
+ psk_type: base64
+ psk_name: AUTH-PSK
+ connection_type: initiate
+ vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438}
+ipsec_route_based_ospf:
+ router_id: 2.2.2.2
+ networks: [10.100.100.0/30, 192.168.0.0/24, 192.168.1.0/24]
+ passive_interfaces: [eth2, eth3]
+ipsec_route_based_default_gateway: 10.0.1.1
diff --git a/examples/ipsec-route-based/inventory.yml b/examples/ipsec-route-based/inventory.yml
new file mode 100644
index 0000000..4d42e0d
--- /dev/null
+++ b/examples/ipsec-route-based/inventory.yml
@@ -0,0 +1,18 @@
+---
+# docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html
+# "vyos" is the router this collection configures. "cisco" is a second VyOS in
+# the lab standing in for the page's Cisco router; on a real network, configure
+# the Cisco side as shown on the page and remove it from this inventory.
+all:
+ children:
+ vpn:
+ hosts:
+ vyos:
+ ansible_host: clab-ipsec-route-based-vyos # your router's address
+ cisco:
+ ansible_host: clab-ipsec-route-based-cisco
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/ipsec-route-based/site.yml b/examples/ipsec-route-based/site.yml
new file mode 100644
index 0000000..db7d07b
--- /dev/null
+++ b/examples/ipsec-route-based/site.yml
@@ -0,0 +1,12 @@
+---
+- name: Route-based site-to-site IPsec
+ hosts: vpn
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.ipsec_route_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/ipsec-route-based/topology.clab.yml b/examples/ipsec-route-based/topology.clab.yml
new file mode 100644
index 0000000..23e49ac
--- /dev/null
+++ b/examples/ipsec-route-based/topology.clab.yml
@@ -0,0 +1,25 @@
+name: ipsec-route-based
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ vyos:
+ kind: vyosnetworks_vyos
+ cisco:
+ kind: vyosnetworks_vyos
+ isp:
+ kind: linux
+ image: alpine:3
+ exec: ["sysctl -w net.ipv4.ip_forward=1", "ip addr add 10.0.1.1/30 dev eth1", "ip addr add 10.0.2.1/30 dev eth2"]
+ pc1: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.0.2/24 dev eth1", "ip route replace default via 192.168.0.1"]}
+ pc2: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.1.2/24 dev eth1", "ip route replace default via 192.168.1.1"]}
+ pc3: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.10.2/24 dev eth1", "ip route replace default via 192.168.10.1"]}
+ pc4: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.11.2/24 dev eth1", "ip route replace default via 192.168.11.1"]}
+ links:
+ - endpoints: ["vyos:eth1", "isp:eth1"]
+ - endpoints: ["cisco:eth1", "isp:eth2"]
+ - endpoints: ["vyos:eth2", "pc1:eth1"]
+ - endpoints: ["vyos:eth3", "pc2:eth1"]
+ - endpoints: ["cisco:eth2", "pc3:eth1"]
+ - endpoints: ["cisco:eth3", "pc4:eth1"]
diff --git a/examples/ipsec-route-based/verify.yml b/examples/ipsec-route-based/verify.yml
new file mode 100644
index 0000000..268ff9c
--- /dev/null
+++ b/examples/ipsec-route-based/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the VPN
+ hosts: vpn
+ gather_facts: false
+ tasks:
+ - name: IPsec and OSPF checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
diff --git a/examples/ospf-unnumbered/group_vars/fabric.yml b/examples/ospf-unnumbered/group_vars/fabric.yml
new file mode 100644
index 0000000..9fa7a6c
--- /dev/null
+++ b/examples/ospf-unnumbered/group_vars/fabric.yml
@@ -0,0 +1,4 @@
+---
+ospf_unnumbered_interfaces: [eth1, eth2]
+ospf_unnumbered_md5_key: yourpassword # use ansible-vault for real devices
+ospf_unnumbered_group: fabric
diff --git a/examples/ospf-unnumbered/host_vars/routerA.yml b/examples/ospf-unnumbered/host_vars/routerA.yml
new file mode 100644
index 0000000..e3803e6
--- /dev/null
+++ b/examples/ospf-unnumbered/host_vars/routerA.yml
@@ -0,0 +1,5 @@
+---
+ospf_unnumbered_router_id: 192.168.0.1
+# LAN address; eth0 on the docs page, eth3 here because containerlab uses eth0 for management
+base_interfaces:
+ - {name: eth3, addresses: [10.0.0.1/24]}
diff --git a/examples/ospf-unnumbered/host_vars/routerB.yml b/examples/ospf-unnumbered/host_vars/routerB.yml
new file mode 100644
index 0000000..b2aac66
--- /dev/null
+++ b/examples/ospf-unnumbered/host_vars/routerB.yml
@@ -0,0 +1,4 @@
+---
+ospf_unnumbered_router_id: 192.168.0.2
+base_interfaces:
+ - {name: eth3, addresses: [10.0.0.2/24]}
diff --git a/examples/ospf-unnumbered/inventory.yml b/examples/ospf-unnumbered/inventory.yml
new file mode 100644
index 0000000..97bc8d4
--- /dev/null
+++ b/examples/ospf-unnumbered/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/ospf-unnumbered.html
+all:
+ children:
+ fabric:
+ hosts:
+ routerA:
+ ansible_host: clab-ospf-unnumbered-routerA # your router's address
+ routerB:
+ ansible_host: clab-ospf-unnumbered-routerB
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/ospf-unnumbered/site.yml b/examples/ospf-unnumbered/site.yml
new file mode 100644
index 0000000..ad9bd0a
--- /dev/null
+++ b/examples/ospf-unnumbered/site.yml
@@ -0,0 +1,12 @@
+---
+- name: OSPF unnumbered with ECMP
+ hosts: fabric
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.ospf_unnumbered
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/ospf-unnumbered/topology.clab.yml b/examples/ospf-unnumbered/topology.clab.yml
new file mode 100644
index 0000000..4b2ae23
--- /dev/null
+++ b/examples/ospf-unnumbered/topology.clab.yml
@@ -0,0 +1,25 @@
+name: ospf-unnumbered
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ routerA:
+ kind: vyosnetworks_vyos
+ routerB:
+ kind: vyosnetworks_vyos
+ # shared 10.0.0.0/24 LAN, as on the docs page: a Linux bridge plus a test host
+ lan:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set br0 up
+ - ip addr add 10.0.0.10/24 dev br0
+ links:
+ - endpoints: ["routerA:eth1", "routerB:eth1"]
+ - endpoints: ["routerA:eth2", "routerB:eth2"]
+ - endpoints: ["routerA:eth3", "lan:eth1"]
+ - endpoints: ["routerB:eth3", "lan:eth2"]
diff --git a/examples/ospf-unnumbered/verify.yml b/examples/ospf-unnumbered/verify.yml
new file mode 100644
index 0000000..f5b7b6f
--- /dev/null
+++ b/examples/ospf-unnumbered/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the OSPF fabric
+ hosts: fabric
+ gather_facts: false
+ tasks:
+ - name: OSPF checks (all routers in one play for the route checks)
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ospf_unnumbered
+ tasks_from: verify
diff --git a/examples/policy-ipsec-firewall/group_vars/sites.yml b/examples/policy-ipsec-firewall/group_vars/sites.yml
new file mode 100644
index 0000000..72cb49a
--- /dev/null
+++ b/examples/policy-ipsec-firewall/group_vars/sites.yml
@@ -0,0 +1,5 @@
+---
+# IPsec settings shared by both routers, as on the page
+ipsec_policy_based_ike_group: {name: IKE-GROUP, key_exchange: ikev2, proposal_id: 1, dh_group: 14, encryption: aes256, hash: sha256}
+ipsec_policy_based_esp_group: {name: ESP-GROUP, mode: tunnel, proposal_id: 1, encryption: aes256, hash: sha256}
+ipsec_policy_based_interfaces: [eth3]
diff --git a/examples/policy-ipsec-firewall/host_vars/left.yml b/examples/policy-ipsec-firewall/host_vars/left.yml
new file mode 100644
index 0000000..e6fe1ee
--- /dev/null
+++ b/examples/policy-ipsec-firewall/host_vars/left.yml
@@ -0,0 +1,98 @@
+---
+# WAN is eth3 here, eth0 on the page (containerlab uses eth0 for management).
+# Input rule 5 keeps containerlab management reachable - drop it on a real router
+# and make sure your management source is allowed (rule 20, TRUSTED) instead.
+ipsec_policy_based_peers:
+ - name: RIGHT
+ psk_name: RIGHT
+ psk: p4ssw0rd # use ansible-vault for real devices
+ authentication_ids: false
+ local_address: 198.51.100.14
+ remote_address: 192.0.2.130
+ connection_type: initiate
+ tunnels:
+ - {id: 0, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.21.0/24}
+ - {id: 1, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.22.0/24}
+ - {id: 2, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.21.0/24}
+ - {id: 3, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.22.0/24}
+ipsec_policy_based_default_gateway: 198.51.100.13
+firewall_groups:
+ network:
+ - name: LOCAL-NETS
+ networks: [10.1.11.0/24, 10.1.12.0/24]
+ - name: REMOTE-NETS
+ networks: [10.2.21.0/24, 10.2.22.0/24]
+ - name: TRUSTED
+ networks: [198.51.100.125/32, 203.0.113.0/24, 10.1.11.0/24, 192.168.70.0/24]
+firewall_ipv4:
+ forward:
+ default_action: drop
+ rules:
+ - number: 1
+ action: accept
+ state: {established: true, related: true}
+ - number: 2
+ action: drop
+ state: {invalid: true}
+ - number: 10
+ action: accept
+ source:
+ group: {network_group: LOCAL-NETS}
+ - number: 20
+ action: accept
+ source:
+ group: {network_group: REMOTE-NETS}
+ destination:
+ group: {network_group: LOCAL-NETS}
+ input:
+ default_action: drop
+ rules:
+ - number: 1
+ action: accept
+ state: {established: true, related: true}
+ - number: 2
+ action: drop
+ state: {invalid: true}
+ - number: 5
+ action: accept
+ description: containerlab management
+ inbound_interface: {name: eth0}
+ - number: 10
+ action: accept
+ protocol: udp
+ destination: {port: '500,4500'}
+ inbound_interface: {name: eth3}
+ - number: 15
+ action: accept
+ protocol: esp
+ inbound_interface: {name: eth3}
+ - number: 20
+ action: accept
+ protocol: tcp
+ destination: {port: '22'}
+ source:
+ group: {network_group: TRUSTED}
+ - number: 25
+ action: accept
+ protocol: udp
+ destination: {port: '53'}
+ source:
+ group: {network_group: LOCAL-NETS}
+ - {number: 30, action: accept, protocol: icmp}
+nat_source_rules:
+ - id: 10
+ exclude: true
+ outbound_interface: {name: eth3}
+ source: {network_group: LOCAL-NETS}
+ destination: {network_group: REMOTE-NETS}
+ - id: 20
+ outbound_interface: {name: eth3}
+ source: {network_group: LOCAL-NETS}
+ translation: {address: masquerade}
+base_interfaces:
+ - name: eth3
+ addresses: [198.51.100.14/30]
+ - name: eth1.111
+ addresses: [10.1.11.1/24]
+ - name: eth2.112
+ addresses: [10.1.12.1/24]
diff --git a/examples/policy-ipsec-firewall/host_vars/right.yml b/examples/policy-ipsec-firewall/host_vars/right.yml
new file mode 100644
index 0000000..ab629da
--- /dev/null
+++ b/examples/policy-ipsec-firewall/host_vars/right.yml
@@ -0,0 +1,23 @@
+---
+# The page sets no default route on RIGHT; it needs one to reach LEFT.
+ipsec_policy_based_peers:
+ - name: LEFT
+ psk_name: LEFT
+ psk: p4ssw0rd # use ansible-vault for real devices
+ authentication_ids: false
+ local_address: 192.0.2.130
+ remote_address: 198.51.100.14
+ connection_type: none
+ tunnels:
+ - {id: 0, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.11.0/24}
+ - {id: 1, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.11.0/24}
+ - {id: 2, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.12.0/24}
+ - {id: 3, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.12.0/24}
+base_interfaces:
+ - name: eth3
+ addresses: [192.0.2.130/30]
+ - name: eth1.221
+ addresses: [10.2.21.1/24]
+ - name: eth2.222
+ addresses: [10.2.22.1/24]
+ipsec_policy_based_default_gateway: 192.0.2.129
diff --git a/examples/policy-ipsec-firewall/inventory.yml b/examples/policy-ipsec-firewall/inventory.yml
new file mode 100644
index 0000000..95eeddb
--- /dev/null
+++ b/examples/policy-ipsec-firewall/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html
+all:
+ children:
+ sites:
+ hosts:
+ left:
+ ansible_host: clab-policy-ipsec-firewall-left # your router's address
+ right:
+ ansible_host: clab-policy-ipsec-firewall-right
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/policy-ipsec-firewall/site.yml b/examples/policy-ipsec-firewall/site.yml
new file mode 100644
index 0000000..87ea9a5
--- /dev/null
+++ b/examples/policy-ipsec-firewall/site.yml
@@ -0,0 +1,15 @@
+---
+- name: Policy-based IPsec with firewall and NAT
+ hosts: sites
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.ipsec_policy_based
+ # firewall and nat only have inputs on LEFT, as on the page; on RIGHT they do nothing
+ - vyos.blueprints.firewall
+ - vyos.blueprints.nat
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/policy-ipsec-firewall/topology.clab.yml b/examples/policy-ipsec-firewall/topology.clab.yml
new file mode 100644
index 0000000..e512c9c
--- /dev/null
+++ b/examples/policy-ipsec-firewall/topology.clab.yml
@@ -0,0 +1,51 @@
+name: policy-ipsec-firewall
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ left:
+ kind: vyosnetworks_vyos
+ right:
+ kind: vyosnetworks_vyos
+ isp:
+ kind: linux
+ image: alpine:3
+ exec:
+ - sysctl -w net.ipv4.ip_forward=1
+ - ip addr add 198.51.100.13/30 dev eth1
+ - ip addr add 192.0.2.129/30 dev eth2
+ - ip addr add 203.0.113.1/24 dev eth3
+ internet:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 203.0.113.10/24 dev eth1", "ip route replace default via 203.0.113.1"]
+ l11:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.111 type vlan id 111", "ip link set eth1.111 up",
+ "ip addr add 10.1.11.10/24 dev eth1.111", "ip route replace default via 10.1.11.1"]
+ l12:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.112 type vlan id 112", "ip link set eth1.112 up",
+ "ip addr add 10.1.12.10/24 dev eth1.112", "ip route replace default via 10.1.12.1"]
+ r21:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.221 type vlan id 221", "ip link set eth1.221 up",
+ "ip addr add 10.2.21.10/24 dev eth1.221", "ip route replace default via 10.2.21.1"]
+ r22:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.222 type vlan id 222", "ip link set eth1.222 up",
+ "ip addr add 10.2.22.10/24 dev eth1.222", "ip route replace default via 10.2.22.1"]
+ links:
+ # WAN is eth3 here (eth0 on the page; eth0 is containerlab management)
+ - endpoints: ["left:eth3", "isp:eth1"]
+ - endpoints: ["right:eth3", "isp:eth2"]
+ - endpoints: ["isp:eth3", "internet:eth1"]
+ - endpoints: ["left:eth1", "l11:eth1"]
+ - endpoints: ["left:eth2", "l12:eth1"]
+ - endpoints: ["right:eth1", "r21:eth1"]
+ - endpoints: ["right:eth2", "r22:eth1"]
diff --git a/examples/policy-ipsec-firewall/verify.yml b/examples/policy-ipsec-firewall/verify.yml
new file mode 100644
index 0000000..d1006cf
--- /dev/null
+++ b/examples/policy-ipsec-firewall/verify.yml
@@ -0,0 +1,22 @@
+---
+- name: Check both sites
+ hosts: sites
+ gather_facts: false
+ tasks:
+ - name: IPsec checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_policy_based
+ tasks_from: verify
+
+- name: Check firewall and NAT on LEFT
+ hosts: left
+ gather_facts: false
+ tasks:
+ - name: Firewall checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.firewall
+ tasks_from: verify
+ - name: NAT checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.nat
+ tasks_from: verify
diff --git a/examples/vrf-firewall/group_vars/router.yml b/examples/vrf-firewall/group_vars/router.yml
new file mode 100644
index 0000000..3045bce
--- /dev/null
+++ b/examples/vrf-firewall/group_vars/router.yml
@@ -0,0 +1,51 @@
+---
+# The page's WAN is PPPoE (pppoe0); this example uses eth3 instead, because
+# PPPoE needs an access concentrator. Swap eth3 back to pppoe0 on a real router.
+base_interfaces:
+ - {name: eth1, addresses: [10.100.100.1/24]}
+ - {name: eth2}
+ - {name: eth2.150, addresses: [10.150.150.1/24]}
+ - {name: eth2.160, addresses: [10.160.160.1/24]}
+ - {name: eth2.3500, addresses: [172.16.20.1/24]}
+ - {name: eth3, addresses: [203.0.113.1/24]}
+vrf_firewall_vrfs:
+ - name: MGMT
+ table: 102
+ interfaces: [eth1]
+ routes:
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: WAN
+ table: 101
+ interfaces: [eth3]
+ routes:
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: LAN
+ table: 103
+ interfaces: [eth2.150, eth2.160]
+ routes:
+ - {dest: 0.0.0.0/0, interface: eth3, vrf: WAN}
+ - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: PROD
+ table: 104
+ interfaces: [eth2.3500]
+ routes:
+ - {dest: 0.0.0.0/0, interface: eth3, vrf: WAN}
+ - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT}
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+
+vrf_firewall_forward_rules:
+ - {number: 10, description: MGMT - Allow to LAN and PROD, inbound_interface: MGMT, outbound_interface: eth2*}
+ - {number: 99, action: drop, description: MGMT - Drop all going to mgmt, outbound_interface: eth1}
+ - {number: 120, description: LAN - Allow to PROD, inbound_interface: LAN, outbound_interface: eth2.3500}
+ - {number: 130, description: LAN - Allow internet, inbound_interface: LAN, outbound_interface: eth3}
+
+vrf_firewall_input_rules:
+ # containerlab management only - on a real router the page allows input from MGMT only
+ - {number: 5, description: containerlab management, inbound_interface: eth0}
+ - {number: 10, description: MGMT - Allow input, inbound_interface: MGMT}
diff --git a/examples/vrf-firewall/inventory.yml b/examples/vrf-firewall/inventory.yml
new file mode 100644
index 0000000..f3e6b10
--- /dev/null
+++ b/examples/vrf-firewall/inventory.yml
@@ -0,0 +1,13 @@
+---
+# docs.vyos.io/en/1.5/configexamples/fwall-and-vrf.html
+all:
+ children:
+ router:
+ hosts:
+ r1:
+ ansible_host: clab-vrf-firewall-r1 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/vrf-firewall/site.yml b/examples/vrf-firewall/site.yml
new file mode 100644
index 0000000..0f0b66a
--- /dev/null
+++ b/examples/vrf-firewall/site.yml
@@ -0,0 +1,12 @@
+---
+- name: VRFs and firewall
+ hosts: router
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.vrf_firewall
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/vrf-firewall/topology.clab.yml b/examples/vrf-firewall/topology.clab.yml
new file mode 100644
index 0000000..0612a1f
--- /dev/null
+++ b/examples/vrf-firewall/topology.clab.yml
@@ -0,0 +1,43 @@
+name: vrf-firewall
+topology:
+ nodes:
+ r1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ mgmt:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 10.100.100.10/24 dev eth1", "ip route replace default via 10.100.100.1"]
+ # VLAN-aware bridge for the eth2 trunk (vif 150 = LAN, vif 3500 = PROD)
+ sw:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge vlan_filtering 1
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set eth3 master br0
+ - bridge vlan add dev eth1 vid 150
+ - bridge vlan add dev eth1 vid 3500
+ - bridge vlan add dev eth2 vid 150 pvid untagged
+ - bridge vlan add dev eth3 vid 3500 pvid untagged
+ - ip link set br0 up
+ lan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 10.150.150.10/24 dev eth1", "ip route replace default via 10.150.150.1"]
+ prod:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 172.16.20.10/24 dev eth1", "ip route replace default via 172.16.20.1"]
+ # stands in for the page's PPPoE uplink
+ wan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 203.0.113.100/24 dev eth1", "ip route replace default via 203.0.113.1"]
+ links:
+ - endpoints: ["r1:eth1", "mgmt:eth1"]
+ - endpoints: ["r1:eth2", "sw:eth1"]
+ - endpoints: ["sw:eth2", "lan:eth1"]
+ - endpoints: ["sw:eth3", "prod:eth1"]
+ - endpoints: ["r1:eth3", "wan:eth1"]
diff --git a/examples/vrf-firewall/verify.yml b/examples/vrf-firewall/verify.yml
new file mode 100644
index 0000000..6a66c8f
--- /dev/null
+++ b/examples/vrf-firewall/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the VRFs
+ hosts: router
+ gather_facts: false
+ tasks:
+ - name: VRF checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.vrf_firewall
+ tasks_from: verify
diff --git a/examples/zone-policy/group_vars/firewall.yml b/examples/zone-policy/group_vars/firewall.yml
new file mode 100644
index 0000000..13c0188
--- /dev/null
+++ b/examples/zone-policy/group_vars/firewall.yml
@@ -0,0 +1,80 @@
+---
+# Router on a stick, as on the docs page. The page trunks VLANs 10/20/30 on
+# eth0; this example uses eth1 because containerlab reserves eth0 for
+# management.
+base_interfaces:
+ - {name: eth1, description: trunk}
+ - {name: eth1.10, description: WAN, addresses: [172.16.10.1/24, "2001:db8:0:9999::1/64"]}
+ - {name: eth1.20, description: LAN, addresses: [192.168.100.1/24, "2001:db8:0:aaaa::1/64"]}
+ - {name: eth1.30, description: DMZ, addresses: [192.168.200.1/24, "2001:db8:0:bbbb::1/64"]}
+
+zone_firewall_zones:
+ # mgmt exists only so Ansible keeps its SSH session in containerlab. On a real
+ # router follow the page: the admin console (192.168.100.10) reaches the router
+ # through the lan-local rule 800, so make sure that rule is in place first.
+ - {name: mgmt, interfaces: [eth0]}
+ - {name: wan, interfaces: [eth1.10]}
+ - {name: lan, interfaces: [eth1.20]}
+ - {name: dmz, interfaces: [eth1.30]}
+ - {name: local, local: true}
+
+zone_firewall_policies:
+ - {from: mgmt, to: local, default_action: accept}
+ - from: wan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}}
+ - {number: 200, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "80,443"}}
+ - {number: 500, protocol: tcp, destination: {address: 192.168.200.200, port: "25"}}
+ - {number: 500, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "25"}}
+ - {number: 600, protocol: tcp, destination: {address: 192.168.200.200, port: "53"}}
+ - {number: 600, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "53"}}
+ - from: dmz
+ to: local
+ rules:
+ - {number: 400, protocol: tcp, destination: {port: "123"}}
+ - {number: 600, protocol: tcp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: lan
+ to: local
+ rules:
+ - {number: 400, protocol: tcp, destination: {port: "123"}}
+ - {number: 600, protocol: tcp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {port: "22"}}
+ - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {port: "22"}}
+ - from: lan
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - {number: 800, protocol: tcp, destination: {port: "22"}}
+ - from: dmz
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - {number: 600, protocol: tcp_udp, destination: {port: "53"}}
+ - {number: 800, protocol: tcp, destination: {port: "22"}}
+ - from: local
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - from: local
+ to: dmz
+ rules:
+ - {number: 500, protocol: tcp, destination: {port: "25"}}
+ - {number: 600, protocol: tcp_udp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: local
+ to: lan
+ rules:
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: lan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {address: 192.168.200.200, port: "22"}}
+ - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {address: "2001:db8:0:bbbb::200", port: "22"}}
+ - {number: 900, protocol: tcp, destination: {port: "993"}}
diff --git a/examples/zone-policy/inventory.yml b/examples/zone-policy/inventory.yml
new file mode 100644
index 0000000..206412d
--- /dev/null
+++ b/examples/zone-policy/inventory.yml
@@ -0,0 +1,13 @@
+---
+# docs.vyos.io/en/1.5/configexamples/zone-policy.html
+all:
+ children:
+ firewall:
+ hosts:
+ fw1:
+ ansible_host: clab-zone-policy-fw1 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/zone-policy/site.yml b/examples/zone-policy/site.yml
new file mode 100644
index 0000000..4d82cdf
--- /dev/null
+++ b/examples/zone-policy/site.yml
@@ -0,0 +1,12 @@
+---
+- name: Zone-based firewall
+ hosts: firewall
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.zone_firewall
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/zone-policy/topology.clab.yml b/examples/zone-policy/topology.clab.yml
new file mode 100644
index 0000000..63080d2
--- /dev/null
+++ b/examples/zone-policy/topology.clab.yml
@@ -0,0 +1,40 @@
+name: zone-policy
+topology:
+ nodes:
+ fw1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ # one host per network on its own VLAN, behind a VLAN-aware bridge
+ sw:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge vlan_filtering 1
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set eth3 master br0
+ - ip link set eth4 master br0
+ - bridge vlan add dev eth1 vid 10
+ - bridge vlan add dev eth1 vid 20
+ - bridge vlan add dev eth1 vid 30
+ - bridge vlan add dev eth2 vid 10 pvid untagged
+ - bridge vlan add dev eth3 vid 20 pvid untagged
+ - bridge vlan add dev eth4 vid 30 pvid untagged
+ - ip link set br0 up
+ wan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 172.16.10.100/24 dev eth1", "ip route replace default via 172.16.10.1"]
+ lan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.100.10/24 dev eth1", "ip route replace default via 192.168.100.1"]
+ dmz:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.200.200/24 dev eth1", "ip route replace default via 192.168.200.1"]
+ links:
+ - endpoints: ["fw1:eth1", "sw:eth1"]
+ - endpoints: ["sw:eth2", "wan:eth1"]
+ - endpoints: ["sw:eth3", "lan:eth1"]
+ - endpoints: ["sw:eth4", "dmz:eth1"]
diff --git a/examples/zone-policy/verify.yml b/examples/zone-policy/verify.yml
new file mode 100644
index 0000000..3132524
--- /dev/null
+++ b/examples/zone-policy/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the zone firewall
+ hosts: firewall
+ gather_facts: false
+ tasks:
+ - name: Zone checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.zone_firewall
+ tasks_from: verify