diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst
index 60f521eb..568dc581 100644
--- a/docs/vyos.vyos.vyos_nat_module.rst
+++ b/docs/vyos.vyos.vyos_nat_module.rst
@@ -1,1661 +1,1676 @@
.. _vyos.vyos.vyos_nat_module:
******************
vyos.vyos.vyos_nat
******************
**NAT resource module**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module manages NAT configuration on devices running Vyos
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
config
dictionary
|
|
The desired configuration for the NAT resource represented as a dictionary.
|
|
cgnat
dictionary
|
|
|
|
|
log_allocation
boolean
|
|
Whether to log CGNAT address allocations.
|
|
|
pool
dictionary
|
|
+ Configuration for CGNAT pools.
|
|
|
|
external
list
/ elements=dictionary
|
|
+ List of external NAT pools for CGNAT.
|
|
|
|
|
external_port_range
string
|
|
Port range to use for NAT translations in this external pool.
|
|
|
|
|
name
string
/ required
|
|
Name of the external NAT pool.
|
|
|
|
|
per_user_limit_port
integer
|
|
Maximum number of ports allocated per user.
|
|
|
|
|
ranges
list
/ elements=string
|
|
List of external IP addresses or prefixes in the pool.
|
|
|
|
internal
list
/ elements=dictionary
|
|
+ List of internal NAT pools for CGNAT.
|
|
|
|
|
name
string
/ required
|
|
Name of the internal NAT pool.
|
|
|
|
|
ranges
list
/ elements=string
|
|
List of internal IP addresses or prefixes in the pool.
|
|
|
rule
list
/ elements=dictionary
|
|
+ List of CGNAT rules.
|
|
|
|
id
integer
/ required
|
|
Rule number for CGNAT.
|
|
|
|
source
dictionary
|
|
+ Source configuration for CGNAT translation.
|
|
|
|
|
pool
string
|
|
Source pool to use for CGNAT translation.
|
|
|
|
translation
dictionary
|
|
+ Translation configuration for CGNAT.
|
|
|
|
|
pool
string
|
|
Translation pool to use for CGNAT translation.
|
|
destination
dictionary
|
|
+ Configuration for destination NAT rules.
|
|
|
rule
list
/ elements=dictionary
|
|
+ List of destination NAT rules.
|
|
|
|
description
string
|
|
User-friendly description of the destination NAT rule.
|
|
|
|
destination
dictionary
|
|
+ Match criteria for destination NAT.
|
|
|
|
|
address
string
|
|
IP address, subnet, or range to match for destination NAT.
|
|
|
|
|
disable
boolean
|
|
Disable this destination NAT rule.
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT.
|
|
|
|
|
fqdn
string
|
|
Fully qualified domain name to match for destination NAT.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this destination NAT rule.
|
|
|
|
|
port
string
|
|
Port number or range for destination NAT, can include named ports or comma-separated lists.
|
|
|
|
|
protocol
string
|
|
Protocol to match (TCP, UDP, ICMP, etc.).
|
|
|
|
id
integer
/ required
|
|
Rule number for destination NAT.
|
|
source
dictionary
|
|
+ Configuration for source NAT rules.
|
|
|
rule
list
/ elements=dictionary
|
|
+ List of source NAT rules.
|
|
|
|
description
string
|
|
User-friendly description of the source NAT rule.
|
|
|
|
destination
dictionary
|
|
+ Match criteria for source NAT.
|
|
|
|
|
address
string
|
|
IP address, subnet, or range to match for source NAT.
|
|
|
|
id
integer
/ required
|
|
Rule number for source NAT.
|
|
static
dictionary
|
|
+ Configuration for static NAT rules.
|
|
|
rule
list
/ elements=dictionary
|
|
+ List of static NAT rules.
|
|
|
|
description
string
|
|
User-friendly description of the static NAT rule.
|
|
|
|
id
integer
/ required
|
|
Rule number for static NAT (one-to-one).
|
|
|
|
inbound_interface
list
/ elements=string
|
|
List of inbound interfaces that this static NAT rule applies to.
|
|
|
|
translation
dictionary
|
|
+ Translation configuration for static NAT.
|
|
|
|
|
address
string
|
|
IP address or prefix to translate to (destination of the static NAT).
|
|
running_config
string
|
|
This option is used only with state parsed.
The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep ntp.
The states replaced and overridden have identical behaviour for this module.
The state parsed reads the configuration from show configuration commands | grep ntp option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
|
|
state
string
|
Choices:
- deleted
merged ←
- overridden
- replaced
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|