summaryrefslogtreecommitdiff
path: root/examples/policy-ipsec-firewall
diff options
context:
space:
mode:
Diffstat (limited to 'examples/policy-ipsec-firewall')
-rw-r--r--examples/policy-ipsec-firewall/group_vars/sites.yml5
-rw-r--r--examples/policy-ipsec-firewall/host_vars/left.yml98
-rw-r--r--examples/policy-ipsec-firewall/host_vars/right.yml23
-rw-r--r--examples/policy-ipsec-firewall/inventory.yml15
-rw-r--r--examples/policy-ipsec-firewall/site.yml15
-rw-r--r--examples/policy-ipsec-firewall/topology.clab.yml51
-rw-r--r--examples/policy-ipsec-firewall/verify.yml22
7 files changed, 229 insertions, 0 deletions
diff --git a/examples/policy-ipsec-firewall/group_vars/sites.yml b/examples/policy-ipsec-firewall/group_vars/sites.yml
new file mode 100644
index 0000000..72cb49a
--- /dev/null
+++ b/examples/policy-ipsec-firewall/group_vars/sites.yml
@@ -0,0 +1,5 @@
+---
+# IPsec settings shared by both routers, as on the page
+ipsec_policy_based_ike_group: {name: IKE-GROUP, key_exchange: ikev2, proposal_id: 1, dh_group: 14, encryption: aes256, hash: sha256}
+ipsec_policy_based_esp_group: {name: ESP-GROUP, mode: tunnel, proposal_id: 1, encryption: aes256, hash: sha256}
+ipsec_policy_based_interfaces: [eth3]
diff --git a/examples/policy-ipsec-firewall/host_vars/left.yml b/examples/policy-ipsec-firewall/host_vars/left.yml
new file mode 100644
index 0000000..e6fe1ee
--- /dev/null
+++ b/examples/policy-ipsec-firewall/host_vars/left.yml
@@ -0,0 +1,98 @@
+---
+# WAN is eth3 here, eth0 on the page (containerlab uses eth0 for management).
+# Input rule 5 keeps containerlab management reachable - drop it on a real router
+# and make sure your management source is allowed (rule 20, TRUSTED) instead.
+ipsec_policy_based_peers:
+ - name: RIGHT
+ psk_name: RIGHT
+ psk: p4ssw0rd # use ansible-vault for real devices
+ authentication_ids: false
+ local_address: 198.51.100.14
+ remote_address: 192.0.2.130
+ connection_type: initiate
+ tunnels:
+ - {id: 0, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.21.0/24}
+ - {id: 1, local_prefix: 10.1.11.0/24, remote_prefix: 10.2.22.0/24}
+ - {id: 2, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.21.0/24}
+ - {id: 3, local_prefix: 10.1.12.0/24, remote_prefix: 10.2.22.0/24}
+ipsec_policy_based_default_gateway: 198.51.100.13
+firewall_groups:
+ network:
+ - name: LOCAL-NETS
+ networks: [10.1.11.0/24, 10.1.12.0/24]
+ - name: REMOTE-NETS
+ networks: [10.2.21.0/24, 10.2.22.0/24]
+ - name: TRUSTED
+ networks: [198.51.100.125/32, 203.0.113.0/24, 10.1.11.0/24, 192.168.70.0/24]
+firewall_ipv4:
+ forward:
+ default_action: drop
+ rules:
+ - number: 1
+ action: accept
+ state: {established: true, related: true}
+ - number: 2
+ action: drop
+ state: {invalid: true}
+ - number: 10
+ action: accept
+ source:
+ group: {network_group: LOCAL-NETS}
+ - number: 20
+ action: accept
+ source:
+ group: {network_group: REMOTE-NETS}
+ destination:
+ group: {network_group: LOCAL-NETS}
+ input:
+ default_action: drop
+ rules:
+ - number: 1
+ action: accept
+ state: {established: true, related: true}
+ - number: 2
+ action: drop
+ state: {invalid: true}
+ - number: 5
+ action: accept
+ description: containerlab management
+ inbound_interface: {name: eth0}
+ - number: 10
+ action: accept
+ protocol: udp
+ destination: {port: '500,4500'}
+ inbound_interface: {name: eth3}
+ - number: 15
+ action: accept
+ protocol: esp
+ inbound_interface: {name: eth3}
+ - number: 20
+ action: accept
+ protocol: tcp
+ destination: {port: '22'}
+ source:
+ group: {network_group: TRUSTED}
+ - number: 25
+ action: accept
+ protocol: udp
+ destination: {port: '53'}
+ source:
+ group: {network_group: LOCAL-NETS}
+ - {number: 30, action: accept, protocol: icmp}
+nat_source_rules:
+ - id: 10
+ exclude: true
+ outbound_interface: {name: eth3}
+ source: {network_group: LOCAL-NETS}
+ destination: {network_group: REMOTE-NETS}
+ - id: 20
+ outbound_interface: {name: eth3}
+ source: {network_group: LOCAL-NETS}
+ translation: {address: masquerade}
+base_interfaces:
+ - name: eth3
+ addresses: [198.51.100.14/30]
+ - name: eth1.111
+ addresses: [10.1.11.1/24]
+ - name: eth2.112
+ addresses: [10.1.12.1/24]
diff --git a/examples/policy-ipsec-firewall/host_vars/right.yml b/examples/policy-ipsec-firewall/host_vars/right.yml
new file mode 100644
index 0000000..ab629da
--- /dev/null
+++ b/examples/policy-ipsec-firewall/host_vars/right.yml
@@ -0,0 +1,23 @@
+---
+# The page sets no default route on RIGHT; it needs one to reach LEFT.
+ipsec_policy_based_peers:
+ - name: LEFT
+ psk_name: LEFT
+ psk: p4ssw0rd # use ansible-vault for real devices
+ authentication_ids: false
+ local_address: 192.0.2.130
+ remote_address: 198.51.100.14
+ connection_type: none
+ tunnels:
+ - {id: 0, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.11.0/24}
+ - {id: 1, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.11.0/24}
+ - {id: 2, local_prefix: 10.2.21.0/24, remote_prefix: 10.1.12.0/24}
+ - {id: 3, local_prefix: 10.2.22.0/24, remote_prefix: 10.1.12.0/24}
+base_interfaces:
+ - name: eth3
+ addresses: [192.0.2.130/30]
+ - name: eth1.221
+ addresses: [10.2.21.1/24]
+ - name: eth2.222
+ addresses: [10.2.22.1/24]
+ipsec_policy_based_default_gateway: 192.0.2.129
diff --git a/examples/policy-ipsec-firewall/inventory.yml b/examples/policy-ipsec-firewall/inventory.yml
new file mode 100644
index 0000000..95eeddb
--- /dev/null
+++ b/examples/policy-ipsec-firewall/inventory.yml
@@ -0,0 +1,15 @@
+---
+# docs.vyos.io/en/1.5/configexamples/policy-based-ipsec-and-firewall.html
+all:
+ children:
+ sites:
+ hosts:
+ left:
+ ansible_host: clab-policy-ipsec-firewall-left # your router's address
+ right:
+ ansible_host: clab-policy-ipsec-firewall-right
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/policy-ipsec-firewall/site.yml b/examples/policy-ipsec-firewall/site.yml
new file mode 100644
index 0000000..87ea9a5
--- /dev/null
+++ b/examples/policy-ipsec-firewall/site.yml
@@ -0,0 +1,15 @@
+---
+- name: Policy-based IPsec with firewall and NAT
+ hosts: sites
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.ipsec_policy_based
+ # firewall and nat only have inputs on LEFT, as on the page; on RIGHT they do nothing
+ - vyos.blueprints.firewall
+ - vyos.blueprints.nat
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/policy-ipsec-firewall/topology.clab.yml b/examples/policy-ipsec-firewall/topology.clab.yml
new file mode 100644
index 0000000..e512c9c
--- /dev/null
+++ b/examples/policy-ipsec-firewall/topology.clab.yml
@@ -0,0 +1,51 @@
+name: policy-ipsec-firewall
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:latest}
+ nodes:
+ left:
+ kind: vyosnetworks_vyos
+ right:
+ kind: vyosnetworks_vyos
+ isp:
+ kind: linux
+ image: alpine:3
+ exec:
+ - sysctl -w net.ipv4.ip_forward=1
+ - ip addr add 198.51.100.13/30 dev eth1
+ - ip addr add 192.0.2.129/30 dev eth2
+ - ip addr add 203.0.113.1/24 dev eth3
+ internet:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 203.0.113.10/24 dev eth1", "ip route replace default via 203.0.113.1"]
+ l11:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.111 type vlan id 111", "ip link set eth1.111 up",
+ "ip addr add 10.1.11.10/24 dev eth1.111", "ip route replace default via 10.1.11.1"]
+ l12:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.112 type vlan id 112", "ip link set eth1.112 up",
+ "ip addr add 10.1.12.10/24 dev eth1.112", "ip route replace default via 10.1.12.1"]
+ r21:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.221 type vlan id 221", "ip link set eth1.221 up",
+ "ip addr add 10.2.21.10/24 dev eth1.221", "ip route replace default via 10.2.21.1"]
+ r22:
+ kind: linux
+ image: alpine:3
+ exec: ["ip link add link eth1 name eth1.222 type vlan id 222", "ip link set eth1.222 up",
+ "ip addr add 10.2.22.10/24 dev eth1.222", "ip route replace default via 10.2.22.1"]
+ links:
+ # WAN is eth3 here (eth0 on the page; eth0 is containerlab management)
+ - endpoints: ["left:eth3", "isp:eth1"]
+ - endpoints: ["right:eth3", "isp:eth2"]
+ - endpoints: ["isp:eth3", "internet:eth1"]
+ - endpoints: ["left:eth1", "l11:eth1"]
+ - endpoints: ["left:eth2", "l12:eth1"]
+ - endpoints: ["right:eth1", "r21:eth1"]
+ - endpoints: ["right:eth2", "r22:eth1"]
diff --git a/examples/policy-ipsec-firewall/verify.yml b/examples/policy-ipsec-firewall/verify.yml
new file mode 100644
index 0000000..d1006cf
--- /dev/null
+++ b/examples/policy-ipsec-firewall/verify.yml
@@ -0,0 +1,22 @@
+---
+- name: Check both sites
+ hosts: sites
+ gather_facts: false
+ tasks:
+ - name: IPsec checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_policy_based
+ tasks_from: verify
+
+- name: Check firewall and NAT on LEFT
+ hosts: left
+ gather_facts: false
+ tasks:
+ - name: Firewall checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.firewall
+ tasks_from: verify
+ - name: NAT checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.nat
+ tasks_from: verify