diff options
Diffstat (limited to 'examples/ipsec-route-based')
| -rw-r--r-- | examples/ipsec-route-based/group_vars/vpn.yml | 17 | ||||
| -rw-r--r-- | examples/ipsec-route-based/host_vars/cisco.yml | 20 | ||||
| -rw-r--r-- | examples/ipsec-route-based/host_vars/vyos.yml | 20 | ||||
| -rw-r--r-- | examples/ipsec-route-based/inventory.yml | 18 | ||||
| -rw-r--r-- | examples/ipsec-route-based/site.yml | 12 | ||||
| -rw-r--r-- | examples/ipsec-route-based/topology.clab.yml | 25 | ||||
| -rw-r--r-- | examples/ipsec-route-based/verify.yml | 9 |
7 files changed, 121 insertions, 0 deletions
diff --git a/examples/ipsec-route-based/group_vars/vpn.yml b/examples/ipsec-route-based/group_vars/vpn.yml new file mode 100644 index 0000000..092d64b --- /dev/null +++ b/examples/ipsec-route-based/group_vars/vpn.yml @@ -0,0 +1,17 @@ +--- +# IKE and IPsec parameters from the page's tables +ipsec_route_based_ike_group: + name: IKE-GROUP + key_exchange: ikev1 + lifetime: 28800 + dh_group: 14 + encryption: aes128 + hash: sha1 + close_action: start + dead_peer_detection: {action: restart, interval: 10, timeout: 30} +ipsec_route_based_esp_group: + name: ESP-GROUP + lifetime: 3600 + pfs: disable + encryption: aes256 + hash: sha256 diff --git a/examples/ipsec-route-based/host_vars/cisco.yml b/examples/ipsec-route-based/host_vars/cisco.yml new file mode 100644 index 0000000..f536639 --- /dev/null +++ b/examples/ipsec-route-based/host_vars/cisco.yml @@ -0,0 +1,20 @@ +--- +# Lab stand-in for the page's Cisco router, using the page's Cisco values +base_interfaces: + - {name: eth1, addresses: [10.0.2.2/30]} + - {name: eth2, addresses: [192.168.10.1/24]} + - {name: eth3, addresses: [192.168.11.1/24]} +ipsec_route_based_peers: + - name: VYOS + local_address: 10.0.2.2 + remote_address: 10.0.1.2 + psk: dGVzdA== + psk_type: base64 + psk_name: AUTH-PSK + connection_type: none + vti: {interface: vti1, address: 10.100.100.2/30, mtu: 1438} +ipsec_route_based_ospf: + router_id: 1.1.1.1 + networks: [10.100.100.0/30, 192.168.10.0/24, 192.168.11.0/24] + passive_interfaces: [eth2, eth3] +ipsec_route_based_default_gateway: 10.0.2.1 diff --git a/examples/ipsec-route-based/host_vars/vyos.yml b/examples/ipsec-route-based/host_vars/vyos.yml new file mode 100644 index 0000000..8674a81 --- /dev/null +++ b/examples/ipsec-route-based/host_vars/vyos.yml @@ -0,0 +1,20 @@ +--- +# WAN is eth1 here, eth0 on the page (containerlab uses eth0 for management) +base_interfaces: + - {name: eth1, addresses: [10.0.1.2/30]} + - {name: eth2, addresses: [192.168.0.1/24]} + - {name: eth3, addresses: [192.168.1.1/24]} +ipsec_route_based_peers: + - name: CISCO + local_address: 10.0.1.2 + remote_address: 10.0.2.2 + psk: dGVzdA== # use ansible-vault for real devices + psk_type: base64 + psk_name: AUTH-PSK + connection_type: initiate + vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438} +ipsec_route_based_ospf: + router_id: 2.2.2.2 + networks: [10.100.100.0/30, 192.168.0.0/24, 192.168.1.0/24] + passive_interfaces: [eth2, eth3] +ipsec_route_based_default_gateway: 10.0.1.1 diff --git a/examples/ipsec-route-based/inventory.yml b/examples/ipsec-route-based/inventory.yml new file mode 100644 index 0000000..4d42e0d --- /dev/null +++ b/examples/ipsec-route-based/inventory.yml @@ -0,0 +1,18 @@ +--- +# docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html +# "vyos" is the router this collection configures. "cisco" is a second VyOS in +# the lab standing in for the page's Cisco router; on a real network, configure +# the Cisco side as shown on the page and remove it from this inventory. +all: + children: + vpn: + hosts: + vyos: + ansible_host: clab-ipsec-route-based-vyos # your router's address + cisco: + ansible_host: clab-ipsec-route-based-cisco + vars: + ansible_network_os: vyos.vyos.vyos + ansible_connection: ansible.netcommon.network_cli + ansible_user: admin + ansible_password: admin # use ansible-vault for real devices diff --git a/examples/ipsec-route-based/site.yml b/examples/ipsec-route-based/site.yml new file mode 100644 index 0000000..db7d07b --- /dev/null +++ b/examples/ipsec-route-based/site.yml @@ -0,0 +1,12 @@ +--- +- name: Route-based site-to-site IPsec + hosts: vpn + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ipsec_route_based + post_tasks: + - name: Show rendered commands + ansible.builtin.debug: + var: vyos_blueprints_rendered + when: show_rendered | default(false) | bool diff --git a/examples/ipsec-route-based/topology.clab.yml b/examples/ipsec-route-based/topology.clab.yml new file mode 100644 index 0000000..23e49ac --- /dev/null +++ b/examples/ipsec-route-based/topology.clab.yml @@ -0,0 +1,25 @@ +name: ipsec-route-based +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:latest} + nodes: + vyos: + kind: vyosnetworks_vyos + cisco: + kind: vyosnetworks_vyos + isp: + kind: linux + image: alpine:3 + exec: ["sysctl -w net.ipv4.ip_forward=1", "ip addr add 10.0.1.1/30 dev eth1", "ip addr add 10.0.2.1/30 dev eth2"] + pc1: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.0.2/24 dev eth1", "ip route replace default via 192.168.0.1"]} + pc2: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.1.2/24 dev eth1", "ip route replace default via 192.168.1.1"]} + pc3: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.10.2/24 dev eth1", "ip route replace default via 192.168.10.1"]} + pc4: {kind: linux, image: "alpine:3", exec: ["ip addr add 192.168.11.2/24 dev eth1", "ip route replace default via 192.168.11.1"]} + links: + - endpoints: ["vyos:eth1", "isp:eth1"] + - endpoints: ["cisco:eth1", "isp:eth2"] + - endpoints: ["vyos:eth2", "pc1:eth1"] + - endpoints: ["vyos:eth3", "pc2:eth1"] + - endpoints: ["cisco:eth2", "pc3:eth1"] + - endpoints: ["cisco:eth3", "pc4:eth1"] diff --git a/examples/ipsec-route-based/verify.yml b/examples/ipsec-route-based/verify.yml new file mode 100644 index 0000000..268ff9c --- /dev/null +++ b/examples/ipsec-route-based/verify.yml @@ -0,0 +1,9 @@ +--- +- name: Check the VPN + hosts: vpn + gather_facts: false + tasks: + - name: IPsec and OSPF checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify |
