diff options
Diffstat (limited to 'extensions/molecule/vrf_firewall/verify.yml')
| -rw-r--r-- | extensions/molecule/vrf_firewall/verify.yml | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/extensions/molecule/vrf_firewall/verify.yml b/extensions/molecule/vrf_firewall/verify.yml new file mode 100644 index 0000000..82989cc --- /dev/null +++ b/extensions/molecule/vrf_firewall/verify.yml @@ -0,0 +1,36 @@ +--- +- name: Verify role state + hosts: vyos + gather_facts: false + tasks: + - name: Run role checks + ansible.builtin.include_role: + name: vyos.blueprints.vrf_firewall + tasks_from: verify + +- name: Verify traffic between VRFs against the page's requirements + hosts: localhost + gather_facts: false + vars: + _flows: + - {from: mgmt, to: 10.150.150.10, allowed: true, why: "MGMT may connect to LAN"} + - {from: mgmt, to: 172.16.20.10, allowed: true, why: "MGMT may connect to PROD"} + - {from: mgmt, to: 203.0.113.100, allowed: false, why: "MGMT may not reach the internet"} + - {from: lan, to: 172.16.20.10, allowed: true, why: "LAN may connect to PROD"} + - {from: lan, to: 203.0.113.100, allowed: true, why: "LAN may reach the internet"} + - {from: lan, to: 10.100.100.10, allowed: false, why: "nothing may connect to MGMT"} + - {from: prod, to: 10.150.150.10, allowed: false, why: "PROD only accepts connections"} + # The page's text says WAN may connect to PROD, but its configuration has + # no rule for it, so the configuration (default drop) is what is tested. + - {from: wan, to: 172.16.20.10, allowed: false, why: "no WAN->PROD rule in the page's configuration"} + tasks: + - name: Ping across VRFs + ansible.builtin.command: + cmd: docker exec clab-bp-vrf-{{ item.from }} ping -c 2 -W 2 {{ item.to }} + become: "{{ lookup('ansible.builtin.env', 'CLAB_BECOME', default='true') | bool }}" + register: _ping + changed_when: false + failed_when: (_ping.rc == 0) != item.allowed + loop: "{{ _flows }}" + loop_control: + label: "{{ item.from }} -> {{ item.to }} ({{ item.why }})" |
