diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst
index fa2a890c..607ad0ca 100644
--- a/docs/vyos.vyos.vyos_nat_module.rst
+++ b/docs/vyos.vyos.vyos_nat_module.rst
@@ -1,1560 +1,301 @@
.. _vyos.vyos.vyos_nat_module:
******************
vyos.vyos.vyos_nat
******************
**NAT resource module**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module manages NAT configuration on devices running Vyos
Parameters
----------
.. raw:: html
- | Parameter |
+ Parameter |
Choices/Defaults |
Comments |
- |
-
- config
-
-
- dictionary
-
- |
-
- |
-
- The desired configuration for the NAT resource represented as a dictionary.
- |
-
-
- |
-
-
- cgnat
-
-
- dictionary
-
- |
-
- |
-
- Configuration for Carrier Grade NAT (CGNAT).
- |
-
-
- |
- |
-
-
- log_allocation
-
-
- boolean
-
- |
-
-
- |
-
- Whether to log CGNAT address allocations.
- |
-
-
- |
- |
-
-
- pool
-
-
- dictionary
-
- |
-
- |
-
- Configuration for CGNAT pools.
- |
-
-
- |
- |
- |
-
-
- external
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of external NAT pools for CGNAT.
- |
-
-
- |
- |
- |
- |
-
-
- external_port_range
-
-
- string
-
- |
-
- |
-
- Port range to use for NAT translations in this external pool.
- |
-
-
- |
- |
- |
- |
-
-
- name
-
-
- string
- / required
-
- |
-
- |
-
- Name of the external NAT pool.
- |
-
-
- |
- |
- |
- |
-
-
- per_user_limit
-
-
- dictionary
-
- |
-
- |
-
- Per-user limit configuration for the external pool.
- |
-
-
- |
- |
- |
- |
- |
-
-
- port
-
-
- integer
-
- |
-
- |
-
- Maximum number of ports allocated per user.
- |
-
-
-
- |
- |
- |
- |
-
-
- range
-
-
- list
- / elements=string
-
- |
-
- |
-
- List of external IP addresses or prefixes in the pool.
- |
-
-
-
- |
- |
- |
-
-
- internal
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of internal NAT pools for CGNAT.
- |
-
-
- |
- |
- |
- |
-
-
- name
-
-
- string
- / required
-
- |
-
- |
-
- Name of the internal NAT pool.
- |
-
-
- |
- |
- |
- |
-
-
- range
-
-
- list
- / elements=string
-
- |
-
- |
-
- List of internal IP addresses or prefixes in the pool.
- |
-
-
-
-
- |
- |
-
-
- rule
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of CGNAT rules.
- |
-
-
- |
- |
- |
-
-
- id
-
-
- integer
- / required
-
- |
-
- |
-
- Rule number for CGNAT.
- |
-
-
- |
- |
- |
-
-
- source
-
-
- dictionary
-
- |
-
- |
-
- Source configuration for CGNAT translation.
- |
-
-
- |
- |
- |
- |
-
-
- pool
-
-
- string
-
- |
-
- |
-
- Source pool to use for CGNAT translation.
- |
-
-
-
- |
- |
- |
-
-
- translation
-
-
- dictionary
-
- |
-
- |
-
- Translation configuration for CGNAT.
- |
-
-
- |
- |
- |
- |
-
-
- pool
-
-
- string
-
- |
-
- |
-
- Translation pool to use for CGNAT translation.
- |
-
-
-
-
-
- |
-
-
- destination
-
-
- dictionary
-
- |
-
- |
-
- Configuration for destination NAT rules.
- |
-
-
- |
- |
-
-
- rule
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of destination NAT rules.
- |
-
-
- |
- |
- |
-
-
- description
-
-
- string
-
- |
-
- |
-
- User-friendly description of the destination NAT rule.
- |
-
-
- |
- |
- |
-
-
- destination
-
-
- dictionary
-
- |
-
- |
-
- Match criteria for destination NAT.
- |
-
-
- |
- |
- |
- |
-
-
- address
-
-
- string
-
- |
-
- |
-
- IP address, subnet, or range to match for destination NAT.
- |
-
-
- |
- |
- |
- |
-
-
- disable
-
-
- boolean
-
- |
-
-
- |
-
- Disable this destination NAT rule.
- |
-
-
- |
- |
- |
- |
-
-
- exclude
-
-
- boolean
-
- |
-
-
- |
-
- Exclude packets matching this rule from NAT.
- |
-
-
- |
- |
- |
- |
-
-
- fqdn
-
-
- string
-
- |
-
- |
-
- Fully qualified domain name to match for destination NAT.
- |
-
-
- |
- |
- |
- |
-
-
- group
-
-
- dictionary
-
- |
-
- |
-
- Address/network/port group to match for destination NAT.
- |
-
-
- |
- |
- |
- |
- |
-
-
- address_group
-
-
- string
-
- |
-
- |
-
- Address group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- domain_group
-
-
- string
-
- |
-
- |
-
- Domain group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- mac_group
-
-
- string
-
- |
-
- |
-
- MAC address group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- network_group
-
-
- string
-
- |
-
- |
-
- Network group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- port_group
-
-
- string
-
- |
-
- |
-
- Port group name to match.
- |
-
-
-
- |
- |
- |
- |
-
-
- log
-
-
- boolean
-
- |
-
-
- |
-
- Log packets hitting this destination NAT rule.
- |
-
-
- |
- |
- |
- |
-
-
- port
-
-
- string
-
- |
-
- |
-
- Port number or range for destination NAT.
- |
-
-
- |
- |
- |
- |
-
-
- protocol
-
-
- string
-
- |
-
- |
-
- Protocol to match (TCP, UDP, ICMP, etc.).
- |
-
-
-
- |
- |
- |
-
-
- id
-
-
- integer
- / required
-
- |
-
- |
-
- Rule number for destination NAT.
- |
-
-
-
-
- |
-
-
- source
-
-
- dictionary
-
- |
-
- |
-
- Configuration for source NAT rules.
- |
-
-
- |
- |
-
-
- rule
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of source NAT rules.
- |
-
-
- |
- |
- |
-
-
- description
-
-
- string
-
- |
-
- |
-
- User-friendly description of the source NAT rule.
- |
-
-
- |
- |
- |
-
-
- destination
-
-
- dictionary
-
- |
-
- |
-
- Match criteria for source NAT.
- |
-
-
- |
- |
- |
- |
-
-
- address
-
-
- string
-
- |
-
- |
-
- IP address, subnet, or range to match for source NAT.
- |
-
-
- |
- |
- |
- |
-
-
- disable
-
-
- boolean
-
- |
-
-
- |
-
- Disable this source NAT rule.
- |
-
-
- |
- |
- |
- |
-
-
- exclude
-
-
- boolean
-
- |
-
-
- |
-
- Exclude packets matching this rule from NAT.
- |
-
-
- |
- |
- |
- |
-
-
- fqdn
-
-
- string
-
- |
-
- |
-
- Fully qualified domain name to match for source NAT.
- |
-
-
- |
- |
- |
- |
-
-
- group
-
-
- dictionary
-
- |
-
- |
-
- Address/network/port group to match for source NAT.
- |
-
-
- |
- |
- |
- |
- |
-
-
- address_group
-
-
- string
-
- |
-
- |
-
- Address group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- domain_group
-
-
- string
-
- |
-
- |
-
- Domain group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- mac_group
-
-
- string
-
- |
-
- |
-
- MAC address group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- network_group
-
-
- string
-
- |
-
- |
-
- Network group name to match.
- |
-
-
- |
- |
- |
- |
- |
-
-
- port_group
-
-
- string
-
- |
-
- |
-
- Port group name to match.
- |
-
-
-
- |
- |
- |
- |
-
-
- log
-
-
- boolean
-
- |
-
-
- |
-
- Log packets hitting this source NAT rule.
- |
-
-
- |
- |
- |
- |
-
-
- port
-
-
- string
-
- |
-
- |
-
- Port number or range for source NAT.
- |
-
-
- |
- |
- |
- |
- protocol
-
-
- string
-
- |
-
- |
-
- Protocol to match (TCP, UDP, ICMP, etc.).
- |
-
-
-
- |
- |
- |
-
-
- id
-
-
- integer
- / required
-
- |
-
- |
-
- Rule number for source NAT.
- |
-
-
-
-
- |
-
-
- static
+ config
dictionary
|
|
- Configuration for static NAT rules.
- |
-
-
- |
- |
-
-
- rule
-
-
- list
- / elements=dictionary
-
- |
-
- |
-
- List of static NAT rules.
+ The desired configuration for the NAT resource represented as a dictionary.
|
|
- |
- |
-
-
- description
-
-
- string
-
- |
-
- |
-
- User-friendly description of the static NAT rule.
- |
-
-
- |
- |
- |
-
+ |
- destination
+ nat
dictionary
|
|
- Match criteria for static NAT.
- |
-
-
- |
- |
- |
- |
-
-
- address
-
-
- string
-
- |
-
- |
-
- IP address, subnet, or range to match for static NAT.
+ Configuration for NAT rules.
|
- |
- |
- |
-
-
- disable
-
-
- boolean
-
- |
-
-
- |
-
- Disable this static NAT rule.
- |
-
-
- |
- |
- |
-
-
- id
-
-
- integer
- / required
-
- |
-
- |
-
- Rule number for static NAT (one-to-one).
- |
-
-
- |
- |
- |
-
-
- inbound_interface
-
-
- list
- / elements=string
-
- |
-
- |
-
- List of inbound interfaces that this static NAT rule applies to.
- |
-
-
- |
- |
- |
-
-
- log
-
-
- boolean
-
- |
-
-
- |
-
- Log packets hitting this static NAT rule.
- |
-
-
- |
- |
- |
-
-
- translation
-
-
- dictionary
-
- |
-
- |
-
- Translation configuration for static NAT.
- |
-
-
- |
- |
- |
- |
-
- address
-
-
- string
-
- |
-
- |
-
- IP address or prefix to translate to.
- |
-
-
-
-
-
-
- |
running_config
string
|
|
This option is used only with state parsed.
The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep nat.
The states replaced and overridden have identical behaviour for this module.
The state parsed reads the configuration from show configuration commands | grep nat option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
|
- |
+ |
state
string
|
Choices:
- deleted
merged ←
- overridden
- replaced
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|