diff --git a/docs/vyos.vyos.vyos_vpn_ipsec_module.rst b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst
index 68c3d384..9bc46ac5 100644
--- a/docs/vyos.vyos.vyos_vpn_ipsec_module.rst
+++ b/docs/vyos.vyos.vyos_vpn_ipsec_module.rst
@@ -1,1779 +1,1573 @@
.. _vyos.vyos.vyos_vpn_ipsec_module:
************************
vyos.vyos.vyos_vpn_ipsec
************************
**Manages global IPsec (ike-group, esp-group, profile, authentication, options) attributes of VyOS network devices.**
Version added: 6.2.0
.. contents::
:local:
:depth: 1
Synopsis
--------
-- This module manages global VPN IPsec configuration on VyOS devices — IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules.
+- This module manages global VPN IPsec configuration on VyOS devices -- IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules.
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
config
dictionary
|
|
IPsec global configuration.
|
|
authentication
dictionary
|
|
Global pre-shared-key and post-quantum pre-shared-key definitions.
|
|
|
ppk
list
/ elements=dictionary
|
|
List of post-quantum pre-shared keys.
|
|
|
|
id
list
/ elements=string
|
|
ID(s) for PPK.
|
|
|
|
name
string
/ required
|
|
Post-quantum pre-shared key name.
|
|
|
|
secret
string
|
|
Post-quantum pre-shared secret key.
|
|
|
|
secret_type
string
|
Choices:
- base64
- hex
- plaintext
|
Secret encoding type.
|
|
|
psk
list
/ elements=dictionary
|
|
List of pre-shared keys.
|
|
|
|
dhcp_interface
list
/ elements=string
|
|
DHCP interface(s) supplying next-hop IP address.
|
|
|
|
id
list
/ elements=string
|
|
ID(s) for authentication.
|
|
|
|
name
string
/ required
|
|
Pre-shared key name.
|
|
|
|
secret
string
|
|
IKE pre-shared secret key.
|
|
|
|
secret_type
string
|
Choices:
- base64
- hex
- plaintext
|
Secret encoding type.
|
|
disable_uniqreqids
boolean
|
|
Disable requirement for unique IDs in the Security Database.
|
|
esp_group
list
/ elements=dictionary
|
|
List of ESP groups.
|
|
|
compression
boolean
|
|
Enable ESP compression.
|
|
|
disable_rekey
boolean
|
|
Do not locally initiate a re-key of the SA; remote peer must re-key before expiration.
|
|
|
life_bytes
integer
|
|
Security Association byte count to expire.
|
|
|
life_packets
integer
|
|
Security Association packet count to expire.
|
|
|
lifetime
integer
|
|
Security Association time to expire, in seconds.
|
|
|
mode
string
|
Choices:
- tunnel
- transport
|
ESP mode.
|
|
|
name
string
/ required
|
|
The name of the ESP group.
|
|
|
pfs
string
|
- Choices:
- - enable
- - disable
- - dh-group1
- - dh-group2
- - dh-group5
- - dh-group14
- - dh-group15
- - dh-group16
- - dh-group17
- - dh-group18
- - dh-group19
- - dh-group20
- - dh-group21
- - dh-group22
- - dh-group23
- - dh-group24
- - dh-group25
- - dh-group26
- - dh-group27
- - dh-group28
- - dh-group29
- - dh-group30
- - dh-group31
- - dh-group32
-
|
- ESP Perfect Forward Secrecy.
+ ESP Perfect Forward Secrecy. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
|
|
|
proposal
list
/ elements=dictionary
|
|
List of ESP proposals.
|
|
|
|
encryption
string
|
- Choices:
- - null
- - aes128
- - aes192
- - aes256
- - aes128ctr
- - aes192ctr
- - aes256ctr
- - aes128ccm64
- - aes192ccm64
- - aes256ccm64
- - aes128ccm96
- - aes192ccm96
- - aes256ccm96
- - aes128ccm128
- - aes192ccm128
- - aes256ccm128
- - aes128gcm64
- - aes192gcm64
- - aes256gcm64
- - aes128gcm96
- - aes192gcm96
- - aes256gcm96
- - aes128gcm128
- - aes192gcm128
- - aes256gcm128
- - aes128gmac
- - aes192gmac
- - aes256gmac
- - 3des
- - blowfish128
- - blowfish192
- - blowfish256
- - camellia128
- - camellia192
- - camellia256
- - camellia128ctr
- - camellia192ctr
- - camellia256ctr
- - camellia128ccm64
- - camellia192ccm64
- - camellia256ccm64
- - camellia128ccm96
- - camellia192ccm96
- - camellia256ccm96
- - camellia128ccm128
- - camellia192ccm128
- - camellia256ccm128
- - serpent128
- - serpent192
- - serpent256
- - twofish128
- - twofish192
- - twofish256
- - cast128
- - chacha20poly1305
-
|
- Encryption algorithm.
+ Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
|
|
|
|
hash
string
|
- Choices:
- - md5
- - md5_128
- - sha1
- - sha1_160
- - sha256
- - sha256_96
- - sha384
- - sha512
- - aesxcbc
- - aescmac
- - aes128gmac
- - aes192gmac
- - aes256gmac
-
|
- Hash algorithm.
+ Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
|
|
|
|
proposal_id
integer
|
|
The proposal identifier.
|
|
ike_group
list
/ elements=dictionary
|
|
List of IKE groups.
|
|
|
close_action
string
|
|
Action to take if a child SA is unexpectedly closed.
|
|
|
dead_peer_detection
dictionary
|
|
Dead Peer Detection (DPD).
|
|
|
|
action
string
|
Choices:
- trap
- clear
- restart
|
Keep-alive failure action.
|
|
|
|
interval
integer
|
|
Keep-alive interval in seconds.
|
|
|
|
timeout
integer
|
|
Dead Peer Detection keep-alive timeout (IKEv1 only), in seconds.
|
|
|
disable_mobike
boolean
|
|
Disable MOBIKE support (IKEv2 only).
|
|
|
ikev2_reauth
boolean
|
|
Re-authentication of the remote peer during an IKE re-key (IKEv2 only).
|
|
|
key_exchange
string
|
|
IKE version.
|
|
|
lifetime
integer
|
|
IKE lifetime in seconds.
|
|
|
mode
string
|
|
IKEv1 phase 1 mode.
|
|
|
name
string
/ required
|
|
The name of the IKE group.
|
|
|
proposal
list
/ elements=dictionary
|
|
List of IKE proposals.
|
|
|
|
dh_group
integer
|
- Choices:
- - 1
- - 2
- - 5
- - 14
- - 15
- - 16
- - 17
- - 18
- - 19
- - 20
- - 21
- - 22
- - 23
- - 24
- - 25
- - 26
- - 27
- - 28
- - 29
- - 30
- - 31
- - 32
-
|
- Diffie-Hellman group.
+ Diffie-Hellman group. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
|
|
|
|
encryption
string
|
- Choices:
- - null
- - aes128
- - aes192
- - aes256
- - aes128ctr
- - aes192ctr
- - aes256ctr
- - aes128ccm64
- - aes192ccm64
- - aes256ccm64
- - aes128ccm96
- - aes192ccm96
- - aes256ccm96
- - aes128ccm128
- - aes192ccm128
- - aes256ccm128
- - aes128gcm64
- - aes192gcm64
- - aes256gcm64
- - aes128gcm96
- - aes192gcm96
- - aes256gcm96
- - aes128gcm128
- - aes192gcm128
- - aes256gcm128
- - aes128gmac
- - aes192gmac
- - aes256gmac
- - 3des
- - blowfish128
- - blowfish192
- - blowfish256
- - camellia128
- - camellia192
- - camellia256
- - camellia128ctr
- - camellia192ctr
- - camellia256ctr
- - camellia128ccm64
- - camellia192ccm64
- - camellia256ccm64
- - camellia128ccm96
- - camellia192ccm96
- - camellia256ccm96
- - camellia128ccm128
- - camellia192ccm128
- - camellia256ccm128
- - serpent128
- - serpent192
- - serpent256
- - twofish128
- - twofish192
- - twofish256
- - cast128
- - chacha20poly1305
-
|
- Encryption algorithm.
+ Encryption algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side, not enumerated here since the set is version-dependent.
|
|
|
|
hash
string
|
- Choices:
- - md5
- - md5_128
- - sha1
- - sha1_160
- - sha256
- - sha256_96
- - sha384
- - sha512
- - aesxcbc
- - aescmac
- - aes128gmac
- - aes192gmac
- - aes256gmac
-
|
- Hash algorithm.
+ Hash algorithm. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
|
|
|
|
prf
string
|
- Choices:
- - prfmd5
- - prfsha1
- - prfaesxcbc
- - prfaescmac
- - prfsha256
- - prfsha384
- - prfsha512
-
|
- Pseudo-Random Function.
+ Pseudo-Random Function. See VyOS/strongSwan documentation for the full set of valid values -- validated device-side.
|
|
|
|
proposal_id
integer
|
|
The proposal identifier.
|
|
interface
list
/ elements=string
|
|
Interface(s) IPsec listens on. If omitted, listens on all interfaces.
|
|
log
dictionary
|
|
+ IPsec logging settings.
|
|
|
level
integer
|
-
|
Global IPsec logging level.
|
|
|
subsystem
list
/ elements=string
|
- Choices:
- - dmn
- - mgr
- - ike
- - chd
- - job
- - cfg
- - knl
- - net
- - asn
- - enc
- - lib
- - esp
- - tls
- - tnc
- - imc
- - imv
- - pts
- - any
-
|
Per-subsystem logging levels to enable.
|
|
options
dictionary
|
|
+ Global IPsec options.
|
|
|
disable_route_autoinstall
boolean
|
|
Do not automatically install routes to remote networks.
|
|
|
flexvpn
boolean
|
|
Allow FlexVPN vendor ID payload (IKEv2 only).
|
|
|
interface
string
|
|
Single interface for IPsec options scope (distinct from top-level interface list).
|
|
|
retransmission
dictionary
|
|
+ IPsec retransmission settings.
|
|
|
|
attempts
integer
|
|
Maximum number of retransmissions.
|
|
|
|
base
float
|
|
Base of exponential backoff.
|
|
|
|
timeout
integer
|
|
Timeout in seconds before the first retransmission.
|
|
|
virtual_ip
boolean
|
|
Allow install of virtual-ip addresses.
|
|
profile
list
/ elements=dictionary
|
|
List of VPN IPsec profiles (used for e.g. DMVPN/GRE tunnel binding).
|
|
|
authentication
dictionary
|
|
+ Authentication settings for this profile.
|
|
|
|
mode
string
|
Choices:
- pre-shared-secret
|
Authentication mode.
|
|
|
|
pre_shared_secret
string
|
|
Pre-shared secret key.
|
|
|
bind_tunnel
list
/ elements=string
|
|
Tunnel interface(s) associated with this profile.
|
|
|
disable
boolean
|
|
Disable this profile.
|
|
|
esp_group
string
|
|
ESP group name to use for this profile.
|
|
|
ike_group
string
|
|
IKE group name to use for this profile.
|
|
|
name
string
/ required
|
|
Profile name.
|
+
+ |
+
+ running_config
+
+
+ string
+
+ |
+
+ |
+
+ This option is used only with state parsed.
+ The value of this option should be the output received from the VyOS device by executing the command show configuration commands | match "vpn ipsec".
+ The states replaced and overridden have identical behaviour for this module with respect to named collections (ike_group, esp_group, profile, authentication), but differ in scope -- see the module description for detail.
+ The state parsed reads the configuration from the running_config option and transforms it into Ansible structured data as per the resource module's argspec, returned in the parsed key within the result.
+ |
+
|
state
string
|
Choices:
merged ←
- replaced
- overridden
- deleted
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|