summaryrefslogtreecommitdiff
path: root/examples/zone-policy
diff options
context:
space:
mode:
Diffstat (limited to 'examples/zone-policy')
-rw-r--r--examples/zone-policy/group_vars/firewall.yml80
-rw-r--r--examples/zone-policy/inventory.yml13
-rw-r--r--examples/zone-policy/site.yml12
-rw-r--r--examples/zone-policy/topology.clab.yml40
-rw-r--r--examples/zone-policy/verify.yml9
5 files changed, 154 insertions, 0 deletions
diff --git a/examples/zone-policy/group_vars/firewall.yml b/examples/zone-policy/group_vars/firewall.yml
new file mode 100644
index 0000000..13c0188
--- /dev/null
+++ b/examples/zone-policy/group_vars/firewall.yml
@@ -0,0 +1,80 @@
+---
+# Router on a stick, as on the docs page. The page trunks VLANs 10/20/30 on
+# eth0; this example uses eth1 because containerlab reserves eth0 for
+# management.
+base_interfaces:
+ - {name: eth1, description: trunk}
+ - {name: eth1.10, description: WAN, addresses: [172.16.10.1/24, "2001:db8:0:9999::1/64"]}
+ - {name: eth1.20, description: LAN, addresses: [192.168.100.1/24, "2001:db8:0:aaaa::1/64"]}
+ - {name: eth1.30, description: DMZ, addresses: [192.168.200.1/24, "2001:db8:0:bbbb::1/64"]}
+
+zone_firewall_zones:
+ # mgmt exists only so Ansible keeps its SSH session in containerlab. On a real
+ # router follow the page: the admin console (192.168.100.10) reaches the router
+ # through the lan-local rule 800, so make sure that rule is in place first.
+ - {name: mgmt, interfaces: [eth0]}
+ - {name: wan, interfaces: [eth1.10]}
+ - {name: lan, interfaces: [eth1.20]}
+ - {name: dmz, interfaces: [eth1.30]}
+ - {name: local, local: true}
+
+zone_firewall_policies:
+ - {from: mgmt, to: local, default_action: accept}
+ - from: wan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {address: 192.168.200.200, port: "80,443"}}
+ - {number: 200, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "80,443"}}
+ - {number: 500, protocol: tcp, destination: {address: 192.168.200.200, port: "25"}}
+ - {number: 500, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "25"}}
+ - {number: 600, protocol: tcp, destination: {address: 192.168.200.200, port: "53"}}
+ - {number: 600, protocol: tcp, destination: {address: "2001:db8:0:bbbb::200", port: "53"}}
+ - from: dmz
+ to: local
+ rules:
+ - {number: 400, protocol: tcp, destination: {port: "123"}}
+ - {number: 600, protocol: tcp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: lan
+ to: local
+ rules:
+ - {number: 400, protocol: tcp, destination: {port: "123"}}
+ - {number: 600, protocol: tcp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {port: "22"}}
+ - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {port: "22"}}
+ - from: lan
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - {number: 800, protocol: tcp, destination: {port: "22"}}
+ - from: dmz
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - {number: 600, protocol: tcp_udp, destination: {port: "53"}}
+ - {number: 800, protocol: tcp, destination: {port: "22"}}
+ - from: local
+ to: wan
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 300, protocol: tcp, destination: {port: "20,21"}}
+ - from: local
+ to: dmz
+ rules:
+ - {number: 500, protocol: tcp, destination: {port: "25"}}
+ - {number: 600, protocol: tcp_udp, destination: {port: "53"}}
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: local
+ to: lan
+ rules:
+ - {number: 700, protocol: tcp, destination: {port: "67,68"}}
+ - from: lan
+ to: dmz
+ rules:
+ - {number: 200, protocol: tcp, destination: {port: "80,443"}}
+ - {number: 800, protocol: tcp, source: {address: 192.168.100.10}, destination: {address: 192.168.200.200, port: "22"}}
+ - {number: 800, protocol: tcp, source: {address: "2001:db8:0:aaaa::10"}, destination: {address: "2001:db8:0:bbbb::200", port: "22"}}
+ - {number: 900, protocol: tcp, destination: {port: "993"}}
diff --git a/examples/zone-policy/inventory.yml b/examples/zone-policy/inventory.yml
new file mode 100644
index 0000000..206412d
--- /dev/null
+++ b/examples/zone-policy/inventory.yml
@@ -0,0 +1,13 @@
+---
+# docs.vyos.io/en/1.5/configexamples/zone-policy.html
+all:
+ children:
+ firewall:
+ hosts:
+ fw1:
+ ansible_host: clab-zone-policy-fw1 # your router's address
+ vars:
+ ansible_network_os: vyos.vyos.vyos
+ ansible_connection: ansible.netcommon.network_cli
+ ansible_user: admin
+ ansible_password: admin # use ansible-vault for real devices
diff --git a/examples/zone-policy/site.yml b/examples/zone-policy/site.yml
new file mode 100644
index 0000000..4d82cdf
--- /dev/null
+++ b/examples/zone-policy/site.yml
@@ -0,0 +1,12 @@
+---
+- name: Zone-based firewall
+ hosts: firewall
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.zone_firewall
+ post_tasks:
+ - name: Show rendered commands
+ ansible.builtin.debug:
+ var: vyos_blueprints_rendered
+ when: show_rendered | default(false) | bool
diff --git a/examples/zone-policy/topology.clab.yml b/examples/zone-policy/topology.clab.yml
new file mode 100644
index 0000000..63080d2
--- /dev/null
+++ b/examples/zone-policy/topology.clab.yml
@@ -0,0 +1,40 @@
+name: zone-policy
+topology:
+ nodes:
+ fw1:
+ kind: vyosnetworks_vyos
+ image: ${VYOS_IMAGE:=vyos:latest}
+ # one host per network on its own VLAN, behind a VLAN-aware bridge
+ sw:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge vlan_filtering 1
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set eth3 master br0
+ - ip link set eth4 master br0
+ - bridge vlan add dev eth1 vid 10
+ - bridge vlan add dev eth1 vid 20
+ - bridge vlan add dev eth1 vid 30
+ - bridge vlan add dev eth2 vid 10 pvid untagged
+ - bridge vlan add dev eth3 vid 20 pvid untagged
+ - bridge vlan add dev eth4 vid 30 pvid untagged
+ - ip link set br0 up
+ wan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 172.16.10.100/24 dev eth1", "ip route replace default via 172.16.10.1"]
+ lan:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.100.10/24 dev eth1", "ip route replace default via 192.168.100.1"]
+ dmz:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 192.168.200.200/24 dev eth1", "ip route replace default via 192.168.200.1"]
+ links:
+ - endpoints: ["fw1:eth1", "sw:eth1"]
+ - endpoints: ["sw:eth2", "wan:eth1"]
+ - endpoints: ["sw:eth3", "lan:eth1"]
+ - endpoints: ["sw:eth4", "dmz:eth1"]
diff --git a/examples/zone-policy/verify.yml b/examples/zone-policy/verify.yml
new file mode 100644
index 0000000..3132524
--- /dev/null
+++ b/examples/zone-policy/verify.yml
@@ -0,0 +1,9 @@
+---
+- name: Check the zone firewall
+ hosts: firewall
+ gather_facts: false
+ tasks:
+ - name: Zone checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.zone_firewall
+ tasks_from: verify