diff --git a/docs/vyos.vyos.vyos_vpn_ipsec_module.rst b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst index 68c3d384..9bc46ac5 100644 --- a/docs/vyos.vyos.vyos_vpn_ipsec_module.rst +++ b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst @@ -1,1779 +1,1573 @@ .. _vyos.vyos.vyos_vpn_ipsec_module: ************************ vyos.vyos.vyos_vpn_ipsec ************************ **Manages global IPsec (ike-group, esp-group, profile, authentication, options) attributes of VyOS network devices.** Version added: 6.2.0 .. contents:: :local: :depth: 1 Synopsis -------- -- This module manages global VPN IPsec configuration on VyOS devices — IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules. +- This module manages global VPN IPsec configuration on VyOS devices -- IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules. Parameters ---------- .. raw:: html + + + + +
Parameter Choices/Defaults Comments
config
dictionary
IPsec global configuration.
authentication
dictionary
Global pre-shared-key and post-quantum pre-shared-key definitions.
ppk
list / elements=dictionary
List of post-quantum pre-shared keys.
id
list / elements=string
ID(s) for PPK.
name
string / required
Post-quantum pre-shared key name.
secret
string
Post-quantum pre-shared secret key.
secret_type
string
    Choices:
  • base64
  • hex
  • plaintext
Secret encoding type.
psk
list / elements=dictionary
List of pre-shared keys.
dhcp_interface
list / elements=string
DHCP interface(s) supplying next-hop IP address.
id
list / elements=string
ID(s) for authentication.
name
string / required
Pre-shared key name.
secret
string
IKE pre-shared secret key.
secret_type
string
    Choices:
  • base64
  • hex
  • plaintext
Secret encoding type.
disable_uniqreqids
boolean
    Choices:
  • no
  • yes
Disable requirement for unique IDs in the Security Database.
esp_group
list / elements=dictionary
List of ESP groups.
compression
boolean
    Choices:
  • no
  • yes
Enable ESP compression.
disable_rekey
boolean
    Choices:
  • no
  • yes
Do not locally initiate a re-key of the SA; remote peer must re-key before expiration.
life_bytes
integer
Security Association byte count to expire.
life_packets
integer
Security Association packet count to expire.
lifetime
integer
Security Association time to expire, in seconds.
mode
string
    Choices:
  • tunnel
  • transport
ESP mode.
name
string / required
The name of the ESP group.
pfs
string
-
    Choices: -
  • enable
  • -
  • disable
  • -
  • dh-group1
  • -
  • dh-group2
  • -
  • dh-group5
  • -
  • dh-group14
  • -
  • dh-group15
  • -
  • dh-group16
  • -
  • dh-group17
  • -
  • dh-group18
  • -
  • dh-group19
  • -
  • dh-group20
  • -
  • dh-group21
  • -
  • dh-group22
  • -
  • dh-group23
  • -
  • dh-group24
  • -
  • dh-group25
  • -
  • dh-group26
  • -
  • dh-group27
  • -
  • dh-group28
  • -
  • dh-group29
  • -
  • dh-group30
  • -
  • dh-group31
  • -
  • dh-group32
  • -
-
ESP Perfect Forward Secrecy.
+
ESP Perfect Forward Secrecy. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
proposal
list / elements=dictionary
List of ESP proposals.
encryption
string
-
    Choices: -
  • null
  • -
  • aes128
  • -
  • aes192
  • -
  • aes256
  • -
  • aes128ctr
  • -
  • aes192ctr
  • -
  • aes256ctr
  • -
  • aes128ccm64
  • -
  • aes192ccm64
  • -
  • aes256ccm64
  • -
  • aes128ccm96
  • -
  • aes192ccm96
  • -
  • aes256ccm96
  • -
  • aes128ccm128
  • -
  • aes192ccm128
  • -
  • aes256ccm128
  • -
  • aes128gcm64
  • -
  • aes192gcm64
  • -
  • aes256gcm64
  • -
  • aes128gcm96
  • -
  • aes192gcm96
  • -
  • aes256gcm96
  • -
  • aes128gcm128
  • -
  • aes192gcm128
  • -
  • aes256gcm128
  • -
  • aes128gmac
  • -
  • aes192gmac
  • -
  • aes256gmac
  • -
  • 3des
  • -
  • blowfish128
  • -
  • blowfish192
  • -
  • blowfish256
  • -
  • camellia128
  • -
  • camellia192
  • -
  • camellia256
  • -
  • camellia128ctr
  • -
  • camellia192ctr
  • -
  • camellia256ctr
  • -
  • camellia128ccm64
  • -
  • camellia192ccm64
  • -
  • camellia256ccm64
  • -
  • camellia128ccm96
  • -
  • camellia192ccm96
  • -
  • camellia256ccm96
  • -
  • camellia128ccm128
  • -
  • camellia192ccm128
  • -
  • camellia256ccm128
  • -
  • serpent128
  • -
  • serpent192
  • -
  • serpent256
  • -
  • twofish128
  • -
  • twofish192
  • -
  • twofish256
  • -
  • cast128
  • -
  • chacha20poly1305
  • -
-
Encryption algorithm.
+
Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
hash
string
-
    Choices: -
  • md5
  • -
  • md5_128
  • -
  • sha1
  • -
  • sha1_160
  • -
  • sha256
  • -
  • sha256_96
  • -
  • sha384
  • -
  • sha512
  • -
  • aesxcbc
  • -
  • aescmac
  • -
  • aes128gmac
  • -
  • aes192gmac
  • -
  • aes256gmac
  • -
-
Hash algorithm.
+
Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
proposal_id
integer
The proposal identifier.
ike_group
list / elements=dictionary
List of IKE groups.
close_action
string
    Choices:
  • none
  • trap
  • start
Action to take if a child SA is unexpectedly closed.
dead_peer_detection
dictionary
Dead Peer Detection (DPD).
action
string
    Choices:
  • trap
  • clear
  • restart
Keep-alive failure action.
interval
integer
Keep-alive interval in seconds.
timeout
integer
Dead Peer Detection keep-alive timeout (IKEv1 only), in seconds.
disable_mobike
boolean
    Choices:
  • no
  • yes
Disable MOBIKE support (IKEv2 only).
ikev2_reauth
boolean
    Choices:
  • no
  • yes
Re-authentication of the remote peer during an IKE re-key (IKEv2 only).
key_exchange
string
    Choices:
  • ikev1
  • ikev2
IKE version.
lifetime
integer
IKE lifetime in seconds.
mode
string
    Choices:
  • main
  • aggressive
IKEv1 phase 1 mode.
name
string / required
The name of the IKE group.
proposal
list / elements=dictionary
List of IKE proposals.
dh_group
integer
-
    Choices: -
  • 1
  • -
  • 2
  • -
  • 5
  • -
  • 14
  • -
  • 15
  • -
  • 16
  • -
  • 17
  • -
  • 18
  • -
  • 19
  • -
  • 20
  • -
  • 21
  • -
  • 22
  • -
  • 23
  • -
  • 24
  • -
  • 25
  • -
  • 26
  • -
  • 27
  • -
  • 28
  • -
  • 29
  • -
  • 30
  • -
  • 31
  • -
  • 32
  • -
-
Diffie-Hellman group.
+
Diffie-Hellman group. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
encryption
string
-
    Choices: -
  • null
  • -
  • aes128
  • -
  • aes192
  • -
  • aes256
  • -
  • aes128ctr
  • -
  • aes192ctr
  • -
  • aes256ctr
  • -
  • aes128ccm64
  • -
  • aes192ccm64
  • -
  • aes256ccm64
  • -
  • aes128ccm96
  • -
  • aes192ccm96
  • -
  • aes256ccm96
  • -
  • aes128ccm128
  • -
  • aes192ccm128
  • -
  • aes256ccm128
  • -
  • aes128gcm64
  • -
  • aes192gcm64
  • -
  • aes256gcm64
  • -
  • aes128gcm96
  • -
  • aes192gcm96
  • -
  • aes256gcm96
  • -
  • aes128gcm128
  • -
  • aes192gcm128
  • -
  • aes256gcm128
  • -
  • aes128gmac
  • -
  • aes192gmac
  • -
  • aes256gmac
  • -
  • 3des
  • -
  • blowfish128
  • -
  • blowfish192
  • -
  • blowfish256
  • -
  • camellia128
  • -
  • camellia192
  • -
  • camellia256
  • -
  • camellia128ctr
  • -
  • camellia192ctr
  • -
  • camellia256ctr
  • -
  • camellia128ccm64
  • -
  • camellia192ccm64
  • -
  • camellia256ccm64
  • -
  • camellia128ccm96
  • -
  • camellia192ccm96
  • -
  • camellia256ccm96
  • -
  • camellia128ccm128
  • -
  • camellia192ccm128
  • -
  • camellia256ccm128
  • -
  • serpent128
  • -
  • serpent192
  • -
  • serpent256
  • -
  • twofish128
  • -
  • twofish192
  • -
  • twofish256
  • -
  • cast128
  • -
  • chacha20poly1305
  • -
-
Encryption algorithm.
+
Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
hash
string
-
    Choices: -
  • md5
  • -
  • md5_128
  • -
  • sha1
  • -
  • sha1_160
  • -
  • sha256
  • -
  • sha256_96
  • -
  • sha384
  • -
  • sha512
  • -
  • aesxcbc
  • -
  • aescmac
  • -
  • aes128gmac
  • -
  • aes192gmac
  • -
  • aes256gmac
  • -
-
Hash algorithm.
+
Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
prf
string
-
    Choices: -
  • prfmd5
  • -
  • prfsha1
  • -
  • prfaesxcbc
  • -
  • prfaescmac
  • -
  • prfsha256
  • -
  • prfsha384
  • -
  • prfsha512
  • -
-
Pseudo-Random Function.
+
Pseudo-Random Function. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
proposal_id
integer
The proposal identifier.
interface
list / elements=string
Interface(s) IPsec listens on. If omitted, listens on all interfaces.
log
dictionary
+
IPsec logging settings.
level
integer
-
    Choices: -
  • 0
  • -
  • 1
  • -
  • 2
  • -
Global IPsec logging level.
subsystem
list / elements=string
-
    Choices: -
  • dmn
  • -
  • mgr
  • -
  • ike
  • -
  • chd
  • -
  • job
  • -
  • cfg
  • -
  • knl
  • -
  • net
  • -
  • asn
  • -
  • enc
  • -
  • lib
  • -
  • esp
  • -
  • tls
  • -
  • tnc
  • -
  • imc
  • -
  • imv
  • -
  • pts
  • -
  • any
  • -
Per-subsystem logging levels to enable.
options
dictionary
+
Global IPsec options.
disable_route_autoinstall
boolean
    Choices:
  • no
  • yes
Do not automatically install routes to remote networks.
flexvpn
boolean
    Choices:
  • no
  • yes
Allow FlexVPN vendor ID payload (IKEv2 only).
interface
string
Single interface for IPsec options scope (distinct from top-level interface list).
retransmission
dictionary
+
IPsec retransmission settings.
attempts
integer
Maximum number of retransmissions.
base
float
Base of exponential backoff.
timeout
integer
Timeout in seconds before the first retransmission.
virtual_ip
boolean
    Choices:
  • no
  • yes
Allow install of virtual-ip addresses.
profile
list / elements=dictionary
List of VPN IPsec profiles (used for e.g. DMVPN/GRE tunnel binding).
authentication
dictionary
+
Authentication settings for this profile.
mode
string
    Choices:
  • pre-shared-secret
Authentication mode.
pre_shared_secret
string
Pre-shared secret key.
bind_tunnel
list / elements=string
Tunnel interface(s) associated with this profile.
disable
boolean
    Choices:
  • no
  • yes
Disable this profile.
esp_group
string
ESP group name to use for this profile.
ike_group
string
IKE group name to use for this profile.
name
string / required
Profile name.
+
+ running_config + +
+ string +
+
+ +
This option is used only with state parsed.
+
The value of this option should be the output received from the VyOS device by executing the command show configuration commands | match "vpn ipsec".
+
The states replaced and overridden have identical behaviour for this module with respect to named collections (ike_group, esp_group, profile, authentication), but differ in scope -- see the module description for detail.
+
The state parsed reads the configuration from the running_config option and transforms it into Ansible structured data as per the resource module's argspec, returned in the parsed key within the result.
+
state
string
    Choices:
  • merged ←
  • replaced
  • overridden
  • deleted
  • gathered
  • rendered
  • parsed
The state the configuration should be left in.

Notes ----- .. note:: - Tested against VyOS 1.4 and 1.5. - Source of truth for field types/choices: device node.def templates under /opt/vyatta/share/vyatta-cfg/templates/vpn/ipsec/. Examples -------- .. code-block:: yaml # ------------------- # Using merged # ------------------- # Before state: # ------------- # vyos@vyos:~$ show configuration commands | match "vpn ipsec" # (empty) # Task # ------------- # - name: Merge provided configuration with device configuration # vyos.vyos.vyos_vpn_ipsec: # config: # esp_group: # - name: ESP-TEST # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # ike_group: # - name: IKE-TEST # key_exchange: ikev2 # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # dh_group: 14 # state: merged # Task output: # ------------- # "commands": [ # "set vpn ipsec esp-group ESP-TEST", # "set vpn ipsec esp-group ESP-TEST proposal 1", # "set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256", # "set vpn ipsec esp-group ESP-TEST proposal 1 hash sha256", # "set vpn ipsec ike-group IKE-TEST", # "set vpn ipsec ike-group IKE-TEST key-exchange ikev2", # "set vpn ipsec ike-group IKE-TEST proposal 1", # "set vpn ipsec ike-group IKE-TEST proposal 1 encryption aes256", # "set vpn ipsec ike-group IKE-TEST proposal 1 hash sha256", # "set vpn ipsec ike-group IKE-TEST proposal 1 dh-group 14" # ] # ------------------- # Using gathered # ------------------- # Task # ------------- # - name: Gather current vpn_ipsec configuration # vyos.vyos.vyos_vpn_ipsec: # state: gathered # ------------------- # Using deleted # ------------------- # Task # ------------- # - name: Remove all vpn_ipsec configuration # vyos.vyos.vyos_vpn_ipsec: # state: deleted # ------------------- # Using rendered # ------------------- # Task # ------------- # - name: Render configuration without touching the device # vyos.vyos.vyos_vpn_ipsec: # config: # esp_group: # - name: ESP-TEST # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # state: rendered # ------------------- # Using parsed # ------------------- # Task # ------------- # - name: Parse raw config text into structured facts # vyos.vyos.vyos_vpn_ipsec: # running_config: "{{ lookup('file', './vpn_ipsec.cfg') }}" # state: parsed Return Values ------------- Common return values are documented `here `_, the following are the fields unique to this module: .. raw:: html
Key Returned Description
after
dictionary
when changed
The resulting configuration after module execution.

Sample:
This output will always be in the same format as the module argspec.
before
dictionary
when state is merged, replaced, overridden or deleted
The configuration prior to the module execution.

Sample:
This output will always be in the same format as the module argspec.
commands
list
when state is merged, replaced, overridden or deleted
The set of commands pushed to the remote device.

Sample:
['set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256', 'set vpn ipsec ike-group IKE-TEST key-exchange ikev2']
gathered
dictionary
when state is gathered
Facts about the network resource gathered from the remote device as structured data.

Sample:
This output will always be in the same format as the module argspec.
parsed
dictionary
when state is parsed
The device native config provided in running_config option parsed into structured data as per module argspec.

Sample:
This output will always be in the same format as the module argspec.
rendered
list
when state is rendered
The provided configuration in the task rendered in device-native format (offline).

Sample:
['set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256']


Status ------ Authors ~~~~~~~ -- Evgeny (@omnom62) +- Evgeny Molotkov (@omnom62) diff --git a/plugins/module_utils/network/vyos/argspec/vpn_ipsec/vpn_ipsec.py b/plugins/module_utils/network/vyos/argspec/vpn_ipsec/vpn_ipsec.py index 809aad34..75fc1ce5 100644 --- a/plugins/module_utils/network/vyos/argspec/vpn_ipsec/vpn_ipsec.py +++ b/plugins/module_utils/network/vyos/argspec/vpn_ipsec/vpn_ipsec.py @@ -1,223 +1,206 @@ # -*- coding: utf-8 -*- # Copyright 2026 Red Hat # GNU General Public License v3.0+ # (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) from __future__ import absolute_import, division, print_function __metaclass__ = type ############################################# # WARNING # ############################################# # # This file is auto generated by the # cli_rm_builder. # # Manually editing this file is not advised. # # To update the argspec make the desired changes # in the module docstring and re-run # cli_rm_builder. # ############################################# """ The arg spec for the vyos_vpn_ipsec module """ class Vpn_ipsecArgs(object): # pylint: disable=R0903 """The arg spec for the vyos_vpn_ipsec module""" argument_spec = { "config": { "type": "dict", "options": { "ike_group": { "type": "list", "elements": "dict", "options": { "name": {"type": "str", "required": True}, "close_action": { "type": "str", "choices": ["none", "trap", "start"], }, "dead_peer_detection": { "type": "dict", "options": { "action": { "type": "str", "choices": ["trap", "clear", "restart"], }, "interval": {"type": "int"}, "timeout": {"type": "int"}, }, }, "disable_mobike": {"type": "bool"}, "ikev2_reauth": {"type": "bool"}, "key_exchange": { "type": "str", "choices": ["ikev1", "ikev2"], }, "lifetime": {"type": "int"}, "mode": {"type": "str", "choices": ["main", "aggressive"]}, "proposal": { "type": "list", "elements": "dict", "options": { "proposal_id": {"type": "int"}, - "dh_group": { - "type": "int", - }, - "encryption": { - "type": "str", - }, - "hash": { - "type": "str", - }, - "prf": { - "type": "str", - }, + "dh_group": {"type": "int"}, + "encryption": {"type": "str"}, + "hash": {"type": "str"}, + "prf": {"type": "str"}, }, }, }, }, "esp_group": { "type": "list", "elements": "dict", "options": { "name": {"type": "str", "required": True}, "compression": {"type": "bool"}, "disable_rekey": {"type": "bool"}, "life_bytes": {"type": "int"}, "life_packets": {"type": "int"}, "lifetime": {"type": "int"}, "mode": { "type": "str", "choices": ["tunnel", "transport"], }, - "pfs": { - "type": "str", - }, + "pfs": {"type": "str"}, "proposal": { "type": "list", "elements": "dict", "options": { "proposal_id": {"type": "int"}, - "encryption": { - "type": "str", - }, - "hash": { - "type": "str", - }, + "encryption": {"type": "str"}, + "hash": {"type": "str"}, }, }, }, }, "authentication": { "type": "dict", "options": { "psk": { "type": "list", "elements": "dict", "options": { "name": {"type": "str", "required": True}, "id": {"type": "list", "elements": "str"}, "dhcp_interface": { "type": "list", "elements": "str", }, "secret": {"type": "str", "no_log": True}, "secret_type": { "type": "str", "choices": ["base64", "hex", "plaintext"], }, }, }, "ppk": { "type": "list", "elements": "dict", "options": { "name": {"type": "str", "required": True}, "id": {"type": "list", "elements": "str"}, "secret": {"type": "str", "no_log": True}, "secret_type": { "type": "str", "choices": ["base64", "hex", "plaintext"], }, }, }, }, }, "profile": { "type": "list", "elements": "dict", "options": { "name": {"type": "str", "required": True}, "authentication": { "type": "dict", "options": { "mode": { "type": "str", "choices": ["pre-shared-secret"], }, - "pre_shared_secret": { - "type": "str", - "no_log": True, - }, + "pre_shared_secret": {"type": "str", "no_log": True}, }, }, "bind_tunnel": {"type": "list", "elements": "str"}, "disable": {"type": "bool"}, "esp_group": {"type": "str"}, "ike_group": {"type": "str"}, }, }, "interface": {"type": "list", "elements": "str"}, "log": { "type": "dict", "options": { - "level": {"type": "int", "choices": [0, 1, 2]}, + "level": {"type": "int"}, "subsystem": { "type": "list", "elements": "str", }, }, }, "options": { "type": "dict", "options": { "disable_route_autoinstall": {"type": "bool"}, "flexvpn": {"type": "bool"}, "interface": {"type": "str"}, "retransmission": { "type": "dict", "options": { "attempts": {"type": "int"}, "base": {"type": "float"}, "timeout": {"type": "int"}, }, }, "virtual_ip": {"type": "bool"}, }, }, "disable_uniqreqids": {"type": "bool"}, }, }, "running_config": {"type": "str"}, "state": { "type": "str", "choices": [ "merged", "replaced", "overridden", "deleted", "gathered", "rendered", "parsed", ], "default": "merged", }, } # pylint: disable=C0301 diff --git a/plugins/modules/vyos_vpn_ipsec.py b/plugins/modules/vyos_vpn_ipsec.py index 0e021a04..68fb5fc7 100644 --- a/plugins/modules/vyos_vpn_ipsec.py +++ b/plugins/modules/vyos_vpn_ipsec.py @@ -1,589 +1,473 @@ #!/usr/bin/python # -*- coding: utf-8 -*- # Copyright 2026 Red Hat # GNU General Public License v3.0+ # (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) """ The module file for vyos_vpn_ipsec """ from __future__ import absolute_import, division, print_function __metaclass__ = type DOCUMENTATION = """ module: vyos_vpn_ipsec short_description: Manages global IPsec (ike-group, esp-group, profile, authentication, options) attributes of VyOS network devices. -description: This module manages global VPN IPsec configuration on VyOS devices — IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules. +description: This module manages global VPN IPsec configuration on VyOS devices + -- IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global + options. Site-to-site peers and IKEv2 remote-access connections are handled by + separate modules. version_added: 6.2.0 -author: Evgeny (@omnom62) +author: Evgeny Molotkov (@omnom62) notes: - Tested against VyOS 1.4 and 1.5. - "Source of truth for field types/choices: device node.def templates under /opt/vyatta/share/vyatta-cfg/templates/vpn/ipsec/." options: config: description: IPsec global configuration. type: dict suboptions: ike_group: description: List of IKE groups. type: list elements: dict suboptions: name: description: The name of the IKE group. type: str required: true close_action: description: Action to take if a child SA is unexpectedly closed. type: str choices: [none, trap, start] dead_peer_detection: description: Dead Peer Detection (DPD). type: dict suboptions: action: description: Keep-alive failure action. type: str choices: [trap, clear, restart] interval: description: Keep-alive interval in seconds. type: int timeout: description: Dead Peer Detection keep-alive timeout (IKEv1 only), in seconds. type: int disable_mobike: description: Disable MOBIKE support (IKEv2 only). type: bool ikev2_reauth: description: Re-authentication of the remote peer during an IKE re-key (IKEv2 only). type: bool key_exchange: description: IKE version. type: str choices: [ikev1, ikev2] lifetime: description: IKE lifetime in seconds. type: int mode: description: IKEv1 phase 1 mode. type: str choices: [main, aggressive] proposal: description: List of IKE proposals. type: list elements: dict suboptions: proposal_id: description: The proposal identifier. type: int dh_group: - description: Diffie-Hellman group. + description: Diffie-Hellman group. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side, not enumerated here since + the set is version-dependent. type: int - choices: [1, 2, 5, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32] encryption: - description: Encryption algorithm. + description: Encryption algorithm. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side, not enumerated here since + the set is version-dependent. type: str - choices: - - "null" - - aes128 - - aes192 - - aes256 - - aes128ctr - - aes192ctr - - aes256ctr - - aes128ccm64 - - aes192ccm64 - - aes256ccm64 - - aes128ccm96 - - aes192ccm96 - - aes256ccm96 - - aes128ccm128 - - aes192ccm128 - - aes256ccm128 - - aes128gcm64 - - aes192gcm64 - - aes256gcm64 - - aes128gcm96 - - aes192gcm96 - - aes256gcm96 - - aes128gcm128 - - aes192gcm128 - - aes256gcm128 - - aes128gmac - - aes192gmac - - aes256gmac - - 3des - - blowfish128 - - blowfish192 - - blowfish256 - - camellia128 - - camellia192 - - camellia256 - - camellia128ctr - - camellia192ctr - - camellia256ctr - - camellia128ccm64 - - camellia192ccm64 - - camellia256ccm64 - - camellia128ccm96 - - camellia192ccm96 - - camellia256ccm96 - - camellia128ccm128 - - camellia192ccm128 - - camellia256ccm128 - - serpent128 - - serpent192 - - serpent256 - - twofish128 - - twofish192 - - twofish256 - - cast128 - - chacha20poly1305 hash: - description: Hash algorithm. + description: Hash algorithm. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side. type: str - choices: [md5, md5_128, sha1, sha1_160, sha256, sha256_96, sha384, sha512, aesxcbc, aescmac, aes128gmac, aes192gmac, aes256gmac] prf: - description: Pseudo-Random Function. + description: Pseudo-Random Function. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side. type: str - choices: [prfmd5, prfsha1, prfaesxcbc, prfaescmac, prfsha256, prfsha384, prfsha512] esp_group: description: List of ESP groups. type: list elements: dict suboptions: name: description: The name of the ESP group. type: str required: true compression: description: Enable ESP compression. type: bool disable_rekey: description: Do not locally initiate a re-key of the SA; remote peer must re-key before expiration. type: bool life_bytes: description: Security Association byte count to expire. type: int life_packets: description: Security Association packet count to expire. type: int lifetime: description: Security Association time to expire, in seconds. type: int mode: description: ESP mode. type: str choices: [tunnel, transport] pfs: - description: ESP Perfect Forward Secrecy. + description: ESP Perfect Forward Secrecy. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side, not enumerated here since + the set is version-dependent. type: str - choices: - - enable - - disable - - dh-group1 - - dh-group2 - - dh-group5 - - dh-group14 - - dh-group15 - - dh-group16 - - dh-group17 - - dh-group18 - - dh-group19 - - dh-group20 - - dh-group21 - - dh-group22 - - dh-group23 - - dh-group24 - - dh-group25 - - dh-group26 - - dh-group27 - - dh-group28 - - dh-group29 - - dh-group30 - - dh-group31 - - dh-group32 proposal: description: List of ESP proposals. type: list elements: dict suboptions: proposal_id: description: The proposal identifier. type: int encryption: - description: Encryption algorithm. + description: Encryption algorithm. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side, not enumerated here since + the set is version-dependent. type: str - choices: - - "null" - - aes128 - - aes192 - - aes256 - - aes128ctr - - aes192ctr - - aes256ctr - - aes128ccm64 - - aes192ccm64 - - aes256ccm64 - - aes128ccm96 - - aes192ccm96 - - aes256ccm96 - - aes128ccm128 - - aes192ccm128 - - aes256ccm128 - - aes128gcm64 - - aes192gcm64 - - aes256gcm64 - - aes128gcm96 - - aes192gcm96 - - aes256gcm96 - - aes128gcm128 - - aes192gcm128 - - aes256gcm128 - - aes128gmac - - aes192gmac - - aes256gmac - - 3des - - blowfish128 - - blowfish192 - - blowfish256 - - camellia128 - - camellia192 - - camellia256 - - camellia128ctr - - camellia192ctr - - camellia256ctr - - camellia128ccm64 - - camellia192ccm64 - - camellia256ccm64 - - camellia128ccm96 - - camellia192ccm96 - - camellia256ccm96 - - camellia128ccm128 - - camellia192ccm128 - - camellia256ccm128 - - serpent128 - - serpent192 - - serpent256 - - twofish128 - - twofish192 - - twofish256 - - cast128 - - chacha20poly1305 hash: - description: Hash algorithm. + description: Hash algorithm. See VyOS/strongSwan documentation for the + full set of valid values -- validated device-side. type: str - choices: [md5, md5_128, sha1, sha1_160, sha256, sha256_96, sha384, sha512, aesxcbc, aescmac, aes128gmac, aes192gmac, aes256gmac] authentication: description: Global pre-shared-key and post-quantum pre-shared-key definitions. type: dict suboptions: psk: description: List of pre-shared keys. type: list elements: dict suboptions: name: description: Pre-shared key name. type: str required: true id: description: ID(s) for authentication. type: list elements: str dhcp_interface: description: DHCP interface(s) supplying next-hop IP address. type: list elements: str secret: description: IKE pre-shared secret key. type: str - no_log: true secret_type: description: Secret encoding type. type: str choices: [base64, hex, plaintext] ppk: description: List of post-quantum pre-shared keys. type: list elements: dict suboptions: name: description: Post-quantum pre-shared key name. type: str required: true id: description: ID(s) for PPK. type: list elements: str secret: description: Post-quantum pre-shared secret key. type: str - no_log: true secret_type: description: Secret encoding type. type: str choices: [base64, hex, plaintext] profile: description: List of VPN IPsec profiles (used for e.g. DMVPN/GRE tunnel binding). type: list elements: dict suboptions: name: description: Profile name. type: str required: true authentication: + description: Authentication settings for this profile. type: dict suboptions: mode: description: Authentication mode. type: str choices: [pre-shared-secret] pre_shared_secret: description: Pre-shared secret key. type: str - no_log: true bind_tunnel: description: Tunnel interface(s) associated with this profile. type: list elements: str disable: description: Disable this profile. type: bool esp_group: description: ESP group name to use for this profile. type: str ike_group: description: IKE group name to use for this profile. type: str interface: description: Interface(s) IPsec listens on. If omitted, listens on all interfaces. type: list elements: str log: + description: IPsec logging settings. type: dict suboptions: level: description: Global IPsec logging level. type: int - choices: [0, 1, 2] subsystem: description: Per-subsystem logging levels to enable. type: list elements: str - choices: [dmn, mgr, ike, chd, job, cfg, knl, net, asn, enc, lib, esp, tls, tnc, imc, imv, pts, any] options: + description: Global IPsec options. type: dict suboptions: disable_route_autoinstall: description: Do not automatically install routes to remote networks. type: bool flexvpn: description: Allow FlexVPN vendor ID payload (IKEv2 only). type: bool interface: description: Single interface for IPsec options scope (distinct from top-level interface list). type: str retransmission: + description: IPsec retransmission settings. type: dict suboptions: attempts: description: Maximum number of retransmissions. type: int base: description: Base of exponential backoff. type: float timeout: description: Timeout in seconds before the first retransmission. type: int virtual_ip: description: Allow install of virtual-ip addresses. type: bool disable_uniqreqids: description: Disable requirement for unique IDs in the Security Database. type: bool + running_config: + description: + - This option is used only with state I(parsed). + - The value of this option should be the output received from the VyOS device by + executing the command B(show configuration commands | match "vpn ipsec"). + - The states I(replaced) and I(overridden) have identical behaviour for this module + with respect to named collections (ike_group, esp_group, profile, authentication), + but differ in scope -- see the module description for detail. + - The state I(parsed) reads the configuration from the C(running_config) option and + transforms it into Ansible structured data as per the resource module's argspec, + returned in the I(parsed) key within the result. + type: str state: description: The state the configuration should be left in. type: str choices: [merged, replaced, overridden, deleted, gathered, rendered, parsed] default: merged """ EXAMPLES = """ # ------------------- # Using merged # ------------------- # Before state: # ------------- # vyos@vyos:~$ show configuration commands | match "vpn ipsec" # (empty) # Task # ------------- # - name: Merge provided configuration with device configuration # vyos.vyos.vyos_vpn_ipsec: # config: # esp_group: # - name: ESP-TEST # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # ike_group: # - name: IKE-TEST # key_exchange: ikev2 # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # dh_group: 14 # state: merged # Task output: # ------------- # "commands": [ # "set vpn ipsec esp-group ESP-TEST", # "set vpn ipsec esp-group ESP-TEST proposal 1", # "set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256", # "set vpn ipsec esp-group ESP-TEST proposal 1 hash sha256", # "set vpn ipsec ike-group IKE-TEST", # "set vpn ipsec ike-group IKE-TEST key-exchange ikev2", # "set vpn ipsec ike-group IKE-TEST proposal 1", # "set vpn ipsec ike-group IKE-TEST proposal 1 encryption aes256", # "set vpn ipsec ike-group IKE-TEST proposal 1 hash sha256", # "set vpn ipsec ike-group IKE-TEST proposal 1 dh-group 14" # ] # ------------------- # Using gathered # ------------------- # Task # ------------- # - name: Gather current vpn_ipsec configuration # vyos.vyos.vyos_vpn_ipsec: # state: gathered # ------------------- # Using deleted # ------------------- # Task # ------------- # - name: Remove all vpn_ipsec configuration # vyos.vyos.vyos_vpn_ipsec: # state: deleted # ------------------- # Using rendered # ------------------- # Task # ------------- # - name: Render configuration without touching the device # vyos.vyos.vyos_vpn_ipsec: # config: # esp_group: # - name: ESP-TEST # proposal: # - proposal_id: 1 # encryption: aes256 # hash: sha256 # state: rendered # ------------------- # Using parsed # ------------------- # Task # ------------- # - name: Parse raw config text into structured facts # vyos.vyos.vyos_vpn_ipsec: # running_config: "{{ lookup('file', './vpn_ipsec.cfg') }}" # state: parsed """ RETURN = """ before: description: The configuration prior to the module execution. returned: when I(state) is C(merged), C(replaced), C(overridden) or C(deleted) type: dict sample: > This output will always be in the same format as the module argspec. after: description: The resulting configuration after module execution. returned: when changed type: dict sample: > This output will always be in the same format as the module argspec. commands: description: The set of commands pushed to the remote device. returned: when I(state) is C(merged), C(replaced), C(overridden) or C(deleted) type: list sample: - set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256 - set vpn ipsec ike-group IKE-TEST key-exchange ikev2 rendered: description: The provided configuration in the task rendered in device-native format (offline). returned: when I(state) is C(rendered) type: list sample: - set vpn ipsec esp-group ESP-TEST proposal 1 encryption aes256 gathered: description: Facts about the network resource gathered from the remote device as structured data. returned: when I(state) is C(gathered) type: dict sample: > This output will always be in the same format as the module argspec. parsed: description: The device native config provided in I(running_config) option parsed into structured data as per module argspec. returned: when I(state) is C(parsed) type: dict sample: > This output will always be in the same format as the module argspec. """ from ansible.module_utils.basic import AnsibleModule from ansible_collections.vyos.vyos.plugins.module_utils.network.vyos.argspec.vpn_ipsec.vpn_ipsec import ( Vpn_ipsecArgs, ) from ansible_collections.vyos.vyos.plugins.module_utils.network.vyos.config.vpn_ipsec.vpn_ipsec import ( Vpn_ipsec, ) def main(): """ Main entry point for module execution :returns: the result form module invocation """ module = AnsibleModule( argument_spec=Vpn_ipsecArgs.argument_spec, mutually_exclusive=[["config", "running_config"]], required_if=[ ["state", "merged", ["config"]], ["state", "replaced", ["config"]], ["state", "overridden", ["config"]], ["state", "rendered", ["config"]], ["state", "parsed", ["running_config"]], ], supports_check_mode=True, ) result = Vpn_ipsec(module).execute_module() module.exit_json(**result) if __name__ == "__main__": main()