summaryrefslogtreecommitdiff
path: root/extensions/molecule/zone_firewall
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /extensions/molecule/zone_firewall
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'extensions/molecule/zone_firewall')
-rw-r--r--extensions/molecule/zone_firewall/converge.yml7
-rw-r--r--extensions/molecule/zone_firewall/inventory.yml33
-rw-r--r--extensions/molecule/zone_firewall/molecule.yml27
-rw-r--r--extensions/molecule/zone_firewall/topology.clab.yml34
-rw-r--r--extensions/molecule/zone_firewall/verify.yml30
5 files changed, 131 insertions, 0 deletions
diff --git a/extensions/molecule/zone_firewall/converge.yml b/extensions/molecule/zone_firewall/converge.yml
new file mode 100644
index 0000000..03e3ad7
--- /dev/null
+++ b/extensions/molecule/zone_firewall/converge.yml
@@ -0,0 +1,7 @@
+---
+- name: Converge
+ hosts: vyos
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.zone_firewall
diff --git a/extensions/molecule/zone_firewall/inventory.yml b/extensions/molecule/zone_firewall/inventory.yml
new file mode 100644
index 0000000..6e9f461
--- /dev/null
+++ b/extensions/molecule/zone_firewall/inventory.yml
@@ -0,0 +1,33 @@
+---
+all:
+ children:
+ vyos:
+ hosts:
+ r1:
+ ansible_host: clab-bp-zfw-r1
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin
+ base_interfaces:
+ - {name: eth1, addresses: [172.16.10.1/24]}
+ - {name: eth2, addresses: [192.168.100.1/24]}
+ - {name: eth3, addresses: [192.168.200.1/24]}
+ zone_firewall_zones:
+ # containerlab management; keeps Ansible's SSH session working
+ - {name: mgmt, interfaces: [eth0]}
+ - {name: wan, interfaces: [eth1]}
+ - {name: lan, interfaces: [eth2]}
+ - {name: dmz, interfaces: [eth3]}
+ - {name: local, local: true}
+ zone_firewall_policies:
+ - {from: mgmt, to: local, default_action: accept}
+ - from: wan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}}
+ - from: lan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
diff --git a/extensions/molecule/zone_firewall/molecule.yml b/extensions/molecule/zone_firewall/molecule.yml
new file mode 100644
index 0000000..612af0a
--- /dev/null
+++ b/extensions/molecule/zone_firewall/molecule.yml
@@ -0,0 +1,27 @@
+---
+# VyOS runs as a container (containerlab kind vyosnetworks_vyos);
+# the lab is deployed in prepare and destroyed in cleanup.
+dependency:
+ name: galaxy
+ enabled: false
+driver:
+ name: default
+ options:
+ managed: false
+platforms:
+ - name: r1
+provisioner:
+ name: ansible
+ config_options:
+ defaults:
+ host_key_checking: false
+ persistent_connection:
+ command_timeout: 60
+ inventory:
+ links:
+ hosts: inventory.yml
+ playbooks:
+ prepare: ../_shared/lab_up.yml
+ cleanup: ../_shared/lab_down.yml
+verifier:
+ name: ansible
diff --git a/extensions/molecule/zone_firewall/topology.clab.yml b/extensions/molecule/zone_firewall/topology.clab.yml
new file mode 100644
index 0000000..9be83a6
--- /dev/null
+++ b/extensions/molecule/zone_firewall/topology.clab.yml
@@ -0,0 +1,34 @@
+name: bp-zfw
+topology:
+ nodes:
+ r1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:blueprints-ci}
+ wan:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 172.16.10.100/24 dev eth1
+ - ip route replace default via 172.16.10.1
+ - apk add --no-cache busybox-extras
+ - httpd -p 80 -h /tmp
+ lan:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.100.10/24 dev eth1
+ - ip route replace default via 192.168.100.1
+ - apk add --no-cache busybox-extras
+ - httpd -p 80 -h /tmp
+ dmz:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip addr add 192.168.200.200/24 dev eth1
+ - ip route replace default via 192.168.200.1
+ - apk add --no-cache busybox-extras
+ - httpd -p 80 -h /tmp
+ links:
+ - endpoints: ["r1:eth1", "wan:eth1"]
+ - endpoints: ["r1:eth2", "lan:eth1"]
+ - endpoints: ["r1:eth3", "dmz:eth1"]
diff --git a/extensions/molecule/zone_firewall/verify.yml b/extensions/molecule/zone_firewall/verify.yml
new file mode 100644
index 0000000..16584f3
--- /dev/null
+++ b/extensions/molecule/zone_firewall/verify.yml
@@ -0,0 +1,30 @@
+---
+- name: Verify role state
+ hosts: vyos
+ gather_facts: false
+ tasks:
+ - name: Run role checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.zone_firewall
+ tasks_from: verify
+
+- name: Verify traffic between zones
+ hosts: localhost
+ gather_facts: false
+ vars:
+ _flows:
+ - {from: lan, to: 192.168.200.200, allowed: true, why: "LAN can access DMZ resources"}
+ - {from: wan, to: 192.168.200.200, allowed: true, why: "inbound WAN connects to the DMZ host"}
+ - {from: dmz, to: 192.168.100.10, allowed: false, why: "DMZ cannot access LAN resources"}
+ - {from: wan, to: 192.168.100.10, allowed: false, why: "WAN cannot reach the LAN"}
+ tasks:
+ - name: Try HTTP across zones
+ ansible.builtin.command:
+ cmd: docker exec clab-bp-zfw-{{ item.from }} wget -q -T 3 -O /dev/null http://{{ item.to }}/
+ become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}"
+ register: _http
+ changed_when: false
+ failed_when: (_http.rc == 0) != item.allowed
+ loop: "{{ _flows }}"
+ loop_control:
+ label: "{{ item.from }} -> {{ item.to }} ({{ item.why }})"