summaryrefslogtreecommitdiff
path: root/roles/ipsec_route_based/templates
diff options
context:
space:
mode:
Diffstat (limited to 'roles/ipsec_route_based/templates')
-rw-r--r--roles/ipsec_route_based/templates/bgp_address_family.yml.j220
-rw-r--r--roles/ipsec_route_based/templates/bgp_global.yml.j229
-rw-r--r--roles/ipsec_route_based/templates/interface_routes.yml.j25
-rw-r--r--roles/ipsec_route_based/templates/ospf_interfaces.yml.j212
-rw-r--r--roles/ipsec_route_based/templates/ospfv2.yml.j29
-rw-r--r--roles/ipsec_route_based/templates/vpn_ipsec.yml.j251
-rw-r--r--roles/ipsec_route_based/templates/vpn_ipsec_s2s.yml.j227
-rw-r--r--roles/ipsec_route_based/templates/vti.yml.j29
-rw-r--r--roles/ipsec_route_based/templates/vti_cli.j24
-rw-r--r--roles/ipsec_route_based/templates/vti_l3.yml.j25
10 files changed, 171 insertions, 0 deletions
diff --git a/roles/ipsec_route_based/templates/bgp_address_family.yml.j2 b/roles/ipsec_route_based/templates/bgp_address_family.yml.j2
new file mode 100644
index 0000000..97e88cd
--- /dev/null
+++ b/roles/ipsec_route_based/templates/bgp_address_family.yml.j2
@@ -0,0 +1,20 @@
+{% set b = _ipsec_route_based_bgp %}
+as_number: {{ b.asn | int }}
+{% if b.networks | default([]) %}
+address_family:
+ - afi: ipv4
+ networks:
+{% for n in b.networks %}
+ - prefix: {{ n | to_json }}
+{% endfor %}
+{% endif %}
+{% set soft = b.neighbors | selectattr('soft_reconfiguration_inbound', 'defined') | selectattr('soft_reconfiguration_inbound') | list %}
+{% if soft %}
+neighbors:
+{% for n in soft %}
+ - neighbor_address: {{ n.address | to_json }}
+ address_family:
+ - afi: ipv4
+ soft_reconfiguration: true
+{% endfor %}
+{% endif %}
diff --git a/roles/ipsec_route_based/templates/bgp_global.yml.j2 b/roles/ipsec_route_based/templates/bgp_global.yml.j2
new file mode 100644
index 0000000..f4bcf33
--- /dev/null
+++ b/roles/ipsec_route_based/templates/bgp_global.yml.j2
@@ -0,0 +1,29 @@
+{% set b = _ipsec_route_based_bgp %}
+as_number: {{ b.asn | int }}
+{% if b.router_id is defined %}
+bgp_params:
+ router_id: {{ b.router_id | to_json }}
+{% endif %}
+neighbor:
+{% for n in b.neighbors %}
+ - address: {{ n.address | to_json }}
+ remote_as: {{ n.remote_as | int }}
+{% if n.holdtime is defined or n.keepalive is defined %}
+ timers:
+{% if n.holdtime is defined %}
+ holdtime: {{ n.holdtime | int }}
+{% endif %}
+{% if n.keepalive is defined %}
+ keepalive: {{ n.keepalive | int }}
+{% endif %}
+{% endif %}
+{% if n.disable_connected_check | default(true) | bool %}
+ disable_connected_check: true
+{% endif %}
+{% if n.ebgp_multihop is defined %}
+ ebgp_multihop: {{ n.ebgp_multihop | int }}
+{% endif %}
+{% if n.update_source is defined %}
+ update_source: {{ n.update_source | to_json }}
+{% endif %}
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/interface_routes.yml.j2 b/roles/ipsec_route_based/templates/interface_routes.yml.j2
new file mode 100644
index 0000000..8039e19
--- /dev/null
+++ b/roles/ipsec_route_based/templates/interface_routes.yml.j2
@@ -0,0 +1,5 @@
+{% for r in ipsec_route_based_interface_routes %}
+- dest: {{ r.dest | to_json }}
+ next_hops:
+ - interface: {{ r.interface | to_json }}
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/ospf_interfaces.yml.j2 b/roles/ipsec_route_based/templates/ospf_interfaces.yml.j2
new file mode 100644
index 0000000..09452ea
--- /dev/null
+++ b/roles/ipsec_route_based/templates/ospf_interfaces.yml.j2
@@ -0,0 +1,12 @@
+{% for i in _ipsec_route_based_ospf.passive_interfaces | default([]) %}
+- name: {{ i }}
+ address_family:
+ - afi: ipv4
+ passive: true
+{% endfor %}
+{% for p in ipsec_route_based_peers %}
+- name: {{ p.vti.interface }}
+ address_family:
+ - afi: ipv4
+ network: point-to-point
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/ospfv2.yml.j2 b/roles/ipsec_route_based/templates/ospfv2.yml.j2
new file mode 100644
index 0000000..93ee2ff
--- /dev/null
+++ b/roles/ipsec_route_based/templates/ospfv2.yml.j2
@@ -0,0 +1,9 @@
+{% set o = _ipsec_route_based_ospf %}
+parameters:
+ router_id: {{ o.router_id | to_json }}
+areas:
+ - area_id: {{ o.area | default('0') | string | to_json }}
+ network:
+{% for n in o.networks %}
+ - address: {{ n | to_json }}
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/vpn_ipsec.yml.j2 b/roles/ipsec_route_based/templates/vpn_ipsec.yml.j2
new file mode 100644
index 0000000..a9eab25
--- /dev/null
+++ b/roles/ipsec_route_based/templates/vpn_ipsec.yml.j2
@@ -0,0 +1,51 @@
+{#- Optional settings are rendered only when given. -#}
+{% set ike = ipsec_route_based_ike_group %}
+{% set esp = ipsec_route_based_esp_group %}
+{% set dpd = ike.dead_peer_detection | default({}, true) %}
+ike_group:
+ - name: {{ ike.name | default('IKE-GROUP') | to_json }}
+ key_exchange: {{ ike.key_exchange | default('ikev2') }}
+{% if ike.lifetime is defined and ike.lifetime is not none %}
+ lifetime: {{ ike.lifetime | int }}
+{% endif %}
+{% if ike.close_action is defined and ike.close_action %}
+ close_action: {{ ike.close_action }}
+{% endif %}
+{% if ike.ikev2_reauth | default(false) | bool %}
+ ikev2_reauth: true
+{% endif %}
+{% if dpd %}
+ dead_peer_detection:
+{% for k in ['action', 'interval', 'timeout'] if dpd[k] is defined and dpd[k] is not none %}
+ {{ k }}: {{ dpd[k] }}
+{% endfor %}
+{% endif %}
+ proposal:
+ - proposal_id: {{ ike.proposal_id | default(10) | int }}
+ dh_group: {{ ike.dh_group | default(14) | int }}
+ encryption: {{ ike.encryption | default('aes256') | to_json }}
+ hash: {{ ike.hash | default('sha256') | to_json }}
+esp_group:
+ - name: {{ esp.name | default('ESP-GROUP') | to_json }}
+{% if esp.mode is defined and esp.mode %}
+ mode: {{ esp.mode }}
+{% endif %}
+{% if esp.lifetime is defined and esp.lifetime is not none %}
+ lifetime: {{ esp.lifetime | int }}
+{% endif %}
+{% if esp.pfs is defined and esp.pfs %}
+ pfs: {{ esp.pfs | to_json }}
+{% endif %}
+ proposal:
+ - proposal_id: {{ esp.proposal_id | default(10) | int }}
+ encryption: {{ esp.encryption | default('aes256') | to_json }}
+ hash: {{ esp.hash | default('sha256') | to_json }}
+authentication:
+ psk: {{ _ipsec_route_based_psks | to_json }}
+{% if ipsec_route_based_interfaces %}
+interface: {{ ipsec_route_based_interfaces | to_json }}
+{% endif %}
+{% if ipsec_route_based_disable_route_autoinstall | bool %}
+options:
+ disable_route_autoinstall: true
+{% endif %}
diff --git a/roles/ipsec_route_based/templates/vpn_ipsec_s2s.yml.j2 b/roles/ipsec_route_based/templates/vpn_ipsec_s2s.yml.j2
new file mode 100644
index 0000000..2dba193
--- /dev/null
+++ b/roles/ipsec_route_based/templates/vpn_ipsec_s2s.yml.j2
@@ -0,0 +1,27 @@
+{% set esp_name = ipsec_route_based_esp_group.name | default('ESP-GROUP') %}
+peer:
+{% for p in ipsec_route_based_peers %}
+ - name: {{ p.name | to_json }}
+{% if p.description is defined %}
+ description: {{ p.description | to_json }}
+{% endif %}
+ authentication:
+ mode: pre-shared-secret
+ local_id: {{ p.local_id | default(p.local_address) | to_json }}
+ remote_id: {{ p.remote_id | default(p.remote_address) | to_json }}
+ connection_type: {{ p.connection_type | default('initiate') }}
+{% if not (p.esp_group_on_vti | default(false) | bool) %}
+ default_esp_group: {{ esp_name | to_json }}
+{% endif %}
+ ike_group: {{ ipsec_route_based_ike_group.name | default('IKE-GROUP') | to_json }}
+{% if p.ikev2_reauth is defined %}
+ ikev2_reauth: {{ p.ikev2_reauth | to_json }}
+{% endif %}
+ local_address: {{ p.local_address | to_json }}
+ remote_address: [{{ p.remote_address | to_json }}]
+ vti:
+ bind: {{ p.vti.interface | to_json }}
+{% if p.esp_group_on_vti | default(false) | bool %}
+ esp_group: {{ esp_name | to_json }}
+{% endif %}
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/vti.yml.j2 b/roles/ipsec_route_based/templates/vti.yml.j2
new file mode 100644
index 0000000..2047055
--- /dev/null
+++ b/roles/ipsec_route_based/templates/vti.yml.j2
@@ -0,0 +1,9 @@
+{% for p in ipsec_route_based_peers %}
+- name: {{ p.vti.interface }}
+{% if p.vti.mtu is defined %}
+ mtu: {{ p.vti.mtu | int }}
+{% endif %}
+{% if p.vti.description is defined %}
+ description: {{ p.vti.description | to_json }}
+{% endif %}
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/vti_cli.j2 b/roles/ipsec_route_based/templates/vti_cli.j2
new file mode 100644
index 0000000..8dddeb0
--- /dev/null
+++ b/roles/ipsec_route_based/templates/vti_cli.j2
@@ -0,0 +1,4 @@
+{# MSS clamping on VTIs: vyos_interfaces has no option for it. #}
+{% for p in ipsec_route_based_peers if p.vti.adjust_mss is defined %}
+set interfaces vti {{ p.vti.interface }} ip adjust-mss '{{ p.vti.adjust_mss }}'
+{% endfor %}
diff --git a/roles/ipsec_route_based/templates/vti_l3.yml.j2 b/roles/ipsec_route_based/templates/vti_l3.yml.j2
new file mode 100644
index 0000000..a54b5de
--- /dev/null
+++ b/roles/ipsec_route_based/templates/vti_l3.yml.j2
@@ -0,0 +1,5 @@
+{% for p in ipsec_route_based_peers %}
+- name: {{ p.vti.interface }}
+ ipv4:
+ - address: {{ p.vti.address | to_json }}
+{% endfor %}