--- all: children: vyos: children: vpn: hosts: r1: ansible_host: clab-bp-ipsec-vyos base_interfaces: - {name: eth1, addresses: [10.0.1.2/30]} - {name: eth2, addresses: [192.168.0.1/24]} ipsec_route_based_peers: - name: CISCO local_address: 10.0.1.2 remote_address: 10.0.2.2 psk: molecule-psk connection_type: initiate vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438} ipsec_route_based_ospf: router_id: 2.2.2.2 networks: [10.100.100.0/30, 192.168.0.0/24] passive_interfaces: [eth2] ipsec_route_based_default_gateway: 10.0.1.1 r2: ansible_host: clab-bp-ipsec-cisco base_interfaces: - {name: eth1, addresses: [10.0.2.2/30]} - {name: eth2, addresses: [192.168.10.1/24]} ipsec_route_based_peers: - name: VYOS local_address: 10.0.2.2 remote_address: 10.0.1.2 psk: molecule-psk connection_type: none vti: {interface: vti1, address: 10.100.100.2/30, mtu: 1438} ipsec_route_based_ospf: router_id: 1.1.1.1 networks: [10.100.100.0/30, 192.168.10.0/24] passive_interfaces: [eth2] ipsec_route_based_default_gateway: 10.0.2.1 vars: # proposals from the page's IKE and IPsec parameter tables ipsec_route_based_ike_group: name: IKE-GROUP key_exchange: ikev1 lifetime: 28800 dh_group: 14 encryption: aes128 hash: sha1 ipsec_route_based_esp_group: name: ESP-GROUP lifetime: 3600 pfs: disable encryption: aes256 hash: sha256 vars: ansible_network_os: vyos.vyos.vyos ansible_connection: ansible.netcommon.network_cli ansible_user: admin ansible_password: admin