summaryrefslogtreecommitdiff
path: root/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml
diff options
context:
space:
mode:
Diffstat (limited to 'extensions/molecule/ipsec_route_based_bgp_dual/verify.yml')
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/verify.yml47
1 files changed, 47 insertions, 0 deletions
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml
new file mode 100644
index 0000000..34bee33
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml
@@ -0,0 +1,47 @@
+---
+- name: Verify both tunnels and BGP sessions
+ hosts: vpn
+ gather_facts: false
+ tasks:
+ - name: Wait for IKE, IPsec and BGP
+ ansible.builtin.pause:
+ seconds: 60
+ run_once: true
+
+ - name: Run role checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
+
+- name: Verify redundancy - traffic survives losing the primary tunnel
+ hosts: r1
+ gather_facts: false
+ vars:
+ _ping: docker exec clab-bp-azure2-onprem ping -c 3 -W 2 10.0.1.10
+ _become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}"
+ tasks:
+ - name: Ping the VNet with both tunnels up
+ ansible.builtin.command: "{{ _ping }}"
+ delegate_to: localhost
+ become: "{{ _become }}"
+ changed_when: false
+
+ - name: Take the primary tunnel down
+ vyos.vyos.vyos_config:
+ lines:
+ - set vpn ipsec site-to-site peer azure-primary disable
+
+ - name: Wait for BGP to converge on the secondary path
+ ansible.builtin.pause:
+ seconds: 40
+
+ - name: Ping the VNet over the secondary tunnel only
+ ansible.builtin.command: "{{ _ping }}"
+ delegate_to: localhost
+ become: "{{ _become }}"
+ changed_when: false
+
+ - name: Bring the primary tunnel back
+ vyos.vyos.vyos_config:
+ lines:
+ - delete vpn ipsec site-to-site peer azure-primary disable