diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-05 20:56:05 +1000 |
| commit | 8ee802e41374942965b6b93cfb4534725ef45145 (patch) | |
| tree | ef3e5579bd767422caa6fe77cea6a7b5d2d8562c /roles/ipsec_route_based/tasks/verify.yml | |
| parent | 748df2bc1d35fa285dd3fe46916e1230408778c7 (diff) | |
| download | vyos.blueprints-main.tar.gz vyos.blueprints-main.zip | |
T9393: new rolesmain
Diffstat (limited to 'roles/ipsec_route_based/tasks/verify.yml')
| -rw-r--r-- | roles/ipsec_route_based/tasks/verify.yml | 52 |
1 files changed, 52 insertions, 0 deletions
diff --git a/roles/ipsec_route_based/tasks/verify.yml b/roles/ipsec_route_based/tasks/verify.yml new file mode 100644 index 0000000..42edd24 --- /dev/null +++ b/roles/ipsec_route_based/tasks/verify.yml @@ -0,0 +1,52 @@ +--- +- name: Read IPsec SAs + vyos.vyos.vyos_command: + commands: + - show vpn ipsec sa + register: _ipsec_route_based_v_sa + +- name: The IPsec SA of every peer is up + ansible.builtin.assert: + that: _ipsec_route_based_v_sa.stdout[0] is search('(?m)^' ~ (item.name | regex_escape) ~ '-vti\s+up\b') + fail_msg: "IPsec SA {{ item.name }}-vti is not up" + quiet: true + loop: "{{ ipsec_route_based_peers }}" + loop_control: + label: "{{ item.name }}" + +- name: Read OSPF neighbours + vyos.vyos.vyos_command: + commands: + - show ip ospf neighbor + register: _ipsec_route_based_v_ospf + when: ipsec_route_based_ospf | default({}, true) | length > 0 + +- name: A Full OSPF adjacency on every VTI + ansible.builtin.assert: + that: _ipsec_route_based_v_ospf.stdout[0] is search('Full.*\s' ~ (item.vti.interface | regex_escape) ~ ':') + fail_msg: "no Full OSPF adjacency on {{ item.vti.interface }}" + quiet: true + loop: "{{ ipsec_route_based_peers }}" + loop_control: + label: "{{ item.vti.interface }}" + when: ipsec_route_based_ospf | default({}, true) | length > 0 + +- name: Read BGP neighbours + vyos.vyos.vyos_command: + commands: + - show bgp summary + register: _ipsec_route_based_v_bgp + when: ipsec_route_based_bgp | default({}, true) | length > 0 + +- name: Every BGP session is established + # An established neighbour shows its Up/Down time followed by a prefix count. + ansible.builtin.assert: + that: >- + _ipsec_route_based_v_bgp.stdout[0] is search('(?m)^' ~ (item.address | regex_escape) + ~ '\s.*\s(\d{2}:\d{2}:\d{2}|\d+[dwh]\S*)\s+\d+\b') + fail_msg: "BGP session to {{ item.address }} is not established" + quiet: true + loop: "{{ (ipsec_route_based_bgp | default({}, true)).neighbors | default([]) }}" + loop_control: + label: "{{ item.address }}" + when: ipsec_route_based_bgp | default({}, true) | length > 0 |
