diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst
index b5c97b49..fa2a890c 100644
--- a/docs/vyos.vyos.vyos_nat_module.rst
+++ b/docs/vyos.vyos.vyos_nat_module.rst
@@ -1,1677 +1,1560 @@
.. _vyos.vyos.vyos_nat_module:
******************
vyos.vyos.vyos_nat
******************
**NAT resource module**
Version added: 1.0.0
.. contents::
:local:
:depth: 1
Synopsis
--------
- This module manages NAT configuration on devices running Vyos
Parameters
----------
.. raw:: html
- | Parameter |
+ Parameter |
Choices/Defaults |
Comments |
- |
+ |
config
dictionary
|
|
The desired configuration for the NAT resource represented as a dictionary.
|
|
-
+ |
cgnat
dictionary
|
|
Configuration for Carrier Grade NAT (CGNAT).
|
|
|
-
+ |
log_allocation
boolean
|
|
Whether to log CGNAT address allocations.
|
|
|
-
+ |
pool
dictionary
|
|
Configuration for CGNAT pools.
|
|
|
|
-
+ |
external
list
/ elements=dictionary
|
|
List of external NAT pools for CGNAT.
|
|
|
|
|
-
+ |
external_port_range
string
|
|
Port range to use for NAT translations in this external pool.
|
|
|
|
|
-
+ |
name
string
/ required
|
|
Name of the external NAT pool.
|
|
|
|
|
+
+
+ per_user_limit
+
+
+ dictionary
+
+ |
+
+ |
+
+ Per-user limit configuration for the external pool.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
- per_user_limit_port
+ port
integer
|
|
Maximum number of ports allocated per user.
|
+
|
|
|
|
-
+ |
- ranges
+ range
list
/ elements=string
|
|
List of external IP addresses or prefixes in the pool.
|
|
|
|
-
+ |
internal
list
/ elements=dictionary
|
|
List of internal NAT pools for CGNAT.
|
|
|
|
|
-
+ |
name
string
/ required
|
|
Name of the internal NAT pool.
|
|
|
|
|
-
+ |
- ranges
+ range
list
/ elements=string
|
|
List of internal IP addresses or prefixes in the pool.
|
|
|
-
+ |
rule
list
/ elements=dictionary
|
|
List of CGNAT rules.
|
|
|
|
-
+ |
id
integer
/ required
|
|
Rule number for CGNAT.
|
|
|
|
-
+ |
source
dictionary
|
|
Source configuration for CGNAT translation.
|
|
|
|
|
-
+ |
pool
string
|
|
Source pool to use for CGNAT translation.
|
|
|
|
-
+ |
translation
dictionary
|
|
Translation configuration for CGNAT.
|
|
|
|
|
-
+ |
pool
string
|
|
Translation pool to use for CGNAT translation.
|
|
-
+ |
destination
dictionary
|
|
Configuration for destination NAT rules.
|
|
|
-
+ |
rule
list
/ elements=dictionary
|
|
List of destination NAT rules.
|
|
|
|
-
+ |
description
string
|
|
User-friendly description of the destination NAT rule.
|
|
|
|
-
+ |
destination
dictionary
|
|
Match criteria for destination NAT.
|
|
|
|
|
-
+ |
address
string
|
|
IP address, subnet, or range to match for destination NAT.
|
|
|
|
|
-
+ |
disable
boolean
|
|
Disable this destination NAT rule.
|
|
|
|
|
-
+ |
exclude
boolean
|
|
Exclude packets matching this rule from NAT.
|
|
|
|
|
-
+ |
fqdn
string
|
|
Fully qualified domain name to match for destination NAT.
|
|
|
|
|
-
+ |
- log
+ group
- boolean
+ dictionary
|
-
|
- Log packets hitting this destination NAT rule.
+ Address/network/port group to match for destination NAT.
|
-
+
+ |
|
|
|
|
- port
+ address_group
string
|
|
- Port number or range for destination NAT, can include named ports or comma-separated lists.
+ Address group name to match.
|
|
|
|
|
+ |
- protocol
+ domain_group
string
|
|
- Protocol to match (TCP, UDP, ICMP, etc.).
+ Domain group name to match.
|
-
|
|
|
-
+ | |
+ |
+
- id
+ mac_group
- integer
- / required
+ string
|
|
- Rule number for destination NAT.
+ MAC address group name to match.
|
-
-
|
-
+ | |
+ |
+ |
+ |
+
- source
+ network_group
- dictionary
+ string
|
|
- Configuration for source NAT rules.
+ Network group name to match.
|
-
+
|
|
-
+ | |
+ |
+ |
+
- rule
+ port_group
- list
- / elements=dictionary
+ string
|
|
- List of source NAT rules.
+ Port group name to match.
|
-
+
+
+ |
|
|
|
- description
+ log
- string
+ boolean
|
+
|
- User-friendly description of the source NAT rule.
+ Log packets hitting this destination NAT rule.
|
|
|
|
+ |
- destination
+ port
- dictionary
+ string
|
|
- Match criteria for source NAT.
+ Port number or range for destination NAT.
|
-
+
|
|
|
|
-
+ |
- address
+ protocol
string
|
|
- IP address, subnet, or range to match for source NAT.
+ Protocol to match (TCP, UDP, ICMP, etc.).
|
|
|
|
-
+ |
id
integer
/ required
|
|
- Rule number for source NAT.
+ Rule number for destination NAT.
|
|
-
+ |
- static
+ source
dictionary
|
|
- Configuration for static NAT rules.
+ Configuration for source NAT rules.
|
|
|
-
+ |
rule
list
/ elements=dictionary
|
|
- List of static NAT rules.
+ List of source NAT rules.
|
|
|
|
-
+ |
description
string
|
|
- User-friendly description of the static NAT rule.
+ User-friendly description of the source NAT rule.
|
|
|
|
+
+
+ destination
+
+
+ dictionary
+
+ |
+
+ |
+
+ Match criteria for source NAT.
+ |
+
+
+ |
+ |
+ |
+ |
- id
+ address
- integer
- / required
+ string
|
|
- Rule number for static NAT (one-to-one).
+ IP address, subnet, or range to match for source NAT.
|
|
|
|
+ |
- inbound_interface
+ disable
- list
- / elements=string
+ boolean
|
+
|
- List of inbound interfaces that this static NAT rule applies to.
+ Disable this source NAT rule.
|
|
|
|
+ |
- translation
+ exclude
- dictionary
+ boolean
|
+
|
- Translation configuration for static NAT.
+ Exclude packets matching this rule from NAT.
|
-
+
|
|
|
|
-
+ |
- address
+ fqdn
string
|
|
- IP address or prefix to translate to (destination of the static NAT).
+ Fully qualified domain name to match for source NAT.
|
-
-
-
-
- |
+ | |
+ |
+ |
+ |
+
- running_config
+ group
- string
+ dictionary
|
|
- This option is used only with state parsed.
- The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep ntp.
- The states replaced and overridden have identical behaviour for this module.
- The state parsed reads the configuration from show configuration commands | grep ntp option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
+ Address/network/port group to match for source NAT.
|
-
- |
+ |
+ |
+ |
+ |
+ |
+ |
+
- state
+ address_group
string
|
- Choices:
- - deleted
- merged ←
- - overridden
- - replaced
- - gathered
- - rendered
- - parsed
-
|
- The state the configuration should be left in.
+ Address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ domain_group
+
+
+ string
+
+ |
+
+ |
+
+ Domain group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ mac_group
+
+
+ string
+
+ |
+
+ |
+
+ MAC address group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ network_group
+
+
+ string
+
+ |
+
+ |
+
+ Network group name to match.
+ |
+
+
+ |
+ |
+ |
+ |
+ |
+
+
+ port_group
+
+
+ string
+
+ |
+
+ |
+
+ Port group name to match.
|
-
-