summaryrefslogtreecommitdiff
path: root/extensions/molecule/ipsec_route_based_bgp_dual
diff options
context:
space:
mode:
Diffstat (limited to 'extensions/molecule/ipsec_route_based_bgp_dual')
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/converge.yml7
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml115
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml29
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml39
-rw-r--r--extensions/molecule/ipsec_route_based_bgp_dual/verify.yml47
5 files changed, 237 insertions, 0 deletions
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml b/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml
new file mode 100644
index 0000000..0fb7a50
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/converge.yml
@@ -0,0 +1,7 @@
+---
+- name: Converge
+ hosts: vpn
+ gather_facts: false
+ roles:
+ - vyos.blueprints.base
+ - vyos.blueprints.ipsec_route_based
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml b/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml
new file mode 100644
index 0000000..84d5c9d
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/inventory.yml
@@ -0,0 +1,115 @@
+---
+# Values from docs.vyos.io/en/1.5/configexamples/azure-vpn-dual-bgp.html, except:
+# - no NAT in the lab, so local_address is the public IP 198.51.100.3;
+# - the second gateway instance is on its own ISP subnet (203.0.114.0/24);
+# - disable-route-autoinstall is set (see ipsec_route_based_bgp/inventory.yml);
+# - both sides announce a LAN so the test can ping across BGP-learned routes.
+all:
+ children:
+ vyos:
+ children:
+ vpn:
+ hosts:
+ r1:
+ ansible_host: clab-bp-azure2-vyos
+ base_interfaces:
+ - name: eth1
+ addresses: [198.51.100.3/24]
+ - name: eth2
+ addresses: [10.10.2.1/24]
+ ipsec_route_based_peers:
+ - name: azure-primary
+ description: AZURE PRIMARY TUNNEL
+ psk_name: azure
+ psk: molecule-psk
+ local_address: 198.51.100.3
+ remote_address: 203.0.113.2
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.10.1.5/32, adjust_mss: '1350'}
+ - name: azure-secondary
+ description: AZURE secondary TUNNEL
+ psk_name: azure
+ psk: molecule-psk
+ local_address: 198.51.100.3
+ remote_address: 203.0.114.3
+ connection_type: initiate
+ ikev2_reauth: inherit
+ esp_group_on_vti: true
+ vti: {interface: vti2, address: 10.10.1.6/32, adjust_mss: '1350'}
+ ipsec_route_based_interfaces: [eth1]
+ ipsec_route_based_interface_routes:
+ - {dest: 10.0.0.4/32, interface: vti1}
+ - {dest: 10.0.0.5/32, interface: vti2}
+ ipsec_route_based_bgp:
+ asn: 64499
+ networks: [10.10.2.0/24]
+ neighbors:
+ - {address: 10.0.0.4, remote_as: 65540, holdtime: 30, keepalive: 10, soft_reconfiguration_inbound: true}
+ - {address: 10.0.0.5, remote_as: 65540, holdtime: 30, keepalive: 10, soft_reconfiguration_inbound: true}
+ ipsec_route_based_default_gateway: 198.51.100.1
+ r2:
+ ansible_host: clab-bp-azure2-azure1
+ base_interfaces:
+ - name: eth1
+ addresses: [203.0.113.2/24]
+ - name: eth2
+ addresses: [10.0.1.1/24]
+ ipsec_route_based_peers:
+ - name: 198.51.100.3
+ psk_name: onprem
+ psk: molecule-psk
+ local_address: 203.0.113.2
+ remote_address: 198.51.100.3
+ connection_type: none
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.0.0.4/32}
+ ipsec_route_based_interfaces: [eth1]
+ ipsec_route_based_interface_routes:
+ - {dest: 10.10.1.5/32, interface: vti1}
+ ipsec_route_based_bgp:
+ asn: 65540
+ networks: [10.0.1.0/24]
+ neighbors:
+ - {address: 10.10.1.5, remote_as: 64499, holdtime: 30, keepalive: 10}
+ ipsec_route_based_default_gateway: 203.0.113.1
+ r3:
+ ansible_host: clab-bp-azure2-azure2
+ base_interfaces:
+ - name: eth1
+ addresses: [203.0.114.3/24]
+ - name: eth2
+ addresses: [10.0.1.2/24]
+ ipsec_route_based_peers:
+ - name: 198.51.100.3
+ psk_name: onprem
+ psk: molecule-psk
+ local_address: 203.0.114.3
+ remote_address: 198.51.100.3
+ connection_type: none
+ esp_group_on_vti: true
+ vti: {interface: vti1, address: 10.0.0.5/32}
+ ipsec_route_based_interfaces: [eth1]
+ ipsec_route_based_interface_routes:
+ - {dest: 10.10.1.6/32, interface: vti1}
+ ipsec_route_based_bgp:
+ asn: 65540
+ networks: [10.0.1.0/24]
+ neighbors:
+ - {address: 10.10.1.6, remote_as: 64499, holdtime: 30, keepalive: 10}
+ ipsec_route_based_default_gateway: 203.0.114.1
+ vars:
+ ipsec_route_based_ike_group:
+ name: AZURE
+ key_exchange: ikev2
+ ikev2_reauth: true
+ lifetime: 28800
+ proposal_id: 1
+ dh_group: 2
+ encryption: aes256
+ hash: sha1
+ dead_peer_detection: {action: restart, interval: 15, timeout: 30}
+ ipsec_route_based_esp_group: {name: AZURE, lifetime: 3600, mode: tunnel, pfs: dh-group2, proposal_id: 1, encryption: aes256, hash: sha1}
+ ipsec_route_based_disable_route_autoinstall: true
+ vars: {ansible_network_os: vyos.vyos.vyos, ansible_connection: ansible.netcommon.network_cli, ansible_user: admin, ansible_password: admin}
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml b/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml
new file mode 100644
index 0000000..11a5f84
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/molecule.yml
@@ -0,0 +1,29 @@
+---
+# VyOS runs as a container (containerlab kind vyosnetworks_vyos);
+# the lab is deployed in prepare and destroyed in cleanup.
+dependency:
+ name: galaxy
+ enabled: false
+driver:
+ name: default
+ options:
+ managed: false
+platforms:
+ - name: r1
+ - name: r2
+ - name: r3
+provisioner:
+ name: ansible
+ config_options:
+ defaults:
+ host_key_checking: false
+ persistent_connection:
+ command_timeout: 60
+ inventory:
+ links:
+ hosts: inventory.yml
+ playbooks:
+ prepare: ../_shared/lab_up.yml
+ cleanup: ../_shared/lab_down.yml
+verifier:
+ name: ansible
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml b/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml
new file mode 100644
index 0000000..140aee6
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/topology.clab.yml
@@ -0,0 +1,39 @@
+name: bp-azure2
+topology:
+ kinds:
+ vyosnetworks_vyos:
+ image: ${VYOS_IMAGE:=vyos:blueprints-ci}
+ nodes:
+ vyos:
+ kind: vyosnetworks_vyos
+ # two VyOS standing in for the active-active Azure VNet gateway instances
+ azure1:
+ kind: vyosnetworks_vyos
+ azure2:
+ kind: vyosnetworks_vyos
+ isp:
+ kind: linux
+ image: alpine:3
+ exec: ["sysctl -w net.ipv4.ip_forward=1", "ip addr add 198.51.100.1/24 dev eth1", "ip addr add 203.0.113.1/24 dev eth2", "ip addr add 203.0.114.1/24 dev eth3"]
+ onprem:
+ kind: linux
+ image: alpine:3
+ exec: ["ip addr add 10.10.2.10/24 dev eth1", "ip route replace default via 10.10.2.1"]
+ # the "VNet": one host behind both gateway instances
+ vm:
+ kind: linux
+ image: alpine:3
+ exec:
+ - ip link add br0 type bridge
+ - ip link set eth1 master br0
+ - ip link set eth2 master br0
+ - ip link set br0 up
+ - ip addr add 10.0.1.10/24 dev br0
+ - ip route replace 10.10.0.0/16 nexthop via 10.0.1.1 nexthop via 10.0.1.2
+ links:
+ - endpoints: ["vyos:eth1", "isp:eth1"]
+ - endpoints: ["azure1:eth1", "isp:eth2"]
+ - endpoints: ["azure2:eth1", "isp:eth3"]
+ - endpoints: ["vyos:eth2", "onprem:eth1"]
+ - endpoints: ["azure1:eth2", "vm:eth1"]
+ - endpoints: ["azure2:eth2", "vm:eth2"]
diff --git a/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml
new file mode 100644
index 0000000..34bee33
--- /dev/null
+++ b/extensions/molecule/ipsec_route_based_bgp_dual/verify.yml
@@ -0,0 +1,47 @@
+---
+- name: Verify both tunnels and BGP sessions
+ hosts: vpn
+ gather_facts: false
+ tasks:
+ - name: Wait for IKE, IPsec and BGP
+ ansible.builtin.pause:
+ seconds: 60
+ run_once: true
+
+ - name: Run role checks
+ ansible.builtin.include_role:
+ name: vyos.blueprints.ipsec_route_based
+ tasks_from: verify
+
+- name: Verify redundancy - traffic survives losing the primary tunnel
+ hosts: r1
+ gather_facts: false
+ vars:
+ _ping: docker exec clab-bp-azure2-onprem ping -c 3 -W 2 10.0.1.10
+ _become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}"
+ tasks:
+ - name: Ping the VNet with both tunnels up
+ ansible.builtin.command: "{{ _ping }}"
+ delegate_to: localhost
+ become: "{{ _become }}"
+ changed_when: false
+
+ - name: Take the primary tunnel down
+ vyos.vyos.vyos_config:
+ lines:
+ - set vpn ipsec site-to-site peer azure-primary disable
+
+ - name: Wait for BGP to converge on the secondary path
+ ansible.builtin.pause:
+ seconds: 40
+
+ - name: Ping the VNet over the secondary tunnel only
+ ansible.builtin.command: "{{ _ping }}"
+ delegate_to: localhost
+ become: "{{ _become }}"
+ changed_when: false
+
+ - name: Bring the primary tunnel back
+ vyos.vyos.vyos_config:
+ lines:
+ - delete vpn ipsec site-to-site peer azure-primary disable