blob: 92b460c5f05af3e2ba4fa82840e36fca6dfab3d2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
|
---
all:
children:
vyos:
children:
vpn:
hosts:
r1:
ansible_host: clab-bp-ipsec-vyos
base_interfaces:
- {name: eth1, addresses: [10.0.1.2/30]}
- {name: eth2, addresses: [192.168.0.1/24]}
ipsec_route_based_peers:
- name: CISCO
local_address: 10.0.1.2
remote_address: 10.0.2.2
psk: molecule-psk
connection_type: initiate
vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438}
ipsec_route_based_ospf:
router_id: 2.2.2.2
networks: [10.100.100.0/30, 192.168.0.0/24]
passive_interfaces: [eth2]
ipsec_route_based_default_gateway: 10.0.1.1
r2:
ansible_host: clab-bp-ipsec-cisco
base_interfaces:
- {name: eth1, addresses: [10.0.2.2/30]}
- {name: eth2, addresses: [192.168.10.1/24]}
ipsec_route_based_peers:
- name: VYOS
local_address: 10.0.2.2
remote_address: 10.0.1.2
psk: molecule-psk
connection_type: none
vti: {interface: vti1, address: 10.100.100.2/30, mtu: 1438}
ipsec_route_based_ospf:
router_id: 1.1.1.1
networks: [10.100.100.0/30, 192.168.10.0/24]
passive_interfaces: [eth2]
ipsec_route_based_default_gateway: 10.0.2.1
vars:
# proposals from the page's IKE and IPsec parameter tables
ipsec_route_based_ike_group:
name: IKE-GROUP
key_exchange: ikev1
lifetime: 28800
dh_group: 14
encryption: aes128
hash: sha1
ipsec_route_based_esp_group:
name: ESP-GROUP
lifetime: 3600
pfs: disable
encryption: aes256
hash: sha256
vars:
ansible_network_os: vyos.vyos.vyos
ansible_connection: ansible.netcommon.network_cli
ansible_user: admin
ansible_password: admin
|