summaryrefslogtreecommitdiff
path: root/roles/ipsec_route_based/tasks/verify.yml
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /roles/ipsec_route_based/tasks/verify.yml
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'roles/ipsec_route_based/tasks/verify.yml')
-rw-r--r--roles/ipsec_route_based/tasks/verify.yml52
1 files changed, 52 insertions, 0 deletions
diff --git a/roles/ipsec_route_based/tasks/verify.yml b/roles/ipsec_route_based/tasks/verify.yml
new file mode 100644
index 0000000..42edd24
--- /dev/null
+++ b/roles/ipsec_route_based/tasks/verify.yml
@@ -0,0 +1,52 @@
+---
+- name: Read IPsec SAs
+ vyos.vyos.vyos_command:
+ commands:
+ - show vpn ipsec sa
+ register: _ipsec_route_based_v_sa
+
+- name: The IPsec SA of every peer is up
+ ansible.builtin.assert:
+ that: _ipsec_route_based_v_sa.stdout[0] is search('(?m)^' ~ (item.name | regex_escape) ~ '-vti\s+up\b')
+ fail_msg: "IPsec SA {{ item.name }}-vti is not up"
+ quiet: true
+ loop: "{{ ipsec_route_based_peers }}"
+ loop_control:
+ label: "{{ item.name }}"
+
+- name: Read OSPF neighbours
+ vyos.vyos.vyos_command:
+ commands:
+ - show ip ospf neighbor
+ register: _ipsec_route_based_v_ospf
+ when: ipsec_route_based_ospf | default({}, true) | length > 0
+
+- name: A Full OSPF adjacency on every VTI
+ ansible.builtin.assert:
+ that: _ipsec_route_based_v_ospf.stdout[0] is search('Full.*\s' ~ (item.vti.interface | regex_escape) ~ ':')
+ fail_msg: "no Full OSPF adjacency on {{ item.vti.interface }}"
+ quiet: true
+ loop: "{{ ipsec_route_based_peers }}"
+ loop_control:
+ label: "{{ item.vti.interface }}"
+ when: ipsec_route_based_ospf | default({}, true) | length > 0
+
+- name: Read BGP neighbours
+ vyos.vyos.vyos_command:
+ commands:
+ - show bgp summary
+ register: _ipsec_route_based_v_bgp
+ when: ipsec_route_based_bgp | default({}, true) | length > 0
+
+- name: Every BGP session is established
+ # An established neighbour shows its Up/Down time followed by a prefix count.
+ ansible.builtin.assert:
+ that: >-
+ _ipsec_route_based_v_bgp.stdout[0] is search('(?m)^' ~ (item.address | regex_escape)
+ ~ '\s.*\s(\d{2}:\d{2}:\d{2}|\d+[dwh]\S*)\s+\d+\b')
+ fail_msg: "BGP session to {{ item.address }} is not established"
+ quiet: true
+ loop: "{{ (ipsec_route_based_bgp | default({}, true)).neighbors | default([]) }}"
+ loop_control:
+ label: "{{ item.address }}"
+ when: ipsec_route_based_bgp | default({}, true) | length > 0