summaryrefslogtreecommitdiff
path: root/examples
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-06 08:40:09 +1000
committeromnom62 <omnom62@outlook.com>2026-10-06 08:40:09 +1000
commitf0bd8a9aec89892ec4e9249c8b51b383aea8a7f2 (patch)
tree430a3872734354551b79f6f30ccdaba0f538b765 /examples
parent8ee802e41374942965b6b93cfb4534725ef45145 (diff)
downloadvyos.blueprints-f0bd8a9aec89892ec4e9249c8b51b383aea8a7f2.tar.gz
vyos.blueprints-f0bd8a9aec89892ec4e9249c8b51b383aea8a7f2.zip
T9393: new roles
Diffstat (limited to 'examples')
-rw-r--r--examples/README.md10
-rw-r--r--examples/dmvpn-dual-hub/group_vars/dmvpn.yml29
-rw-r--r--examples/dmvpn-dual-hub/host_vars/hub1.yml32
-rw-r--r--examples/dmvpn-dual-hub/host_vars/hub2.yml32
-rw-r--r--examples/dmvpn-dual-hub/host_vars/spoke2.yml63
-rw-r--r--examples/dmvpn-dual-hub/host_vars/spoke3.yml64
-rw-r--r--examples/dmvpn-dual-hub/inventory.yml20
-rw-r--r--examples/dmvpn-dual-hub/site.yml14
-rw-r--r--examples/dmvpn-dual-hub/topology.clab.yml37
-rw-r--r--examples/dmvpn-dual-hub/verify.yml10
-rw-r--r--examples/gcp-ha-vpn-bgp/group_vars/edges.yml29
-rw-r--r--examples/gcp-ha-vpn-bgp/host_vars/edge1.yml32
-rw-r--r--examples/gcp-ha-vpn-bgp/host_vars/edge2.yml32
-rw-r--r--examples/gcp-ha-vpn-bgp/inventory.yml18
-rw-r--r--examples/gcp-ha-vpn-bgp/site.yml11
-rw-r--r--examples/gcp-ha-vpn-bgp/verify.yml9
-rw-r--r--examples/ha-walkthrough/group_vars/routers.yml120
-rw-r--r--examples/ha-walkthrough/host_vars/router1.yml85
-rw-r--r--examples/ha-walkthrough/host_vars/router2.yml75
-rw-r--r--examples/ha-walkthrough/inventory.yml15
-rw-r--r--examples/ha-walkthrough/site.yml18
-rw-r--r--examples/ha-walkthrough/topology.clab.yml54
-rw-r--r--examples/ha-walkthrough/verify.yml17
-rw-r--r--examples/inter-vrf/group_vars/core.yml136
-rw-r--r--examples/inter-vrf/inventory.yml17
-rw-r--r--examples/inter-vrf/isp.yml25
-rw-r--r--examples/inter-vrf/site.yml13
-rw-r--r--examples/inter-vrf/topology.clab.yml48
-rw-r--r--examples/inter-vrf/verify.yml9
-rw-r--r--examples/isis-segment-routing/group_vars/p_routers.yml5
-rw-r--r--examples/isis-segment-routing/host_vars/P1-VyOS.yml31
-rw-r--r--examples/isis-segment-routing/host_vars/P2-VyOS.yml31
-rw-r--r--examples/isis-segment-routing/host_vars/P3.yml31
-rw-r--r--examples/isis-segment-routing/inventory.yml17
-rw-r--r--examples/isis-segment-routing/site.yml12
-rw-r--r--examples/isis-segment-routing/topology.clab.yml16
-rw-r--r--examples/isis-segment-routing/verify.yml9
-rw-r--r--examples/l2tp-lns/group_vars/lns.yml38
-rw-r--r--examples/l2tp-lns/inventory.yml14
-rw-r--r--examples/l2tp-lns/site.yml13
-rw-r--r--examples/l2tp-lns/topology.clab.yml45
-rw-r--r--examples/l2tp-lns/verify.yml9
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml21
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml19
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml19
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml34
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml30
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml30
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml34
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml54
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml63
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml54
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml36
-rw-r--r--examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml36
-rw-r--r--examples/l3vpn-hub-and-spoke/inventory.yml43
-rw-r--r--examples/l3vpn-hub-and-spoke/site.yml16
-rw-r--r--examples/l3vpn-hub-and-spoke/verify.yml27
-rw-r--r--examples/pppoe-ipv6-home/group_vars/home.yml73
-rw-r--r--examples/pppoe-ipv6-home/inventory.yml17
-rw-r--r--examples/pppoe-ipv6-home/isp.yml21
-rw-r--r--examples/pppoe-ipv6-home/site.yml13
-rw-r--r--examples/pppoe-ipv6-home/topology.clab.yml19
-rw-r--r--examples/pppoe-ipv6-home/verify.yml13
-rw-r--r--examples/qos/host_vars/vyos2.yml42
-rw-r--r--examples/qos/host_vars/vyos3.yml45
-rw-r--r--examples/qos/host_vars/vyos4.yml31
-rw-r--r--examples/qos/inventory.yml16
-rw-r--r--examples/qos/site.yml12
-rw-r--r--examples/qos/topology.clab.yml32
-rw-r--r--examples/qos/verify.yml9
-rw-r--r--examples/wan-load-balancing/group_vars/wan.yml51
-rw-r--r--examples/wan-load-balancing/inventory.yml13
-rw-r--r--examples/wan-load-balancing/site.yml12
-rw-r--r--examples/wan-load-balancing/topology.clab.yml32
-rw-r--r--examples/wan-load-balancing/variants/example2.yml11
-rw-r--r--examples/wan-load-balancing/variants/example3.yml11
-rw-r--r--examples/wan-load-balancing/variants/example4.yml25
-rw-r--r--examples/wan-load-balancing/variants/example5.yml30
-rw-r--r--examples/wan-load-balancing/verify.yml9
79 files changed, 2398 insertions, 0 deletions
diff --git a/examples/README.md b/examples/README.md
index 8c149d5..f2ac5ab 100644
--- a/examples/README.md
+++ b/examples/README.md
@@ -17,6 +17,16 @@ Each directory is a complete, runnable Ansible project:
| `flexvpn-cisco/` | `gre_tunnel`, `ipsec_policy_based` | [Site-to-Site IPSec VPN to Cisco using FlexVPN](https://docs.vyos.io/en/1.5/configexamples/site-2-site-cisco.html) (no containerlab topology: needs a Cisco FlexVPN hub) |
| `azure-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html) (no containerlab topology: the far end is Azure) |
| `azure-vpn-dual-bgp/` | `ipsec_route_based` | [Route-Based Redundant Site-to-Site VPN to Azure (BGP over IKEv2/IPsec)](https://docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html) (no containerlab topology: the far end is Azure) |
+| `gcp-ha-vpn-bgp/` | `ipsec_route_based` | [Route-Based Site-to-Site VPN to Google Cloud HA VPN](https://docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html) (no containerlab topology: the far end is Google Cloud) |
+| `ha-walkthrough/` | `bonding`, `base`, `ha_vrrp`, `nat`, `wireguard`, `route_policy`, `ospf`, `bgp` | [High Availability Walkthrough](https://docs.vyos.io/en/1.5/configexamples/ha.html) - the complete page |
+| `inter-vrf/` | `base`, `route_policy`, `vrf_lite` | [Inter-VRF Routing over VRF Lite](https://docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html) (run `isp.yml` for the lab ISP) |
+| `wan-load-balancing/` | `base`, `wan_load_balance` | [WAN Load Balancer examples](https://docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html) - example 1 by default, `-e @variants/exampleN.yml` for examples 2-5 |
+| `pppoe-ipv6-home/` | `pppoe`, `router_advert`, `firewall` | [PPPoE IPv6 Basic Setup for Home Network](https://docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html) (run `isp.yml` for the lab ISP) |
+| `qos/` | `base`, `qos` | [QoS example](https://docs.vyos.io/en/1.5/configexamples/qos.html) |
+| `isis-segment-routing/` | `base`, `isis` | [Segment-routing IS-IS example](https://docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html) (P3 is a VyOS stand-in for the XRv in the lab) |
+| `l3vpn-hub-and-spoke/` | `base`, `ospf`, `mpls_ldp`, `l3vpn`, `vrf_lite`, `bgp` | [L3VPN for Hub-and-Spoke connectivity with VyOS](https://docs.vyos.io/en/1.5/configexamples/l3vpn-hub-and-spoke.html) (all 12 routers; reduced lab in the Molecule scenario) |
+| `l2tp-lns/` | `base`, `nat`, `l2tp_lns` | [PPPoE over L2TP](https://docs.vyos.io/en/1.5/configexamples/lac-lns.html) (the lab topology stands in for the Cisco LAC and adds FreeRADIUS) |
+| `dmvpn-dual-hub/` | `base`, `gre_tunnel`, `dmvpn`, `ospf` | [DMVPN Dual HUB Dual Cloud](https://docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html) (VyOS hubs and spokes) |
Most examples ship a `topology.clab.yml`, so you can try them against
containerized VyOS before pointing it at real routers:
diff --git a/examples/dmvpn-dual-hub/group_vars/dmvpn.yml b/examples/dmvpn-dual-hub/group_vars/dmvpn.yml
new file mode 100644
index 0000000..8570c1a
--- /dev/null
+++ b/examples/dmvpn-dual-hub/group_vars/dmvpn.yml
@@ -0,0 +1,29 @@
+---
+# Shared by all VyOS DMVPN nodes - docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html
+# WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management).
+dmvpn_ipsec:
+ interfaces:
+ - eth1
+ ike_group:
+ name: IKE-HUB
+ key_exchange: ikev1
+ lifetime: 3600
+ proposal_id: 1
+ dh_group: 2
+ encryption: aes256
+ hash: sha1
+ esp_group:
+ name: ESP-HUB
+ lifetime: 1800
+ mode: transport
+ pfs: disable
+ proposal_id: 1
+ encryption: aes256
+ hash: sha1
+ profile:
+ name: NHRPVPN
+ psk: '{{ vault_dmvpn_psk }}'
+ bind_tunnels: '{{ gre_tunnel_interfaces | map(attribute=''name'') | list }}'
+dmvpn_drop_unprotected_gre:
+ rule: 10
+ospf_passive_interface_default: true
diff --git a/examples/dmvpn-dual-hub/host_vars/hub1.yml b/examples/dmvpn-dual-hub/host_vars/hub1.yml
new file mode 100644
index 0000000..868c9aa
--- /dev/null
+++ b/examples/dmvpn-dual-hub/host_vars/hub1.yml
@@ -0,0 +1,32 @@
+---
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.0.0.2/30
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.0.0.1
+gre_tunnel_interfaces:
+ - name: tun100
+ addresses:
+ - 10.100.100.1/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 42
+ source_interface: eth1
+dmvpn_nhrp_tunnels:
+ - name: tun100
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: dynamic
+ network_id: 1
+ redirect: true
+ registration_no_unique: true
+ospf_interfaces:
+ - name: tun100
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+base_hostname: HUB-1
diff --git a/examples/dmvpn-dual-hub/host_vars/hub2.yml b/examples/dmvpn-dual-hub/host_vars/hub2.yml
new file mode 100644
index 0000000..07699e5
--- /dev/null
+++ b/examples/dmvpn-dual-hub/host_vars/hub2.yml
@@ -0,0 +1,32 @@
+---
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.0.1.2/30
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.0.1.1
+gre_tunnel_interfaces:
+ - name: tun101
+ addresses:
+ - 10.100.101.1/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 43
+ source_interface: eth1
+dmvpn_nhrp_tunnels:
+ - name: tun101
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: dynamic
+ network_id: 2
+ redirect: true
+ registration_no_unique: true
+ospf_interfaces:
+ - name: tun101
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+base_hostname: HUB-2
diff --git a/examples/dmvpn-dual-hub/host_vars/spoke2.yml b/examples/dmvpn-dual-hub/host_vars/spoke2.yml
new file mode 100644
index 0000000..911052e
--- /dev/null
+++ b/examples/dmvpn-dual-hub/host_vars/spoke2.yml
@@ -0,0 +1,63 @@
+---
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.0.12.2/30
+ - name: eth2
+ addresses:
+ - 192.168.12.1/24
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.0.12.1
+gre_tunnel_interfaces:
+ - name: tun100
+ addresses:
+ - 10.100.100.12/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 42
+ source_interface: eth1
+ - name: tun101
+ addresses:
+ - 10.100.101.12/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 43
+ source_interface: eth1
+dmvpn_nhrp_tunnels:
+ - name: tun100
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: 10.0.0.2
+ network_id: 1
+ nhs:
+ - tunnel_ip: dynamic
+ nbma: 10.0.0.2
+ registration_no_unique: true
+ shortcut: true
+ - name: tun101
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: 10.0.1.2
+ network_id: 2
+ nhs:
+ - tunnel_ip: dynamic
+ nbma: 10.0.1.2
+ registration_no_unique: true
+ shortcut: true
+ospf_interfaces:
+ - name: eth2
+ area: '0'
+ - name: tun100
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+ - name: tun101
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+base_hostname: SPOKE-2
diff --git a/examples/dmvpn-dual-hub/host_vars/spoke3.yml b/examples/dmvpn-dual-hub/host_vars/spoke3.yml
new file mode 100644
index 0000000..2923f63
--- /dev/null
+++ b/examples/dmvpn-dual-hub/host_vars/spoke3.yml
@@ -0,0 +1,64 @@
+---
+# the page shows no tunnel-interface block for Spoke-3; it mirrors Spoke-2 with .13
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.0.13.2/30
+ - name: eth2
+ addresses:
+ - 192.168.13.1/24
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.0.13.1
+gre_tunnel_interfaces:
+ - name: tun100
+ addresses:
+ - 10.100.100.13/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 42
+ source_interface: eth1
+ - name: tun101
+ addresses:
+ - 10.100.101.13/32
+ enable_multicast: true
+ encapsulation: gre
+ adjust_mss: '1360'
+ mtu: 1436
+ key: 43
+ source_interface: eth1
+dmvpn_nhrp_tunnels:
+ - name: tun100
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: 10.0.0.2
+ network_id: 1
+ nhs:
+ - tunnel_ip: dynamic
+ nbma: 10.0.0.2
+ registration_no_unique: true
+ shortcut: true
+ - name: tun101
+ authentication: '{{ vault_nhrp_authentication }}'
+ holdtime: 300
+ multicast: 10.0.1.2
+ network_id: 2
+ nhs:
+ - tunnel_ip: dynamic
+ nbma: 10.0.1.2
+ registration_no_unique: true
+ shortcut: true
+ospf_interfaces:
+ - name: eth2
+ area: '0'
+ - name: tun100
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+ - name: tun101
+ area: '0'
+ network: point-to-multipoint
+ passive: false
+base_hostname: SPOKE-3
diff --git a/examples/dmvpn-dual-hub/inventory.yml b/examples/dmvpn-dual-hub/inventory.yml
new file mode 100644
index 0000000..4d256f6
--- /dev/null
+++ b/examples/dmvpn-dual-hub/inventory.yml
@@ -0,0 +1,20 @@
+---
+# docs.vyos.io/en/1.5/configexamples/dmvpn-dualhub-dualcloud.html - the VyOS
+# hubs and spokes (Spoke-1 is the Cisco router on the page).
+all:
+ children:
+ dmvpn:
+ hosts:
+ hub1:
+ ansible_host: clab-dmvpn-dual-hub-hub1 # your router's address
+ hub2:
+ ansible_host: clab-dmvpn-dual-hub-hub2
+ spoke2:
+ ansible_host: clab-dmvpn-dual-hub-spoke2
+ spoke3:
+ ansible_host: clab-dmvpn-dual-hub-spoke3
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/dmvpn-dual-hub/site.yml b/examples/dmvpn-dual-hub/site.yml
new file mode 100644
index 0000000..9d5f1a5
--- /dev/null
+++ b/examples/dmvpn-dual-hub/site.yml
@@ -0,0 +1,14 @@
+---
+- name: DMVPN dual hub, dual cloud
+ hosts: dmvpn
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # underlay addresses and default route
+ - vyos.blueprints.gre_tunnel # multipoint GRE tunnels
+ - vyos.blueprints.dmvpn # NHRP, IPsec profile, GRE protection rule
+ - vyos.blueprints.ospf # OSPF over the tunnels
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/dmvpn-dual-hub/topology.clab.yml b/examples/dmvpn-dual-hub/topology.clab.yml
new file mode 100644
index 0000000..22ecf62
--- /dev/null
+++ b/examples/dmvpn-dual-hub/topology.clab.yml
@@ -0,0 +1,37 @@
+# Needs GRE, NHRP and IPsec (xfrm) support on the container host.
+name: dmvpn-dual-hub
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ hub1: {kind: vyosnetworks_vyos}
+ hub2: {kind: vyosnetworks_vyos}
+ spoke2: {kind: vyosnetworks_vyos}
+ spoke3: {kind: vyosnetworks_vyos}
+ # the "internet" between all WAN links (10.0.X.1 on each /30)
+ isp:
+ kind: linux
+ image: alpine:3
+ exec:
+ - sysctl -w net.ipv4.ip_forward=1
+ - ip addr add 10.0.0.1/30 dev eth1
+ - ip addr add 10.0.1.1/30 dev eth2
+ - ip addr add 10.0.12.1/30 dev eth3
+ - ip addr add 10.0.13.1/30 dev eth4
+ pc2:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.12.2/24 dev eth1", "ip route replace default via 192.168.12.1"]
+ pc3:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.13.2/24 dev eth1", "ip route replace default via 192.168.13.1"]
+ links:
+ # WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management)
+ - endpoints: ["hub1:eth1", "isp:eth1"]
+ - endpoints: ["hub2:eth1", "isp:eth2"]
+ - endpoints: ["spoke2:eth1", "isp:eth3"]
+ - endpoints: ["spoke3:eth1", "isp:eth4"]
+ - endpoints: ["spoke2:eth2", "pc2:eth1"]
+ - endpoints: ["spoke3:eth2", "pc3:eth1"]
diff --git a/examples/dmvpn-dual-hub/verify.yml b/examples/dmvpn-dual-hub/verify.yml
new file mode 100644
index 0000000..6e1eb7f
--- /dev/null
+++ b/examples/dmvpn-dual-hub/verify.yml
@@ -0,0 +1,10 @@
+---
+- name: Check DMVPN
+ hosts: dmvpn
+ gather_facts: false
+ tasks:
+ - name: DMVPN and OSPF checks
+ ansible.builtin.include_role:
+ name: "vyos.blueprints.{{ item }}"
+ tasks_from: verify
+ loop: [dmvpn, ospf]
diff --git a/examples/gcp-ha-vpn-bgp/group_vars/edges.yml b/examples/gcp-ha-vpn-bgp/group_vars/edges.yml
new file mode 100644
index 0000000..d84ed63
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/group_vars/edges.yml
@@ -0,0 +1,29 @@
+---
+# docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html - shared by both edges
+ipsec_route_based_ike_group:
+ name: GCP-IKE
+ key_exchange: ikev2
+ lifetime: 36000
+ proposal_id: 10
+ dh_group: 14
+ encryption: aes256
+ hash: sha256
+ prf: prfsha256
+ dead_peer_detection: {action: restart, interval: 30}
+ipsec_route_based_esp_group:
+ name: GCP-ESP
+ lifetime: 10800
+ mode: tunnel
+ pfs: dh-group14
+ proposal_id: 10
+ encryption: aes256
+ hash: sha256
+ipsec_route_based_interfaces: [eth0]
+ipsec_route_based_disable_route_autoinstall: true
+ipsec_route_based_policy:
+ prefix_lists:
+ - {name: GCP-IN, rules: [{sequence: 10, action: permit, prefix: 10.70.0.0/20}]}
+ - {name: GCP-OUT, rules: [{sequence: 10, action: permit, prefix: 10.80.0.0/24}]}
+ route_maps:
+ - {name: GCP-IN, rules: [{sequence: 10, action: permit, prefix_list: GCP-IN}, {sequence: 20, action: deny}]}
+ - {name: GCP-OUT, rules: [{sequence: 10, action: permit, prefix_list: GCP-OUT}, {sequence: 20, action: deny}]}
diff --git a/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml b/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml
new file mode 100644
index 0000000..3f4d32e
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/host_vars/edge1.yml
@@ -0,0 +1,32 @@
+---
+ipsec_route_based_peers:
+ - name: gcp-ha-vpn-0
+ description: Google Cloud HA VPN tunnel 0
+ psk_name: gcp-ha-vpn-0
+ psk: example-gcp-ha-vpn-psk-0 # use ansible-vault; high-entropy in production
+ local_address: 198.51.100.10
+ remote_address: 203.0.113.10
+ connection_type: initiate
+ esp_group_on_vti: true
+ vti:
+ interface: vti10
+ address: 169.254.10.1/30
+ description: Google Cloud HA VPN tunnel 0
+ adjust_mss: '1350'
+ipsec_route_based_interface_routes:
+ - dest: 169.254.10.2/32
+ interface: vti10
+ipsec_route_based_bgp:
+ asn: 65010
+ router_id: 10.80.0.11
+ networks:
+ - 10.80.0.0/24
+ neighbors:
+ - address: 169.254.10.2
+ remote_as: 64514
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
+ route_map_import: GCP-IN
+ route_map_export: GCP-OUT
diff --git a/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml b/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml
new file mode 100644
index 0000000..dc40e0d
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/host_vars/edge2.yml
@@ -0,0 +1,32 @@
+---
+ipsec_route_based_peers:
+ - name: gcp-ha-vpn-1
+ description: Google Cloud HA VPN tunnel 1
+ psk_name: gcp-ha-vpn-1
+ psk: example-gcp-ha-vpn-psk-1 # use ansible-vault; high-entropy in production
+ local_address: 198.51.100.11
+ remote_address: 203.0.113.11
+ connection_type: initiate
+ esp_group_on_vti: true
+ vti:
+ interface: vti11
+ address: 169.254.10.5/30
+ description: Google Cloud HA VPN tunnel 1
+ adjust_mss: '1350'
+ipsec_route_based_interface_routes:
+ - dest: 169.254.10.6/32
+ interface: vti11
+ipsec_route_based_bgp:
+ asn: 65010
+ router_id: 10.80.0.12
+ networks:
+ - 10.80.0.0/24
+ neighbors:
+ - address: 169.254.10.6
+ remote_as: 64514
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
+ route_map_import: GCP-IN
+ route_map_export: GCP-OUT
diff --git a/examples/gcp-ha-vpn-bgp/inventory.yml b/examples/gcp-ha-vpn-bgp/inventory.yml
new file mode 100644
index 0000000..5ca4cbc
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/inventory.yml
@@ -0,0 +1,18 @@
+---
+# docs.vyos.io/en/1.5/configexamples/gcp-ha-vpn-bgp.html
+# Only the two VyOS edge peers are configured here; the HA VPN gateway, Cloud
+# Router, external VPN gateway and tunnels are created in Google Cloud as the
+# page describes.
+all:
+ children:
+ edges:
+ hosts:
+ edge1:
+ ansible_host: 198.51.100.10 # your edge 1 address
+ edge2:
+ ansible_host: 198.51.100.11 # your edge 2 address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/gcp-ha-vpn-bgp/site.yml b/examples/gcp-ha-vpn-bgp/site.yml
new file mode 100644
index 0000000..6b32f46
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/site.yml
@@ -0,0 +1,11 @@
+---
+- name: Route-based VPN to Google Cloud HA VPN
+ hosts: edges
+ gather_facts: false
+ roles:
+ - vyos.blueprints.ipsec_route_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/gcp-ha-vpn-bgp/verify.yml b/examples/gcp-ha-vpn-bgp/verify.yml
new file mode 100644
index 0000000..ff08323
--- /dev/null
+++ b/examples/gcp-ha-vpn-bgp/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check both edge peers
+ hosts: edges
+ gather_facts: false
+ tasks:
+ - name: IPsec and BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
diff --git a/examples/ha-walkthrough/group_vars/routers.yml b/examples/ha-walkthrough/group_vars/routers.yml
new file mode 100644
index 0000000..8c7be76
--- /dev/null
+++ b/examples/ha-walkthrough/group_vars/routers.yml
@@ -0,0 +1,120 @@
+---
+# Shared by both routers - docs.vyos.io/en/1.5/configexamples/ha.html
+
+# --- VRRP, conntrack-sync and the temporary default route (part 1)
+ha_vrrp_pair_group: routers
+ha_vrrp_sync_group:
+ name: sync
+ members:
+ - int
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 192.0.2.11
+
+# --- OSPF over WireGuard - filters and OSPF settings (part 2)
+route_policy_access_lists:
+ - number: 150
+ description: Outbound OSPF Redistribution
+ rules:
+ - number: 10
+ action: permit
+ destination:
+ any: true
+ source:
+ network: 10.200.201.0
+ inverse_mask: 0.0.0.255
+ - number: 20
+ action: permit
+ destination:
+ any: true
+ source:
+ network: 203.0.113.0
+ inverse_mask: 0.0.0.255
+ - number: 100
+ action: deny
+ destination:
+ any: true
+ source:
+ any: true
+ - number: 100
+ description: Inbound OSPF Routes from Peers
+ rules:
+ - number: 10
+ action: deny
+ destination:
+ any: true
+ source:
+ network: 10.201.0.0
+ inverse_mask: 0.0.255.255
+ - number: 100
+ action: permit
+ destination:
+ any: true
+ source:
+ any: true
+ospf_areas:
+ - id: 0.0.0.0
+ authentication: md5
+ networks:
+ - 10.254.60.0/24
+ospf_reference_bandwidth: 10000
+ospf_log_adjacency_changes: true
+ospf_abr_type: cisco
+ospf_redistribute:
+ - type: connected
+ospf_redistribute_access_lists:
+ connected: 150
+ospf_import_route_map: PUBOSPF
+
+# --- Route policy for OSPF import (PUBOSPF) and BGP export (BGPOUT, BGPPREPENDOUT)
+route_policy_prefix_lists:
+ - name: BGPOUT
+ description: BGP Export List
+ rules:
+ - sequence: 10
+ action: deny
+ description: Do not advertise short masks
+ ge: 25
+ prefix: 0.0.0.0/0
+ - sequence: 100
+ action: permit
+ description: Our network
+ prefix: 203.0.113.0/24
+ - sequence: 10000
+ action: deny
+ prefix: 0.0.0.0/0
+route_policy_route_maps:
+ - name: PUBOSPF
+ rules:
+ - sequence: 100
+ action: deny
+ match_access_list: '100'
+ - sequence: 500
+ action: permit
+ - name: BGPOUT
+ description: BGP Export Filter
+ rules:
+ - sequence: 10
+ action: permit
+ match_prefix_list: BGPOUT
+ - sequence: 10000
+ action: deny
+ - name: BGPPREPENDOUT
+ description: BGP Export Filter
+ rules:
+ - sequence: 10
+ action: permit
+ set_as_path_prepend: 65551 65551 65551
+ match_prefix_list: BGPOUT
+ - sequence: 10000
+ action: deny
+
+# --- BGP (part 3)
+bgp_asn: 65551
+bgp_networks:
+ - 192.0.2.0/24
+bgp_redistribute:
+ - type: connected
+ metric: 50
+ - type: ospf
+ metric: 50
diff --git a/examples/ha-walkthrough/host_vars/router1.yml b/examples/ha-walkthrough/host_vars/router1.yml
new file mode 100644
index 0000000..e33bd2c
--- /dev/null
+++ b/examples/ha-walkthrough/host_vars/router1.yml
@@ -0,0 +1,85 @@
+---
+# router1 (VM): trunk on eth1 here, eth0 on the page (containerlab uses eth0 for management)
+base_interfaces:
+ - name: eth1.50
+ addresses:
+ - 192.0.2.21/24
+ - name: eth1.100
+ addresses:
+ - 203.0.113.2/24
+ - name: eth1.201
+ addresses:
+ - 10.200.201.2/24
+ha_vrrp_priority: 200
+ha_vrrp_groups:
+ - name: int
+ vrid: 201
+ interface: eth1.201
+ address:
+ - 10.200.201.1/24
+ - name: public
+ vrid: 113
+ interface: eth1.100
+ address:
+ - 203.0.113.1/24
+ha_vrrp_local_addresses:
+ int: 10.200.201.2
+ public: 203.0.113.2
+ha_vrrp_conntrack_sync:
+ interface: eth1.201
+ accept_protocols:
+ - tcp
+ - udp
+ - icmp
+ event_listen_queue_size: 8
+ mcast_group: 224.0.0.50
+ sync_queue_size: 8
+ disable_helpers: true
+nat_source_rules:
+ - id: 10
+ outbound_interface:
+ name: eth1.50
+ source:
+ address: 10.200.201.0/24
+ destination:
+ address: '!192.0.2.0/24'
+ translation:
+ address: 203.0.113.1
+
+# --- part 2: WireGuard link to offsite1 and OSPF over it (keep the private key in ansible-vault)
+wireguard_interfaces:
+ - name: wg01
+ addresses:
+ - 10.254.60.1/30
+ description: router1-to-offsite1
+ port: 50001
+ peers:
+ - name: OFFSITE1
+ allowed_ips:
+ - 0.0.0.0/0
+ address: 203.0.113.3
+ port: 50001
+ persistent_keepalive: 15
+ public_key: GEFMOWzAyau42/HwdwfXnrfHdIISQF8YHj35rOgSZ0o=
+ private_key: '{{ vault_wg01_private_key }}'
+ospf_router_id: 10.254.60.1
+ospf_interfaces:
+ - name: wg01
+ md5_key: i360KoCwUGZvPq7e # use ansible-vault for real devices
+ md5_key_id: 1
+ cost: 11
+ dead_interval: 5
+ hello_interval: 1
+ network: point-to-point
+ priority: 1
+ retransmit_interval: 5
+ transmit_delay: 1
+
+# --- part 3: BGP session to the provider
+bgp_router_id: 192.0.2.21
+bgp_neighbors:
+ - address: 192.0.2.11
+ remote_as: 65550
+ update_source: 192.0.2.21
+ soft_reconfiguration_inbound: true
+ route_map_export: BGPOUT
diff --git a/examples/ha-walkthrough/host_vars/router2.yml b/examples/ha-walkthrough/host_vars/router2.yml
new file mode 100644
index 0000000..b4aefbc
--- /dev/null
+++ b/examples/ha-walkthrough/host_vars/router2.yml
@@ -0,0 +1,75 @@
+---
+# router2 (hardware): LACP bond0 of eth1/eth2 here, eth0/eth1 on the page
+base_interfaces:
+ - name: bond0.50
+ addresses:
+ - 192.0.2.22/24
+ - name: bond0.100
+ addresses:
+ - 203.0.113.3/24
+ - name: bond0.201
+ addresses:
+ - 10.200.201.3/24
+ha_vrrp_priority: 100
+ha_vrrp_groups:
+ - name: int
+ vrid: 201
+ interface: bond0.201
+ address:
+ - 10.200.201.1/24
+ - name: public
+ vrid: 113
+ interface: bond0.100
+ address:
+ - 203.0.113.1/24
+ha_vrrp_local_addresses:
+ int: 10.200.201.3
+ public: 203.0.113.3
+ha_vrrp_conntrack_sync:
+ interface: bond0.201
+ accept_protocols:
+ - tcp
+ - udp
+ - icmp
+ event_listen_queue_size: 8
+ mcast_group: 224.0.0.50
+ sync_queue_size: 8
+ disable_helpers: true
+nat_source_rules:
+ - id: 10
+ outbound_interface:
+ name: bond0.50
+ source:
+ address: 10.200.201.0/24
+ destination:
+ address: '!192.0.2.0/24'
+ translation:
+ address: 203.0.113.1
+bonding_interfaces:
+ - name: bond0
+ description: Switch Port-Channel
+ hash_policy: layer2
+ members:
+ - eth1
+ - eth2
+ mode: 802.3ad
+
+# --- part 2: as described in "Duplicate configuration", give router2 its own
+# WireGuard link(s) to the offsite routers (a different /30 from 10.254.60.0/24
+# per link) with the same OSPF interface settings, and a unique router-id, e.g.:
+# wireguard_interfaces:
+# - name: wg01
+# addresses: [10.254.60.5/30]
+# ...
+# ospf_router_id: 10.254.60.5
+# ospf_interfaces: [...]
+
+# --- part 3: BGP session to the provider, exporting with the AS-path prepend
+# (the page: "identical, but use BGPPREPENDOUT"; peer per the Example Network)
+bgp_router_id: 192.0.2.22
+bgp_neighbors:
+ - address: 192.0.2.12
+ remote_as: 65550
+ update_source: 192.0.2.22
+ soft_reconfiguration_inbound: true
+ route_map_export: BGPPREPENDOUT
diff --git a/examples/ha-walkthrough/inventory.yml b/examples/ha-walkthrough/inventory.yml
new file mode 100644
index 0000000..ba48d0d
--- /dev/null
+++ b/examples/ha-walkthrough/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/ha.html
+all:
+ children:
+ routers:
+ hosts:
+ router1:
+ ansible_host: clab-ha-walkthrough-router1 # your router's address
+ router2:
+ ansible_host: clab-ha-walkthrough-router2
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/ha-walkthrough/site.yml b/examples/ha-walkthrough/site.yml
new file mode 100644
index 0000000..9c1923d
--- /dev/null
+++ b/examples/ha-walkthrough/site.yml
@@ -0,0 +1,18 @@
+---
+- name: High Availability Walkthrough
+ hosts: routers
+ gather_facts: false
+ roles:
+ - vyos.blueprints.bonding # router2 only (bond0)
+ - vyos.blueprints.base # VLAN addresses, temporary default route
+ - vyos.blueprints.ha_vrrp # VRRP groups, sync-group, conntrack-sync
+ - vyos.blueprints.nat # masquerade 10.200.201.0/24 to 203.0.113.1
+ - vyos.blueprints.wireguard # links to the offsite routers
+ - vyos.blueprints.route_policy # access-lists 100/150, route-map PUBOSPF
+ - vyos.blueprints.ospf # OSPF over WireGuard with import/export filters
+ - vyos.blueprints.bgp # BGP to the provider, BGPOUT / BGPPREPENDOUT
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/ha-walkthrough/topology.clab.yml b/examples/ha-walkthrough/topology.clab.yml
new file mode 100644
index 0000000..d711374
--- /dev/null
+++ b/examples/ha-walkthrough/topology.clab.yml
@@ -0,0 +1,54 @@
+name: ha-walkthrough
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ router1:
+ kind: vyosnetworks_vyos
+ router2:
+ kind: vyosnetworks_vyos
+ # "switch pair": VLAN-aware bridge, router2's ports bonded with LACP as on the page.
+ # LACP needs the kernel bonding module on the container host.
+ sw:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge vlan_filtering 1
+ - ip link add bond0 type bond mode 802.3ad
+ - ip link set eth2 down
+ - ip link set eth3 down
+ - ip link set eth2 master bond0
+ - ip link set eth3 master bond0
+ - ip link set bond0 up
+ - ip link set eth1 master br0
+ - ip link set bond0 master br0
+ - ip link set eth4 master br0
+ - ip link set eth5 master br0
+ - bridge vlan add dev eth1 vid 50
+ - bridge vlan add dev eth1 vid 100
+ - bridge vlan add dev eth1 vid 201
+ - bridge vlan add dev bond0 vid 50
+ - bridge vlan add dev bond0 vid 100
+ - bridge vlan add dev bond0 vid 201
+ - bridge vlan add dev eth4 vid 50 pvid untagged
+ - bridge vlan add dev eth5 vid 201 pvid untagged
+ - ip link set br0 up
+ # upstream router (VLAN 50); 198.51.100.100 stands for "the internet"
+ upstream:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.0.2.11/24 dev eth1
+ - ip addr add 198.51.100.100/32 dev lo
+ - ip route add 203.0.113.0/24 via 192.0.2.21
+ internal:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 10.200.201.10/24 dev eth1", "ip route replace default via 10.200.201.1"]
+ links:
+ - endpoints: ["router1:eth1", "sw:eth1"]
+ - endpoints: ["router2:eth1", "sw:eth2"]
+ - endpoints: ["router2:eth2", "sw:eth3"]
+ - endpoints: ["sw:eth4", "upstream:eth1"]
+ - endpoints: ["sw:eth5", "internal:eth1"]
diff --git a/examples/ha-walkthrough/verify.yml b/examples/ha-walkthrough/verify.yml
new file mode 100644
index 0000000..8c714ca
--- /dev/null
+++ b/examples/ha-walkthrough/verify.yml
@@ -0,0 +1,17 @@
+---
+- name: Check the HA pair
+ hosts: routers
+ gather_facts: false
+ tasks:
+ - name: VRRP checks (both routers in one play for the one-MASTER check)
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ha_vrrp
+ tasks_from: verify
+ - name: NAT checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.nat
+ tasks_from: verify
+ - name: BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.bgp
+ tasks_from: verify
diff --git a/examples/inter-vrf/group_vars/core.yml b/examples/inter-vrf/group_vars/core.yml
new file mode 100644
index 0000000..965e45a
--- /dev/null
+++ b/examples/inter-vrf/group_vars/core.yml
@@ -0,0 +1,136 @@
+---
+# Core router - docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html
+# (Appendix-A, plus the Appendix-B import filter on LAN2). Interfaces are
+# eth1-eth4 here, eth0-eth3 on the page (containerlab uses eth0 for management).
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.1.1.1/30
+ - 2001:db8::/127
+ - name: eth2
+ addresses:
+ - 172.16.2.1/30
+ - 2001:db8::2/127
+ - name: eth3
+ addresses:
+ - 192.168.3.1/30
+ - 2001:db8::4/127
+ - name: eth4
+ addresses:
+ - 10.2.2.1/30
+ - 2001:db8::6/127
+vrf_lite_asn: 64496
+vrf_lite_vrfs:
+ - name: Internet
+ table: 104
+ interfaces:
+ - eth4
+ rd: 64496:100
+ route_targets_export:
+ - 64496:100
+ route_targets_import:
+ - '64496:1'
+ - '64496:2'
+ neighbors:
+ - address: 10.2.2.2
+ remote_as: 64497
+ - address: 2001:db8::7
+ remote_as: 64497
+ - name: LAN1
+ table: 101
+ interfaces:
+ - eth1
+ routes:
+ - dest: 10.0.0.0/24
+ next_hop: 10.1.1.2
+ - dest: 2001:db8:0:1::/64
+ next_hop: 2001:db8::1
+ rd: '64496:1'
+ route_targets_export:
+ - '64496:1'
+ route_targets_import:
+ - 64496:100
+ - '64496:50'
+ - '64496:2'
+ redistribute:
+ - static
+ - name: LAN2
+ table: 102
+ interfaces:
+ - eth2
+ routes:
+ - dest: 172.16.0.0/24
+ next_hop: 172.16.2.2
+ - dest: 2001:db8:0:2::/64
+ next_hop: 2001:db8::3
+ rd: '64496:2'
+ route_targets_export:
+ - '64496:2'
+ route_targets_import:
+ - 64496:100
+ - '64496:50'
+ - '64496:1'
+ redistribute:
+ - static
+ import_route_map:
+ ipv4: LAN2-Internet
+ ipv6: LAN2-Internet-v6
+ - name: Management
+ table: 103
+ interfaces:
+ - eth3
+ routes:
+ - dest: 192.168.0.0/24
+ next_hop: 192.168.3.2
+ - dest: 2001:db8:0:3::/64
+ next_hop: 2001:db8::5
+ rd: '64496:50'
+ route_targets_export:
+ - '64496:50'
+ route_targets_import:
+ - '64496:1'
+ - '64496:2'
+ redistribute:
+ - static
+route_policy_prefix_lists:
+ - name: LAN2-Internet
+ rules:
+ - sequence: 1
+ action: permit
+ le: 24
+ prefix: 198.51.0.0/16
+ - sequence: 2
+ action: permit
+ prefix: 192.0.2.0/24
+ - sequence: 3
+ action: permit
+ prefix: 192.168.0.0/24
+ - sequence: 4
+ action: permit
+ prefix: 10.0.0.0/24
+ - name: LAN2-Internet-v6
+ afi: ipv6
+ rules:
+ - sequence: 1
+ action: permit
+ prefix: 2001:db8:1::/48
+ - sequence: 2
+ action: permit
+ prefix: 2001:db8:2::/48
+ - sequence: 3
+ action: permit
+ prefix: 2001:db8:0:3::/64
+ - sequence: 4
+ action: permit
+ prefix: 2001:db8:0:1::/64
+route_policy_route_maps:
+ - name: LAN2-Internet
+ rules:
+ - sequence: 1
+ action: permit
+ match_prefix_list: LAN2-Internet
+ - name: LAN2-Internet-v6
+ rules:
+ - sequence: 1
+ action: permit
+ match_prefix_list6: LAN2-Internet-v6
diff --git a/examples/inter-vrf/inventory.yml b/examples/inter-vrf/inventory.yml
new file mode 100644
index 0000000..1ca61f3
--- /dev/null
+++ b/examples/inter-vrf/inventory.yml
@@ -0,0 +1,17 @@
+---
+# docs.vyos.io/en/1.5/configexamples/inter-vrf-routing-vrf-lite.html
+all:
+ children:
+ core:
+ hosts:
+ core1:
+ ansible_host: clab-inter-vrf-core # your router's address
+ provider:
+ hosts:
+ isp:
+ ansible_host: clab-inter-vrf-isp # lab only, see isp.yml
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/inter-vrf/isp.yml b/examples/inter-vrf/isp.yml
new file mode 100644
index 0000000..2637b45
--- /dev/null
+++ b/examples/inter-vrf/isp.yml
@@ -0,0 +1,25 @@
+---
+- name: Configure the ISP router as on the page in the containerlab lab (the ISP is not part of the blueprint)
+ hosts: provider
+ gather_facts: false
+ tasks:
+ - name: Apply the page's ISP configuration (eth1 instead of eth3)
+ vyos.vyos.vyos_config:
+ lines:
+ - set interfaces dummy dum0 address '192.0.2.1/24'
+ - set interfaces dummy dum0 address '2001:db8:1::1/48'
+ - set interfaces dummy dum1 address '198.51.100.1/24'
+ - set interfaces dummy dum1 address '2001:db8:2::1/48'
+ - set interfaces dummy dum2 address '203.0.113.1/24'
+ - set interfaces dummy dum2 address '2001:db8:3::1/48'
+ - set interfaces ethernet eth1 address '10.2.2.2/30'
+ - set interfaces ethernet eth1 address '2001:db8::7/127'
+ - set protocols bgp address-family ipv4-unicast redistribute connected
+ - set protocols bgp address-family ipv6-unicast redistribute connected
+ - set protocols bgp system-as '64497'
+ - set protocols bgp neighbor 10.2.2.1 address-family ipv4-unicast default-originate
+ - set protocols bgp neighbor 10.2.2.1 remote-as '64496'
+ - set protocols bgp neighbor 2001:db8::6 address-family ipv6-unicast default-originate
+ - set protocols bgp neighbor 2001:db8::6 remote-as '64496'
+ - set protocols static route 0.0.0.0/0 next-hop 10.2.2.1
+ - set protocols static route6 ::/0 next-hop 2001:db8::6
diff --git a/examples/inter-vrf/site.yml b/examples/inter-vrf/site.yml
new file mode 100644
index 0000000..2e3ae95
--- /dev/null
+++ b/examples/inter-vrf/site.yml
@@ -0,0 +1,13 @@
+---
+- name: Inter-VRF routing over VRF Lite - core router
+ hosts: core
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # interface addresses
+ - vyos.blueprints.route_policy # Appendix-B prefix-lists and route-maps
+ - vyos.blueprints.vrf_lite # VRFs, static routes, RD/RT, VPN import/export
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/inter-vrf/topology.clab.yml b/examples/inter-vrf/topology.clab.yml
new file mode 100644
index 0000000..582190b
--- /dev/null
+++ b/examples/inter-vrf/topology.clab.yml
@@ -0,0 +1,48 @@
+name: inter-vrf
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ core:
+ kind: vyosnetworks_vyos
+ isp:
+ kind: vyosnetworks_vyos
+ # remote networks from the page, as Linux hosts: link address, a "dum0"
+ # network and a default route to the core
+ lan1:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.1.1.2/30 dev eth1
+ - ip -6 addr add 2001:db8::1/127 dev eth1
+ - ip link add dum0 type dummy
+ - ip link set dum0 up
+ - ip addr add 10.0.0.1/24 dev dum0
+ - ip -6 addr add 2001:db8:0:1::1/64 dev dum0
+ - ip route replace default via 10.1.1.1
+ - ip -6 route replace default via 2001:db8::
+ lan2:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 172.16.2.2/30 dev eth1
+ - ip link add dum0 type dummy
+ - ip link set dum0 up
+ - ip addr add 172.16.0.1/24 dev dum0
+ - ip route replace default via 172.16.2.1
+ mgmt:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.3.2/30 dev eth1
+ - ip link add dum0 type dummy
+ - ip link set dum0 up
+ - ip addr add 192.168.0.1/24 dev dum0
+ - ip route replace default via 192.168.3.1
+ links:
+ # Core eth1-eth4 here = eth0-eth3 on the page (containerlab uses eth0 for management)
+ - endpoints: ["core:eth1", "lan1:eth1"]
+ - endpoints: ["core:eth2", "lan2:eth1"]
+ - endpoints: ["core:eth3", "mgmt:eth1"]
+ - endpoints: ["core:eth4", "isp:eth1"]
diff --git a/examples/inter-vrf/verify.yml b/examples/inter-vrf/verify.yml
new file mode 100644
index 0000000..dd246de
--- /dev/null
+++ b/examples/inter-vrf/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the core router
+ hosts: core
+ gather_facts: false
+ tasks:
+ - name: VRF and VRF BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.vrf_lite
+ tasks_from: verify
diff --git a/examples/isis-segment-routing/group_vars/p_routers.yml b/examples/isis-segment-routing/group_vars/p_routers.yml
new file mode 100644
index 0000000..ea7b34c
--- /dev/null
+++ b/examples/isis-segment-routing/group_vars/p_routers.yml
@@ -0,0 +1,5 @@
+---
+# Shared IS-IS settings - docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html
+isis_level: level-2
+isis_log_adjacency_changes: true
+isis_metric_style: wide
diff --git a/examples/isis-segment-routing/host_vars/P1-VyOS.yml b/examples/isis-segment-routing/host_vars/P1-VyOS.yml
new file mode 100644
index 0000000..a1ef98a
--- /dev/null
+++ b/examples/isis-segment-routing/host_vars/P1-VyOS.yml
@@ -0,0 +1,31 @@
+---
+# P1 as on the page; its eth3 link (192.0.2.21/30) is not in the lab topology
+base_hostname: P1-VyOS
+base_interfaces:
+ - name: dum0
+ addresses:
+ - 192.0.2.1/32
+ - name: eth1
+ mtu: 8000
+ addresses:
+ - 192.0.2.5/30
+ - name: eth3
+ mtu: 8000
+ addresses:
+ - 192.0.2.21/30
+isis_net: 49.0000.0000.0000.0001.00
+isis_interfaces:
+ - name: dum0
+ passive: true
+ - name: eth1
+ network: point-to-point
+ - name: eth3
+ network: point-to-point
+isis_segment_routing:
+ maximum_label_depth: 8
+ prefixes:
+ - prefix: 192.0.2.1/32
+ index: 1
+isis_mpls_interfaces:
+ - eth1
+ - eth3
diff --git a/examples/isis-segment-routing/host_vars/P2-VyOS.yml b/examples/isis-segment-routing/host_vars/P2-VyOS.yml
new file mode 100644
index 0000000..65eda94
--- /dev/null
+++ b/examples/isis-segment-routing/host_vars/P2-VyOS.yml
@@ -0,0 +1,31 @@
+---
+# P2 as on the page; its eth3 link (192.0.2.26/30) is not in the lab topology
+base_hostname: P2-VyOS
+base_interfaces:
+ - name: dum0
+ addresses:
+ - 192.0.2.2/32
+ - name: eth2
+ mtu: 8000
+ addresses:
+ - 192.0.2.17/30
+ - name: eth3
+ mtu: 8000
+ addresses:
+ - 192.0.2.26/30
+isis_net: 49.0000.0000.0000.0002.00
+isis_interfaces:
+ - name: dum0
+ passive: true
+ - name: eth2
+ network: point-to-point
+ - name: eth3
+ network: point-to-point
+isis_segment_routing:
+ maximum_label_depth: 8
+ prefixes:
+ - prefix: 192.0.2.2/32
+ index: 2
+isis_mpls_interfaces:
+ - eth2
+ - eth3
diff --git a/examples/isis-segment-routing/host_vars/P3.yml b/examples/isis-segment-routing/host_vars/P3.yml
new file mode 100644
index 0000000..9c0d75f
--- /dev/null
+++ b/examples/isis-segment-routing/host_vars/P3.yml
@@ -0,0 +1,31 @@
+---
+# Lab only: VyOS stand-in for the page's Cisco XRv-P3 (configure the real P3 as on the page)
+base_hostname: P3
+base_interfaces:
+ - name: dum0
+ addresses:
+ - 192.0.2.3/32
+ - name: eth1
+ mtu: 8000
+ addresses:
+ - 192.0.2.6/30
+ - name: eth2
+ mtu: 8000
+ addresses:
+ - 192.0.2.18/30
+isis_net: 49.0000.0000.0000.0003.00
+isis_interfaces:
+ - name: dum0
+ passive: true
+ - name: eth1
+ network: point-to-point
+ - name: eth2
+ network: point-to-point
+isis_segment_routing:
+ maximum_label_depth: 8
+ prefixes:
+ - prefix: 192.0.2.3/32
+ index: 3
+isis_mpls_interfaces:
+ - eth1
+ - eth2
diff --git a/examples/isis-segment-routing/inventory.yml b/examples/isis-segment-routing/inventory.yml
new file mode 100644
index 0000000..3f1d4b5
--- /dev/null
+++ b/examples/isis-segment-routing/inventory.yml
@@ -0,0 +1,17 @@
+---
+# docs.vyos.io/en/1.5/configexamples/segment-routing-isis.html
+all:
+ children:
+ p_routers:
+ hosts:
+ P1-VyOS:
+ ansible_host: clab-isis-segment-routing-p1 # your router's address
+ P2-VyOS:
+ ansible_host: clab-isis-segment-routing-p2
+ P3:
+ ansible_host: clab-isis-segment-routing-p3 # lab only, see host_vars/P3.yml
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/isis-segment-routing/site.yml b/examples/isis-segment-routing/site.yml
new file mode 100644
index 0000000..0c08754
--- /dev/null
+++ b/examples/isis-segment-routing/site.yml
@@ -0,0 +1,12 @@
+---
+- name: IS-IS with MPLS segment routing
+ hosts: p_routers
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # loopback, link addresses and MTU, hostname
+ - vyos.blueprints.isis # IS-IS, segment routing, MPLS interfaces
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/isis-segment-routing/topology.clab.yml b/examples/isis-segment-routing/topology.clab.yml
new file mode 100644
index 0000000..7e31a7f
--- /dev/null
+++ b/examples/isis-segment-routing/topology.clab.yml
@@ -0,0 +1,16 @@
+name: isis-segment-routing
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ p1:
+ kind: vyosnetworks_vyos
+ p2:
+ kind: vyosnetworks_vyos
+ # VyOS standing in for the page's Cisco XRv-P3
+ p3:
+ kind: vyosnetworks_vyos
+ links:
+ - endpoints: ["p1:eth1", "p3:eth1"] # 192.0.2.4/30
+ - endpoints: ["p3:eth2", "p2:eth2"] # 192.0.2.16/30
diff --git a/examples/isis-segment-routing/verify.yml b/examples/isis-segment-routing/verify.yml
new file mode 100644
index 0000000..2096eca
--- /dev/null
+++ b/examples/isis-segment-routing/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check IS-IS and segment routing
+ hosts: p_routers
+ gather_facts: false
+ tasks:
+ - name: IS-IS checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.isis
+ tasks_from: verify
diff --git a/examples/l2tp-lns/group_vars/lns.yml b/examples/l2tp-lns/group_vars/lns.yml
new file mode 100644
index 0000000..928afea
--- /dev/null
+++ b/examples/l2tp-lns/group_vars/lns.yml
@@ -0,0 +1,38 @@
+---
+# The LNS - docs.vyos.io/en/1.5/configexamples/lac-lns.html
+# eth1 here is eth0 on the page (containerlab uses eth0 for management).
+# Keep the RADIUS key and the L2TP tunnel secret in ansible-vault; the tunnel
+# secret must match "l2tp tunnel password" and the host name "local name" on
+# the LAC.
+base_hostname: vyos
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 192.168.139.100/24
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 192.168.139.2
+nat_source_rules:
+ - id: 100
+ outbound_interface:
+ name: eth1
+ source:
+ address: 10.0.0.0/24
+ translation:
+ address: masquerade
+l2tp_lns_authentication:
+ mode: radius
+ radius_servers:
+ - address: 192.168.139.110
+ key: '{{ vault_radius_key }}'
+l2tp_lns_pools:
+ - name: TEST-POOL
+ range: 10.0.0.2-10.0.0.100
+l2tp_lns_default_pool: TEST-POOL
+l2tp_lns_gateway_address: 10.0.0.1
+l2tp_lns_lac_host_name: LAC
+l2tp_lns_shared_secret: '{{ vault_l2tp_tunnel_secret }}'
+l2tp_lns_name_servers:
+ - 8.8.8.8
+l2tp_lns_ppp_options:
+ disable_ccp: true
diff --git a/examples/l2tp-lns/inventory.yml b/examples/l2tp-lns/inventory.yml
new file mode 100644
index 0000000..f9e06ba
--- /dev/null
+++ b/examples/l2tp-lns/inventory.yml
@@ -0,0 +1,14 @@
+---
+# docs.vyos.io/en/1.5/configexamples/lac-lns.html - VyOS is the LNS; the LAC
+# (Cisco on the page) and the RADIUS server are configured separately.
+all:
+ children:
+ lns:
+ hosts:
+ lns1:
+ ansible_host: clab-l2tp-lns-lns # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/l2tp-lns/site.yml b/examples/l2tp-lns/site.yml
new file mode 100644
index 0000000..e6dcb50
--- /dev/null
+++ b/examples/l2tp-lns/site.yml
@@ -0,0 +1,13 @@
+---
+- name: L2TP network server for PPPoE subscribers forwarded by a LAC
+ hosts: lns
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # address and default route
+ - vyos.blueprints.nat # masquerade the client pool
+ - vyos.blueprints.l2tp_lns # LNS with RADIUS authentication
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/l2tp-lns/topology.clab.yml b/examples/l2tp-lns/topology.clab.yml
new file mode 100644
index 0000000..7adc4f5
--- /dev/null
+++ b/examples/l2tp-lns/topology.clab.yml
@@ -0,0 +1,45 @@
+# EXPERIMENTAL: needs the ppp and l2tp_ppp kernel modules on the container host;
+# the xl2tpd and FreeRADIUS setup below is lab scaffolding.
+name: l2tp-lns
+topology:
+ nodes:
+ lns:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ # 192.168.139.0/24 segment shared by the LNS, the LAC and the RADIUS server
+ sw:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set eth3 master br0
+ - ip link set br0 up
+ radius:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.139.110/24 dev eth1
+ - apk add --no-cache freeradius
+ - sh -c 'printf "client lns {\n ipaddr = 192.168.139.100\n secret = radiustest\n}\n" >> /etc/raddb/clients.conf'
+ - sh -c 'sed -i "1i test@vyos.io Cleartext-Password := \"test\"" /etc/raddb/mods-config/files/authorize'
+ - radiusd
+ # stands in for the page's Cisco LAC and the Windows PPPoE client
+ lac:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.139.101/24 dev eth1
+ - apk add --no-cache xl2tpd ppp
+ - mkdir -p /var/run/xl2tpd /etc/ppp/peers
+ - sh -c 'printf "[lac lns]\nlns = 192.168.139.100\nhostname = LAC\nchallenge = yes\npppoptfile = /etc/ppp/options.l2tp\nlength bit = yes\n" > /etc/xl2tpd/xl2tpd.conf'
+ - sh -c 'printf "* LAC test123\nLAC * test123\n" > /etc/xl2tpd/l2tp-secrets && chmod 600 /etc/xl2tpd/l2tp-secrets'
+ - sh -c 'printf "name test@vyos.io\nnoauth\nnoccp\nrefuse-eap\nrequire-chap\nnodefaultroute\nmtu 1400\nmru 1400\n" > /etc/ppp/options.l2tp'
+ - sh -c 'printf "test@vyos.io * test *\n" > /etc/ppp/chap-secrets && chmod 600 /etc/ppp/chap-secrets'
+ - xl2tpd
+ links:
+ # LNS eth1 here = eth0 on the page (containerlab uses eth0 for management)
+ - endpoints: ["lns:eth1", "sw:eth1"]
+ - endpoints: ["radius:eth1", "sw:eth2"]
+ - endpoints: ["lac:eth1", "sw:eth3"]
diff --git a/examples/l2tp-lns/verify.yml b/examples/l2tp-lns/verify.yml
new file mode 100644
index 0000000..279a500
--- /dev/null
+++ b/examples/l2tp-lns/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the LNS
+ hosts: lns
+ gather_facts: false
+ tasks:
+ - name: LNS checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.l2tp_lns
+ tasks_from: verify
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml
new file mode 100644
index 0000000..1d9583b
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-HUB.yml
@@ -0,0 +1,21 @@
+---
+base_interfaces:
+ - name: dum20
+ addresses:
+ - 10.0.0.100/32
+ - name: eth0
+ addresses:
+ - 10.80.80.2/24
+bgp_asn: 65035
+bgp_router_id: 10.80.80.2
+bgp_networks:
+ - 10.0.0.100/32
+bgp_log_neighbor_changes: true
+bgp_neighbors:
+ - address: 10.80.80.1
+ remote_as: 65001
+ ebgp_multihop: 2
+ update_source: eth0
+bgp_redistribute:
+ - type: connected
+base_hostname: VyOS-CE1-HUB
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml
new file mode 100644
index 0000000..08825d0
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE1-SPOKE.yml
@@ -0,0 +1,19 @@
+---
+base_interfaces:
+ - name: dum20
+ addresses:
+ - 10.0.0.80/32
+ - name: eth0
+ addresses:
+ - 10.50.50.2/24
+bgp_asn: 65035
+bgp_router_id: 10.50.50.2
+bgp_networks:
+ - 10.0.0.80/32
+bgp_log_neighbor_changes: true
+bgp_neighbors:
+ - address: 10.50.50.1
+ remote_as: 65001
+ ebgp_multihop: 2
+ update_source: eth0
+base_hostname: VyOS-CE1-SPOKE
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml
new file mode 100644
index 0000000..95f098a
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-CE2-SPOKE.yml
@@ -0,0 +1,19 @@
+---
+base_interfaces:
+ - name: dum20
+ addresses:
+ - 10.0.0.90/32
+ - name: eth0
+ addresses:
+ - 10.60.60.2/24
+bgp_asn: 65035
+bgp_router_id: 10.60.60.2
+bgp_networks:
+ - 10.0.0.90/32
+bgp_log_neighbor_changes: true
+bgp_neighbors:
+ - address: 10.60.60.1
+ remote_as: 65001
+ ebgp_multihop: 2
+ update_source: eth0
+base_hostname: VyOS-CE2-SPOKE
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml
new file mode 100644
index 0000000..95ff9e7
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P1.yml
@@ -0,0 +1,34 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.3/32
+ - name: eth0
+ addresses:
+ - 172.16.30.1/24
+ - name: eth1
+ addresses:
+ - 172.16.40.1/24
+ - name: eth2
+ addresses:
+ - 172.16.90.1/24
+ - name: eth3
+ addresses:
+ - 172.16.10.1/24
+ - name: eth5
+ addresses:
+ - 172.16.100.1/24
+ospf_router_id: 10.0.0.3
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.3
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+ - eth2
+ - eth3
+ - eth5
+base_hostname: VyOS-P1
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml
new file mode 100644
index 0000000..b07a4b1
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P2.yml
@@ -0,0 +1,30 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.4/32
+ - name: eth0
+ addresses:
+ - 172.16.30.2/24
+ - name: eth1
+ addresses:
+ - 172.16.20.1/24
+ - name: eth2
+ addresses:
+ - 172.16.120.1/24
+ - name: eth3
+ addresses:
+ - 172.16.60.1/24
+ospf_router_id: 10.0.0.4
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.4
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+ - eth2
+ - eth3
+base_hostname: VyOS-P2
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml
new file mode 100644
index 0000000..ae8f0d5
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P3.yml
@@ -0,0 +1,30 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.5/32
+ - name: eth0
+ addresses:
+ - 172.16.110.1/24
+ - name: eth1
+ addresses:
+ - 172.16.40.2/24
+ - name: eth2
+ addresses:
+ - 172.16.50.1/24
+ - name: eth3
+ addresses:
+ - 172.16.70.1/24
+ospf_router_id: 10.0.0.5
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.5
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+ - eth2
+ - eth3
+base_hostname: VyOS-P3
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml
new file mode 100644
index 0000000..4740ea6
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-P4.yml
@@ -0,0 +1,34 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.6/32
+ - name: eth0
+ addresses:
+ - 172.16.80.2/24
+ - name: eth1
+ addresses:
+ - 172.16.130.1/24
+ - name: eth2
+ addresses:
+ - 172.16.50.2/24
+ - name: eth3
+ addresses:
+ - 172.16.60.2/24
+ - name: eth5
+ addresses:
+ - 172.16.140.1/24
+ospf_router_id: 10.0.0.6
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.6
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+ - eth2
+ - eth3
+ - eth5
+base_hostname: VyOS-P4
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml
new file mode 100644
index 0000000..5b9c0d5
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE1.yml
@@ -0,0 +1,54 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.7/32
+ - name: eth0
+ addresses:
+ - 172.16.90.2/24
+ - name: eth3
+ addresses:
+ - 10.50.50.1/24
+ospf_router_id: 10.0.0.7
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.7
+mpls_ldp_interfaces:
+ - eth0
+l3vpn_asn: 65001
+l3vpn_router_id: 10.0.0.7
+l3vpn_peer_group:
+ name: RR_VPNv4
+ remote_as: 65001
+ update_source: dum10
+l3vpn_neighbors:
+ - address: 10.0.0.1
+ nexthop_self: true
+ - address: 10.0.0.2
+ nexthop_self: true
+vrf_lite_asn: 65001
+vrf_lite_vrfs:
+ - name: BLUE_SPOKE
+ table: 200
+ interfaces:
+ - eth3
+ families:
+ - ipv4
+ label_vpn_export: auto
+ networks:
+ - 10.50.50.0/24
+ rd: 10.50.50.1:1011
+ route_targets_export:
+ - 65035:1011
+ route_targets_import:
+ - 65035:1030
+ redistribute:
+ - connected
+ neighbors:
+ - address: 10.50.50.2
+ remote_as: 65035
+ as_override: true
+base_hostname: VyOS-PE1
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml
new file mode 100644
index 0000000..0788ed0
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE2.yml
@@ -0,0 +1,63 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.8/32
+ - name: eth0
+ addresses:
+ - 172.16.110.2/24
+ - name: eth1
+ addresses:
+ - 172.16.100.2/24
+ - name: eth2
+ addresses:
+ - 172.16.80.1/24
+ - name: eth3
+ addresses:
+ - 10.80.80.1/24
+ospf_router_id: 10.0.0.8
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.8
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+l3vpn_asn: 65001
+l3vpn_router_id: 10.0.0.8
+l3vpn_peer_group:
+ name: RR_VPNv4
+ remote_as: 65001
+ update_source: dum10
+l3vpn_neighbors:
+ - address: 10.0.0.1
+ nexthop_self: true
+ - address: 10.0.0.2
+ nexthop_self: true
+vrf_lite_asn: 65001
+vrf_lite_vrfs:
+ - name: BLUE_HUB
+ table: 400
+ interfaces:
+ - eth3
+ families:
+ - ipv4
+ label_vpn_export: auto
+ networks:
+ - 10.80.80.0/24
+ rd: 10.80.80.1:1011
+ route_targets_export:
+ - 65035:1030
+ route_targets_import:
+ - 65035:1011
+ - 65050:2011
+ - 65035:1030
+ redistribute:
+ - connected
+ neighbors:
+ - address: 10.80.80.2
+ remote_as: 65035
+ as_override: true
+base_hostname: VyOS-PE2
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml
new file mode 100644
index 0000000..abc5dde
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-PE3.yml
@@ -0,0 +1,54 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.10/32
+ - name: eth0
+ addresses:
+ - 172.16.140.2/24
+ - name: eth3
+ addresses:
+ - 10.60.60.1/24
+ospf_router_id: 10.0.0.10
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.10
+mpls_ldp_interfaces:
+ - eth0
+l3vpn_asn: 65001
+l3vpn_router_id: 10.0.0.10
+l3vpn_peer_group:
+ name: RR_VPNv4
+ remote_as: 65001
+ update_source: dum10
+l3vpn_neighbors:
+ - address: 10.0.0.1
+ nexthop_self: true
+ - address: 10.0.0.2
+ nexthop_self: true
+vrf_lite_asn: 65001
+vrf_lite_vrfs:
+ - name: BLUE_SPOKE
+ table: 200
+ interfaces:
+ - eth3
+ families:
+ - ipv4
+ label_vpn_export: auto
+ networks:
+ - 10.60.60.0/24
+ rd: 10.60.60.1:1011
+ route_targets_export:
+ - 65035:1011
+ route_targets_import:
+ - 65035:1030
+ redistribute:
+ - connected
+ neighbors:
+ - address: 10.60.60.2
+ remote_as: 65035
+ as_override: true
+base_hostname: VyOS-PE3
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml
new file mode 100644
index 0000000..08e1271
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR1.yml
@@ -0,0 +1,36 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.1/32
+ - name: eth1
+ addresses:
+ - 172.16.20.2/24
+ - name: eth2
+ addresses:
+ - 172.16.10.2/24
+ospf_router_id: 10.0.0.1
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.1
+mpls_ldp_interfaces:
+ - eth1
+ - eth2
+l3vpn_asn: 65001
+l3vpn_router_id: 10.0.0.1
+l3vpn_cluster_id: 10.0.0.1
+l3vpn_peer_group:
+ name: RR_VPNv4
+ remote_as: 65001
+ update_source: dum10
+l3vpn_neighbors:
+ - address: 10.0.0.7
+ route_reflector_client: true
+ - address: 10.0.0.8
+ route_reflector_client: true
+ - address: 10.0.0.10
+ route_reflector_client: true
+base_hostname: VyOS-RR1
diff --git a/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml
new file mode 100644
index 0000000..55bb756
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/host_vars/VyOS-RR2.yml
@@ -0,0 +1,36 @@
+---
+base_interfaces:
+ - name: dum10
+ addresses:
+ - 10.0.0.2/32
+ - name: eth0
+ addresses:
+ - 172.16.80.1/24
+ - name: eth1
+ addresses:
+ - 172.16.70.2/24
+ospf_router_id: 10.0.0.2
+ospf_areas:
+ - id: '0'
+ networks:
+ - 0.0.0.0/0
+ospf_abr_type: cisco
+mpls_ldp_router_id: 10.0.0.2
+mpls_ldp_interfaces:
+ - eth0
+ - eth1
+l3vpn_asn: 65001
+l3vpn_router_id: 10.0.0.2
+l3vpn_cluster_id: 10.0.0.1
+l3vpn_peer_group:
+ name: RR_VPNv4
+ remote_as: 65001
+ update_source: dum10
+l3vpn_neighbors:
+ - address: 10.0.0.7
+ route_reflector_client: true
+ - address: 10.0.0.8
+ route_reflector_client: true
+ - address: 10.0.0.10
+ route_reflector_client: true
+base_hostname: VyOS-RR2
diff --git a/examples/l3vpn-hub-and-spoke/inventory.yml b/examples/l3vpn-hub-and-spoke/inventory.yml
new file mode 100644
index 0000000..f672ea1
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/inventory.yml
@@ -0,0 +1,43 @@
+---
+# docs.vyos.io/en/1.5/configexamples/l3vpn-hub-and-spoke.html - all twelve routers.
+# For a containerlab try-out, use the reduced lab in
+# extensions/molecule/l3vpn_hub_and_spoke (one RR, one P router).
+all:
+ children:
+ p_routers:
+ hosts:
+ VyOS-P1:
+ ansible_host: 192.0.2.1 # your router's address
+ VyOS-P2:
+ ansible_host: 192.0.2.2 # your router's address
+ VyOS-P3:
+ ansible_host: 192.0.2.3 # your router's address
+ VyOS-P4:
+ ansible_host: 192.0.2.4 # your router's address
+ route_reflectors:
+ hosts:
+ VyOS-RR1:
+ ansible_host: 192.0.2.1 # your router's address
+ VyOS-RR2:
+ ansible_host: 192.0.2.2 # your router's address
+ pe_routers:
+ hosts:
+ VyOS-PE1:
+ ansible_host: 192.0.2.1 # your router's address
+ VyOS-PE2:
+ ansible_host: 192.0.2.2 # your router's address
+ VyOS-PE3:
+ ansible_host: 192.0.2.3 # your router's address
+ ce_routers:
+ hosts:
+ VyOS-CE1-SPOKE:
+ ansible_host: 192.0.2.1 # your router's address
+ VyOS-CE1-HUB:
+ ansible_host: 192.0.2.2 # your router's address
+ VyOS-CE2-SPOKE:
+ ansible_host: 192.0.2.3 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/l3vpn-hub-and-spoke/site.yml b/examples/l3vpn-hub-and-spoke/site.yml
new file mode 100644
index 0000000..3907543
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/site.yml
@@ -0,0 +1,16 @@
+---
+- name: MPLS L3VPN hub-and-spoke
+ hosts: all
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # loopbacks and link addresses
+ - vyos.blueprints.ospf # step 1: IGP (P, PE, RR)
+ - vyos.blueprints.mpls_ldp # step 1: MPLS and LDP (P, PE, RR)
+ - vyos.blueprints.l3vpn # step 2: iBGP VPNv4 with route reflectors (PE, RR)
+ - vyos.blueprints.vrf_lite # step 3: PE VRFs with RD, RT and CE neighbours
+ - vyos.blueprints.bgp # step 4: CE eBGP to the PE
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/l3vpn-hub-and-spoke/verify.yml b/examples/l3vpn-hub-and-spoke/verify.yml
new file mode 100644
index 0000000..0c5b84f
--- /dev/null
+++ b/examples/l3vpn-hub-and-spoke/verify.yml
@@ -0,0 +1,27 @@
+---
+- name: Check the provider network
+ hosts: p_routers:route_reflectors:pe_routers
+ gather_facts: false
+ tasks:
+ - name: LDP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.mpls_ldp
+ tasks_from: verify
+
+- name: Check VPNv4 sessions
+ hosts: route_reflectors:pe_routers
+ gather_facts: false
+ tasks:
+ - name: VPNv4 checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.l3vpn
+ tasks_from: verify
+
+- name: Check CE sessions
+ hosts: ce_routers
+ gather_facts: false
+ tasks:
+ - name: BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.bgp
+ tasks_from: verify
diff --git a/examples/pppoe-ipv6-home/group_vars/home.yml b/examples/pppoe-ipv6-home/group_vars/home.yml
new file mode 100644
index 0000000..18cafe0
--- /dev/null
+++ b/examples/pppoe-ipv6-home/group_vars/home.yml
@@ -0,0 +1,73 @@
+---
+# Home router - docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html
+# Set username, password (ansible-vault) and service name to your ISP's values.
+# WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0
+# for management). The lab ISP delegates a /56, hence length 56 and sla-id 0;
+# with a /64 from your ISP, drop both as on the page.
+pppoe_interfaces:
+ - name: pppoe0
+ source_interface: eth1
+ username: molecule
+ password: '{{ vault_pppoe_password }}'
+ service_name: ISP
+ ipv6_autoconf: true
+ prefix_delegation:
+ - id: 0
+ length: 56
+ interfaces:
+ - name: eth2
+ address: '100'
+ sla_id: 0
+router_advert_interfaces:
+ - name: eth2
+ link_mtu: 1492
+ name_servers:
+ - 2001:db8::53
+ prefixes:
+ - prefix: ::/64
+ valid_lifetime: 172800
+firewall_ipv6:
+ names:
+ WAN_IN:
+ default_action: drop
+ rules:
+ - number: 10
+ action: accept
+ state:
+ established: true
+ related: true
+ - number: 20
+ action: accept
+ protocol: icmpv6
+ WAN_LOCAL:
+ default_action: drop
+ rules:
+ - number: 10
+ action: accept
+ state:
+ established: true
+ related: true
+ - number: 20
+ action: accept
+ protocol: icmpv6
+ - number: 30
+ action: accept
+ protocol: udp
+ source:
+ port: '547'
+ destination:
+ port: '546'
+ forward:
+ rules:
+ - number: 10
+ action: jump
+ jump_target: WAN_IN
+ inbound_interface:
+ name: pppoe0
+ input:
+ rules:
+ - number: 10
+ action: jump
+ jump_target: WAN_LOCAL
+ inbound_interface:
+ name: pppoe0
diff --git a/examples/pppoe-ipv6-home/inventory.yml b/examples/pppoe-ipv6-home/inventory.yml
new file mode 100644
index 0000000..3f53a29
--- /dev/null
+++ b/examples/pppoe-ipv6-home/inventory.yml
@@ -0,0 +1,17 @@
+---
+# docs.vyos.io/en/1.5/configexamples/pppoe-ipv6-basic.html
+all:
+ children:
+ home:
+ hosts:
+ r1:
+ ansible_host: clab-pppoe-ipv6-home-r1 # your router's address
+ provider:
+ hosts:
+ isp:
+ ansible_host: clab-pppoe-ipv6-home-isp # lab only, see isp.yml
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/pppoe-ipv6-home/isp.yml b/examples/pppoe-ipv6-home/isp.yml
new file mode 100644
index 0000000..f554535
--- /dev/null
+++ b/examples/pppoe-ipv6-home/isp.yml
@@ -0,0 +1,21 @@
+---
+- name: Configure the ISP's PPPoE server in the containerlab lab (the ISP is not part of the blueprint)
+ hosts: provider
+ gather_facts: false
+ tasks:
+ - name: PPPoE server with IPv4, IPv6 and prefix delegation
+ vyos.vyos.vyos_config:
+ lines:
+ - set interfaces dummy dum0 address '2001:db8:ffff::1/128'
+ - set service pppoe-server authentication mode 'local'
+ - set service pppoe-server authentication local-users username molecule password '{{ vault_pppoe_password }}'
+ - set service pppoe-server client-ip-pool POOL4 range '100.64.0.10-100.64.0.20'
+ - set service pppoe-server default-pool 'POOL4'
+ - set service pppoe-server gateway-address '100.64.0.1'
+ - set service pppoe-server client-ipv6-pool POOL6 prefix '2001:db8:8002::/48' mask '64'
+ - set service pppoe-server client-ipv6-pool POOL6 delegate '2001:db8:8003::/48' delegation-prefix '56'
+ - set service pppoe-server default-ipv6-pool 'POOL6'
+ - set service pppoe-server ppp-options ipv6 'allow'
+ - set service pppoe-server service-name 'ISP'
+ - set service pppoe-server interface eth1
+ no_log: true
diff --git a/examples/pppoe-ipv6-home/site.yml b/examples/pppoe-ipv6-home/site.yml
new file mode 100644
index 0000000..b4ccb5d
--- /dev/null
+++ b/examples/pppoe-ipv6-home/site.yml
@@ -0,0 +1,13 @@
+---
+- name: PPPoE with DHCPv6-PD and SLAAC for a home network
+ hosts: home
+ gather_facts: false
+ roles:
+ - vyos.blueprints.pppoe # PPPoE client, IPv6 autoconf, prefix delegation
+ - vyos.blueprints.router_advert # SLAAC and RDNSS on the LAN
+ - vyos.blueprints.firewall # WAN_IN / WAN_LOCAL IPv6 firewall
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/pppoe-ipv6-home/topology.clab.yml b/examples/pppoe-ipv6-home/topology.clab.yml
new file mode 100644
index 0000000..6e8c7ca
--- /dev/null
+++ b/examples/pppoe-ipv6-home/topology.clab.yml
@@ -0,0 +1,19 @@
+name: pppoe-ipv6-home
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ r1:
+ kind: vyosnetworks_vyos
+ # VyOS PPPoE server standing in for the ISP (needs PPP kernel support on the host)
+ isp:
+ kind: vyosnetworks_vyos
+ pc:
+ kind: linux
+ image: alpine:3
+ exec: ["sysctl -w net.ipv6.conf.eth1.accept_ra=1", "ip link set eth1 up"]
+ links:
+ # WAN eth1 / LAN eth2 here = eth0 / eth1 on the page (containerlab uses eth0 for management)
+ - endpoints: ["r1:eth1", "isp:eth1"]
+ - endpoints: ["r1:eth2", "pc:eth1"]
diff --git a/examples/pppoe-ipv6-home/verify.yml b/examples/pppoe-ipv6-home/verify.yml
new file mode 100644
index 0000000..d63571f
--- /dev/null
+++ b/examples/pppoe-ipv6-home/verify.yml
@@ -0,0 +1,13 @@
+---
+- name: Check the home router
+ hosts: home
+ gather_facts: false
+ tasks:
+ - name: PPPoE checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.pppoe
+ tasks_from: verify
+ - name: Firewall checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.firewall
+ tasks_from: verify
diff --git a/examples/qos/host_vars/vyos2.yml b/examples/qos/host_vars/vyos2.yml
new file mode 100644
index 0000000..6afaa1e
--- /dev/null
+++ b/examples/qos/host_vars/vyos2.yml
@@ -0,0 +1,42 @@
+---
+# interfaces shifted by one (containerlab uses eth0 for management)
+base_hostname: vyos2
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.1.1.1/24
+ - name: eth3
+ addresses:
+ - 10.9.9.1/24
+base_static_routes:
+ - dest: 172.17.1.0/24
+ next_hop: 10.1.1.100
+qos_shapers:
+ - name: vyos2
+ classes:
+ - id: 10
+ bandwidth: 100%
+ burst: 15k
+ queue_type: fair-queue
+ set_dscp: CS5
+ matches:
+ - name: VYOS2
+ ip:
+ dscp: CS4
+ - id: 20
+ bandwidth: 5mbit
+ description: for VyOS3 eth0
+ matches:
+ - name: VyOS3
+ ip:
+ source:
+ address: 10.1.1.100/32
+ default:
+ bandwidth: 100%
+ burst: 15k
+ ceiling: 100%
+ priority: 7
+ queue_type: fair-queue
+qos_interfaces:
+ - name: eth3
+ egress: vyos2
diff --git a/examples/qos/host_vars/vyos3.yml b/examples/qos/host_vars/vyos3.yml
new file mode 100644
index 0000000..10edbdf
--- /dev/null
+++ b/examples/qos/host_vars/vyos3.yml
@@ -0,0 +1,45 @@
+---
+# interfaces shifted by one (containerlab uses eth0 for management)
+base_hostname: vyos3
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 10.1.1.100/24
+ - name: eth2
+ addresses:
+ - 172.17.1.1/24
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.1.1.1
+qos_shapers:
+ - name: vyos3
+ classes:
+ - id: 10
+ set_dscp: CS4
+ matches:
+ - name: ADDRESS10
+ ip:
+ source:
+ address: 172.17.1.2/32
+ - id: 20
+ set_dscp: CS5
+ matches:
+ - name: ADDRESS20
+ ip:
+ source:
+ address: 172.17.1.3/32
+ - id: 30
+ set_dscp: CS6
+ matches:
+ - name: ADDRESS30
+ ip:
+ source:
+ address: 172.17.1.4/32
+ default:
+ bandwidth: 10%
+ ceiling: 100%
+ priority: 7
+ queue_type: fair-queue
+qos_interfaces:
+ - name: eth1
+ egress: vyos3
diff --git a/examples/qos/host_vars/vyos4.yml b/examples/qos/host_vars/vyos4.yml
new file mode 100644
index 0000000..80f86c9
--- /dev/null
+++ b/examples/qos/host_vars/vyos4.yml
@@ -0,0 +1,31 @@
+---
+# not part of the lab topology; page values (eth0) for a real router
+base_hostname: vyos4
+base_interfaces:
+ - name: eth0
+ addresses:
+ - 10.2.1.100/24
+base_static_routes:
+ - dest: 0.0.0.0/0
+ next_hop: 10.2.1.1
+qos_shapers:
+ - name: vyos4
+ classes:
+ - id: 10
+ bandwidth: 100%
+ burst: 15k
+ queue_type: fair-queue
+ set_dscp: CS4
+ matches:
+ - name: ALL
+ ether:
+ protocol: all
+ default:
+ bandwidth: 10%
+ burst: 15k
+ ceiling: 100%
+ priority: 7
+ queue_type: fair-queue
+qos_interfaces:
+ - name: eth0
+ egress: vyos4
diff --git a/examples/qos/inventory.yml b/examples/qos/inventory.yml
new file mode 100644
index 0000000..9cb381a
--- /dev/null
+++ b/examples/qos/inventory.yml
@@ -0,0 +1,16 @@
+---
+# docs.vyos.io/en/1.5/configexamples/qos.html
+all:
+ children:
+ qos:
+ hosts:
+ vyos3:
+ ansible_host: clab-qos-vyos3 # your router's address
+ vyos2:
+ ansible_host: clab-qos-vyos2
+ # vyos4: # add with its address on a real network
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/qos/site.yml b/examples/qos/site.yml
new file mode 100644
index 0000000..9515881
--- /dev/null
+++ b/examples/qos/site.yml
@@ -0,0 +1,12 @@
+---
+- name: QoS - DSCP marking and shaping
+ hosts: qos
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # addresses and static routes
+ - vyos.blueprints.qos # shaper policies, DSCP re-marking, attachment
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/qos/topology.clab.yml b/examples/qos/topology.clab.yml
new file mode 100644
index 0000000..fe1dcff
--- /dev/null
+++ b/examples/qos/topology.clab.yml
@@ -0,0 +1,32 @@
+name: qos
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ vyos3:
+ kind: vyosnetworks_vyos
+ vyos2:
+ kind: vyosnetworks_vyos
+ # one host holding the page's four VPC addresses
+ vpcs:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 172.17.1.2/24 dev eth1
+ - ip addr add 172.17.1.3/24 dev eth1
+ - ip addr add 172.17.1.4/24 dev eth1
+ - ip addr add 172.17.1.40/24 dev eth1
+ - ip route replace default via 172.17.1.1
+ sink:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 10.9.9.10/24 dev eth1
+ - ip route replace default via 10.9.9.1
+ - apk add --no-cache tcpdump
+ links:
+ # interfaces shifted by one (containerlab uses eth0 for management)
+ - endpoints: ["vyos3:eth1", "vyos2:eth1"]
+ - endpoints: ["vyos3:eth2", "vpcs:eth1"]
+ - endpoints: ["vyos2:eth3", "sink:eth1"]
diff --git a/examples/qos/verify.yml b/examples/qos/verify.yml
new file mode 100644
index 0000000..d0746a9
--- /dev/null
+++ b/examples/qos/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check QoS
+ hosts: qos
+ gather_facts: false
+ tasks:
+ - name: QoS checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.qos
+ tasks_from: verify
diff --git a/examples/wan-load-balancing/group_vars/wan.yml b/examples/wan-load-balancing/group_vars/wan.yml
new file mode 100644
index 0000000..f3ff1d6
--- /dev/null
+++ b/examples/wan-load-balancing/group_vars/wan.yml
@@ -0,0 +1,51 @@
+---
+# docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html - Example 1
+# (distribute load evenly). Interfaces are shifted by one: page eth0/eth1/eth2
+# are eth1/eth2/eth3 here (containerlab uses eth0 for management).
+# Switch designs with: ansible-playbook -i inventory.yml site.yml -e @variants/example2.yml
+base_static_routes:
+ - dest: 33.44.55.66/32
+ next_hop: 11.22.33.1
+ - dest: 44.55.66.77/32
+ next_hop: 11.22.33.1
+ - dest: 55.66.77.88/32
+ next_hop: 22.33.44.1
+ - dest: 66.77.88.99/32
+ next_hop: 22.33.44.1
+wan_load_balance_interfaces:
+ - name: eth1
+ failure_count: 5
+ nexthop: 11.22.33.1
+ tests:
+ - id: 10
+ type: ping
+ target: 33.44.55.66
+ - id: 20
+ type: ping
+ target: 44.55.66.77
+ - name: eth2
+ failure_count: 4
+ nexthop: 22.33.44.1
+ tests:
+ - id: 10
+ type: ping
+ target: 55.66.77.88
+ - id: 20
+ type: ping
+ target: 66.77.88.99
+wan_load_balance_rules:
+ - number: 10
+ inbound_interface: eth3
+ interfaces:
+ - name: eth1
+ - name: eth2
+base_interfaces:
+ - name: eth1
+ addresses:
+ - 11.22.33.2/24
+ - name: eth2
+ addresses:
+ - 22.33.44.2/24
+ - name: eth3
+ addresses:
+ - 10.0.0.1/24
diff --git a/examples/wan-load-balancing/inventory.yml b/examples/wan-load-balancing/inventory.yml
new file mode 100644
index 0000000..98a6069
--- /dev/null
+++ b/examples/wan-load-balancing/inventory.yml
@@ -0,0 +1,13 @@
+---
+# docs.vyos.io/en/1.5/configexamples/wan-load-balancing.html
+all:
+ children:
+ wan:
+ hosts:
+ r1:
+ ansible_host: clab-wan-load-balancing-r1 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/wan-load-balancing/site.yml b/examples/wan-load-balancing/site.yml
new file mode 100644
index 0000000..dfc8d77
--- /dev/null
+++ b/examples/wan-load-balancing/site.yml
@@ -0,0 +1,12 @@
+---
+- name: WAN load balancing
+ hosts: wan
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base # addresses and routes to the ping targets
+ - vyos.blueprints.wan_load_balance # health checks and rules
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/wan-load-balancing/topology.clab.yml b/examples/wan-load-balancing/topology.clab.yml
new file mode 100644
index 0000000..336ada0
--- /dev/null
+++ b/examples/wan-load-balancing/topology.clab.yml
@@ -0,0 +1,32 @@
+name: wan-load-balancing
+topology:
+ nodes:
+ r1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ # each ISP answers its two health-check targets and a shared "internet" address
+ isp1:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 11.22.33.1/24 dev eth1
+ - ip addr add 33.44.55.66/32 dev lo
+ - ip addr add 44.55.66.77/32 dev lo
+ - ip addr add 198.51.100.100/32 dev lo
+ isp2:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 22.33.44.1/24 dev eth1
+ - ip addr add 55.66.77.88/32 dev lo
+ - ip addr add 66.77.88.99/32 dev lo
+ - ip addr add 198.51.100.100/32 dev lo
+ lan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 10.0.0.10/24 dev eth1", "ip route replace default via 10.0.0.1"]
+ links:
+ # page eth0/eth1/eth2 = eth1/eth2/eth3 here (containerlab uses eth0 for management)
+ - endpoints: ["r1:eth1", "isp1:eth1"]
+ - endpoints: ["r1:eth2", "isp2:eth1"]
+ - endpoints: ["r1:eth3", "lan:eth1"]
diff --git a/examples/wan-load-balancing/variants/example2.yml b/examples/wan-load-balancing/variants/example2.yml
new file mode 100644
index 0000000..67cfe78
--- /dev/null
+++ b/examples/wan-load-balancing/variants/example2.yml
@@ -0,0 +1,11 @@
+---
+# Example 2: failover based on interface weights
+wan_load_balance_rules:
+ - number: 10
+ failover: true
+ inbound_interface: eth3
+ interfaces:
+ - name: eth1
+ weight: 10
+ - name: eth2
+ weight: 1
diff --git a/examples/wan-load-balancing/variants/example3.yml b/examples/wan-load-balancing/variants/example3.yml
new file mode 100644
index 0000000..2a8e313
--- /dev/null
+++ b/examples/wan-load-balancing/variants/example3.yml
@@ -0,0 +1,11 @@
+---
+# Example 3: failover based on rule order
+wan_load_balance_rules:
+ - number: 10
+ inbound_interface: eth3
+ interfaces:
+ - name: eth1
+ - number: 20
+ inbound_interface: eth3
+ interfaces:
+ - name: eth2
diff --git a/examples/wan-load-balancing/variants/example4.yml b/examples/wan-load-balancing/variants/example4.yml
new file mode 100644
index 0000000..94e8728
--- /dev/null
+++ b/examples/wan-load-balancing/variants/example4.yml
@@ -0,0 +1,25 @@
+---
+# Example 4: rule order, secondary link only for SIP
+wan_load_balance_rules:
+ - number: 10
+ inbound_interface: eth3
+ interfaces:
+ - name: eth1
+ - number: 20
+ inbound_interface: eth3
+ interfaces:
+ - name: eth2
+ destination:
+ port: sip
+ protocol: tcp
+base_static_routes:
+ - dest: 33.44.55.66/32
+ next_hop: 11.22.33.1
+ - dest: 44.55.66.77/32
+ next_hop: 11.22.33.1
+ - dest: 55.66.77.88/32
+ next_hop: 22.33.44.1
+ - dest: 66.77.88.99/32
+ next_hop: 22.33.44.1
+ - dest: 0.0.0.0/0
+ next_hop: 11.22.33.1
diff --git a/examples/wan-load-balancing/variants/example5.yml b/examples/wan-load-balancing/variants/example5.yml
new file mode 100644
index 0000000..0cd5cb6
--- /dev/null
+++ b/examples/wan-load-balancing/variants/example5.yml
@@ -0,0 +1,30 @@
+---
+# Example 5: exclude traffic between local subnets
+wan_load_balance_rules:
+ - number: 5
+ exclude: true
+ inbound_interface: eth+
+ destination:
+ address: 10.0.0.0/8
+ - number: 10
+ inbound_interface: eth3
+ interfaces:
+ - name: eth1
+ - number: 20
+ inbound_interface: eth3
+ interfaces:
+ - name: eth2
+ destination:
+ port: sip
+ protocol: tcp
+base_static_routes:
+ - dest: 33.44.55.66/32
+ next_hop: 11.22.33.1
+ - dest: 44.55.66.77/32
+ next_hop: 11.22.33.1
+ - dest: 55.66.77.88/32
+ next_hop: 22.33.44.1
+ - dest: 66.77.88.99/32
+ next_hop: 22.33.44.1
+ - dest: 0.0.0.0/0
+ next_hop: 11.22.33.1
diff --git a/examples/wan-load-balancing/verify.yml b/examples/wan-load-balancing/verify.yml
new file mode 100644
index 0000000..70ea282
--- /dev/null
+++ b/examples/wan-load-balancing/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check WAN load balancing
+ hosts: wan
+ gather_facts: false
+ tasks:
+ - name: Load-balancer checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.wan_load_balance
+ tasks_from: verify