diff options
Diffstat (limited to 'extensions/molecule/ipsec_route_based_bgp_dual')
5 files changed, 237 insertions, 0 deletions
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml b/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml new file mode 100644 index 0000000..0fb7a50 --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml @@ -0,0 +1,7 @@ +--- +- name: Converge + hosts: vpn + gather_facts: false + roles: + - vyos.blueprints.base + - vyos.blueprints.ipsec_route_based diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml b/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml new file mode 100644 index 0000000..84d5c9d --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml @@ -0,0 +1,115 @@ +--- +# Values from docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html, except: +# - no NAT in the lab, so local_address is the public IP 198.51.100.3; +# - the second gateway instance is on its own ISP subnet (203.0.114.0/24); +# - disable-route-autoinstall is set (see ipsec_route_based_bgp/inventory.yml); +# - both sides announce a LAN so the test can ping across BGP-learned routes. +all: + children: + vyos: + children: + vpn: + hosts: + r1: + ansible_host: clab-bp-azure2-vyos + base_interfaces: + - name: eth1 + addresses: [198.51.100.3/24] + - name: eth2 + addresses: [10.10.2.1/24] + ipsec_route_based_peers: + - name: azure-primary + description: AZURE PRIMARY TUNNEL + psk_name: azure + psk: molecule-psk + local_address: 198.51.100.3 + remote_address: 203.0.113.2 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti1, address: 10.10.1.5/32, adjust_mss: '1350'} + - name: azure-secondary + description: AZURE secondary TUNNEL + psk_name: azure + psk: molecule-psk + local_address: 198.51.100.3 + remote_address: 203.0.114.3 + connection_type: initiate + ikev2_reauth: inherit + esp_group_on_vti: true + vti: {interface: vti2, address: 10.10.1.6/32, adjust_mss: '1350'} + ipsec_route_based_interfaces: [eth1] + ipsec_route_based_interface_routes: + - {dest: 10.0.0.4/32, interface: vti1} + - {dest: 10.0.0.5/32, interface: vti2} + ipsec_route_based_bgp: + asn: 64499 + networks: [10.10.2.0/24] + neighbors: + - {address: 10.0.0.4, remote_as: 65540, holdtime: 30, keepalive: 10, soft_reconfiguration_inbound: true} + - {address: 10.0.0.5, remote_as: 65540, holdtime: 30, keepalive: 10, soft_reconfiguration_inbound: true} + ipsec_route_based_default_gateway: 198.51.100.1 + r2: + ansible_host: clab-bp-azure2-azure1 + base_interfaces: + - name: eth1 + addresses: [203.0.113.2/24] + - name: eth2 + addresses: [10.0.1.1/24] + ipsec_route_based_peers: + - name: 198.51.100.3 + psk_name: onprem + psk: molecule-psk + local_address: 203.0.113.2 + remote_address: 198.51.100.3 + connection_type: none + esp_group_on_vti: true + vti: {interface: vti1, address: 10.0.0.4/32} + ipsec_route_based_interfaces: [eth1] + ipsec_route_based_interface_routes: + - {dest: 10.10.1.5/32, interface: vti1} + ipsec_route_based_bgp: + asn: 65540 + networks: [10.0.1.0/24] + neighbors: + - {address: 10.10.1.5, remote_as: 64499, holdtime: 30, keepalive: 10} + ipsec_route_based_default_gateway: 203.0.113.1 + r3: + ansible_host: clab-bp-azure2-azure2 + base_interfaces: + - name: eth1 + addresses: [203.0.114.3/24] + - name: eth2 + addresses: [10.0.1.2/24] + ipsec_route_based_peers: + - name: 198.51.100.3 + psk_name: onprem + psk: molecule-psk + local_address: 203.0.114.3 + remote_address: 198.51.100.3 + connection_type: none + esp_group_on_vti: true + vti: {interface: vti1, address: 10.0.0.5/32} + ipsec_route_based_interfaces: [eth1] + ipsec_route_based_interface_routes: + - {dest: 10.10.1.6/32, interface: vti1} + ipsec_route_based_bgp: + asn: 65540 + networks: [10.0.1.0/24] + neighbors: + - {address: 10.10.1.6, remote_as: 64499, holdtime: 30, keepalive: 10} + ipsec_route_based_default_gateway: 203.0.114.1 + vars: + ipsec_route_based_ike_group: + name: AZURE + key_exchange: ikev2 + ikev2_reauth: true + lifetime: 28800 + proposal_id: 1 + dh_group: 2 + encryption: aes256 + hash: sha1 + dead_peer_detection: {action: restart, interval: 15, timeout: 30} + ipsec_route_based_esp_group: {name: AZURE, lifetime: 3600, mode: tunnel, pfs: dh-group2, proposal_id: 1, encryption: aes256, hash: sha1} + ipsec_route_based_disable_route_autoinstall: true + vars: {ansible_network_os: vyos.vyos.vyos, ansible_connection: ansible.netcommon.network_cli, ansible_user: admin, ansible_password: admin} diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml b/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml new file mode 100644 index 0000000..11a5f84 --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml @@ -0,0 +1,29 @@ +--- +# VyOS runs as a container (containerlab kind vyosnetworks_vyos); +# the lab is deployed in prepare and destroyed in cleanup. +dependency: + name: galaxy + enabled: false +driver: + name: default + options: + managed: false +platforms: + - name: r1 + - name: r2 + - name: r3 +provisioner: + name: ansible + config_options: + defaults: + host_key_checking: false + persistent_connection: + command_timeout: 60 + inventory: + links: + hosts: inventory.yml + playbooks: + prepare: ../_shared/lab_up.yml + cleanup: ../_shared/lab_down.yml +verifier: + name: ansible diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml b/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml new file mode 100644 index 0000000..140aee6 --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml @@ -0,0 +1,39 @@ +name: bp-azure2 +topology: + kinds: + vyosnetworks_vyos: + image: ${VYOS_IMAGE:=vyos:blueprints-ci} + nodes: + vyos: + kind: vyosnetworks_vyos + # two VyOS standing in for the active-active Azure VNet gateway instances + azure1: + kind: vyosnetworks_vyos + azure2: + kind: vyosnetworks_vyos + isp: + kind: linux + image: alpine:3 + exec: ["sysctl -w net.ipv4.ip_forward=1", "ip addr add 198.51.100.1/24 dev eth1", "ip addr add 203.0.113.1/24 dev eth2", "ip addr add 203.0.114.1/24 dev eth3"] + onprem: + kind: linux + image: alpine:3 + exec: ["ip addr add 10.10.2.10/24 dev eth1", "ip route replace default via 10.10.2.1"] + # the "VNet": one host behind both gateway instances + vm: + kind: linux + image: alpine:3 + exec: + - ip link add br0 type bridge + - ip link set eth1 master br0 + - ip link set eth2 master br0 + - ip link set br0 up + - ip addr add 10.0.1.10/24 dev br0 + - ip route replace 10.10.0.0/16 nexthop via 10.0.1.1 nexthop via 10.0.1.2 + links: + - endpoints: ["vyos:eth1", "isp:eth1"] + - endpoints: ["azure1:eth1", "isp:eth2"] + - endpoints: ["azure2:eth1", "isp:eth3"] + - endpoints: ["vyos:eth2", "onprem:eth1"] + - endpoints: ["azure1:eth2", "vm:eth1"] + - endpoints: ["azure2:eth2", "vm:eth2"] diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml new file mode 100644 index 0000000..34bee33 --- /dev/null +++ b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml @@ -0,0 +1,47 @@ +--- +- name: Verify both tunnels and BGP sessions + hosts: vpn + gather_facts: false + tasks: + - name: Wait for IKE, IPsec and BGP + ansible.builtin.pause: + seconds: 60 + run_once: true + + - name: Run role checks + ansible.builtin.include_role: + name: vyos.blueprints.ipsec_route_based + tasks_from: verify + +- name: Verify redundancy - traffic survives losing the primary tunnel + hosts: r1 + gather_facts: false + vars: + _ping: docker exec clab-bp-azure2-onprem ping -c 3 -W 2 10.0.1.10 + _become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}" + tasks: + - name: Ping the VNet with both tunnels up + ansible.builtin.command: "{{ _ping }}" + delegate_to: localhost + become: "{{ _become }}" + changed_when: false + + - name: Take the primary tunnel down + vyos.vyos.vyos_config: + lines: + - set vpn ipsec site-to-site peer azure-primary disable + + - name: Wait for BGP to converge on the secondary path + ansible.builtin.pause: + seconds: 40 + + - name: Ping the VNet over the secondary tunnel only + ansible.builtin.command: "{{ _ping }}" + delegate_to: localhost + become: "{{ _become }}" + changed_when: false + + - name: Bring the primary tunnel back + vyos.vyos.vyos_config: + lines: + - delete vpn ipsec site-to-site peer azure-primary disable |
