diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /extensions/molecule/zone_firewall | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'extensions/molecule/zone_firewall')
| -rw-r--r-- | extensions/molecule/zone_firewall/converge.yml | 7 | ||||
| -rw-r--r-- | extensions/molecule/zone_firewall/inventory.yml | 33 | ||||
| -rw-r--r-- | extensions/molecule/zone_firewall/molecule.yml | 27 | ||||
| -rw-r--r-- | extensions/molecule/zone_firewall/topology.clab.yml | 34 | ||||
| -rw-r--r-- | extensions/molecule/zone_firewall/verify.yml | 30 |
5 files changed, 131 insertions, 0 deletions
diff --git a/extensions/molecule/zone_firewall/converge.yml b/extensions/molecule/zone_firewall/converge.yml new file mode 100644 index 0000000..03e3ad7 --- /dev/null +++ b/extensions/molecule/zone_firewall/converge.yml @@ -0,0 +1,7 @@ +--- +- name: Converge + hosts: vyos + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.zone_firewall diff --git a/extensions/molecule/zone_firewall/inventory.yml b/extensions/molecule/zone_firewall/inventory.yml new file mode 100644 index 0000000..6e9f461 --- /dev/null +++ b/extensions/molecule/zone_firewall/inventory.yml @@ -0,0 +1,33 @@ +--- +all: + children: + vyos: + hosts: + r1: + ansible_host: clab-bp-zfw-r1 + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin + base_interfaces: + - {name: eth1, addresses: [172.16.10.1/24]} + - {name: eth2, addresses: [192.168.100.1/24]} + - {name: eth3, addresses: [192.168.200.1/24]} + zone_firewall_zones: + # containerlab management; keeps Ansible's SSH session working + - {name: mgmt, interfaces: [eth0]} + - {name: wan, interfaces: [eth1]} + - {name: lan, interfaces: [eth2]} + - {name: dmz, interfaces: [eth3]} + - {name: local, local: true} + zone_firewall_policies: + - {from: mgmt, to: local, default_action: accept} + - from: wan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}} + - from: lan + to: dmz + rules: + - {number: 200, protocol: tcp, destination: {port: "80,443"}} diff --git a/extensions/molecule/zone_firewall/molecule.yml b/extensions/molecule/zone_firewall/molecule.yml new file mode 100644 index 0000000..612af0a --- /dev/null +++ b/extensions/molecule/zone_firewall/molecule.yml @@ -0,0 +1,27 @@ +--- +# VyOS runs as a container (containerlab kind vyosnetworks_vyos); +# the lab is deployed in prepare and destroyed in cleanup. +dependency: + name: galaxy + enabled: false +driver: + name: default + options: + managed: false +platforms: + - name: r1 +provisioner: + name: ansible + config_options: + defaults: + host_key_checking: false + persistent_connection: + command_timeout: 60 + inventory: + links: + hosts: inventory.yml + playbooks: + prepare: ../_shared/lab_up.yml + cleanup: ../_shared/lab_down.yml +verifier: + name: ansible diff --git a/extensions/molecule/zone_firewall/topology.clab.yml b/extensions/molecule/zone_firewall/topology.clab.yml new file mode 100644 index 0000000..9be83a6 --- /dev/null +++ b/extensions/molecule/zone_firewall/topology.clab.yml @@ -0,0 +1,34 @@ +name: bp-zfw +topology: + nodes: + r1: + kind: vyosnetworks_vyos + image: ${VYOS_IMAGE:=vyos:blueprints-ci} + wan: + kind: linux + image: alpine:3 + exec: + - ip addr add 172.16.10.100/24 dev eth1 + - ip route replace default via 172.16.10.1 + - apk add --no-cache busybox-extras + - httpd -p 80 -h /tmp + lan: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.100.10/24 dev eth1 + - ip route replace default via 192.168.100.1 + - apk add --no-cache busybox-extras + - httpd -p 80 -h /tmp + dmz: + kind: linux + image: alpine:3 + exec: + - ip addr add 192.168.200.200/24 dev eth1 + - ip route replace default via 192.168.200.1 + - apk add --no-cache busybox-extras + - httpd -p 80 -h /tmp + links: + - endpoints: ["r1:eth1", "wan:eth1"] + - endpoints: ["r1:eth2", "lan:eth1"] + - endpoints: ["r1:eth3", "dmz:eth1"] diff --git a/extensions/molecule/zone_firewall/verify.yml b/extensions/molecule/zone_firewall/verify.yml new file mode 100644 index 0000000..16584f3 --- /dev/null +++ b/extensions/molecule/zone_firewall/verify.yml @@ -0,0 +1,30 @@ +--- +- name: Verify role state + hosts: vyos + gather_facts: false + tasks: + - name: Run role checks + ansible.builtin.include_role: + name: vyos.blueprints.zone_firewall + tasks_from: verify + +- name: Verify traffic between zones + hosts: localhost + gather_facts: false + vars: + _flows: + - {from: lan, to: 192.168.200.200, allowed: true, why: "LAN can access DMZ resources"} + - {from: wan, to: 192.168.200.200, allowed: true, why: "inbound WAN connects to the DMZ host"} + - {from: dmz, to: 192.168.100.10, allowed: false, why: "DMZ cannot access LAN resources"} + - {from: wan, to: 192.168.100.10, allowed: false, why: "WAN cannot reach the LAN"} + tasks: + - name: Try HTTP across zones + ansible.builtin.command: + cmd: docker exec clab-bp-zfw-{{ item.from }} wget -q -T 3 -O /dev/null http://{{ item.to }}/ + become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}" + register: _http + changed_when: false + failed_when: (_http.rc == 0) != item.allowed + loop: "{{ _flows }}" + loop_control: + label: "{{ item.from }} -> {{ item.to }} ({{ item.why }})" |
