diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /extensions/molecule/ipsec_route_based_bgp_dual/verify.yml | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'extensions/molecule/ipsec_route_based_bgp_dual/verify.yml')
| -rw-r--r-- | extensions/molecule/ipsec_route_based_bgp_dual/verify.yml | 47 |
1 files changed, 47 insertions, 0 deletions
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml new file mode 100644 index 0000000..34bee33 --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml @@ -0,0 +1,47 @@ +--- +- name: Verify both tunnels and BGP sessions + hosts: vpn + gather_facts: false + tasks: + - name: Wait for IKE, IPsec and BGP + ansible.builtin.pause: + seconds: 60 + run_once: true + + - name: Run role checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify + +- name: Verify redundancy - traffic survives losing the primary tunnel + hosts: r1 + gather_facts: false + vars: + _ping: docker exec clab-bp-azure2-onprem ping -c 3 -W 2 10.0.1.10 + _become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}" + tasks: + - name: Ping the VNet with both tunnels up + ansible.builtin.command: "{{ _ping }}" + delegate_to: localhost + become: "{{ _become }}" + changed_when: false + + - name: Take the primary tunnel down + vyos.vyos.vyos_config: + lines: + - set vpn ipsec site-to-site peer azure-primary disable + + - name: Wait for BGP to converge on the secondary path + ansible.builtin.pause: + seconds: 40 + + - name: Ping the VNet over the secondary tunnel only + ansible.builtin.command: "{{ _ping }}" + delegate_to: localhost + become: "{{ _become }}" + changed_when: false + + - name: Bring the primary tunnel back + vyos.vyos.vyos_config: + lines: + - delete vpn ipsec site-to-site peer azure-primary disable |
