diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-06 08:40:09 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-06 08:40:09 +1000 |
| commit | f0bd8a9aec89892ec4e9249c8b51b383aea8a7f2 (patch) | |
| tree | 430a3872734354551b79f6f30ccdaba0f538b765 /examples | |
| parent | 8ee802e41374942965b6b93cfb4534725ef45145 (diff) | |
| download | vyos.blueprints-f0bd8a9aec89892ec4e9249c8b51b383aea8a7f2.tar.gz vyos.blueprints-f0bd8a9aec89892ec4e9249c8b51b383aea8a7f2.zip | |
T9393: new roles
Diffstat (limited to 'examples')
79 files changed, 2398 insertions, 0 deletions
diff --git a/examples/README.md b/examples/README.md index 8c149d5..f2ac5ab 100644 --- a/examples/README.md +++ b/examples/README.md @@ -17,6 +17,16 @@ Each directory is a complete, runnable Ansible project: | `flexvpn-cisco/` | `gre_tunnel`, `ipsec_policy_based` | [Site-to-Site IPSec VPN to Cisco using FlexVPN](https://docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html) (no containerlab topology: needs a Cisco FlexVPN hub) | | `azure-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html) (no containerlab topology: the far end is Azure) | | `azure-vpn-dual-bgp/` | `ipsec_route_based` | [Route-Based Redundant Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html) (no containerlab topology: the far end is Azure) | +| `gcp-ha-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Google Cloud HA VPN](https://docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html) (no containerlab topology: the far end is Google Cloud) | +| `ha-walkthrough/` | `bonding`, `base`, `ha_vrrp`, `nat`, `wireguard`, `route_policy`, `ospf`, `bgp` | [High Availability Walkthrough](https://docs.vyos.io/en/1.5/configexamples/ha.html) - the complete page | +| `inter-vrf/` | `base`, `route_policy`, `vrf_lite` | [Inter-VRF Routing over VRF Lite](https://docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html) (run `isp.yml` for the lab ISP) | +| `wan-load-balancing/` | `base`, `wan_load_balance` | [WAN Load Balancer examples](https://docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html) - example 1 by default, `-e @variants/exampleN.yml` for examples 2-5 | +| `pppoe-ipv6-home/` | `pppoe`, `router_advert`, `firewall` | [PPPoE IPv6 Basic Setup for Home Network](https://docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html) (run `isp.yml` for the lab ISP) | +| `qos/` | `base`, `qos` | [QoS example](https://docs.vyos.io/en/1.5/configexamples/qos.html) | +| `isis-segment-routing/` | `base`, `isis` | [Segment-routing IS-IS example](https://docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html) (P3 is a VyOS stand-in for the XRv in the lab) | +| `l3vpn-hub-and-spoke/` | `base`, `ospf`, `mpls_ldp`, `l3vpn`, `vrf_lite`, `bgp` | [L3VPN for Hub-and-Spoke connectivity with VyOS](https://docs.vyos.io/en/1.5/configexamples/l3vpn-hub-and-spoke.html) (all 12 routers; reduced lab in the Molecule scenario) | +| `l2tp-lns/` | `base`, `nat`, `l2tp_lns` | [PPPoE over L2TP](https://docs.vyos.io/en/1.5/configexamples/lac-lns.html) (the lab topology stands in for the Cisco LAC and adds FreeRADIUS) | +| `dmvpn-dual-hub/` | `base`, `gre_tunnel`, `dmvpn`, `ospf` | [DMVPN Dual HUB Dual Cloud](https://docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html) (VyOS hubs and spokes) | Most examples ship a `topology.clab.yml`, so you can try them against containerized VyOS before pointing it at real routers: diff --git a/examples/dmvpn-dual-hub/group_vars/dmvpn.yml b/examples/dmvpn-dual-hub/group_vars/dmvpn.yml new file mode 100644 index 0000000..8570c1a --- /dev/null +++ b/examples/dmvpn-dual-hub/group_vars/dmvpn.yml @@ -0,0 +1,29 @@ +--- +# Shared by all VyOS DMVPN nodes - docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html +# WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management). +dmvpn_ipsec: + interfaces: + - eth1 + ike_group: + name: IKE-HUB + key_exchange: ikev1 + lifetime: 3600 + proposal_id: 1 + dh_group: 2 + encryption: aes256 + hash: sha1 + esp_group: + name: ESP-HUB + lifetime: 1800 + mode: transport + pfs: disable + proposal_id: 1 + encryption: aes256 + hash: sha1 + profile: + name: NHRPVPN + psk: '{{ vault_dmvpn_psk }}' + bind_tunnels: '{{ gre_tunnel_interfaces | map(attribute=''name'') | list }}' +dmvpn_drop_unprotected_gre: + rule: 10 +ospf_passive_interface_default: true diff --git a/examples/dmvpn-dual-hub/host_vars/hub1.yml b/examples/dmvpn-dual-hub/host_vars/hub1.yml new file mode 100644 index 0000000..868c9aa --- /dev/null +++ b/examples/dmvpn-dual-hub/host_vars/hub1.yml @@ -0,0 +1,32 @@ +--- +base_interfaces: + - name: eth1 + addresses: + - 10.0.0.2/30 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.0.0.1 +gre_tunnel_interfaces: + - name: tun100 + addresses: + - 10.100.100.1/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 42 + source_interface: eth1 +dmvpn_nhrp_tunnels: + - name: tun100 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: dynamic + network_id: 1 + redirect: true + registration_no_unique: true +ospf_interfaces: + - name: tun100 + area: '0' + network: point-to-multipoint + passive: false +base_hostname: HUB-1 diff --git a/examples/dmvpn-dual-hub/host_vars/hub2.yml b/examples/dmvpn-dual-hub/host_vars/hub2.yml new file mode 100644 index 0000000..07699e5 --- /dev/null +++ b/examples/dmvpn-dual-hub/host_vars/hub2.yml @@ -0,0 +1,32 @@ +--- +base_interfaces: + - name: eth1 + addresses: + - 10.0.1.2/30 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.0.1.1 +gre_tunnel_interfaces: + - name: tun101 + addresses: + - 10.100.101.1/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 43 + source_interface: eth1 +dmvpn_nhrp_tunnels: + - name: tun101 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: dynamic + network_id: 2 + redirect: true + registration_no_unique: true +ospf_interfaces: + - name: tun101 + area: '0' + network: point-to-multipoint + passive: false +base_hostname: HUB-2 diff --git a/examples/dmvpn-dual-hub/host_vars/spoke2.yml b/examples/dmvpn-dual-hub/host_vars/spoke2.yml new file mode 100644 index 0000000..911052e --- /dev/null +++ b/examples/dmvpn-dual-hub/host_vars/spoke2.yml @@ -0,0 +1,63 @@ +--- +base_interfaces: + - name: eth1 + addresses: + - 10.0.12.2/30 + - name: eth2 + addresses: + - 192.168.12.1/24 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.0.12.1 +gre_tunnel_interfaces: + - name: tun100 + addresses: + - 10.100.100.12/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 42 + source_interface: eth1 + - name: tun101 + addresses: + - 10.100.101.12/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 43 + source_interface: eth1 +dmvpn_nhrp_tunnels: + - name: tun100 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: 10.0.0.2 + network_id: 1 + nhs: + - tunnel_ip: dynamic + nbma: 10.0.0.2 + registration_no_unique: true + shortcut: true + - name: tun101 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: 10.0.1.2 + network_id: 2 + nhs: + - tunnel_ip: dynamic + nbma: 10.0.1.2 + registration_no_unique: true + shortcut: true +ospf_interfaces: + - name: eth2 + area: '0' + - name: tun100 + area: '0' + network: point-to-multipoint + passive: false + - name: tun101 + area: '0' + network: point-to-multipoint + passive: false +base_hostname: SPOKE-2 diff --git a/examples/dmvpn-dual-hub/host_vars/spoke3.yml b/examples/dmvpn-dual-hub/host_vars/spoke3.yml new file mode 100644 index 0000000..2923f63 --- /dev/null +++ b/examples/dmvpn-dual-hub/host_vars/spoke3.yml @@ -0,0 +1,64 @@ +--- +# the page shows no tunnel-interface block for Spoke-3; it mirrors Spoke-2 with .13 +base_interfaces: + - name: eth1 + addresses: + - 10.0.13.2/30 + - name: eth2 + addresses: + - 192.168.13.1/24 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.0.13.1 +gre_tunnel_interfaces: + - name: tun100 + addresses: + - 10.100.100.13/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 42 + source_interface: eth1 + - name: tun101 + addresses: + - 10.100.101.13/32 + enable_multicast: true + encapsulation: gre + adjust_mss: '1360' + mtu: 1436 + key: 43 + source_interface: eth1 +dmvpn_nhrp_tunnels: + - name: tun100 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: 10.0.0.2 + network_id: 1 + nhs: + - tunnel_ip: dynamic + nbma: 10.0.0.2 + registration_no_unique: true + shortcut: true + - name: tun101 + authentication: '{{ vault_nhrp_authentication }}' + holdtime: 300 + multicast: 10.0.1.2 + network_id: 2 + nhs: + - tunnel_ip: dynamic + nbma: 10.0.1.2 + registration_no_unique: true + shortcut: true +ospf_interfaces: + - name: eth2 + area: '0' + - name: tun100 + area: '0' + network: point-to-multipoint + passive: false + - name: tun101 + area: '0' + network: point-to-multipoint + passive: false +base_hostname: SPOKE-3 diff --git a/examples/dmvpn-dual-hub/inventory.yml b/examples/dmvpn-dual-hub/inventory.yml new file mode 100644 index 0000000..4d256f6 --- /dev/null +++ b/examples/dmvpn-dual-hub/inventory.yml @@ -0,0 +1,20 @@ +--- +# docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html - the VyOS +# hubs and spokes (Spoke-1 is the Cisco router on the page). +all: + children: + dmvpn: + hosts: + hub1: + ansible_host: clab-dmvpn-dual-hub-hub1 # your router's address + hub2: + ansible_host: clab-dmvpn-dual-hub-hub2 + spoke2: + ansible_host: clab-dmvpn-dual-hub-spoke2 + spoke3: + ansible_host: clab-dmvpn-dual-hub-spoke3 + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/dmvpn-dual-hub/site.yml b/examples/dmvpn-dual-hub/site.yml new file mode 100644 index 0000000..9d5f1a5 --- /dev/null +++ b/examples/dmvpn-dual-hub/site.yml @@ -0,0 +1,14 @@ +--- +- name: DMVPN dual hub, dual cloud + hosts: dmvpn + gather_facts: false + roles: + - vyos.blueprints.base # underlay addresses and default route + - vyos.blueprints.gre_tunnel # multipoint GRE tunnels + - vyos.blueprints.dmvpn # NHRP, IPsec profile, GRE protection rule + - vyos.blueprints.ospf # OSPF over the tunnels + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/dmvpn-dual-hub/topology.clab.yml b/examples/dmvpn-dual-hub/topology.clab.yml new file mode 100644 index 0000000..22ecf62 --- /dev/null +++ b/examples/dmvpn-dual-hub/topology.clab.yml @@ -0,0 +1,37 @@ +# Needs GRE, NHRP and IPsec (xfrm) support on the container host. +name: dmvpn-dual-hub +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + hub1: {kind: vyosnetworks_vyos} + hub2: {kind: vyosnetworks_vyos} + spoke2: {kind: vyosnetworks_vyos} + spoke3: {kind: vyosnetworks_vyos} + # the "internet" between all WAN links (10.0.X.1 on each /30) + isp: + kind: linux + image: alpine:3 + exec: + - sysctl -w net.ipv4.ip_forward=1 + - ip addr add 10.0.0.1/30 dev eth1 + - ip addr add 10.0.1.1/30 dev eth2 + - ip addr add 10.0.12.1/30 dev eth3 + - ip addr add 10.0.13.1/30 dev eth4 + pc2: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.12.2/24 dev eth1", "ip route replace default via 192.168.12.1"] + pc3: + kind: linux + image: alpine:3 + exec: ["ip addr add 192.168.13.2/24 dev eth1", "ip route replace default via 192.168.13.1"] + links: + # WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management) + - endpoints: ["hub1:eth1", "isp:eth1"] + - endpoints: ["hub2:eth1", "isp:eth2"] + - endpoints: ["spoke2:eth1", "isp:eth3"] + - endpoints: ["spoke3:eth1", "isp:eth4"] + - endpoints: ["spoke2:eth2", "pc2:eth1"] + - endpoints: ["spoke3:eth2", "pc3:eth1"] diff --git a/examples/dmvpn-dual-hub/verify.yml b/examples/dmvpn-dual-hub/verify.yml new file mode 100644 index 0000000..6e1eb7f --- /dev/null +++ b/examples/dmvpn-dual-hub/verify.yml @@ -0,0 +1,10 @@ +--- +- name: Check DMVPN + hosts: dmvpn + gather_facts: false + tasks: + - name: DMVPN and OSPF checks + ansible.builtin.include_role: + name: "vyos.blueprints.{{ item }}" + tasks_from: verify + loop: [dmvpn, ospf] diff --git a/examples/gcp-ha-vpn-bgp/group_vars/edges.yml b/examples/gcp-ha-vpn-bgp/group_vars/edges.yml new file mode 100644 index 0000000..d84ed63 --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/group_vars/edges.yml @@ -0,0 +1,29 @@ +--- +# docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html - shared by both edges +ipsec_route_based_ike_group: + name: GCP-IKE + key_exchange: ikev2 + lifetime: 36000 + proposal_id: 10 + dh_group: 14 + encryption: aes256 + hash: sha256 + prf: prfsha256 + dead_peer_detection: {action: restart, interval: 30} +ipsec_route_based_esp_group: + name: GCP-ESP + lifetime: 10800 + mode: tunnel + pfs: dh-group14 + proposal_id: 10 + encryption: aes256 + hash: sha256 +ipsec_route_based_interfaces: [eth0] +ipsec_route_based_disable_route_autoinstall: true +ipsec_route_based_policy: + prefix_lists: + - {name: GCP-IN, rules: [{sequence: 10, action: permit, prefix: 10.70.0.0/20}]} + - {name: GCP-OUT, rules: [{sequence: 10, action: permit, prefix: 10.80.0.0/24}]} + route_maps: + - {name: GCP-IN, rules: [{sequence: 10, action: permit, prefix_list: GCP-IN}, {sequence: 20, action: deny}]} + - {name: GCP-OUT, rules: [{sequence: 10, action: permit, prefix_list: GCP-OUT}, {sequence: 20, action: deny}]} diff --git a/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml b/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml new file mode 100644 index 0000000..3f4d32e --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml @@ -0,0 +1,32 @@ +--- +ipsec_route_based_peers: + - name: gcp-ha-vpn-0 + description: Google Cloud HA VPN tunnel 0 + psk_name: gcp-ha-vpn-0 + psk: example-gcp-ha-vpn-psk-0 # use ansible-vault; high-entropy in production + local_address: 198.51.100.10 + remote_address: 203.0.113.10 + connection_type: initiate + esp_group_on_vti: true + vti: + interface: vti10 + address: 169.254.10.1/30 + description: Google Cloud HA VPN tunnel 0 + adjust_mss: '1350' +ipsec_route_based_interface_routes: + - dest: 169.254.10.2/32 + interface: vti10 +ipsec_route_based_bgp: + asn: 65010 + router_id: 10.80.0.11 + networks: + - 10.80.0.0/24 + neighbors: + - address: 169.254.10.2 + remote_as: 64514 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true + route_map_import: GCP-IN + route_map_export: GCP-OUT diff --git a/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml b/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml new file mode 100644 index 0000000..dc40e0d --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml @@ -0,0 +1,32 @@ +--- +ipsec_route_based_peers: + - name: gcp-ha-vpn-1 + description: Google Cloud HA VPN tunnel 1 + psk_name: gcp-ha-vpn-1 + psk: example-gcp-ha-vpn-psk-1 # use ansible-vault; high-entropy in production + local_address: 198.51.100.11 + remote_address: 203.0.113.11 + connection_type: initiate + esp_group_on_vti: true + vti: + interface: vti11 + address: 169.254.10.5/30 + description: Google Cloud HA VPN tunnel 1 + adjust_mss: '1350' +ipsec_route_based_interface_routes: + - dest: 169.254.10.6/32 + interface: vti11 +ipsec_route_based_bgp: + asn: 65010 + router_id: 10.80.0.12 + networks: + - 10.80.0.0/24 + neighbors: + - address: 169.254.10.6 + remote_as: 64514 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true + route_map_import: GCP-IN + route_map_export: GCP-OUT diff --git a/examples/gcp-ha-vpn-bgp/inventory.yml b/examples/gcp-ha-vpn-bgp/inventory.yml new file mode 100644 index 0000000..5ca4cbc --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/inventory.yml @@ -0,0 +1,18 @@ +--- +# docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html +# Only the two VyOS edge peers are configured here; the HA VPN gateway, Cloud +# Router, external VPN gateway and tunnels are created in Google Cloud as the +# page describes. +all: + children: + edges: + hosts: + edge1: + ansible_host: 198.51.100.10 # your edge 1 address + edge2: + ansible_host: 198.51.100.11 # your edge 2 address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/gcp-ha-vpn-bgp/site.yml b/examples/gcp-ha-vpn-bgp/site.yml new file mode 100644 index 0000000..6b32f46 --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/site.yml @@ -0,0 +1,11 @@ +--- +- name: Route-based VPN to Google Cloud HA VPN + hosts: edges + gather_facts: false + roles: + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/gcp-ha-vpn-bgp/verify.yml b/examples/gcp-ha-vpn-bgp/verify.yml new file mode 100644 index 0000000..ff08323 --- /dev/null +++ b/examples/gcp-ha-vpn-bgp/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check both edge peers + hosts: edges + gather_facts: false + tasks: + - name: IPsec and BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify diff --git a/examples/ha-walkthrough/group_vars/routers.yml b/examples/ha-walkthrough/group_vars/routers.yml new file mode 100644 index 0000000..8c7be76 --- /dev/null +++ b/examples/ha-walkthrough/group_vars/routers.yml @@ -0,0 +1,120 @@ +--- +# Shared by both routers - docs.vyos.io/en/1.5/configexamples/ha.html + +# --- VRRP, conntrack-sync and the temporary default route (part 1) +ha_vrrp_pair_group: routers +ha_vrrp_sync_group: + name: sync + members: + - int +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 192.0.2.11 + +# --- OSPF over WireGuard - filters and OSPF settings (part 2) +route_policy_access_lists: + - number: 150 + description: Outbound OSPF Redistribution + rules: + - number: 10 + action: permit + destination: + any: true + source: + network: 10.200.201.0 + inverse_mask: 0.0.0.255 + - number: 20 + action: permit + destination: + any: true + source: + network: 203.0.113.0 + inverse_mask: 0.0.0.255 + - number: 100 + action: deny + destination: + any: true + source: + any: true + - number: 100 + description: Inbound OSPF Routes from Peers + rules: + - number: 10 + action: deny + destination: + any: true + source: + network: 10.201.0.0 + inverse_mask: 0.0.255.255 + - number: 100 + action: permit + destination: + any: true + source: + any: true +ospf_areas: + - id: 0.0.0.0 + authentication: md5 + networks: + - 10.254.60.0/24 +ospf_reference_bandwidth: 10000 +ospf_log_adjacency_changes: true +ospf_abr_type: cisco +ospf_redistribute: + - type: connected +ospf_redistribute_access_lists: + connected: 150 +ospf_import_route_map: PUBOSPF + +# --- Route policy for OSPF import (PUBOSPF) and BGP export (BGPOUT, BGPPREPENDOUT) +route_policy_prefix_lists: + - name: BGPOUT + description: BGP Export List + rules: + - sequence: 10 + action: deny + description: Do not advertise short masks + ge: 25 + prefix: 0.0.0.0/0 + - sequence: 100 + action: permit + description: Our network + prefix: 203.0.113.0/24 + - sequence: 10000 + action: deny + prefix: 0.0.0.0/0 +route_policy_route_maps: + - name: PUBOSPF + rules: + - sequence: 100 + action: deny + match_access_list: '100' + - sequence: 500 + action: permit + - name: BGPOUT + description: BGP Export Filter + rules: + - sequence: 10 + action: permit + match_prefix_list: BGPOUT + - sequence: 10000 + action: deny + - name: BGPPREPENDOUT + description: BGP Export Filter + rules: + - sequence: 10 + action: permit + set_as_path_prepend: 65551 65551 65551 + match_prefix_list: BGPOUT + - sequence: 10000 + action: deny + +# --- BGP (part 3) +bgp_asn: 65551 +bgp_networks: + - 192.0.2.0/24 +bgp_redistribute: + - type: connected + metric: 50 + - type: ospf + metric: 50 diff --git a/examples/ha-walkthrough/host_vars/router1.yml b/examples/ha-walkthrough/host_vars/router1.yml new file mode 100644 index 0000000..e33bd2c --- /dev/null +++ b/examples/ha-walkthrough/host_vars/router1.yml @@ -0,0 +1,85 @@ +--- +# router1 (VM): trunk on eth1 here, eth0 on the page (containerlab uses eth0 for management) +base_interfaces: + - name: eth1.50 + addresses: + - 192.0.2.21/24 + - name: eth1.100 + addresses: + - 203.0.113.2/24 + - name: eth1.201 + addresses: + - 10.200.201.2/24 +ha_vrrp_priority: 200 +ha_vrrp_groups: + - name: int + vrid: 201 + interface: eth1.201 + address: + - 10.200.201.1/24 + - name: public + vrid: 113 + interface: eth1.100 + address: + - 203.0.113.1/24 +ha_vrrp_local_addresses: + int: 10.200.201.2 + public: 203.0.113.2 +ha_vrrp_conntrack_sync: + interface: eth1.201 + accept_protocols: + - tcp + - udp + - icmp + event_listen_queue_size: 8 + mcast_group: 224.0.0.50 + sync_queue_size: 8 + disable_helpers: true +nat_source_rules: + - id: 10 + outbound_interface: + name: eth1.50 + source: + address: 10.200.201.0/24 + destination: + address: '!192.0.2.0/24' + translation: + address: 203.0.113.1 + +# --- part 2: WireGuard link to offsite1 and OSPF over it (keep the private key in ansible-vault) +wireguard_interfaces: + - name: wg01 + addresses: + - 10.254.60.1/30 + description: router1-to-offsite1 + port: 50001 + peers: + - name: OFFSITE1 + allowed_ips: + - 0.0.0.0/0 + address: 203.0.113.3 + port: 50001 + persistent_keepalive: 15 + public_key: GEFMOWzAyau42/HwdwfXnrfHdIISQF8YHj35rOgSZ0o= + private_key: '{{ vault_wg01_private_key }}' +ospf_router_id: 10.254.60.1 +ospf_interfaces: + - name: wg01 + md5_key: i360KoCwUGZvPq7e # use ansible-vault for real devices + md5_key_id: 1 + cost: 11 + dead_interval: 5 + hello_interval: 1 + network: point-to-point + priority: 1 + retransmit_interval: 5 + transmit_delay: 1 + +# --- part 3: BGP session to the provider +bgp_router_id: 192.0.2.21 +bgp_neighbors: + - address: 192.0.2.11 + remote_as: 65550 + update_source: 192.0.2.21 + soft_reconfiguration_inbound: true + route_map_export: BGPOUT diff --git a/examples/ha-walkthrough/host_vars/router2.yml b/examples/ha-walkthrough/host_vars/router2.yml new file mode 100644 index 0000000..b4aefbc --- /dev/null +++ b/examples/ha-walkthrough/host_vars/router2.yml @@ -0,0 +1,75 @@ +--- +# router2 (hardware): LACP bond0 of eth1/eth2 here, eth0/eth1 on the page +base_interfaces: + - name: bond0.50 + addresses: + - 192.0.2.22/24 + - name: bond0.100 + addresses: + - 203.0.113.3/24 + - name: bond0.201 + addresses: + - 10.200.201.3/24 +ha_vrrp_priority: 100 +ha_vrrp_groups: + - name: int + vrid: 201 + interface: bond0.201 + address: + - 10.200.201.1/24 + - name: public + vrid: 113 + interface: bond0.100 + address: + - 203.0.113.1/24 +ha_vrrp_local_addresses: + int: 10.200.201.3 + public: 203.0.113.3 +ha_vrrp_conntrack_sync: + interface: bond0.201 + accept_protocols: + - tcp + - udp + - icmp + event_listen_queue_size: 8 + mcast_group: 224.0.0.50 + sync_queue_size: 8 + disable_helpers: true +nat_source_rules: + - id: 10 + outbound_interface: + name: bond0.50 + source: + address: 10.200.201.0/24 + destination: + address: '!192.0.2.0/24' + translation: + address: 203.0.113.1 +bonding_interfaces: + - name: bond0 + description: Switch Port-Channel + hash_policy: layer2 + members: + - eth1 + - eth2 + mode: 802.3ad + +# --- part 2: as described in "Duplicate configuration", give router2 its own +# WireGuard link(s) to the offsite routers (a different /30 from 10.254.60.0/24 +# per link) with the same OSPF interface settings, and a unique router-id, e.g.: +# wireguard_interfaces: +# - name: wg01 +# addresses: [10.254.60.5/30] +# ... +# ospf_router_id: 10.254.60.5 +# ospf_interfaces: [...] + +# --- part 3: BGP session to the provider, exporting with the AS-path prepend +# (the page: "identical, but use BGPPREPENDOUT"; peer per the Example Network) +bgp_router_id: 192.0.2.22 +bgp_neighbors: + - address: 192.0.2.12 + remote_as: 65550 + update_source: 192.0.2.22 + soft_reconfiguration_inbound: true + route_map_export: BGPPREPENDOUT diff --git a/examples/ha-walkthrough/inventory.yml b/examples/ha-walkthrough/inventory.yml new file mode 100644 index 0000000..ba48d0d --- /dev/null +++ b/examples/ha-walkthrough/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/ha.html +all: + children: + routers: + hosts: + router1: + ansible_host: clab-ha-walkthrough-router1 # your router's address + router2: + ansible_host: clab-ha-walkthrough-router2 + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/ha-walkthrough/site.yml b/examples/ha-walkthrough/site.yml new file mode 100644 index 0000000..9c1923d --- /dev/null +++ b/examples/ha-walkthrough/site.yml @@ -0,0 +1,18 @@ +--- +- name: High Availability Walkthrough + hosts: routers + gather_facts: false + roles: + - vyos.blueprints.bonding # router2 only (bond0) + - vyos.blueprints.base # VLAN addresses, temporary default route + - vyos.blueprints.ha_vrrp # VRRP groups, sync-group, conntrack-sync + - vyos.blueprints.nat # masquerade 10.200.201.0/24 to 203.0.113.1 + - vyos.blueprints.wireguard # links to the offsite routers + - vyos.blueprints.route_policy # access-lists 100/150, route-map PUBOSPF + - vyos.blueprints.ospf # OSPF over WireGuard with import/export filters + - vyos.blueprints.bgp # BGP to the provider, BGPOUT / BGPPREPENDOUT + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/ha-walkthrough/topology.clab.yml b/examples/ha-walkthrough/topology.clab.yml new file mode 100644 index 0000000..d711374 --- /dev/null +++ b/examples/ha-walkthrough/topology.clab.yml @@ -0,0 +1,54 @@ +name: ha-walkthrough +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + router1: + kind: vyosnetworks_vyos + router2: + kind: vyosnetworks_vyos + # "switch pair": VLAN-aware bridge, router2's ports bonded with LACP as on the page. + # LACP needs the kernel bonding module on the container host. + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge vlan_filtering 1 + - ip link add bond0 type bond mode 802.3ad + - ip link set eth2 down + - ip link set eth3 down + - ip link set eth2 master bond0 + - ip link set eth3 master bond0 + - ip link set bond0 up + - ip link set eth1 master br0 + - ip link set bond0 master br0 + - ip link set eth4 master br0 + - ip link set eth5 master br0 + - bridge vlan add dev eth1 vid 50 + - bridge vlan add dev eth1 vid 100 + - bridge vlan add dev eth1 vid 201 + - bridge vlan add dev bond0 vid 50 + - bridge vlan add dev bond0 vid 100 + - bridge vlan add dev bond0 vid 201 + - bridge vlan add dev eth4 vid 50 pvid untagged + - bridge vlan add dev eth5 vid 201 pvid untagged + - ip link set br0 up + # upstream router (VLAN 50); 198.51.100.100 stands for "the internet" + upstream: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.0.2.11/24 dev eth1 + - ip addr add 198.51.100.100/32 dev lo + - ip route add 203.0.113.0/24 via 192.0.2.21 + internal: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.200.201.10/24 dev eth1", "ip route replace default via 10.200.201.1"] + links: + - endpoints: ["router1:eth1", "sw:eth1"] + - endpoints: ["router2:eth1", "sw:eth2"] + - endpoints: ["router2:eth2", "sw:eth3"] + - endpoints: ["sw:eth4", "upstream:eth1"] + - endpoints: ["sw:eth5", "internal:eth1"] diff --git a/examples/ha-walkthrough/verify.yml b/examples/ha-walkthrough/verify.yml new file mode 100644 index 0000000..8c714ca --- /dev/null +++ b/examples/ha-walkthrough/verify.yml @@ -0,0 +1,17 @@ +--- +- name: Check the HA pair + hosts: routers + gather_facts: false + tasks: + - name: VRRP checks (both routers in one play for the one-MASTER check) + ansible.builtin.include_role: + name: vyos.blueprints.ha_vrrp + tasks_from: verify + - name: NAT checks + ansible.builtin.include_role: + name: vyos.blueprints.nat + tasks_from: verify + - name: BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.bgp + tasks_from: verify diff --git a/examples/inter-vrf/group_vars/core.yml b/examples/inter-vrf/group_vars/core.yml new file mode 100644 index 0000000..965e45a --- /dev/null +++ b/examples/inter-vrf/group_vars/core.yml @@ -0,0 +1,136 @@ +--- +# Core router - docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html +# (Appendix-A, plus the Appendix-B import filter on LAN2). Interfaces are +# eth1-eth4 here, eth0-eth3 on the page (containerlab uses eth0 for management). +base_interfaces: + - name: eth1 + addresses: + - 10.1.1.1/30 + - 2001:db8::/127 + - name: eth2 + addresses: + - 172.16.2.1/30 + - 2001:db8::2/127 + - name: eth3 + addresses: + - 192.168.3.1/30 + - 2001:db8::4/127 + - name: eth4 + addresses: + - 10.2.2.1/30 + - 2001:db8::6/127 +vrf_lite_asn: 64496 +vrf_lite_vrfs: + - name: Internet + table: 104 + interfaces: + - eth4 + rd: 64496:100 + route_targets_export: + - 64496:100 + route_targets_import: + - '64496:1' + - '64496:2' + neighbors: + - address: 10.2.2.2 + remote_as: 64497 + - address: 2001:db8::7 + remote_as: 64497 + - name: LAN1 + table: 101 + interfaces: + - eth1 + routes: + - dest: 10.0.0.0/24 + next_hop: 10.1.1.2 + - dest: 2001:db8:0:1::/64 + next_hop: 2001:db8::1 + rd: '64496:1' + route_targets_export: + - '64496:1' + route_targets_import: + - 64496:100 + - '64496:50' + - '64496:2' + redistribute: + - static + - name: LAN2 + table: 102 + interfaces: + - eth2 + routes: + - dest: 172.16.0.0/24 + next_hop: 172.16.2.2 + - dest: 2001:db8:0:2::/64 + next_hop: 2001:db8::3 + rd: '64496:2' + route_targets_export: + - '64496:2' + route_targets_import: + - 64496:100 + - '64496:50' + - '64496:1' + redistribute: + - static + import_route_map: + ipv4: LAN2-Internet + ipv6: LAN2-Internet-v6 + - name: Management + table: 103 + interfaces: + - eth3 + routes: + - dest: 192.168.0.0/24 + next_hop: 192.168.3.2 + - dest: 2001:db8:0:3::/64 + next_hop: 2001:db8::5 + rd: '64496:50' + route_targets_export: + - '64496:50' + route_targets_import: + - '64496:1' + - '64496:2' + redistribute: + - static +route_policy_prefix_lists: + - name: LAN2-Internet + rules: + - sequence: 1 + action: permit + le: 24 + prefix: 198.51.0.0/16 + - sequence: 2 + action: permit + prefix: 192.0.2.0/24 + - sequence: 3 + action: permit + prefix: 192.168.0.0/24 + - sequence: 4 + action: permit + prefix: 10.0.0.0/24 + - name: LAN2-Internet-v6 + afi: ipv6 + rules: + - sequence: 1 + action: permit + prefix: 2001:db8:1::/48 + - sequence: 2 + action: permit + prefix: 2001:db8:2::/48 + - sequence: 3 + action: permit + prefix: 2001:db8:0:3::/64 + - sequence: 4 + action: permit + prefix: 2001:db8:0:1::/64 +route_policy_route_maps: + - name: LAN2-Internet + rules: + - sequence: 1 + action: permit + match_prefix_list: LAN2-Internet + - name: LAN2-Internet-v6 + rules: + - sequence: 1 + action: permit + match_prefix_list6: LAN2-Internet-v6 diff --git a/examples/inter-vrf/inventory.yml b/examples/inter-vrf/inventory.yml new file mode 100644 index 0000000..1ca61f3 --- /dev/null +++ b/examples/inter-vrf/inventory.yml @@ -0,0 +1,17 @@ +--- +# docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html +all: + children: + core: + hosts: + core1: + ansible_host: clab-inter-vrf-core # your router's address + provider: + hosts: + isp: + ansible_host: clab-inter-vrf-isp # lab only, see isp.yml + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/inter-vrf/isp.yml b/examples/inter-vrf/isp.yml new file mode 100644 index 0000000..2637b45 --- /dev/null +++ b/examples/inter-vrf/isp.yml @@ -0,0 +1,25 @@ +--- +- name: Configure the ISP router as on the page in the containerlab lab (the ISP is not part of the blueprint) + hosts: provider + gather_facts: false + tasks: + - name: Apply the page's ISP configuration (eth1 instead of eth3) + vyos.vyos.vyos_config: + lines: + - set interfaces dummy dum0 address '192.0.2.1/24' + - set interfaces dummy dum0 address '2001:db8:1::1/48' + - set interfaces dummy dum1 address '198.51.100.1/24' + - set interfaces dummy dum1 address '2001:db8:2::1/48' + - set interfaces dummy dum2 address '203.0.113.1/24' + - set interfaces dummy dum2 address '2001:db8:3::1/48' + - set interfaces ethernet eth1 address '10.2.2.2/30' + - set interfaces ethernet eth1 address '2001:db8::7/127' + - set protocols bgp address-family ipv4-unicast redistribute connected + - set protocols bgp address-family ipv6-unicast redistribute connected + - set protocols bgp system-as '64497' + - set protocols bgp neighbor 10.2.2.1 address-family ipv4-unicast default-originate + - set protocols bgp neighbor 10.2.2.1 remote-as '64496' + - set protocols bgp neighbor 2001:db8::6 address-family ipv6-unicast default-originate + - set protocols bgp neighbor 2001:db8::6 remote-as '64496' + - set protocols static route 0.0.0.0/0 next-hop 10.2.2.1 + - set protocols static route6 ::/0 next-hop 2001:db8::6 diff --git a/examples/inter-vrf/site.yml b/examples/inter-vrf/site.yml new file mode 100644 index 0000000..2e3ae95 --- /dev/null +++ b/examples/inter-vrf/site.yml @@ -0,0 +1,13 @@ +--- +- name: Inter-VRF routing over VRF Lite - core router + hosts: core + gather_facts: false + roles: + - vyos.blueprints.base # interface addresses + - vyos.blueprints.route_policy # Appendix-B prefix-lists and route-maps + - vyos.blueprints.vrf_lite # VRFs, static routes, RD/RT, VPN import/export + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/inter-vrf/topology.clab.yml b/examples/inter-vrf/topology.clab.yml new file mode 100644 index 0000000..582190b --- /dev/null +++ b/examples/inter-vrf/topology.clab.yml @@ -0,0 +1,48 @@ +name: inter-vrf +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + core: + kind: vyosnetworks_vyos + isp: + kind: vyosnetworks_vyos + # remote networks from the page, as Linux hosts: link address, a "dum0" + # network and a default route to the core + lan1: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.1.1.2/30 dev eth1 + - ip -6 addr add 2001:db8::1/127 dev eth1 + - ip link add dum0 type dummy + - ip link set dum0 up + - ip addr add 10.0.0.1/24 dev dum0 + - ip -6 addr add 2001:db8:0:1::1/64 dev dum0 + - ip route replace default via 10.1.1.1 + - ip -6 route replace default via 2001:db8:: + lan2: + kind: linux + image: alpine:3 + exec: + - ip addr add 172.16.2.2/30 dev eth1 + - ip link add dum0 type dummy + - ip link set dum0 up + - ip addr add 172.16.0.1/24 dev dum0 + - ip route replace default via 172.16.2.1 + mgmt: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.3.2/30 dev eth1 + - ip link add dum0 type dummy + - ip link set dum0 up + - ip addr add 192.168.0.1/24 dev dum0 + - ip route replace default via 192.168.3.1 + links: + # Core eth1-eth4 here = eth0-eth3 on the page (containerlab uses eth0 for management) + - endpoints: ["core:eth1", "lan1:eth1"] + - endpoints: ["core:eth2", "lan2:eth1"] + - endpoints: ["core:eth3", "mgmt:eth1"] + - endpoints: ["core:eth4", "isp:eth1"] diff --git a/examples/inter-vrf/verify.yml b/examples/inter-vrf/verify.yml new file mode 100644 index 0000000..dd246de --- /dev/null +++ b/examples/inter-vrf/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the core router + hosts: core + gather_facts: false + tasks: + - name: VRF and VRF BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.vrf_lite + tasks_from: verify diff --git a/examples/isis-segment-routing/group_vars/p_routers.yml b/examples/isis-segment-routing/group_vars/p_routers.yml new file mode 100644 index 0000000..ea7b34c --- /dev/null +++ b/examples/isis-segment-routing/group_vars/p_routers.yml @@ -0,0 +1,5 @@ +--- +# Shared IS-IS settings - docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html +isis_level: level-2 +isis_log_adjacency_changes: true +isis_metric_style: wide diff --git a/examples/isis-segment-routing/host_vars/P1-VyOS.yml b/examples/isis-segment-routing/host_vars/P1-VyOS.yml new file mode 100644 index 0000000..a1ef98a --- /dev/null +++ b/examples/isis-segment-routing/host_vars/P1-VyOS.yml @@ -0,0 +1,31 @@ +--- +# P1 as on the page; its eth3 link (192.0.2.21/30) is not in the lab topology +base_hostname: P1-VyOS +base_interfaces: + - name: dum0 + addresses: + - 192.0.2.1/32 + - name: eth1 + mtu: 8000 + addresses: + - 192.0.2.5/30 + - name: eth3 + mtu: 8000 + addresses: + - 192.0.2.21/30 +isis_net: 49.0000.0000.0000.0001.00 +isis_interfaces: + - name: dum0 + passive: true + - name: eth1 + network: point-to-point + - name: eth3 + network: point-to-point +isis_segment_routing: + maximum_label_depth: 8 + prefixes: + - prefix: 192.0.2.1/32 + index: 1 +isis_mpls_interfaces: + - eth1 + - eth3 diff --git a/examples/isis-segment-routing/host_vars/P2-VyOS.yml b/examples/isis-segment-routing/host_vars/P2-VyOS.yml new file mode 100644 index 0000000..65eda94 --- /dev/null +++ b/examples/isis-segment-routing/host_vars/P2-VyOS.yml @@ -0,0 +1,31 @@ +--- +# P2 as on the page; its eth3 link (192.0.2.26/30) is not in the lab topology +base_hostname: P2-VyOS +base_interfaces: + - name: dum0 + addresses: + - 192.0.2.2/32 + - name: eth2 + mtu: 8000 + addresses: + - 192.0.2.17/30 + - name: eth3 + mtu: 8000 + addresses: + - 192.0.2.26/30 +isis_net: 49.0000.0000.0000.0002.00 +isis_interfaces: + - name: dum0 + passive: true + - name: eth2 + network: point-to-point + - name: eth3 + network: point-to-point +isis_segment_routing: + maximum_label_depth: 8 + prefixes: + - prefix: 192.0.2.2/32 + index: 2 +isis_mpls_interfaces: + - eth2 + - eth3 diff --git a/examples/isis-segment-routing/host_vars/P3.yml b/examples/isis-segment-routing/host_vars/P3.yml new file mode 100644 index 0000000..9c0d75f --- /dev/null +++ b/examples/isis-segment-routing/host_vars/P3.yml @@ -0,0 +1,31 @@ +--- +# Lab only: VyOS stand-in for the page's Cisco XRv-P3 (configure the real P3 as on the page) +base_hostname: P3 +base_interfaces: + - name: dum0 + addresses: + - 192.0.2.3/32 + - name: eth1 + mtu: 8000 + addresses: + - 192.0.2.6/30 + - name: eth2 + mtu: 8000 + addresses: + - 192.0.2.18/30 +isis_net: 49.0000.0000.0000.0003.00 +isis_interfaces: + - name: dum0 + passive: true + - name: eth1 + network: point-to-point + - name: eth2 + network: point-to-point +isis_segment_routing: + maximum_label_depth: 8 + prefixes: + - prefix: 192.0.2.3/32 + index: 3 +isis_mpls_interfaces: + - eth1 + - eth2 diff --git a/examples/isis-segment-routing/inventory.yml b/examples/isis-segment-routing/inventory.yml new file mode 100644 index 0000000..3f1d4b5 --- /dev/null +++ b/examples/isis-segment-routing/inventory.yml @@ -0,0 +1,17 @@ +--- +# docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html +all: + children: + p_routers: + hosts: + P1-VyOS: + ansible_host: clab-isis-segment-routing-p1 # your router's address + P2-VyOS: + ansible_host: clab-isis-segment-routing-p2 + P3: + ansible_host: clab-isis-segment-routing-p3 # lab only, see host_vars/P3.yml + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/isis-segment-routing/site.yml b/examples/isis-segment-routing/site.yml new file mode 100644 index 0000000..0c08754 --- /dev/null +++ b/examples/isis-segment-routing/site.yml @@ -0,0 +1,12 @@ +--- +- name: IS-IS with MPLS segment routing + hosts: p_routers + gather_facts: false + roles: + - vyos.blueprints.base # loopback, link addresses and MTU, hostname + - vyos.blueprints.isis # IS-IS, segment routing, MPLS interfaces + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/isis-segment-routing/topology.clab.yml b/examples/isis-segment-routing/topology.clab.yml new file mode 100644 index 0000000..7e31a7f --- /dev/null +++ b/examples/isis-segment-routing/topology.clab.yml @@ -0,0 +1,16 @@ +name: isis-segment-routing +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + p1: + kind: vyosnetworks_vyos + p2: + kind: vyosnetworks_vyos + # VyOS standing in for the page's Cisco XRv-P3 + p3: + kind: vyosnetworks_vyos + links: + - endpoints: ["p1:eth1", "p3:eth1"] # 192.0.2.4/30 + - endpoints: ["p3:eth2", "p2:eth2"] # 192.0.2.16/30 diff --git a/examples/isis-segment-routing/verify.yml b/examples/isis-segment-routing/verify.yml new file mode 100644 index 0000000..2096eca --- /dev/null +++ b/examples/isis-segment-routing/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check IS-IS and segment routing + hosts: p_routers + gather_facts: false + tasks: + - name: IS-IS checks + ansible.builtin.include_role: + name: vyos.blueprints.isis + tasks_from: verify diff --git a/examples/l2tp-lns/group_vars/lns.yml b/examples/l2tp-lns/group_vars/lns.yml new file mode 100644 index 0000000..928afea --- /dev/null +++ b/examples/l2tp-lns/group_vars/lns.yml @@ -0,0 +1,38 @@ +--- +# The LNS - docs.vyos.io/en/1.5/configexamples/lac-lns.html +# eth1 here is eth0 on the page (containerlab uses eth0 for management). +# Keep the RADIUS key and the L2TP tunnel secret in ansible-vault; the tunnel +# secret must match "l2tp tunnel password" and the host name "local name" on +# the LAC. +base_hostname: vyos +base_interfaces: + - name: eth1 + addresses: + - 192.168.139.100/24 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 192.168.139.2 +nat_source_rules: + - id: 100 + outbound_interface: + name: eth1 + source: + address: 10.0.0.0/24 + translation: + address: masquerade +l2tp_lns_authentication: + mode: radius + radius_servers: + - address: 192.168.139.110 + key: '{{ vault_radius_key }}' +l2tp_lns_pools: + - name: TEST-POOL + range: 10.0.0.2-10.0.0.100 +l2tp_lns_default_pool: TEST-POOL +l2tp_lns_gateway_address: 10.0.0.1 +l2tp_lns_lac_host_name: LAC +l2tp_lns_shared_secret: '{{ vault_l2tp_tunnel_secret }}' +l2tp_lns_name_servers: + - 8.8.8.8 +l2tp_lns_ppp_options: + disable_ccp: true diff --git a/examples/l2tp-lns/inventory.yml b/examples/l2tp-lns/inventory.yml new file mode 100644 index 0000000..f9e06ba --- /dev/null +++ b/examples/l2tp-lns/inventory.yml @@ -0,0 +1,14 @@ +--- +# docs.vyos.io/en/1.5/configexamples/lac-lns.html - VyOS is the LNS; the LAC +# (Cisco on the page) and the RADIUS server are configured separately. +all: + children: + lns: + hosts: + lns1: + ansible_host: clab-l2tp-lns-lns # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/l2tp-lns/site.yml b/examples/l2tp-lns/site.yml new file mode 100644 index 0000000..e6dcb50 --- /dev/null +++ b/examples/l2tp-lns/site.yml @@ -0,0 +1,13 @@ +--- +- name: L2TP network server for PPPoE subscribers forwarded by a LAC + hosts: lns + gather_facts: false + roles: + - vyos.blueprints.base # address and default route + - vyos.blueprints.nat # masquerade the client pool + - vyos.blueprints.l2tp_lns # LNS with RADIUS authentication + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/l2tp-lns/topology.clab.yml b/examples/l2tp-lns/topology.clab.yml new file mode 100644 index 0000000..7adc4f5 --- /dev/null +++ b/examples/l2tp-lns/topology.clab.yml @@ -0,0 +1,45 @@ +# EXPERIMENTAL: needs the ppp and l2tp_ppp kernel modules on the container host; +# the xl2tpd and FreeRADIUS setup below is lab scaffolding. +name: l2tp-lns +topology: + nodes: + lns: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + # 192.168.139.0/24 segment shared by the LNS, the LAC and the RADIUS server + sw: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set eth3 master br0 + - ip link set br0 up + radius: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.139.110/24 dev eth1 + - apk add --no-cache freeradius + - sh -c 'printf "client lns {\n ipaddr = 192.168.139.100\n secret = radiustest\n}\n" >> /etc/raddb/clients.conf' + - sh -c 'sed -i "1i test@vyos.io Cleartext-Password := \"test\"" /etc/raddb/mods-config/files/authorize' + - radiusd + # stands in for the page's Cisco LAC and the Windows PPPoE client + lac: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.139.101/24 dev eth1 + - apk add --no-cache xl2tpd ppp + - mkdir -p /var/run/xl2tpd /etc/ppp/peers + - sh -c 'printf "[lac lns]\nlns = 192.168.139.100\nhostname = LAC\nchallenge = yes\npppoptfile = /etc/ppp/options.l2tp\nlength bit = yes\n" > /etc/xl2tpd/xl2tpd.conf' + - sh -c 'printf "* LAC test123\nLAC * test123\n" > /etc/xl2tpd/l2tp-secrets && chmod 600 /etc/xl2tpd/l2tp-secrets' + - sh -c 'printf "name test@vyos.io\nnoauth\nnoccp\nrefuse-eap\nrequire-chap\nnodefaultroute\nmtu 1400\nmru 1400\n" > /etc/ppp/options.l2tp' + - sh -c 'printf "test@vyos.io * test *\n" > /etc/ppp/chap-secrets && chmod 600 /etc/ppp/chap-secrets' + - xl2tpd + links: + # LNS eth1 here = eth0 on the page (containerlab uses eth0 for management) + - endpoints: ["lns:eth1", "sw:eth1"] + - endpoints: ["radius:eth1", "sw:eth2"] + - endpoints: ["lac:eth1", "sw:eth3"] diff --git a/examples/l2tp-lns/verify.yml b/examples/l2tp-lns/verify.yml new file mode 100644 index 0000000..279a500 --- /dev/null +++ b/examples/l2tp-lns/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the LNS + hosts: lns + gather_facts: false + tasks: + - name: LNS checks + ansible.builtin.include_role: + name: vyos.blueprints.l2tp_lns + tasks_from: verify diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml new file mode 100644 index 0000000..1d9583b --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml @@ -0,0 +1,21 @@ +--- +base_interfaces: + - name: dum20 + addresses: + - 10.0.0.100/32 + - name: eth0 + addresses: + - 10.80.80.2/24 +bgp_asn: 65035 +bgp_router_id: 10.80.80.2 +bgp_networks: + - 10.0.0.100/32 +bgp_log_neighbor_changes: true +bgp_neighbors: + - address: 10.80.80.1 + remote_as: 65001 + ebgp_multihop: 2 + update_source: eth0 +bgp_redistribute: + - type: connected +base_hostname: VyOS-CE1-HUB diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml new file mode 100644 index 0000000..08825d0 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml @@ -0,0 +1,19 @@ +--- +base_interfaces: + - name: dum20 + addresses: + - 10.0.0.80/32 + - name: eth0 + addresses: + - 10.50.50.2/24 +bgp_asn: 65035 +bgp_router_id: 10.50.50.2 +bgp_networks: + - 10.0.0.80/32 +bgp_log_neighbor_changes: true +bgp_neighbors: + - address: 10.50.50.1 + remote_as: 65001 + ebgp_multihop: 2 + update_source: eth0 +base_hostname: VyOS-CE1-SPOKE diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml new file mode 100644 index 0000000..95f098a --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml @@ -0,0 +1,19 @@ +--- +base_interfaces: + - name: dum20 + addresses: + - 10.0.0.90/32 + - name: eth0 + addresses: + - 10.60.60.2/24 +bgp_asn: 65035 +bgp_router_id: 10.60.60.2 +bgp_networks: + - 10.0.0.90/32 +bgp_log_neighbor_changes: true +bgp_neighbors: + - address: 10.60.60.1 + remote_as: 65001 + ebgp_multihop: 2 + update_source: eth0 +base_hostname: VyOS-CE2-SPOKE diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml new file mode 100644 index 0000000..95ff9e7 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml @@ -0,0 +1,34 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.3/32 + - name: eth0 + addresses: + - 172.16.30.1/24 + - name: eth1 + addresses: + - 172.16.40.1/24 + - name: eth2 + addresses: + - 172.16.90.1/24 + - name: eth3 + addresses: + - 172.16.10.1/24 + - name: eth5 + addresses: + - 172.16.100.1/24 +ospf_router_id: 10.0.0.3 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.3 +mpls_ldp_interfaces: + - eth0 + - eth1 + - eth2 + - eth3 + - eth5 +base_hostname: VyOS-P1 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml new file mode 100644 index 0000000..b07a4b1 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml @@ -0,0 +1,30 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.4/32 + - name: eth0 + addresses: + - 172.16.30.2/24 + - name: eth1 + addresses: + - 172.16.20.1/24 + - name: eth2 + addresses: + - 172.16.120.1/24 + - name: eth3 + addresses: + - 172.16.60.1/24 +ospf_router_id: 10.0.0.4 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.4 +mpls_ldp_interfaces: + - eth0 + - eth1 + - eth2 + - eth3 +base_hostname: VyOS-P2 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml new file mode 100644 index 0000000..ae8f0d5 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml @@ -0,0 +1,30 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.5/32 + - name: eth0 + addresses: + - 172.16.110.1/24 + - name: eth1 + addresses: + - 172.16.40.2/24 + - name: eth2 + addresses: + - 172.16.50.1/24 + - name: eth3 + addresses: + - 172.16.70.1/24 +ospf_router_id: 10.0.0.5 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.5 +mpls_ldp_interfaces: + - eth0 + - eth1 + - eth2 + - eth3 +base_hostname: VyOS-P3 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml new file mode 100644 index 0000000..4740ea6 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml @@ -0,0 +1,34 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.6/32 + - name: eth0 + addresses: + - 172.16.80.2/24 + - name: eth1 + addresses: + - 172.16.130.1/24 + - name: eth2 + addresses: + - 172.16.50.2/24 + - name: eth3 + addresses: + - 172.16.60.2/24 + - name: eth5 + addresses: + - 172.16.140.1/24 +ospf_router_id: 10.0.0.6 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.6 +mpls_ldp_interfaces: + - eth0 + - eth1 + - eth2 + - eth3 + - eth5 +base_hostname: VyOS-P4 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml new file mode 100644 index 0000000..5b9c0d5 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml @@ -0,0 +1,54 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.7/32 + - name: eth0 + addresses: + - 172.16.90.2/24 + - name: eth3 + addresses: + - 10.50.50.1/24 +ospf_router_id: 10.0.0.7 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.7 +mpls_ldp_interfaces: + - eth0 +l3vpn_asn: 65001 +l3vpn_router_id: 10.0.0.7 +l3vpn_peer_group: + name: RR_VPNv4 + remote_as: 65001 + update_source: dum10 +l3vpn_neighbors: + - address: 10.0.0.1 + nexthop_self: true + - address: 10.0.0.2 + nexthop_self: true +vrf_lite_asn: 65001 +vrf_lite_vrfs: + - name: BLUE_SPOKE + table: 200 + interfaces: + - eth3 + families: + - ipv4 + label_vpn_export: auto + networks: + - 10.50.50.0/24 + rd: 10.50.50.1:1011 + route_targets_export: + - 65035:1011 + route_targets_import: + - 65035:1030 + redistribute: + - connected + neighbors: + - address: 10.50.50.2 + remote_as: 65035 + as_override: true +base_hostname: VyOS-PE1 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml new file mode 100644 index 0000000..0788ed0 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml @@ -0,0 +1,63 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.8/32 + - name: eth0 + addresses: + - 172.16.110.2/24 + - name: eth1 + addresses: + - 172.16.100.2/24 + - name: eth2 + addresses: + - 172.16.80.1/24 + - name: eth3 + addresses: + - 10.80.80.1/24 +ospf_router_id: 10.0.0.8 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.8 +mpls_ldp_interfaces: + - eth0 + - eth1 +l3vpn_asn: 65001 +l3vpn_router_id: 10.0.0.8 +l3vpn_peer_group: + name: RR_VPNv4 + remote_as: 65001 + update_source: dum10 +l3vpn_neighbors: + - address: 10.0.0.1 + nexthop_self: true + - address: 10.0.0.2 + nexthop_self: true +vrf_lite_asn: 65001 +vrf_lite_vrfs: + - name: BLUE_HUB + table: 400 + interfaces: + - eth3 + families: + - ipv4 + label_vpn_export: auto + networks: + - 10.80.80.0/24 + rd: 10.80.80.1:1011 + route_targets_export: + - 65035:1030 + route_targets_import: + - 65035:1011 + - 65050:2011 + - 65035:1030 + redistribute: + - connected + neighbors: + - address: 10.80.80.2 + remote_as: 65035 + as_override: true +base_hostname: VyOS-PE2 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml new file mode 100644 index 0000000..abc5dde --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml @@ -0,0 +1,54 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.10/32 + - name: eth0 + addresses: + - 172.16.140.2/24 + - name: eth3 + addresses: + - 10.60.60.1/24 +ospf_router_id: 10.0.0.10 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.10 +mpls_ldp_interfaces: + - eth0 +l3vpn_asn: 65001 +l3vpn_router_id: 10.0.0.10 +l3vpn_peer_group: + name: RR_VPNv4 + remote_as: 65001 + update_source: dum10 +l3vpn_neighbors: + - address: 10.0.0.1 + nexthop_self: true + - address: 10.0.0.2 + nexthop_self: true +vrf_lite_asn: 65001 +vrf_lite_vrfs: + - name: BLUE_SPOKE + table: 200 + interfaces: + - eth3 + families: + - ipv4 + label_vpn_export: auto + networks: + - 10.60.60.0/24 + rd: 10.60.60.1:1011 + route_targets_export: + - 65035:1011 + route_targets_import: + - 65035:1030 + redistribute: + - connected + neighbors: + - address: 10.60.60.2 + remote_as: 65035 + as_override: true +base_hostname: VyOS-PE3 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml new file mode 100644 index 0000000..08e1271 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml @@ -0,0 +1,36 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.1/32 + - name: eth1 + addresses: + - 172.16.20.2/24 + - name: eth2 + addresses: + - 172.16.10.2/24 +ospf_router_id: 10.0.0.1 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.1 +mpls_ldp_interfaces: + - eth1 + - eth2 +l3vpn_asn: 65001 +l3vpn_router_id: 10.0.0.1 +l3vpn_cluster_id: 10.0.0.1 +l3vpn_peer_group: + name: RR_VPNv4 + remote_as: 65001 + update_source: dum10 +l3vpn_neighbors: + - address: 10.0.0.7 + route_reflector_client: true + - address: 10.0.0.8 + route_reflector_client: true + - address: 10.0.0.10 + route_reflector_client: true +base_hostname: VyOS-RR1 diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml new file mode 100644 index 0000000..55bb756 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml @@ -0,0 +1,36 @@ +--- +base_interfaces: + - name: dum10 + addresses: + - 10.0.0.2/32 + - name: eth0 + addresses: + - 172.16.80.1/24 + - name: eth1 + addresses: + - 172.16.70.2/24 +ospf_router_id: 10.0.0.2 +ospf_areas: + - id: '0' + networks: + - 0.0.0.0/0 +ospf_abr_type: cisco +mpls_ldp_router_id: 10.0.0.2 +mpls_ldp_interfaces: + - eth0 + - eth1 +l3vpn_asn: 65001 +l3vpn_router_id: 10.0.0.2 +l3vpn_cluster_id: 10.0.0.1 +l3vpn_peer_group: + name: RR_VPNv4 + remote_as: 65001 + update_source: dum10 +l3vpn_neighbors: + - address: 10.0.0.7 + route_reflector_client: true + - address: 10.0.0.8 + route_reflector_client: true + - address: 10.0.0.10 + route_reflector_client: true +base_hostname: VyOS-RR2 diff --git a/examples/l3vpn-hub-and-spoke/inventory.yml b/examples/l3vpn-hub-and-spoke/inventory.yml new file mode 100644 index 0000000..f672ea1 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/inventory.yml @@ -0,0 +1,43 @@ +--- +# docs.vyos.io/en/1.5/configexamples/l3vpn-hub-and-spoke.html - all twelve routers. +# For a containerlab try-out, use the reduced lab in +# extensions/molecule/l3vpn_hub_and_spoke (one RR, one P router). +all: + children: + p_routers: + hosts: + VyOS-P1: + ansible_host: 192.0.2.1 # your router's address + VyOS-P2: + ansible_host: 192.0.2.2 # your router's address + VyOS-P3: + ansible_host: 192.0.2.3 # your router's address + VyOS-P4: + ansible_host: 192.0.2.4 # your router's address + route_reflectors: + hosts: + VyOS-RR1: + ansible_host: 192.0.2.1 # your router's address + VyOS-RR2: + ansible_host: 192.0.2.2 # your router's address + pe_routers: + hosts: + VyOS-PE1: + ansible_host: 192.0.2.1 # your router's address + VyOS-PE2: + ansible_host: 192.0.2.2 # your router's address + VyOS-PE3: + ansible_host: 192.0.2.3 # your router's address + ce_routers: + hosts: + VyOS-CE1-SPOKE: + ansible_host: 192.0.2.1 # your router's address + VyOS-CE1-HUB: + ansible_host: 192.0.2.2 # your router's address + VyOS-CE2-SPOKE: + ansible_host: 192.0.2.3 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/l3vpn-hub-and-spoke/site.yml b/examples/l3vpn-hub-and-spoke/site.yml new file mode 100644 index 0000000..3907543 --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/site.yml @@ -0,0 +1,16 @@ +--- +- name: MPLS L3VPN hub-and-spoke + hosts: all + gather_facts: false + roles: + - vyos.blueprints.base # loopbacks and link addresses + - vyos.blueprints.ospf # step 1: IGP (P, PE, RR) + - vyos.blueprints.mpls_ldp # step 1: MPLS and LDP (P, PE, RR) + - vyos.blueprints.l3vpn # step 2: iBGP VPNv4 with route reflectors (PE, RR) + - vyos.blueprints.vrf_lite # step 3: PE VRFs with RD, RT and CE neighbours + - vyos.blueprints.bgp # step 4: CE eBGP to the PE + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/l3vpn-hub-and-spoke/verify.yml b/examples/l3vpn-hub-and-spoke/verify.yml new file mode 100644 index 0000000..0c5b84f --- /dev/null +++ b/examples/l3vpn-hub-and-spoke/verify.yml @@ -0,0 +1,27 @@ +--- +- name: Check the provider network + hosts: p_routers:route_reflectors:pe_routers + gather_facts: false + tasks: + - name: LDP checks + ansible.builtin.include_role: + name: vyos.blueprints.mpls_ldp + tasks_from: verify + +- name: Check VPNv4 sessions + hosts: route_reflectors:pe_routers + gather_facts: false + tasks: + - name: VPNv4 checks + ansible.builtin.include_role: + name: vyos.blueprints.l3vpn + tasks_from: verify + +- name: Check CE sessions + hosts: ce_routers + gather_facts: false + tasks: + - name: BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.bgp + tasks_from: verify diff --git a/examples/pppoe-ipv6-home/group_vars/home.yml b/examples/pppoe-ipv6-home/group_vars/home.yml new file mode 100644 index 0000000..18cafe0 --- /dev/null +++ b/examples/pppoe-ipv6-home/group_vars/home.yml @@ -0,0 +1,73 @@ +--- +# Home router - docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html +# Set username, password (ansible-vault) and service name to your ISP's values. +# WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 +# for management). The lab ISP delegates a /56, hence length 56 and sla-id 0; +# with a /64 from your ISP, drop both as on the page. +pppoe_interfaces: + - name: pppoe0 + source_interface: eth1 + username: molecule + password: '{{ vault_pppoe_password }}' + service_name: ISP + ipv6_autoconf: true + prefix_delegation: + - id: 0 + length: 56 + interfaces: + - name: eth2 + address: '100' + sla_id: 0 +router_advert_interfaces: + - name: eth2 + link_mtu: 1492 + name_servers: + - 2001:db8::53 + prefixes: + - prefix: ::/64 + valid_lifetime: 172800 +firewall_ipv6: + names: + WAN_IN: + default_action: drop + rules: + - number: 10 + action: accept + state: + established: true + related: true + - number: 20 + action: accept + protocol: icmpv6 + WAN_LOCAL: + default_action: drop + rules: + - number: 10 + action: accept + state: + established: true + related: true + - number: 20 + action: accept + protocol: icmpv6 + - number: 30 + action: accept + protocol: udp + source: + port: '547' + destination: + port: '546' + forward: + rules: + - number: 10 + action: jump + jump_target: WAN_IN + inbound_interface: + name: pppoe0 + input: + rules: + - number: 10 + action: jump + jump_target: WAN_LOCAL + inbound_interface: + name: pppoe0 diff --git a/examples/pppoe-ipv6-home/inventory.yml b/examples/pppoe-ipv6-home/inventory.yml new file mode 100644 index 0000000..3f53a29 --- /dev/null +++ b/examples/pppoe-ipv6-home/inventory.yml @@ -0,0 +1,17 @@ +--- +# docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html +all: + children: + home: + hosts: + r1: + ansible_host: clab-pppoe-ipv6-home-r1 # your router's address + provider: + hosts: + isp: + ansible_host: clab-pppoe-ipv6-home-isp # lab only, see isp.yml + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/pppoe-ipv6-home/isp.yml b/examples/pppoe-ipv6-home/isp.yml new file mode 100644 index 0000000..f554535 --- /dev/null +++ b/examples/pppoe-ipv6-home/isp.yml @@ -0,0 +1,21 @@ +--- +- name: Configure the ISP's PPPoE server in the containerlab lab (the ISP is not part of the blueprint) + hosts: provider + gather_facts: false + tasks: + - name: PPPoE server with IPv4, IPv6 and prefix delegation + vyos.vyos.vyos_config: + lines: + - set interfaces dummy dum0 address '2001:db8:ffff::1/128' + - set service pppoe-server authentication mode 'local' + - set service pppoe-server authentication local-users username molecule password '{{ vault_pppoe_password }}' + - set service pppoe-server client-ip-pool POOL4 range '100.64.0.10-100.64.0.20' + - set service pppoe-server default-pool 'POOL4' + - set service pppoe-server gateway-address '100.64.0.1' + - set service pppoe-server client-ipv6-pool POOL6 prefix '2001:db8:8002::/48' mask '64' + - set service pppoe-server client-ipv6-pool POOL6 delegate '2001:db8:8003::/48' delegation-prefix '56' + - set service pppoe-server default-ipv6-pool 'POOL6' + - set service pppoe-server ppp-options ipv6 'allow' + - set service pppoe-server service-name 'ISP' + - set service pppoe-server interface eth1 + no_log: true diff --git a/examples/pppoe-ipv6-home/site.yml b/examples/pppoe-ipv6-home/site.yml new file mode 100644 index 0000000..b4ccb5d --- /dev/null +++ b/examples/pppoe-ipv6-home/site.yml @@ -0,0 +1,13 @@ +--- +- name: PPPoE with DHCPv6-PD and SLAAC for a home network + hosts: home + gather_facts: false + roles: + - vyos.blueprints.pppoe # PPPoE client, IPv6 autoconf, prefix delegation + - vyos.blueprints.router_advert # SLAAC and RDNSS on the LAN + - vyos.blueprints.firewall # WAN_IN / WAN_LOCAL IPv6 firewall + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/pppoe-ipv6-home/topology.clab.yml b/examples/pppoe-ipv6-home/topology.clab.yml new file mode 100644 index 0000000..6e8c7ca --- /dev/null +++ b/examples/pppoe-ipv6-home/topology.clab.yml @@ -0,0 +1,19 @@ +name: pppoe-ipv6-home +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + r1: + kind: vyosnetworks_vyos + # VyOS PPPoE server standing in for the ISP (needs PPP kernel support on the host) + isp: + kind: vyosnetworks_vyos + pc: + kind: linux + image: alpine:3 + exec: ["sysctl -w net.ipv6.conf.eth1.accept_ra=1", "ip link set eth1 up"] + links: + # WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management) + - endpoints: ["r1:eth1", "isp:eth1"] + - endpoints: ["r1:eth2", "pc:eth1"] diff --git a/examples/pppoe-ipv6-home/verify.yml b/examples/pppoe-ipv6-home/verify.yml new file mode 100644 index 0000000..d63571f --- /dev/null +++ b/examples/pppoe-ipv6-home/verify.yml @@ -0,0 +1,13 @@ +--- +- name: Check the home router + hosts: home + gather_facts: false + tasks: + - name: PPPoE checks + ansible.builtin.include_role: + name: vyos.blueprints.pppoe + tasks_from: verify + - name: Firewall checks + ansible.builtin.include_role: + name: vyos.blueprints.firewall + tasks_from: verify diff --git a/examples/qos/host_vars/vyos2.yml b/examples/qos/host_vars/vyos2.yml new file mode 100644 index 0000000..6afaa1e --- /dev/null +++ b/examples/qos/host_vars/vyos2.yml @@ -0,0 +1,42 @@ +--- +# interfaces shifted by one (containerlab uses eth0 for management) +base_hostname: vyos2 +base_interfaces: + - name: eth1 + addresses: + - 10.1.1.1/24 + - name: eth3 + addresses: + - 10.9.9.1/24 +base_static_routes: + - dest: 172.17.1.0/24 + next_hop: 10.1.1.100 +qos_shapers: + - name: vyos2 + classes: + - id: 10 + bandwidth: 100% + burst: 15k + queue_type: fair-queue + set_dscp: CS5 + matches: + - name: VYOS2 + ip: + dscp: CS4 + - id: 20 + bandwidth: 5mbit + description: for VyOS3 eth0 + matches: + - name: VyOS3 + ip: + source: + address: 10.1.1.100/32 + default: + bandwidth: 100% + burst: 15k + ceiling: 100% + priority: 7 + queue_type: fair-queue +qos_interfaces: + - name: eth3 + egress: vyos2 diff --git a/examples/qos/host_vars/vyos3.yml b/examples/qos/host_vars/vyos3.yml new file mode 100644 index 0000000..10edbdf --- /dev/null +++ b/examples/qos/host_vars/vyos3.yml @@ -0,0 +1,45 @@ +--- +# interfaces shifted by one (containerlab uses eth0 for management) +base_hostname: vyos3 +base_interfaces: + - name: eth1 + addresses: + - 10.1.1.100/24 + - name: eth2 + addresses: + - 172.17.1.1/24 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.1.1.1 +qos_shapers: + - name: vyos3 + classes: + - id: 10 + set_dscp: CS4 + matches: + - name: ADDRESS10 + ip: + source: + address: 172.17.1.2/32 + - id: 20 + set_dscp: CS5 + matches: + - name: ADDRESS20 + ip: + source: + address: 172.17.1.3/32 + - id: 30 + set_dscp: CS6 + matches: + - name: ADDRESS30 + ip: + source: + address: 172.17.1.4/32 + default: + bandwidth: 10% + ceiling: 100% + priority: 7 + queue_type: fair-queue +qos_interfaces: + - name: eth1 + egress: vyos3 diff --git a/examples/qos/host_vars/vyos4.yml b/examples/qos/host_vars/vyos4.yml new file mode 100644 index 0000000..80f86c9 --- /dev/null +++ b/examples/qos/host_vars/vyos4.yml @@ -0,0 +1,31 @@ +--- +# not part of the lab topology; page values (eth0) for a real router +base_hostname: vyos4 +base_interfaces: + - name: eth0 + addresses: + - 10.2.1.100/24 +base_static_routes: + - dest: 0.0.0.0/0 + next_hop: 10.2.1.1 +qos_shapers: + - name: vyos4 + classes: + - id: 10 + bandwidth: 100% + burst: 15k + queue_type: fair-queue + set_dscp: CS4 + matches: + - name: ALL + ether: + protocol: all + default: + bandwidth: 10% + burst: 15k + ceiling: 100% + priority: 7 + queue_type: fair-queue +qos_interfaces: + - name: eth0 + egress: vyos4 diff --git a/examples/qos/inventory.yml b/examples/qos/inventory.yml new file mode 100644 index 0000000..9cb381a --- /dev/null +++ b/examples/qos/inventory.yml @@ -0,0 +1,16 @@ +--- +# docs.vyos.io/en/1.5/configexamples/qos.html +all: + children: + qos: + hosts: + vyos3: + ansible_host: clab-qos-vyos3 # your router's address + vyos2: + ansible_host: clab-qos-vyos2 + # vyos4: # add with its address on a real network + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/qos/site.yml b/examples/qos/site.yml new file mode 100644 index 0000000..9515881 --- /dev/null +++ b/examples/qos/site.yml @@ -0,0 +1,12 @@ +--- +- name: QoS - DSCP marking and shaping + hosts: qos + gather_facts: false + roles: + - vyos.blueprints.base # addresses and static routes + - vyos.blueprints.qos # shaper policies, DSCP re-marking, attachment + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/qos/topology.clab.yml b/examples/qos/topology.clab.yml new file mode 100644 index 0000000..fe1dcff --- /dev/null +++ b/examples/qos/topology.clab.yml @@ -0,0 +1,32 @@ +name: qos +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + vyos3: + kind: vyosnetworks_vyos + vyos2: + kind: vyosnetworks_vyos + # one host holding the page's four VPC addresses + vpcs: + kind: linux + image: alpine:3 + exec: + - ip addr add 172.17.1.2/24 dev eth1 + - ip addr add 172.17.1.3/24 dev eth1 + - ip addr add 172.17.1.4/24 dev eth1 + - ip addr add 172.17.1.40/24 dev eth1 + - ip route replace default via 172.17.1.1 + sink: + kind: linux + image: alpine:3 + exec: + - ip addr add 10.9.9.10/24 dev eth1 + - ip route replace default via 10.9.9.1 + - apk add --no-cache tcpdump + links: + # interfaces shifted by one (containerlab uses eth0 for management) + - endpoints: ["vyos3:eth1", "vyos2:eth1"] + - endpoints: ["vyos3:eth2", "vpcs:eth1"] + - endpoints: ["vyos2:eth3", "sink:eth1"] diff --git a/examples/qos/verify.yml b/examples/qos/verify.yml new file mode 100644 index 0000000..d0746a9 --- /dev/null +++ b/examples/qos/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check QoS + hosts: qos + gather_facts: false + tasks: + - name: QoS checks + ansible.builtin.include_role: + name: vyos.blueprints.qos + tasks_from: verify diff --git a/examples/wan-load-balancing/group_vars/wan.yml b/examples/wan-load-balancing/group_vars/wan.yml new file mode 100644 index 0000000..f3ff1d6 --- /dev/null +++ b/examples/wan-load-balancing/group_vars/wan.yml @@ -0,0 +1,51 @@ +--- +# docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html - Example 1 +# (distribute load evenly). Interfaces are shifted by one: page eth0/eth1/eth2 +# are eth1/eth2/eth3 here (containerlab uses eth0 for management). +# Switch designs with: ansible-playbook -i inventory.yml site.yml -e @variants/example2.yml +base_static_routes: + - dest: 33.44.55.66/32 + next_hop: 11.22.33.1 + - dest: 44.55.66.77/32 + next_hop: 11.22.33.1 + - dest: 55.66.77.88/32 + next_hop: 22.33.44.1 + - dest: 66.77.88.99/32 + next_hop: 22.33.44.1 +wan_load_balance_interfaces: + - name: eth1 + failure_count: 5 + nexthop: 11.22.33.1 + tests: + - id: 10 + type: ping + target: 33.44.55.66 + - id: 20 + type: ping + target: 44.55.66.77 + - name: eth2 + failure_count: 4 + nexthop: 22.33.44.1 + tests: + - id: 10 + type: ping + target: 55.66.77.88 + - id: 20 + type: ping + target: 66.77.88.99 +wan_load_balance_rules: + - number: 10 + inbound_interface: eth3 + interfaces: + - name: eth1 + - name: eth2 +base_interfaces: + - name: eth1 + addresses: + - 11.22.33.2/24 + - name: eth2 + addresses: + - 22.33.44.2/24 + - name: eth3 + addresses: + - 10.0.0.1/24 diff --git a/examples/wan-load-balancing/inventory.yml b/examples/wan-load-balancing/inventory.yml new file mode 100644 index 0000000..98a6069 --- /dev/null +++ b/examples/wan-load-balancing/inventory.yml @@ -0,0 +1,13 @@ +--- +# docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html +all: + children: + wan: + hosts: + r1: + ansible_host: clab-wan-load-balancing-r1 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/wan-load-balancing/site.yml b/examples/wan-load-balancing/site.yml new file mode 100644 index 0000000..dfc8d77 --- /dev/null +++ b/examples/wan-load-balancing/site.yml @@ -0,0 +1,12 @@ +--- +- name: WAN load balancing + hosts: wan + gather_facts: false + roles: + - vyos.blueprints.base # addresses and routes to the ping targets + - vyos.blueprints.wan_load_balance # health checks and rules + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/wan-load-balancing/topology.clab.yml b/examples/wan-load-balancing/topology.clab.yml new file mode 100644 index 0000000..336ada0 --- /dev/null +++ b/examples/wan-load-balancing/topology.clab.yml @@ -0,0 +1,32 @@ +name: wan-load-balancing +topology: + nodes: + r1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:latest} + # each ISP answers its two health-check targets and a shared "internet" address + isp1: + kind: linux + image: alpine:3 + exec: + - ip addr add 11.22.33.1/24 dev eth1 + - ip addr add 33.44.55.66/32 dev lo + - ip addr add 44.55.66.77/32 dev lo + - ip addr add 198.51.100.100/32 dev lo + isp2: + kind: linux + image: alpine:3 + exec: + - ip addr add 22.33.44.1/24 dev eth1 + - ip addr add 55.66.77.88/32 dev lo + - ip addr add 66.77.88.99/32 dev lo + - ip addr add 198.51.100.100/32 dev lo + lan: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.0.0.10/24 dev eth1", "ip route replace default via 10.0.0.1"] + links: + # page eth0/eth1/eth2 = eth1/eth2/eth3 here (containerlab uses eth0 for management) + - endpoints: ["r1:eth1", "isp1:eth1"] + - endpoints: ["r1:eth2", "isp2:eth1"] + - endpoints: ["r1:eth3", "lan:eth1"] diff --git a/examples/wan-load-balancing/variants/example2.yml b/examples/wan-load-balancing/variants/example2.yml new file mode 100644 index 0000000..67cfe78 --- /dev/null +++ b/examples/wan-load-balancing/variants/example2.yml @@ -0,0 +1,11 @@ +--- +# Example 2: failover based on interface weights +wan_load_balance_rules: + - number: 10 + failover: true + inbound_interface: eth3 + interfaces: + - name: eth1 + weight: 10 + - name: eth2 + weight: 1 diff --git a/examples/wan-load-balancing/variants/example3.yml b/examples/wan-load-balancing/variants/example3.yml new file mode 100644 index 0000000..2a8e313 --- /dev/null +++ b/examples/wan-load-balancing/variants/example3.yml @@ -0,0 +1,11 @@ +--- +# Example 3: failover based on rule order +wan_load_balance_rules: + - number: 10 + inbound_interface: eth3 + interfaces: + - name: eth1 + - number: 20 + inbound_interface: eth3 + interfaces: + - name: eth2 diff --git a/examples/wan-load-balancing/variants/example4.yml b/examples/wan-load-balancing/variants/example4.yml new file mode 100644 index 0000000..94e8728 --- /dev/null +++ b/examples/wan-load-balancing/variants/example4.yml @@ -0,0 +1,25 @@ +--- +# Example 4: rule order, secondary link only for SIP +wan_load_balance_rules: + - number: 10 + inbound_interface: eth3 + interfaces: + - name: eth1 + - number: 20 + inbound_interface: eth3 + interfaces: + - name: eth2 + destination: + port: sip + protocol: tcp +base_static_routes: + - dest: 33.44.55.66/32 + next_hop: 11.22.33.1 + - dest: 44.55.66.77/32 + next_hop: 11.22.33.1 + - dest: 55.66.77.88/32 + next_hop: 22.33.44.1 + - dest: 66.77.88.99/32 + next_hop: 22.33.44.1 + - dest: 0.0.0.0/0 + next_hop: 11.22.33.1 diff --git a/examples/wan-load-balancing/variants/example5.yml b/examples/wan-load-balancing/variants/example5.yml new file mode 100644 index 0000000..0cd5cb6 --- /dev/null +++ b/examples/wan-load-balancing/variants/example5.yml @@ -0,0 +1,30 @@ +--- +# Example 5: exclude traffic between local subnets +wan_load_balance_rules: + - number: 5 + exclude: true + inbound_interface: eth+ + destination: + address: 10.0.0.0/8 + - number: 10 + inbound_interface: eth3 + interfaces: + - name: eth1 + - number: 20 + inbound_interface: eth3 + interfaces: + - name: eth2 + destination: + port: sip + protocol: tcp +base_static_routes: + - dest: 33.44.55.66/32 + next_hop: 11.22.33.1 + - dest: 44.55.66.77/32 + next_hop: 11.22.33.1 + - dest: 55.66.77.88/32 + next_hop: 22.33.44.1 + - dest: 66.77.88.99/32 + next_hop: 22.33.44.1 + - dest: 0.0.0.0/0 + next_hop: 11.22.33.1 diff --git a/examples/wan-load-balancing/verify.yml b/examples/wan-load-balancing/verify.yml new file mode 100644 index 0000000..70ea282 --- /dev/null +++ b/examples/wan-load-balancing/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check WAN load balancing + hosts: wan + gather_facts: false + tasks: + - name: Load-balancer checks + ansible.builtin.include_role: + name: vyos.blueprints.wan_load_balance + tasks_from: verify |
