diff options
Diffstat (limited to 'examples/azure-vpn-bgp')
| -rw-r--r-- | examples/azure-vpn-bgp/group_vars/onprem.yml | 45 | ||||
| -rw-r--r-- | examples/azure-vpn-bgp/inventory.yml | 15 | ||||
| -rw-r--r-- | examples/azure-vpn-bgp/site.yml | 11 | ||||
| -rw-r--r-- | examples/azure-vpn-bgp/verify.yml | 9 |
4 files changed, 80 insertions, 0 deletions
diff --git a/examples/azure-vpn-bgp/group_vars/onprem.yml b/examples/azure-vpn-bgp/group_vars/onprem.yml new file mode 100644 index 0000000..fdada7a --- /dev/null +++ b/examples/azure-vpn-bgp/group_vars/onprem.yml @@ -0,0 +1,45 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html +ipsec_route_based_peers: + - name: 203.0.113.2 + description: AZURE PRIMARY TUNNEL + psk_name: azure + psk: ch00s3-4-s3cur3-psk # use ansible-vault for real devices + local_address: 10.10.0.5 # private IP; the device is behind NAT + local_id: 198.51.100.3 # public IP + remote_address: 203.0.113.2 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti1, address: 10.10.1.5/32, description: Azure Tunnel, adjust_mss: "1350"} +ipsec_route_based_ike_group: + name: AZURE + key_exchange: ikev2 + ikev2_reauth: true + lifetime: 28800 + proposal_id: 1 + dh_group: 2 + encryption: aes256 + hash: sha1 + dead_peer_detection: {action: restart, interval: 15, timeout: 30} +ipsec_route_based_esp_group: + name: AZURE + lifetime: 3600 + mode: tunnel + pfs: dh-group2 + proposal_id: 1 + encryption: aes256 + hash: sha1 +ipsec_route_based_interfaces: [eth0] +ipsec_route_based_disable_route_autoinstall: false # the page does not set it +ipsec_route_based_interface_routes: + - {dest: 10.0.0.4/32, interface: vti1} +ipsec_route_based_bgp: + asn: 64499 + neighbors: + - address: 10.0.0.4 + remote_as: 65540 + holdtime: 30 + keepalive: 10 + disable_connected_check: true + soft_reconfiguration_inbound: true diff --git a/examples/azure-vpn-bgp/inventory.yml b/examples/azure-vpn-bgp/inventory.yml new file mode 100644 index 0000000..787a66e --- /dev/null +++ b/examples/azure-vpn-bgp/inventory.yml @@ -0,0 +1,15 @@ +--- +# docs.vyos.io/en/1.5/configexamples/azure-vpn-bgp.html +# Only the VyOS side is configured here; the Azure VNet gateway, local network +# gateway and connection are created in Azure as the page's prerequisites describe. +all: + children: + onprem: + hosts: + vyos: + ansible_host: 192.0.2.10 # your router's address + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: vyos + ansible_password: vyos # use ansible-vault for real devices diff --git a/examples/azure-vpn-bgp/site.yml b/examples/azure-vpn-bgp/site.yml new file mode 100644 index 0000000..8d27036 --- /dev/null +++ b/examples/azure-vpn-bgp/site.yml @@ -0,0 +1,11 @@ +--- +- name: Route-based VPN to Azure with BGP + hosts: onprem + gather_facts: false + roles: + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/azure-vpn-bgp/verify.yml b/examples/azure-vpn-bgp/verify.yml new file mode 100644 index 0000000..fb4e633 --- /dev/null +++ b/examples/azure-vpn-bgp/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the Azure VPN + hosts: onprem + gather_facts: false + tasks: + - name: IPsec and BGP checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify |
