summaryrefslogtreecommitdiff
path: root/tests/render/cases/vrf_firewall/docs_four_vrfs
diff options
context:
space:
mode:
Diffstat (limited to 'tests/render/cases/vrf_firewall/docs_four_vrfs')
-rw-r--r--tests/render/cases/vrf_firewall/docs_four_vrfs/expected/r1.txt53
-rw-r--r--tests/render/cases/vrf_firewall/docs_four_vrfs/vars.yml43
2 files changed, 96 insertions, 0 deletions
diff --git a/tests/render/cases/vrf_firewall/docs_four_vrfs/expected/r1.txt b/tests/render/cases/vrf_firewall/docs_four_vrfs/expected/r1.txt
new file mode 100644
index 0000000..62951c9
--- /dev/null
+++ b/tests/render/cases/vrf_firewall/docs_four_vrfs/expected/r1.txt
@@ -0,0 +1,53 @@
+set firewall global-options state-policy established action 'accept'
+set firewall global-options state-policy invalid action 'drop'
+set firewall global-options state-policy related action 'accept'
+set firewall ipv4 forward filter default-action 'drop'
+set firewall ipv4 forward filter default-log
+set firewall ipv4 forward filter rule 10
+set firewall ipv4 forward filter rule 10 action 'accept'
+set firewall ipv4 forward filter rule 10 description 'MGMT - Allow to LAN and PROD'
+set firewall ipv4 forward filter rule 10 inbound-interface name MGMT
+set firewall ipv4 forward filter rule 10 outbound-interface name eth2*
+set firewall ipv4 forward filter rule 120
+set firewall ipv4 forward filter rule 120 action 'accept'
+set firewall ipv4 forward filter rule 120 description 'LAN - Allow to PROD'
+set firewall ipv4 forward filter rule 120 inbound-interface name LAN
+set firewall ipv4 forward filter rule 120 outbound-interface name eth2.3500
+set firewall ipv4 forward filter rule 130
+set firewall ipv4 forward filter rule 130 action 'accept'
+set firewall ipv4 forward filter rule 130 description 'LAN - Allow internet'
+set firewall ipv4 forward filter rule 130 inbound-interface name LAN
+set firewall ipv4 forward filter rule 130 outbound-interface name pppoe0
+set firewall ipv4 forward filter rule 99
+set firewall ipv4 forward filter rule 99 action 'drop'
+set firewall ipv4 forward filter rule 99 description 'MGMT - Drop all going to mgmt'
+set firewall ipv4 forward filter rule 99 outbound-interface name eth1
+set firewall ipv4 input filter default-action 'drop'
+set firewall ipv4 input filter default-log
+set firewall ipv4 input filter rule 10
+set firewall ipv4 input filter rule 10 action 'accept'
+set firewall ipv4 input filter rule 10 description 'MGMT - Allow input'
+set firewall ipv4 input filter rule 10 inbound-interface name MGMT
+set interfaces ethernet eth1 vrf 'MGMT'
+set interfaces ethernet eth2 vif 150 vrf 'LAN'
+set interfaces ethernet eth2 vif 160 vrf 'LAN'
+set interfaces ethernet eth2 vif 3500 vrf 'PROD'
+set interfaces pppoe pppoe0 vrf 'WAN'
+set vrf bind-to-all
+set vrf name LAN protocols static route 0.0.0.0/0 interface pppoe0 vrf 'WAN'
+set vrf name LAN protocols static route 10.100.100.0/24 interface eth1 vrf 'MGMT'
+set vrf name LAN protocols static route 172.16.20.0/24 interface eth2.3500 vrf 'PROD'
+set vrf name LAN table 103
+set vrf name MGMT protocols static route 10.150.150.0/24 interface eth2.150 vrf 'LAN'
+set vrf name MGMT protocols static route 10.160.160.0/24 interface eth2.160 vrf 'LAN'
+set vrf name MGMT protocols static route 172.16.20.0/24 interface eth2.3500 vrf 'PROD'
+set vrf name MGMT table 102
+set vrf name PROD protocols static route 0.0.0.0/0 interface pppoe0 vrf 'WAN'
+set vrf name PROD protocols static route 10.100.100.0/24 interface eth1 vrf 'MGMT'
+set vrf name PROD protocols static route 10.150.150.0/24 interface eth2.150 vrf 'LAN'
+set vrf name PROD protocols static route 10.160.160.0/24 interface eth2.160 vrf 'LAN'
+set vrf name PROD table 104
+set vrf name WAN protocols static route 10.150.150.0/24 interface eth2.150 vrf 'LAN'
+set vrf name WAN protocols static route 10.160.160.0/24 interface eth2.160 vrf 'LAN'
+set vrf name WAN protocols static route 172.16.20.0/24 interface eth2.3500 vrf 'PROD'
+set vrf name WAN table 101
diff --git a/tests/render/cases/vrf_firewall/docs_four_vrfs/vars.yml b/tests/render/cases/vrf_firewall/docs_four_vrfs/vars.yml
new file mode 100644
index 0000000..38626df
--- /dev/null
+++ b/tests/render/cases/vrf_firewall/docs_four_vrfs/vars.yml
@@ -0,0 +1,43 @@
+---
+# docs.vyos.io/en/1.5/configexamples/fwall-and-vrf.html
+# Interface addresses and the PPPoE interface itself are outside this role
+# (base role / a later PPPoE role); everything else is from the page.
+vrf_firewall_vrfs:
+ - name: MGMT
+ table: 102
+ interfaces: [eth1]
+ routes:
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: WAN
+ table: 101
+ interfaces: [pppoe0]
+ routes:
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: LAN
+ table: 103
+ interfaces: [eth2.150, eth2.160]
+ routes:
+ - {dest: 0.0.0.0/0, interface: pppoe0, vrf: WAN}
+ - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT}
+ - {dest: 172.16.20.0/24, interface: eth2.3500, vrf: PROD}
+ - name: PROD
+ table: 104
+ interfaces: [eth2.3500]
+ routes:
+ - {dest: 0.0.0.0/0, interface: pppoe0, vrf: WAN}
+ - {dest: 10.100.100.0/24, interface: eth1, vrf: MGMT}
+ - {dest: 10.150.150.0/24, interface: eth2.150, vrf: LAN}
+ - {dest: 10.160.160.0/24, interface: eth2.160, vrf: LAN}
+
+vrf_firewall_forward_rules:
+ - {number: 10, description: MGMT - Allow to LAN and PROD, inbound_interface: MGMT, outbound_interface: eth2*}
+ - {number: 99, action: drop, description: MGMT - Drop all going to mgmt, outbound_interface: eth1}
+ - {number: 120, description: LAN - Allow to PROD, inbound_interface: LAN, outbound_interface: eth2.3500}
+ - {number: 130, description: LAN - Allow internet, inbound_interface: LAN, outbound_interface: pppoe0}
+
+vrf_firewall_input_rules:
+ - {number: 10, description: MGMT - Allow input, inbound_interface: MGMT}