summaryrefslogtreecommitdiff
path: root/examples/azure-vpn-bgp
diff options
context:
space:
mode:
Diffstat (limited to 'examples/azure-vpn-bgp')
-rw-r--r--examples/azure-vpn-bgp/group_vars/onprem.yml45
-rw-r--r--examples/azure-vpn-bgp/inventory.yml15
-rw-r--r--examples/azure-vpn-bgp/site.yml11
-rw-r--r--examples/azure-vpn-bgp/verify.yml9
4 files changed, 80 insertions, 0 deletions
diff --git a/examples/azure-vpn-bgp/group_vars/onprem.yml b/examples/azure-vpn-bgp/group_vars/onprem.yml
new file mode 100644
index 0000000..fdada7a
--- /dev/null
+++ b/examples/azure-vpn-bgp/group_vars/onprem.yml
@@ -0,0 +1,45 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html
+ipsec_route_based_peers:
+ - name: 203.0.113.2
+ description: AZURE PRIMARY TUNNEL
+ psk_name: azure
+ psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices
+ local_address: 10.10.0.5 # private IP; the device is behind NAT
+ local_id: 198.51.100.3 # public IP
+ remote_address: 203.0.113.2
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Tunnel, adjust_mss: "1350"}
+ipsec_route_based_ike_group:
+ name: AZURE
+ key_exchange: ikev2
+ ikev2_reauth: true
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 2
+ encryption: aes256
+ hash: sha1
+ dead_peer_detection: {action: restart, interval: 15, timeout: 30}
+ipsec_route_based_esp_group:
+ name: AZURE
+ lifetime: 3600
+ mode: tunnel
+ pfs: dh-group2
+ proposal_id: 1
+ encryption: aes256
+ hash: sha1
+ipsec_route_based_interfaces: [eth0]
+ipsec_route_based_disable_route_autoinstall: false # the page does not set it
+ipsec_route_based_interface_routes:
+ - {dest: 10.0.0.4/32, interface: vti1}
+ipsec_route_based_bgp:
+ asn: 64499
+ neighbors:
+ - address: 10.0.0.4
+ remote_as: 65540
+ holdtime: 30
+ keepalive: 10
+ disable_connected_check: true
+ soft_reconfiguration_inbound: true
diff --git a/examples/azure-vpn-bgp/inventory.yml b/examples/azure-vpn-bgp/inventory.yml
new file mode 100644
index 0000000..787a66e
--- /dev/null
+++ b/examples/azure-vpn-bgp/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html
+# Only the VyOS side is configured here; the Azure VNet gateway, local network
+# gateway and connection are created in Azure as the page's prerequisites describe.
+all:
+ children:
+ onprem:
+ hosts:
+ vyos:
+ ansible_host: 192.0.2.10 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: vyos
+ ansible_password: vyos # use ansible-vault for real devices
diff --git a/examples/azure-vpn-bgp/site.yml b/examples/azure-vpn-bgp/site.yml
new file mode 100644
index 0000000..8d27036
--- /dev/null
+++ b/examples/azure-vpn-bgp/site.yml
@@ -0,0 +1,11 @@
+---
+- name: Route-based VPN to Azure with BGP
+ hosts: onprem
+ gather_facts: false
+ roles:
+ - vyos.blueprints.ipsec_route_based
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/azure-vpn-bgp/verify.yml b/examples/azure-vpn-bgp/verify.yml
new file mode 100644
index 0000000..fb4e633
--- /dev/null
+++ b/examples/azure-vpn-bgp/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the Azure VPN
+ hosts: onprem
+ gather_facts: false
+ tasks:
+ - name: IPsec and BGP checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify