diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst
index d22515b5..2bacac84 100644
--- a/docs/vyos.vyos.vyos_nat_module.rst
+++ b/docs/vyos.vyos.vyos_nat_module.rst
@@ -1,2804 +1,2803 @@
.. _vyos.vyos.vyos_nat_module:
******************
vyos.vyos.vyos_nat
******************
**NAT resource module**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module manages NAT configuration on devices running Vyos
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
config
dictionary
|
|
The desired configuration for the NAT resource represented as a dictionary.
|
|
nat
dictionary
|
|
Configuration for NAT rules.
|
|
|
cgnat
dictionary
|
|
Configuration for Carrier Grade NAT (CGNAT).
|
|
|
|
log_allocation
boolean
|
|
Whether to log CGNAT address allocations.
|
|
|
|
pool
dictionary
|
|
Configuration for CGNAT pools.
|
|
|
|
|
external
list
/ elements=dictionary
|
|
List of external NAT pools for CGNAT.
|
|
|
|
|
|
external_port_range
string
|
|
Port range to use for NAT translations in this external pool.
|
|
|
|
|
|
name
string
/ required
|
|
Name of the external NAT pool.
|
|
|
|
|
|
per_user_limit
dictionary
|
|
Per-user limit configuration for the external pool.
|
|
|
|
|
|
|
port
integer
|
|
Maximum number of ports allocated per user.
|
|
|
|
|
|
range
list
/ elements=string
|
|
List of external IP addresses or prefixes in the pool.
|
|
|
|
|
internal
list
/ elements=dictionary
|
|
List of internal NAT pools for CGNAT.
|
|
|
|
|
|
name
string
/ required
|
|
Name of the internal NAT pool.
|
|
|
|
|
|
range
list
/ elements=string
|
|
List of internal IP addresses or prefixes in the pool.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of CGNAT rules.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for CGNAT.
|
|
|
|
|
source
dictionary
|
|
Source configuration for CGNAT translation.
|
|
|
|
|
|
pool
string
|
|
Source pool to use for CGNAT translation.
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for CGNAT.
|
|
|
|
|
|
pool
string
|
|
Translation pool to use for CGNAT translation.
|
|
|
destination
dictionary
|
|
Configuration for destination NAT rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of destination NAT rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the destination NAT rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for destination NAT.
|
|
|
|
|
|
address
string
|
|
IP address, subnet, or range to match for destination NAT.
|
|
|
|
|
|
disable
boolean
|
|
Disable this destination NAT rule.
|
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT.
|
|
|
|
|
|
fqdn
string
|
|
Fully qualified domain name to match for destination NAT.
|
|
|
|
|
|
group
dictionary
|
|
Address/network/port group to match for destination NAT.
|
|
|
|
|
|
|
address_group
string
|
|
Address group name to match.
|
|
|
|
|
|
|
domain_group
string
|
|
Domain group name to match.
|
|
|
|
|
|
|
mac_group
string
|
|
MAC address group name to match.
|
|
|
|
|
|
|
network_group
string
|
|
Network group name to match.
|
|
|
|
|
|
|
port_group
string
|
|
Port group name to match.
|
|
|
|
|
|
log
boolean
|
|
Log packets hitting this destination NAT rule.
|
|
|
|
|
|
port
string
|
|
Port number or range for destination NAT.
|
|
|
|
|
|
protocol
string
|
|
Protocol to match (TCP, UDP, ICMP, etc.).
|
|
|
|
|
id
integer
/ required
|
|
Rule number for destination NAT.
|
|
|
source
dictionary
|
|
Configuration for source NAT rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of source NAT rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the source NAT rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for source NAT.
|
|
|
|
|
|
address
string
|
|
IP address, subnet, or range to match for source NAT.
|
|
|
|
|
|
disable
boolean
|
|
Disable this source NAT rule.
|
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT.
|
|
|
|
|
|
fqdn
string
|
|
Fully qualified domain name to match for source NAT.
|
|
|
|
|
|
group
dictionary
|
|
Address/network/port group to match for source NAT.
|
|
|
|
|
|
|
address_group
string
|
|
Address group name to match.
|
|
|
|
|
|
|
domain_group
string
|
|
Domain group name to match.
|
|
|
|
|
|
|
mac_group
string
|
|
MAC address group name to match.
|
|
|
|
|
|
|
network_group
string
|
|
Network group name to match.
|
|
|
|
|
|
|
port_group
string
|
|
Port group name to match.
|
|
|
|
|
|
log
boolean
|
|
Log packets hitting this source NAT rule.
|
|
|
|
|
|
port
string
|
|
Port number or range for source NAT.
|
|
|
|
|
|
protocol
string
|
|
Protocol to match (TCP, UDP, ICMP, etc.).
|
|
|
|
|
id
integer
/ required
|
|
Rule number for source NAT.
|
|
|
static
dictionary
|
|
Configuration for static NAT rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of static NAT rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the static NAT rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for static NAT.
|
|
|
|
|
|
address
string
|
|
IP address, subnet, or range to match for static NAT.
|
|
|
|
|
disable
boolean
|
|
Disable this static NAT rule.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for static NAT (one-to-one).
|
|
|
|
|
inbound_interface
- list
- / elements=string
+ string
|
|
List of inbound interfaces that this static NAT rule applies to.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this static NAT rule.
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for static NAT.
|
|
|
|
|
|
address
string
|
|
IP address or prefix to translate to.
|
|
nat64
dictionary
|
|
Configuration for NAT64 (IPv6-to-IPv4 NAT) rules.
|
|
|
source
dictionary
|
|
Configuration for NAT64 source rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT64 source rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT64 source rule.
|
|
|
|
|
disable
boolean
|
|
Disable this NAT64 source rule.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for NAT64 source rule.
|
|
|
|
|
match
dictionary
|
|
Match criteria for NAT64 source rule.
|
|
|
|
|
|
mark
integer
|
|
Match on firewall mark value (1-2147483647).
|
|
|
|
|
source
dictionary
|
|
Source prefix to match for NAT64 translation.
|
|
|
|
|
|
prefix
string
|
|
IPv6 source prefix to match (h:h:h:h:h:h:h:h/x).
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT64 source rule.
|
|
|
|
|
|
pool
list
/ elements=dictionary
|
|
List of translation pools for NAT64.
|
|
|
|
|
|
|
address
string
|
|
IPv4 address or prefix for translation pool.
|
|
|
|
|
|
|
description
string
|
|
User-friendly description of the translation pool.
|
|
|
|
|
|
|
disable
boolean
|
|
Disable this translation pool.
|
|
|
|
|
|
|
id
integer
/ required
|
|
Pool number (1-999999).
|
|
|
|
|
|
|
port
string
|
|
Port number or range for translation pool.
|
|
|
|
|
|
|
protocol
string
|
|
Protocol for this translation pool entry.
|
|
nat66
dictionary
|
|
Configuration for NAT66 (IPv6-to-IPv6 NAT) rules.
|
|
|
destination
dictionary
|
|
Configuration for NAT66 destination rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT66 destination rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT66 destination rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
IPv6 address or prefix to match. Supports single address (h:h:h:h:h:h:h:h), prefix (h:h:h:h:h:h:h:h/x), and negated forms (!h:h:h:h:h:h:h:h, !h:h:h:h:h:h:h:h/x).
|
|
|
|
|
|
port
string
|
|
Port number, range, or name to match.
|
|
|
|
|
disable
boolean
|
|
Disable this NAT66 destination rule.
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT66.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for NAT66 destination rule.
|
|
|
|
|
inbound_interface
dictionary
|
|
Inbound interface to match for NAT66 destination rule.
|
|
|
|
|
|
name
string
|
|
Interface name to match. Supports wildcard (txt*) and negated (!text) forms.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this NAT66 destination rule.
|
|
|
|
|
protocol
string
|
|
Protocol to match. Supports named protocols, numeric (0-255), negated (!protocol), all, and tcp_udp.
|
|
|
|
|
source
dictionary
|
|
Source match criteria for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
IPv6 source address or prefix to match. Supports single address, prefix, and negated forms.
|
|
|
|
|
|
port
string
|
|
Source port number, range, or name to match.
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
IPv6 address or prefix to translate destination to.
|
|
|
|
|
|
port
string
|
|
Port number or range to translate destination port to.
|
|
|
source
dictionary
|
|
Configuration for NAT66 source rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT66 source rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT66 source rule.
|
|
|
|
|
destination
dictionary
|
|
Destination match criteria for NAT66 source rule.
|
|
|
|
|
|
port
string
|
|
Destination port number, range, or name to match.
|
|
|
|
|
|
prefix
string
|
|
IPv6 destination prefix to match (h:h:h:h:h:h:h:h/x). Supports negated form (!h:h:h:h:h:h:h:h/x).
|
|
|
|
|
disable
boolean
|
|
Disable this NAT66 source rule.
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT66.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for NAT66 source rule.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this NAT66 source rule.
|
|
|
|
|
outbound_interface
dictionary
|
|
Outbound interface to match for NAT66 source rule.
|
|
|
|
|
|
name
string
|
|
Interface name to match. Supports wildcard (txt*) and negated (!text) forms.
|
|
|
|
|
protocol
string
|
|
Protocol to match. Supports named protocols, numeric (0-255), negated (!protocol), all, and tcp_udp.
|
|
|
|
|
source
dictionary
|
|
Source match criteria for NAT66 source rule.
|
|
|
|
|
|
port
string
|
|
Source port number, range, or name to match.
|
|
|
|
|
|
prefix
string
|
|
IPv6 source prefix to match (h:h:h:h:h:h:h:h/x). Supports negated form (!h:h:h:h:h:h:h:h/x).
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT66 source rule.
|
|
|
|
|
|
address
string
|
|
IPv6 address or prefix to translate source to. Use masquerade to masquerade as the outbound interface address.
|
|
|
|
|
|
port
string
|
|
Port number or range to translate source port to.
|
|
running_config
string
|
|
This option is used only with state parsed.
The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep nat.
The states replaced and overridden have identical behaviour for this module.
The state parsed reads the configuration from show configuration commands | grep nat option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
|
|
state
string
|
Choices:
- deleted
merged ←
- overridden
- replaced
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|