From 899a6bf7955592ec40670944a860a1bee97b432c Mon Sep 17 00:00:00 2001
From: omnom62 <75066712+omnom62@users.noreply.github.com>
Date: Fri, 21 Aug 2026 22:12:11 +1000
Subject: T8321: vpn_ipsec modules (#489)
Add VPN IPsec module
---
docs/vyos.vyos.vyos_vpn_ipsec_module.rst | 1553 ++++++++++++++++++++++++++
docs/vyos.vyos.vyos_vpn_ipsec_s2s_module.rst | 1232 ++++++++++++++++++++
2 files changed, 2785 insertions(+)
create mode 100644 docs/vyos.vyos.vyos_vpn_ipsec_module.rst
create mode 100644 docs/vyos.vyos.vyos_vpn_ipsec_s2s_module.rst
(limited to 'docs')
diff --git a/docs/vyos.vyos.vyos_vpn_ipsec_module.rst b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst
new file mode 100644
index 00000000..79ca84b8
--- /dev/null
+++ b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst
@@ -0,0 +1,1553 @@
+.. _vyos.vyos.vyos_vpn_ipsec_module:
+
+
+************************
+vyos.vyos.vyos_vpn_ipsec
+************************
+
+**Manages global IPsec (ike-group, esp-group, profile, authentication, options) attributes of VyOS network devices.**
+
+
+Version added: 1.0.0
+
+.. contents::
+ :local:
+ :depth: 1
+
+
+Synopsis
+--------
+- This module manages global VPN IPsec configuration on VyOS devices -- IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules.
+
+
+
+
+Parameters
+----------
+
+.. raw:: html
+
+
+
+ | Parameter |
+ Choices/Defaults |
+ Comments |
+
+
+ |
+
+ config
+
+
+ dictionary
+
+ |
+
+ |
+
+ IPsec global configuration.
+ |
+
+
+ |
+
+
+ authentication
+
+
+ dictionary
+
+ |
+
+ |
+
+ Global pre-shared-key and post-quantum pre-shared-key definitions.
+ |
+
+
+ |
+ |
+
+
+ ppk
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of post-quantum pre-shared keys.
+ |
+
+
+ |
+ |
+ |
+
+
+ id
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ ID(s) for PPK.
+ |
+
+
+ |
+ |
+ |
+
+
+ name
+
+
+ string
+ / required
+
+ |
+
+ |
+
+ Post-quantum pre-shared key name.
+ |
+
+
+ |
+ |
+ |
+
+
+ secret
+
+
+ string
+
+ |
+
+ |
+
+ Post-quantum pre-shared secret key.
+ |
+
+
+ |
+ |
+ |
+
+
+ secret_type
+
+
+ string
+
+ |
+
+ Choices:
+ - base64
+ - hex
+ - plaintext
+
+ |
+
+ Secret encoding type.
+ |
+
+
+
+ |
+ |
+
+
+ psk
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of pre-shared keys.
+ |
+
+
+ |
+ |
+ |
+
+
+ dhcp_interface
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ DHCP interface(s) supplying next-hop IP address.
+ |
+
+
+ |
+ |
+ |
+
+
+ id
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ ID(s) for authentication.
+ |
+
+
+ |
+ |
+ |
+
+
+ name
+
+
+ string
+ / required
+
+ |
+
+ |
+
+ Pre-shared key name.
+ |
+
+
+ |
+ |
+ |
+
+
+ secret
+
+
+ string
+
+ |
+
+ |
+
+ IKE pre-shared secret key.
+ |
+
+
+ |
+ |
+ |
+
+
+ secret_type
+
+
+ string
+
+ |
+
+ Choices:
+ - base64
+ - hex
+ - plaintext
+
+ |
+
+ Secret encoding type.
+ |
+
+
+
+
+ |
+
+
+ disable_uniqreqids
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Disable requirement for unique IDs in the Security Database.
+ |
+
+
+ |
+
+
+ esp_group
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of ESP groups.
+ |
+
+
+ |
+ |
+
+
+ compression
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Enable ESP compression.
+ |
+
+
+ |
+ |
+
+
+ disable_rekey
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Do not locally initiate a re-key of the SA; remote peer must re-key before expiration.
+ |
+
+
+ |
+ |
+
+
+ life_bytes
+
+
+ integer
+
+ |
+
+ |
+
+ Security Association byte count to expire.
+ |
+
+
+ |
+ |
+
+
+ life_packets
+
+
+ integer
+
+ |
+
+ |
+
+ Security Association packet count to expire.
+ |
+
+
+ |
+ |
+
+
+ lifetime
+
+
+ integer
+
+ |
+
+ |
+
+ Security Association time to expire, in seconds.
+ |
+
+
+ |
+ |
+
+
+ mode
+
+
+ string
+
+ |
+
+ Choices:
+ - tunnel
+ - transport
+
+ |
+
+ ESP mode.
+ |
+
+
+ |
+ |
+
+
+ name
+
+
+ string
+ / required
+
+ |
+
+ |
+
+ The name of the ESP group.
+ |
+
+
+ |
+ |
+
+
+ pfs
+
+
+ string
+
+ |
+
+ |
+
+ ESP Perfect Forward Secrecy. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
+ |
+
+
+ |
+ |
+
+
+ proposal
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of ESP proposals.
+ |
+
+
+ |
+ |
+ |
+
+
+ encryption
+
+
+ string
+
+ |
+
+ |
+
+ Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
+ |
+
+
+ |
+ |
+ |
+
+
+ hash
+
+
+ string
+
+ |
+
+ |
+
+ Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
+ |
+
+
+ |
+ |
+ |
+
+
+ proposal_id
+
+
+ integer
+
+ |
+
+ |
+
+ The proposal identifier.
+ |
+
+
+
+
+ |
+
+
+ ike_group
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of IKE groups.
+ |
+
+
+ |
+ |
+
+
+ close_action
+
+
+ string
+
+ |
+
+ Choices:
+ - none
+ - trap
+ - start
+
+ |
+
+ Action to take if a child SA is unexpectedly closed.
+ |
+
+
+ |
+ |
+
+
+ dead_peer_detection
+
+
+ dictionary
+
+ |
+
+ |
+
+ Dead Peer Detection (DPD).
+ |
+
+
+ |
+ |
+ |
+
+
+ action
+
+
+ string
+
+ |
+
+ Choices:
+ - trap
+ - clear
+ - restart
+
+ |
+
+ Keep-alive failure action.
+ |
+
+
+ |
+ |
+ |
+
+
+ interval
+
+
+ integer
+
+ |
+
+ |
+
+ Keep-alive interval in seconds.
+ |
+
+
+ |
+ |
+ |
+
+
+ timeout
+
+
+ integer
+
+ |
+
+ |
+
+ Dead Peer Detection keep-alive timeout (IKEv1 only), in seconds.
+ |
+
+
+
+ |
+ |
+
+
+ disable_mobike
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Disable MOBIKE support (IKEv2 only).
+ |
+
+
+ |
+ |
+
+
+ ikev2_reauth
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Re-authentication of the remote peer during an IKE re-key (IKEv2 only).
+ |
+
+
+ |
+ |
+
+
+ key_exchange
+
+
+ string
+
+ |
+
+ Choices:
+ - ikev1
+ - ikev2
+
+ |
+
+ IKE version.
+ |
+
+
+ |
+ |
+
+
+ lifetime
+
+
+ integer
+
+ |
+
+ |
+
+ IKE lifetime in seconds.
+ |
+
+
+ |
+ |
+
+
+ mode
+
+
+ string
+
+ |
+
+ Choices:
+ - main
+ - aggressive
+
+ |
+
+ IKEv1 phase 1 mode.
+ |
+
+
+ |
+ |
+
+
+ name
+
+
+ string
+ / required
+
+ |
+
+ |
+
+ The name of the IKE group.
+ |
+
+
+ |
+ |
+
+
+ proposal
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of IKE proposals.
+ |
+
+
+ |
+ |
+ |
+
+
+ dh_group
+
+
+ integer
+
+ |
+
+ |
+
+ Diffie-Hellman group. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
+ |
+
+
+ |
+ |
+ |
+
+
+ encryption
+
+
+ string
+
+ |
+
+ |
+
+ Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
+ |
+
+
+ |
+ |
+ |
+
+
+ hash
+
+
+ string
+
+ |
+
+ |
+
+ Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
+ |
+
+
+ |
+ |
+ |
+
+
+ prf
+
+
+ string
+
+ |
+
+ |
+
+ Pseudo-Random Function. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
+ |
+
+
+ |
+ |
+ |
+
+
+ proposal_id
+
+
+ integer
+
+ |
+
+ |
+
+ The proposal identifier.
+ |
+
+
+
+
+ |
+
+
+ interface
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ Interface(s) IPsec listens on. If omitted, listens on all interfaces.
+ |
+
+
+ |
+
+
+ log
+
+
+ dictionary
+
+ |
+
+ |
+
+ IPsec logging settings.
+ |
+
+
+ |
+ |
+
+
+ level
+
+
+ integer
+
+ |
+
+ |
+
+ Global IPsec logging level.
+ |
+
+
+ |
+ |
+
+
+ subsystem
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ Per-subsystem logging levels to enable.
+ |
+
+
+
+ |
+
+
+ options
+
+
+ dictionary
+
+ |
+
+ |
+
+ Global IPsec options.
+ |
+
+
+ |
+ |
+
+
+ disable_route_autoinstall
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Do not automatically install routes to remote networks.
+ |
+
+
+ |
+ |
+
+
+ flexvpn
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Allow FlexVPN vendor ID payload (IKEv2 only).
+ |
+
+
+ |
+ |
+
+
+ interface
+
+
+ string
+
+ |
+
+ |
+
+ Single interface for IPsec options scope (distinct from top-level interface list).
+ |
+
+
+ |
+ |
+
+
+ retransmission
+
+
+ dictionary
+
+ |
+
+ |
+
+ IPsec retransmission settings.
+ |
+
+
+ |
+ |
+ |
+
+
+ attempts
+
+
+ integer
+
+ |
+
+ |
+
+ Maximum number of retransmissions.
+ |
+
+
+ |
+ |
+ |
+
+
+ base
+
+
+ float
+
+ |
+
+ |
+
+ Base of exponential backoff.
+ |
+
+
+ |
+ |
+ |
+
+
+ timeout
+
+
+ integer
+
+ |
+
+ |
+
+ Timeout in seconds before the first retransmission.
+ |
+
+
+
+ |
+ |
+
+
+ virtual_ip
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Allow install of virtual-ip addresses.
+ |
+
+
+
+ |
+
+
+ profile
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of VPN IPsec profiles (used for e.g. DMVPN/GRE tunnel binding).
+ |
+
+
+ |
+ |
+
+
+ authentication
+
+
+ dictionary
+
+ |
+
+ |
+
+ Authentication settings for this profile.
+ |
+
+
+ |
+ |
+ |
+
+
+ mode
+
+
+ string
+
+ |
+
+ Choices:
+ - pre-shared-secret
+
+ |
+
+ Authentication mode.
+ |
+
+
+ |
+ |
+ |
+
+
+ pre_shared_secret
+
+
+ string
+
+ |
+
+ |
+
+ Pre-shared secret key.
+ |
+
+
+
+ |
+ |
+
+
+ bind_tunnel
+
+
+ list
+ / elements=string
+
+ |
+
+ |
+
+ Tunnel interface(s) associated with this profile.
+ |
+
+
+ |
+ |
+
+
+ disable
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Disable this profile.
+ |
+
+
+ |
+ |
+
+
+ esp_group
+
+
+ string
+
+ |
+
+ |
+
+ ESP group name to use for this profile.
+ |
+
+
+ |
+ |
+
+
+ ike_group
+
+
+ string
+
+ |
+
+ |
+
+ IKE group name to use for this profile.
+ |
+
+
+ |
+ |
+
+
+ name
+
+
+ string
+ / required
+
+ |
+
+ |
+
+ Profile name.
+ |
+
+
+
+
+ |
+
+ running_config
+
+
+ string
+
+ |
+
+ |
+
+ This option is used only with state parsed.
+ The value of this option should be the output received from the VyOS device by executing the command show configuration commands | match "vpn ipsec".
+ The states replaced and overridden have identical behaviour for this module with respect to named collections (ike_group, esp_group, profile, authentication), but differ in scope -- see the module description for detail.
+ The state parsed reads the configuration from the running_config option and transforms it into Ansible structured data as per the resource module's argspec, returned in the parsed key within the result.
+ |
+
+
+ |
+
+ state
+
+
+ string
+
+ |
+
+ Choices:
+ merged ←
+ - replaced
+ - overridden
+ - deleted
+ - gathered
+ - rendered
+ - parsed
+
+ |
+
+ The state the configuration should be left in.
+ |
+
+
+