diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst
index 2bacac84..af9a68fa 100644
--- a/docs/vyos.vyos.vyos_nat_module.rst
+++ b/docs/vyos.vyos.vyos_nat_module.rst
@@ -1,2803 +1,3293 @@
.. _vyos.vyos.vyos_nat_module:
******************
vyos.vyos.vyos_nat
******************
**NAT resource module**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
-- This module manages NAT configuration on devices running Vyos
+- This module manages NAT configuration on devices running VyOS.
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Comments |
|
config
dictionary
|
|
The desired configuration for the NAT resource represented as a dictionary.
|
|
nat
dictionary
|
|
Configuration for NAT rules.
|
|
|
cgnat
dictionary
|
|
Configuration for Carrier Grade NAT (CGNAT).
|
|
|
|
log_allocation
boolean
|
|
- Whether to log CGNAT address allocations.
+ Log CGNAT address allocations.
|
|
|
|
pool
dictionary
|
|
Configuration for CGNAT pools.
|
|
|
|
|
external
list
/ elements=dictionary
|
|
List of external NAT pools for CGNAT.
|
|
|
|
|
|
external_port_range
string
|
|
Port range to use for NAT translations in this external pool.
|
|
|
|
|
|
name
string
/ required
|
|
Name of the external NAT pool.
|
|
|
|
|
|
per_user_limit
dictionary
|
|
Per-user limit configuration for the external pool.
|
|
|
|
|
|
|
port
- integer
+ string
|
|
Maximum number of ports allocated per user.
|
|
|
|
|
|
range
list
/ elements=string
|
|
List of external IP addresses or prefixes in the pool.
|
|
|
|
|
internal
list
/ elements=dictionary
|
|
List of internal NAT pools for CGNAT.
|
|
|
|
|
|
name
string
/ required
|
|
Name of the internal NAT pool.
|
|
|
|
|
|
range
list
/ elements=string
|
|
List of internal IP addresses or prefixes in the pool.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of CGNAT rules.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for CGNAT.
|
|
|
|
|
source
dictionary
|
|
- Source configuration for CGNAT translation.
+ Source pool configuration for CGNAT translation.
|
|
|
|
|
|
pool
string
|
|
- Source pool to use for CGNAT translation.
+ Source pool name to use for CGNAT translation.
|
|
|
|
|
translation
dictionary
|
|
- Translation configuration for CGNAT.
+ Translation pool configuration for CGNAT.
|
|
|
|
|
|
pool
string
|
|
- Translation pool to use for CGNAT translation.
+ Translation pool name to use for CGNAT translation.
|
|
|
destination
dictionary
|
|
Configuration for destination NAT rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of destination NAT rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the destination NAT rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for destination NAT.
|
|
|
|
|
|
address
string
|
|
- IP address, subnet, or range to match for destination NAT.
+ IP address, subnet, or range to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ address_group
+
+
+ string
+
+ |
+
+ |
+
+ Address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ domain_group
+
+
+ string
+
+ |
+
+ |
+
+ Domain group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ fqdn
+
+
+ string
+
+ |
+
+ |
+
+ Fully qualified domain name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ mac_group
+
+
+ string
+
+ |
+
+ |
+
+ MAC address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ network_group
+
+
+ string
+
+ |
+
+ |
+
+ Network group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ port
+
+
+ string
+
+ |
+
+ |
+
+ Port number or range to match.
|
|
|
|
|
|
+
+ port_group
+
+
+ string
+
+ |
+
+ |
+
+ Port group name to match.
+ |
+
+
+
+ |
+ |
+ |
+ |
+
disable
boolean
|
|
Disable this destination NAT rule.
|
|
|
|
|
- |
-
+ |
exclude
boolean
|
|
Exclude packets matching this rule from NAT.
|
|
|
|
|
+
+
+ id
+
+
+ integer
+ / required
+
+ |
+
+ |
+
+ Rule number for destination NAT.
+ |
+
+
+ |
+ |
+ |
+ |
+
+
+ inbound_interface
+
+
+ dictionary
+
+ |
+
+ |
+
+ Match inbound interface.
+ |
+
+
+ |
+ |
+ |
+ |
|
- fqdn
+ group
string
|
|
- Fully qualified domain name to match for destination NAT.
+ Interface group to match.
|
|
|
|
|
|
- group
+ name
- dictionary
+ string
|
|
- Address/network/port group to match for destination NAT.
+ Interface name to match.
|
-
+
+
+ |
+ |
|
|
+
+
+ log
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Log packets hitting this rule.
+ |
+
+
|
|
|
|
-
+ |
- address_group
+ packet_type
string
|
|
- Address group name to match.
+ Packet type to match.
|
|
|
|
|
- |
- |
-
+ |
- domain_group
+ protocol
string
|
|
- Domain group name to match.
+ Protocol to NAT (default all).
|
|
|
|
|
+
+
+ translation
+
+
+ dictionary
+
+ |
+
+ |
+
+ Translation configuration for destination NAT.
+ |
+
+
+ |
+ |
+ |
|
|
-
+ |
- mac_group
+ address
string
|
|
- MAC address group name to match.
+ IP address or prefix to translate destination to.
|
|
|
|
|
|
- |
-
+ |
- network_group
+ address_mapping
string
|
+ Choices:
+ - random
+ - persistent
+
|
- Network group name to match.
+ Address mapping mode for translation.
|
|
|
|
|
|
- |
-
+ |
- port_group
+ port
+
+
+ string
+
+ |
+
+ |
+
+ Port number or range to translate destination port to.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ port_mapping
+
+
+ string
+
+ |
+
+ Choices:
+ - random
+ - none
+
+ |
+
+ Port mapping mode for translation.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ redirect_port
+
+
+ string
+
+ |
+
+ |
+
+ Redirect to local port number.
+ |
+
+
+
+
+
+ |
+ |
+
+
+ source
+
+
+ dictionary
+
+ |
+
+ |
+
+ Configuration for source NAT rules.
+ |
+
+
+ |
+ |
+ |
+
+
+ rule
+
+
+ list
+ / elements=dictionary
+
+ |
+
+ |
+
+ List of source NAT rules.
+ |
+
+
+ |
+ |
+ |
+ |
+
+
+ description
+
+
+ string
+
+ |
+
+ |
+
+ User-friendly description of the source NAT rule.
+ |
+
+
+ |
+ |
+ |
+ |
+
+
+ destination
+
+
+ dictionary
+
+ |
+
+ |
+
+ Destination match criteria for source NAT.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ address
+
+
+ string
+
+ |
+
+ |
+
+ IP address, subnet, or range to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ address_group
+
+
+ string
+
+ |
+
+ |
+
+ Address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ domain_group
+
+
+ string
+
+ |
+
+ |
+
+ Domain group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ fqdn
+
+
+ string
+
+ |
+
+ |
+
+ Fully qualified domain name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ mac_group
+
+
+ string
+
+ |
+
+ |
+
+ MAC address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ network_group
+
+
+ string
+
+ |
+
+ |
+
+ Network group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ port
+
+
+ string
+
+ |
+
+ |
+
+ Port number or range to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ port_group
+
+
+ string
+
+ |
+
+ |
+
+ Port group name to match.
+ |
+
+
+
+ |
+ |
+ |
+ |
+
+
+ disable
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Disable this source NAT rule.
+ |
+
+
+ |
+ |
+ |
+ |
+
+
+ exclude
+
+
+ boolean
+
+ |
+
+
+ |
+
+ Exclude packets matching this rule from NAT.
+ |
+
+
+ |
+ |
+ |
+ |
+
+
+ id
- string
+ integer
+ / required
|
|
- Port group name to match.
+ Rule number for source NAT.
|
-
|
|
|
|
- |
-
+ |
log
boolean
|
|
- Log packets hitting this destination NAT rule.
+ Log packets hitting this rule.
|
|
|
|
|
- |
-
+ |
- port
+ outbound_interface
- string
+ dictionary
|
|
- Port number or range for destination NAT.
+ Match outbound interface.
|
-
+
|
|
|
|
|
- protocol
+ group
string
|
|
- Protocol to match (TCP, UDP, ICMP, etc.).
+ Interface group to match.
|
-
|
|
|
|
-
+ | |
+
- id
+ name
- integer
- / required
+ string
|
|
- Rule number for destination NAT.
+ Interface name to match.
|
-
|
|
-
-
- source
-
-
- dictionary
-
- |
-
- |
-
- Configuration for source NAT rules.
- |
-
-
- |
|
|
-
+ |
- rule
+ packet_type
- list
- / elements=dictionary
+ string
|
|
- List of source NAT rules.
+ Packet type to match.
|
-
+
|
|
|
|
- description
+ protocol
string
|
|
- User-friendly description of the source NAT rule.
+ Protocol to NAT (default all).
|
|
|
|
|
- destination
+ source
dictionary
|
|
- Match criteria for source NAT.
+ Source match criteria for source NAT.
|
|
|
|
|
|
address
string
|
|
- IP address, subnet, or range to match for source NAT.
+ IP address, subnet, or range to match.
|
|
|
|
|
|
- disable
+ address_group
- boolean
+ string
|
-
|
- Disable this source NAT rule.
+ Address group name to match.
|
|
|
|
|
|
- exclude
+ domain_group
- boolean
+ string
|
-
|
- Exclude packets matching this rule from NAT.
+ Domain group name to match.
|
|
|
|
|
|
fqdn
string
|
|
- Fully qualified domain name to match for source NAT.
+ Fully qualified domain name to match.
|
|
|
|
|
|
- group
+ mac_group
- dictionary
+ string
|
|
- Address/network/port group to match for source NAT.
+ MAC address group name to match.
|
-
- |
+
|
|
|
|
|
-
+ |
- address_group
+ network_group
string
|
|
- Address group name to match.
+ Network group name to match.
|
|
|
|
|
|
- |
-
+ |
- domain_group
+ port
string
|
|
- Domain group name to match.
+ Port number or range to match.
|
|
|
|
|
|
- |
-
+ |
- mac_group
+ port_group
string
|
|
- MAC address group name to match.
+ Port group name to match.
|
+
|
|
|
|
- |
- |
-
+ |
- network_group
+ translation
- string
+ dictionary
|
|
- Network group name to match.
+ Translation configuration for source NAT.
|
-
- |
+
|
|
|
|
|
-
+ |
- port_group
+ address
string
|
|
- Port group name to match.
+ IP address or prefix to translate source to. Use masquerade to masquerade as the outbound interface address.
|
-
|
|
|
|
|
- log
+ address_mapping
- boolean
+ string
|
Choices:
- - no
- - yes
+ - random
+ - persistent
|
- Log packets hitting this source NAT rule.
+ Address mapping mode for translation.
|
|
|
|
|
|
port
string
|
|
- Port number or range for source NAT.
+ Port number or range to translate source port to.
|
|
|
|
|
|
- protocol
+ port_mapping
string
|
+ Choices:
+ - random
+ - none
+
|
- Protocol to match (TCP, UDP, ICMP, etc.).
+ Port mapping mode for translation.
|
-
- |
- |
- |
- |
-
-
- id
-
-
- integer
- / required
-
- |
-
- |
-
- Rule number for source NAT.
- |
-
|
|
static
dictionary
|
|
- Configuration for static NAT rules.
+ Configuration for static one-to-one NAT rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of static NAT rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the static NAT rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for static NAT.
|
|
|
|
|
|
address
string
|
|
- IP address, subnet, or range to match for static NAT.
+ IP address, subnet, or range to match.
|
-
- |
- |
- |
- |
-
-
- disable
-
-
- boolean
-
- |
-
-
- |
-
- Disable this static NAT rule.
- |
-
|
|
|
|
id
integer
/ required
|
|
- Rule number for static NAT (one-to-one).
+ Rule number for static NAT.
|
|
|
|
|
inbound_interface
string
|
|
- List of inbound interfaces that this static NAT rule applies to.
+ Inbound interface that this static NAT rule applies to.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this static NAT rule.
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for static NAT.
|
|
|
|
|
|
address
string
|
|
IP address or prefix to translate to.
|
|
nat64
dictionary
|
|
- Configuration for NAT64 (IPv6-to-IPv4 NAT) rules.
+ Configuration for NAT64 (IPv6-to-IPv4) rules.
|
|
|
source
dictionary
|
|
Configuration for NAT64 source rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT64 source rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT64 source rule.
|
|
|
|
|
disable
boolean
|
|
Disable this NAT64 source rule.
|
|
|
|
|
id
integer
/ required
|
|
- Rule number for NAT64 source rule.
+ Rule number for NAT64 source rule (1-999999).
|
|
|
|
|
match
dictionary
|
|
Match criteria for NAT64 source rule.
|
|
|
|
|
|
mark
- integer
+ string
|
|
Match on firewall mark value (1-2147483647).
|
|
|
|
|
source
dictionary
|
|
- Source prefix to match for NAT64 translation.
+ IPv6 source prefix to match for NAT64 translation.
|
|
|
|
|
|
prefix
string
|
|
IPv6 source prefix to match (h:h:h:h:h:h:h:h/x).
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT64 source rule.
|
|
|
|
|
|
pool
list
/ elements=dictionary
|
|
List of translation pools for NAT64.
|
|
|
|
|
|
|
address
string
|
|
IPv4 address or prefix for translation pool.
|
|
|
|
|
|
|
description
string
|
|
User-friendly description of the translation pool.
|
|
|
|
|
|
|
disable
boolean
|
|
Disable this translation pool.
|
|
|
|
|
|
|
id
integer
/ required
|
|
Pool number (1-999999).
|
|
|
|
|
|
|
port
string
|
|
Port number or range for translation pool.
|
|
|
|
|
|
|
protocol
string
|
|
Protocol for this translation pool entry.
|
|
nat66
dictionary
|
|
- Configuration for NAT66 (IPv6-to-IPv6 NAT) rules.
+ Configuration for NAT66 (IPv6-to-IPv6) rules.
|
|
|
destination
dictionary
|
|
Configuration for NAT66 destination rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT66 destination rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT66 destination rule.
|
|
|
|
|
destination
dictionary
|
|
Match criteria for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
- IPv6 address or prefix to match. Supports single address (h:h:h:h:h:h:h:h), prefix (h:h:h:h:h:h:h:h/x), and negated forms (!h:h:h:h:h:h:h:h, !h:h:h:h:h:h:h:h/x).
+ IPv6 address or prefix to match.
|
|
|
|
|
|
port
string
|
|
- Port number, range, or name to match.
+ Port number or range to match.
|
|
|
|
|
disable
boolean
|
|
Disable this NAT66 destination rule.
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT66.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for NAT66 destination rule.
|
|
|
|
|
inbound_interface
dictionary
|
|
Inbound interface to match for NAT66 destination rule.
|
|
|
|
|
|
name
string
|
|
- Interface name to match. Supports wildcard (txt*) and negated (!text) forms.
+ Interface name to match.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this NAT66 destination rule.
|
|
|
|
|
protocol
string
|
|
- Protocol to match. Supports named protocols, numeric (0-255), negated (!protocol), all, and tcp_udp.
+ Protocol to match.
|
|
|
|
|
source
dictionary
|
|
Source match criteria for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
- IPv6 source address or prefix to match. Supports single address, prefix, and negated forms.
+ IPv6 source address or prefix to match.
|
|
|
|
|
|
port
string
|
|
- Source port number, range, or name to match.
+ Source port number or range to match.
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT66 destination rule.
|
|
|
|
|
|
address
string
|
|
IPv6 address or prefix to translate destination to.
|
|
|
|
|
|
port
string
|
|
Port number or range to translate destination port to.
|
|
|
source
dictionary
|
|
Configuration for NAT66 source rules.
|
|
|
|
rule
list
/ elements=dictionary
|
|
List of NAT66 source rules.
|
|
|
|
|
description
string
|
|
User-friendly description of the NAT66 source rule.
|
|
|
|
|
destination
dictionary
|
|
Destination match criteria for NAT66 source rule.
|
|
|
|
|
|
port
string
|
|
- Destination port number, range, or name to match.
+ Destination port number or range to match.
|
|
|
|
|
|
prefix
string
|
|
- IPv6 destination prefix to match (h:h:h:h:h:h:h:h/x). Supports negated form (!h:h:h:h:h:h:h:h/x).
+ IPv6 destination prefix to match (h:h:h:h:h:h:h:h/x).
|
|
|
|
|
disable
boolean
|
|
Disable this NAT66 source rule.
|
|
|
|
|
exclude
boolean
|
|
Exclude packets matching this rule from NAT66.
|
|
|
|
|
id
integer
/ required
|
|
Rule number for NAT66 source rule.
|
|
|
|
|
log
boolean
|
|
Log packets hitting this NAT66 source rule.
|
|
|
|
|
outbound_interface
dictionary
|
|
Outbound interface to match for NAT66 source rule.
|
|
|
|
|
|
name
string
|
|
- Interface name to match. Supports wildcard (txt*) and negated (!text) forms.
+ Interface name to match.
|
|
|
|
|
protocol
string
|
|
- Protocol to match. Supports named protocols, numeric (0-255), negated (!protocol), all, and tcp_udp.
+ Protocol to match.
|
|
|
|
|
source
dictionary
|
|
Source match criteria for NAT66 source rule.
|
|
|
|
|
|
port
string
|
|
- Source port number, range, or name to match.
+ Source port number or range to match.
|
|
|
|
|
|
prefix
string
|
|
- IPv6 source prefix to match (h:h:h:h:h:h:h:h/x). Supports negated form (!h:h:h:h:h:h:h:h/x).
+ IPv6 source prefix to match (h:h:h:h:h:h:h:h/x).
|
|
|
|
|
translation
dictionary
|
|
Translation configuration for NAT66 source rule.
|
|
|
|
|
|
address
string
|
|
IPv6 address or prefix to translate source to. Use masquerade to masquerade as the outbound interface address.
|
|
|
|
|
|
port
string
|
|
Port number or range to translate source port to.
|
|
running_config
string
|
|
This option is used only with state parsed.
- The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep nat.
+ The value of this option should be the output received from the VyOS device by executing the command show configuration commands | grep nat.
+ The state parsed reads the configuration from show configuration commands | grep nat and transforms it into Ansible structured data as per the module argspec. The value is then returned in the parsed key within the result.
The states replaced and overridden have identical behaviour for this module.
- The state parsed reads the configuration from show configuration commands | grep nat option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
|
|
state
string
|
Choices:
- deleted
merged ←
- overridden
- replaced
- gathered
- rendered
- parsed
|
The state the configuration should be left in.
|