.. _vyos.vyos.vyos_vpn_ipsec_s2s_module:
****************************
vyos.vyos.vyos_vpn_ipsec_s2s
****************************
**Manages IPsec site-to-site VPN peers on VyOS network devices.**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module manages VPN IPsec site-to-site peer configuration on VyOS devices -- policy-based tunnels and route-based (VTI) connections. IKE/ESP groups, PSK/PPK authentication, and IPsec profiles are managed by the separate vyos_vpn_ipsec module; peers here reference those by name.
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
config
dictionary
|
|
IPsec site-to-site configuration.
|
|
peer
list
/ elements=dictionary
|
|
List of site-to-site peers.
|
|
|
authentication
dictionary
|
|
Peer authentication settings.
|
|
|
|
local_id
string
|
|
Local ID for peer authentication.
|
|
|
|
mode
string
|
Choices:
- pre-shared-secret
- rsa
- x509
|
Authentication mode.
|
|
|
|
ppk
dictionary
|
|
Post-quantum preshared key reference for this peer.
|
|
|
|
|
id
string
|
|
Post-quantum preshared key ID for this connection.
|
|
|
|
|
required
boolean
|
|
Require a valid PPK for the connection to establish.
|
|
|
|
remote_id
string
|
|
ID for remote authentication.
|
|
|
|
rsa
dictionary
|
|
RSA key authentication.
|
|
|
|
|
local_key
string
|
|
Name of the PKI key-pair with the local private key.
|
|
|
|
|
passphrase
string
|
|
Local private key passphrase.
|
|
|
|
|
remote_key
string
|
|
Name of the PKI key-pair with the remote public key.
|
|
|
|
use_x509_id
boolean
|
|
Use certificate common name as ID.
|
|
|
|
x509
dictionary
|
|
X.509 certificate authentication.
|
|
|
|
|
ca_certificate
list
/ elements=string
|
|
Certificate Authority chain in PKI configuration.
|
|
|
|
|
certificate
string
|
|
Certificate in PKI configuration.
|
|
|
|
|
passphrase
string
|
|
Private key passphrase.
|
|
|
childless
string
|
Choices:
- allow
- prefer
- force
- never
|
Childless IKE SA initiation support.
|
|
|
connection_type
string
|
Choices:
- initiate
- trap
- none
|
Connection type.
|
|
|
default_esp_group
string
|
|
Default ESP group name for tunnels under this peer that don't specify their own.
|
|
|
description
string
|
|
Description.
|
|
|
dhcp_interface
string
|
|
DHCP interface supplying the next-hop IP address.
|
|
|
disable
boolean
|
|
Disable this peer.
|
|
|
force_udp_encapsulation
boolean
|
|
Force UDP encapsulation.
|
|
|
ike_group
string
|
|
IKE group name.
|
|
|
ikev2_reauth
string
|
|
Re-authentication of the remote peer during an IKE re-key (IKEv2 only).
|
|
|
local_address
string
|
|
IPv4 or IPv6 address of a local interface to use for the VPN, or "any".
|
|
|
name
string
/ required
|
|
Connection name of the peer.
|
|
|
remote_address
list
/ elements=string
|
|
IPv4 or IPv6 address(es) of the remote peer, or "any".
|
|
|
replay_window
integer
|
|
IPsec replay window to configure for this CHILD_SA.
|
|
|
tunnel
list
/ elements=dictionary
|
|
Policy-based tunnel definitions for this peer.
|
|
|
|
disable
boolean
|
|
Disable this tunnel.
|
|
|
|
esp_group
string
|
|
ESP group name for this tunnel (overrides the peer's default_esp_group).
|
|
|
|
local
dictionary
|
|
Local traffic selector for this tunnel.
|
|
|
|
|
port
integer
|
|
Local port to match.
|
|
|
|
|
prefix
list
/ elements=string
|
|
Local IPv4 or IPv6 prefix(es) to match.
|
|
|
|
priority
integer
|
|
Priority for this IPsec policy (lowest value is most preferred).
|
|
|
|
protocol
string
|
|
Protocol to match for this tunnel's traffic selector.
|
|
|
|
remote
dictionary
|
|
Remote traffic selector for this tunnel.
|
|
|
|
|
port
integer
|
|
Remote port to match.
|
|
|
|
|
prefix
list
/ elements=string
|
|
Remote IPv4 or IPv6 prefix(es) to match.
|
|
|
|
tunnel_id
integer
/ required
|
|
The tunnel identifier.
|
|
|
virtual_address
list
/ elements=string
|
|
Initiator-requested virtual address(es) from the peer.
|
|
|
vti
dictionary
|
|
Route-based (VTI) connection settings for this peer.
|
|
|
|
bind
string
|
|
VTI tunnel interface associated with this connection.
|
|
|
|
esp_group
string
|
|
ESP group name for this VTI connection.
|
|
|
|
traffic_selector
dictionary
|
|
Traffic selector for the VTI connection.
|
|
|
|
|
local
dictionary
|
|
Local traffic-selector parameters.
|
|
|
|
|
|
prefix
list
/ elements=string
|
|
Local IPv4 or IPv6 prefix(es).
|
|
|
|
|
remote
dictionary
|
|
Remote traffic-selector parameters.
|
|
|
|
|
|
prefix
list
/ elements=string
|
|
Remote IPv4 or IPv6 prefix(es).
|
|
running_config
string
|
|
This option is used only with state parsed.
The value of this option should be the output received from the VyOS device by executing the command show configuration commands | match "vpn ipsec site-to-site".
The state parsed reads the configuration from the running_config option and transforms it into Ansible structured data as per the resource module's argspec, returned in the parsed key within the result.
|
|
state
string
|
Choices:
merged ←
- replaced
- overridden
- deleted
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|