diff --git a/docs/vyos.vyos.vyos_nat_module.rst b/docs/vyos.vyos.vyos_nat_module.rst index b5c97b49..fa2a890c 100644 --- a/docs/vyos.vyos.vyos_nat_module.rst +++ b/docs/vyos.vyos.vyos_nat_module.rst @@ -1,1677 +1,1560 @@ .. _vyos.vyos.vyos_nat_module: ****************** vyos.vyos.vyos_nat ****************** **NAT resource module** Version added: 1.0.0 .. contents:: :local: :depth: 1 Synopsis -------- - This module manages NAT configuration on devices running Vyos Parameters ---------- .. raw:: html - + - - - - - - - + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - + + + - - + + - - - + + + + - + - + + + - + + + + - + - - - - - + + + + + + + + + + + - + - - - - - - + + + + - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + -
ParameterParameter Choices/Defaults Comments
+
config
dictionary
The desired configuration for the NAT resource represented as a dictionary.
+
cgnat
dictionary
Configuration for Carrier Grade NAT (CGNAT).
+
log_allocation
boolean
    Choices:
  • no
  • yes
Whether to log CGNAT address allocations.
+
pool
dictionary
Configuration for CGNAT pools.
+
external
list / elements=dictionary
List of external NAT pools for CGNAT.
+
external_port_range
string
Port range to use for NAT translations in this external pool.
+
name
string / required
Name of the external NAT pool.
+
+ per_user_limit + +
+ dictionary +
+
+ +
Per-user limit configuration for the external pool.
+
- per_user_limit_port + port
integer
Maximum number of ports allocated per user.
+
- ranges + range
list / elements=string
List of external IP addresses or prefixes in the pool.
+
internal
list / elements=dictionary
List of internal NAT pools for CGNAT.
+
name
string / required
Name of the internal NAT pool.
+
- ranges + range
list / elements=string
List of internal IP addresses or prefixes in the pool.
+
rule
list / elements=dictionary
List of CGNAT rules.
+
id
integer / required
Rule number for CGNAT.
+
source
dictionary
Source configuration for CGNAT translation.
+
pool
string
Source pool to use for CGNAT translation.
+
translation
dictionary
Translation configuration for CGNAT.
+
pool
string
Translation pool to use for CGNAT translation.
+
destination
dictionary
Configuration for destination NAT rules.
+
rule
list / elements=dictionary
List of destination NAT rules.
+
description
string
User-friendly description of the destination NAT rule.
+
destination
dictionary
Match criteria for destination NAT.
+
address
string
IP address, subnet, or range to match for destination NAT.
+
disable
boolean
    Choices:
  • no
  • yes
Disable this destination NAT rule.
+
exclude
boolean
    Choices:
  • no
  • yes
Exclude packets matching this rule from NAT.
+
fqdn
string
Fully qualified domain name to match for destination NAT.
+
- log + group
- boolean + dictionary
-
    Choices: -
  • no
  • -
  • yes
  • -
-
Log packets hitting this destination NAT rule.
+
Address/network/port group to match for destination NAT.
- port + address_group
string
-
Port number or range for destination NAT, can include named ports or comma-separated lists.
+
Address group name to match.
- protocol + domain_group
string
-
Protocol to match (TCP, UDP, ICMP, etc.).
+
Domain group name to match.
+
- id + mac_group
- integer - / required + string
-
Rule number for destination NAT.
+
MAC address group name to match.
+
- source + network_group
- dictionary + string
-
Configuration for source NAT rules.
+
Network group name to match.
+
- rule + port_group
- list - / elements=dictionary + string
-
List of source NAT rules.
+
Port group name to match.
- description + log
- string + boolean
+
    Choices: +
  • no
  • +
  • yes
  • +
-
User-friendly description of the source NAT rule.
+
Log packets hitting this destination NAT rule.
- destination + port
- dictionary + string
-
Match criteria for source NAT.
+
Port number or range for destination NAT.
+
- address + protocol
string
-
IP address, subnet, or range to match for source NAT.
+
Protocol to match (TCP, UDP, ICMP, etc.).
+
id
integer / required
-
Rule number for source NAT.
+
Rule number for destination NAT.
+
- static + source
dictionary
-
Configuration for static NAT rules.
+
Configuration for source NAT rules.
+
rule
list / elements=dictionary
-
List of static NAT rules.
+
List of source NAT rules.
+
description
string
-
User-friendly description of the static NAT rule.
+
User-friendly description of the source NAT rule.
+
+ destination + +
+ dictionary +
+
+ +
Match criteria for source NAT.
+
- id + address
- integer - / required + string
-
Rule number for static NAT (one-to-one).
+
IP address, subnet, or range to match for source NAT.
- inbound_interface + disable
- list - / elements=string + boolean
+
    Choices: +
  • no
  • +
  • yes
  • +
-
List of inbound interfaces that this static NAT rule applies to.
+
Disable this source NAT rule.
- translation + exclude
- dictionary + boolean
+
    Choices: +
  • no
  • +
  • yes
  • +
-
Translation configuration for static NAT.
+
Exclude packets matching this rule from NAT.
+
- address + fqdn
string
-
IP address or prefix to translate to (destination of the static NAT).
+
Fully qualified domain name to match for source NAT.
+
- running_config + group
- string + dictionary
-
This option is used only with state parsed.
-
The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep ntp.
-
The states replaced and overridden have identical behaviour for this module.
-
The state parsed reads the configuration from show configuration commands | grep ntp option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
+
Address/network/port group to match for source NAT.
+
- state + address_group
string
-
    Choices: -
  • deleted
  • -
  • merged ←
  • -
  • overridden
  • -
  • replaced
  • -
  • gathered
  • -
  • rendered
  • -
  • parsed
  • -
-
The state the configuration should be left in.
+
Address group name to match.
+
+
+ domain_group + +
+ string +
+
+ +
Domain group name to match.
+
+
+ mac_group + +
+ string +
+
+ +
MAC address group name to match.
+
+
+ network_group + +
+ string +
+
+ +
Network group name to match.
+
+
+ port_group + +
+ string +
+
+ +
Port group name to match.
-
- - -Notes ------ - -.. note:: - - Tested against VyOS 1.3.8, 1.4.2, the upcoming 1.5, and the rolling release of spring 2025 - - This module works with connection ``network_cli``. - - - -Examples --------- -.. code-block:: yaml + + + + + + +
+ log + +
+ boolean +
+ + + + + +
Log packets hitting this source NAT rule.
+ + + + + + + + +
+ port + +
+ string +
+ + + + +
Port number or range for source NAT.
+ + + + + + + + +
+ protocol + +
+ string +
+ + + + +
Protocol to match (TCP, UDP, ICMP, etc.).
+ + - # # ------------------- - # # 1. Using merged - # # ------------------- + + + + + +
+ id + +
+ integer + / required +
+ + + + +
Rule number for source NAT.
+ + - # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - # # Task - # # ------------- - - name: Replace the existing ntp config with the new config - vyos.vyos.vyos_ntp_global: - config: - allow_clients: - - 10.6.6.0/24 - listen_addresses: - - 10.1.3.1 - servers: - - server: 203.0.113.0 - options: - - prefer + + + +
+ static + +
+ dictionary +
+ + + + +
Configuration for static NAT rules.
+ + + + + + +
+ rule + +
+ list + / elements=dictionary +
+ + + + +
List of static NAT rules.
+ + + + + + + +
+ description + +
+ string +
+ + + + +
User-friendly description of the static NAT rule.
+ + + + + + + +
+ destination + +
+ dictionary +
+ + + + +
Match criteria for static NAT.
+ + + + + + + + +
+ address + +
+ string +
+ + + + +
IP address, subnet, or range to match for static NAT.
+ + + + + + + +
+ disable + +
+ boolean +
+ + + + + +
Disable this static NAT rule.
+ + + + + + + +
+ id + +
+ integer + / required +
+ + + + +
Rule number for static NAT (one-to-one).
+ + + + + + + +
+ inbound_interface + +
+ list + / elements=string +
+ + + + +
List of inbound interfaces that this static NAT rule applies to.
+ + + + + + + +
+ log + +
+ boolean +
+ + + + + +
Log packets hitting this static NAT rule.
+ + + + + + + +
+ translation + +
+ dictionary +
+ + + + +
Translation configuration for static NAT.
+ + + + + + + + +
+ address + +
+ string +
+ + + + +
IP address or prefix to translate to.
+ + - # Task output: - # ------------- - # "after": { - # "allow_clients": [ - # "10.6.6.0/24" - # ], - # "listen_addresses": [ - # "10.1.3.1" - # ], - # "servers": [ - # { - # "server": "ser", - # "options": [ - # "prefer" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "before": { - # }, - # "changed": true, - # "commands": [ - # "set service ntp allow-clients address 10.6.6.0/24", - # "set service ntp listen-address 10.1.3.1", - # "set service ntp server 203.0.113.0 prefer" - # ] - # After state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.6.6.0/24' - # set service ntp listen-address '10.1.3.1' - # set service ntp server 203.0.113.0 prefer, - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - # # ------------------- - # # 2. Using replaced - # # ------------------- + + +
+ running_config + +
+ string +
+ + + + +
This option is used only with state parsed.
+
The value of this option should be the output received from the VYOS device by executing the command show configuration commands | grep nat.
+
The states replaced and overridden have identical behaviour for this module.
+
The state parsed reads the configuration from show configuration commands | grep nat option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the parsed key within the result.
+ + + + +
+ state + +
+ string +
+ + + + + +
The state the configuration should be left in.
+ + + +
- # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.4.9.0/24' - # set service ntp allow-clients address '10.4.7.0/24' - # set service ntp allow-clients address '10.1.2.0/24' - # set service ntp allow-clients address '10.2.3.0/24' - # set service ntp listen-address '10.1.9.16' - # set service ntp listen-address '10.5.3.2' - # set service ntp listen-address '10.7.9.21' - # set service ntp listen-address '10.8.9.4' - # set service ntp listen-address '10.4.5.1' - # set service ntp server 10.3.6.5 noselect - # set service ntp server 10.3.6.5 dynamic - # set service ntp server 10.3.6.5 preempt - # set service ntp server 10.3.6.5 prefer - # set service ntp server server4 noselect - # set service ntp server server4 dynamic - # set service ntp server server5 - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - # # Task - # # ------------- - - name: Replace the existing ntp config with the new config - vyos.vyos.vyos_ntp_global: - config: - allow_clients: - - 10.6.6.0/24 - listen_addresses: - - 10.1.3.1 - servers: - - server: 203.0.113.0 - options: - - prefer - state: replaced +Notes +----- +.. note:: + - Tested against VyOS 1.3.8, 1.4.2, the upcoming 1.5, and the rolling release of spring 2025 + - This module works with connection ``network_cli``. - # # Task output: - # # ------------- - # "after": { - # "allow_clients": [ - # "10.6.6.0/24" - # ], - # "listen_addresses": [ - # "10.1.3.1" - # ], - # "servers": [ - # { - # "server": "ser", - # "options": [ - # "prefer" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "before": { - # "allow_clients": [ - # "10.4.7.0/24", - # "10.2.3.0/24", - # "10.1.2.0/24", - # "10.4.9.0/24" - # ], - # "listen_addresses": [ - # "10.7.9.21", - # "10.4.5.1", - # "10.5.3.2", - # "10.8.9.4", - # "10.1.9.16" - # ], - # "servers": [ - # { - # "server": "10.3.6.5", - # "options": [ - # "noselect", - # "dynamic", - # "preempt", - # "prefer" - # ] - # }, - # { - # "server": "server4", - # "options": [ - # "noselect", - # "dynamic" - # ] - # }, - # { - # "server": "server5" - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "changed": true, - # "commands": [ - # "delete service ntp allow-clients address 10.4.7.0/24", - # "delete service ntp allow-clients address 10.2.3.0/24", - # "delete service ntp allow-clients address 10.1.2.0/24", - # "delete service ntp allow-clients address 10.4.9.0/24", - # "delete service ntp listen-address 10.7.9.21", - # "delete service ntp listen-address 10.4.5.1", - # "delete service ntp listen-address 10.5.3.2", - # "delete service ntp listen-address 10.8.9.4", - # "delete service ntp listen-address 10.1.9.16", - # "delete service ntp server 10.3.6.5", - # "delete service ntp server server4", - # "delete service ntp server server5", - # "set service ntp allow-clients address 10.6.6.0/24", - # "set service ntp listen-address 10.1.3.1", - # "set service ntp server 203.0.113.0 prefer" - # ] - # After state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.6.6.0/24' - # set service ntp listen-address '10.1.3.1' - # set service ntp server 203.0.113.0 prefer, - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - # # ------------------- - # # 3. Using overridden - # # ------------------- +Examples +-------- - # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.6.6.0/24' - # set service ntp listen-address '10.1.3.1' - # set service ntp server 203.0.113.0 prefer, - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ +.. code-block:: yaml - # Task - # ------------- - - name: Override ntp config - vyos.vyos.vyos_ntp_global: + # Using merged + - name: Merge NAT source rule + vyos.vyos.vyos_nat: config: - allow_clients: - - 10.3.3.0/24 - listen_addresses: - - 10.7.8.1 - servers: - - server: server1 - options: - - dynamic - - prefer - - - server: server2 - options: - - noselect - - preempt - - - server: serv - state: overridden - - # # Task output: - # # ------------- - # "after": { - # "allow_clients": [ - # "10.3.3.0/24" - # ], - # "listen_addresses": [ - # "10.7.8.1" - # ], - # "servers": [ - # { - # "server": "serv" - # }, - # { - # "server": "server1", - # "options": [ - # "dynamic", - # "prefer" - # ] - # }, - # { - # "server": "server2", - # "options": [ - # "noselect", - # "preempt" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "before": { - # "allow_clients": [ - # "10.6.6.0/24" - # ], - # "listen_addresses": [ - # "10.1.3.1" - # ], - # "servers": [ - # { - # "server": "ser", - # "options": [ - # "prefer" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "changed": true, - # "commands": [ - # "delete service ntp allow-clients address 10.6.6.0/24", - # "delete service ntp listen-address 10.1.3.1", - # "delete service ntp server ser", - # "set service ntp allow-clients address 10.3.3.0/24", - # "set service ntp listen-address 10.7.8.1", - # "set service ntp server server1 dynamic", - # "set service ntp server server1 prefer", - # "set service ntp server server2 noselect", - # "set service ntp server server2 preempt", - # "set service ntp server serv" - # ] - - # After state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.3.3.0/24' - # set service ntp listen-address '10.7.8.1' - # set service ntp server serv - # set service ntp server server1 dynamic - # set service ntp server server1 prefer - # set service ntp server server2 noselect - # set service ntp server server2 preempt - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - # 4. Using gathered - # ------------------- - - # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.3.3.0/24' - # set service ntp listen-address '10.7.8.1' - # set service ntp server serv - # set service ntp server server1 dynamic - # set service ntp server server1 prefer - # set service ntp server server2 noselect - # set service ntp server server2 preempt - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - # Task - # ------------- - - name: Gather ntp config - vyos.vyos.vyos_ntp_global: + source: + rule: + - id: 100 + description: "Outbound masquerade" + state: merged + + # Using gathered + - name: Gather NAT config + vyos.vyos.vyos_nat: state: gathered - # # Task output: - # # ------------- - # "gathered": { - # "allow_clients": [ - # "10.3.3.0/24" - # ], - # "listen_addresses": [ - # "10.7.8.1" - # ], - # "servers": [ - # { - # "server": "serv" - # }, - # { - # "server": "server1", - # "options": [ - # "dynamic", - # "prefer" - # ] - # }, - # { - # "server": "server2", - # "options": [ - # "noselect", - # "preempt" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # } - - # After state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.3.3.0/24' - # set service ntp listen-address '10.7.8.1' - # set service ntp server serv - # set service ntp server server1 dynamic - # set service ntp server server1 prefer - # set service ntp server server2 noselect - # set service ntp server server2 preempt - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - - # # ------------------- - # # 5. Using deleted - # # ------------------- - - # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp allow-clients address '10.3.3.0/24' - # set service ntp listen-address '10.7.8.1' - # set service ntp server serv - # set service ntp server server1 dynamic - # set service ntp server server1 prefer - # set service ntp server server2 noselect - # set service ntp server server2 preempt - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - # # Task - # # ------------- - - name: Delete ntp config - vyos.vyos.vyos_ntp_global: + # Using deleted + - name: Delete NAT config + vyos.vyos.vyos_nat: state: deleted - - # # Task output: - # # ------------- - # "after": { - # "servers": [ - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "before": { - # "allow_clients": [ - # "10.3.3.0/24" - # ], - # "listen_addresses": [ - # "10.7.8.1" - # ], - # "servers": [ - # { - # "server": "serv" - # }, - # { - # "server": "server1", - # "options": [ - # "dynamic", - # "prefer" - # ] - # }, - # { - # "server": "server2", - # "options": [ - # "noselect", - # "preempt" - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # ] - # }, - # "changed": true, - # "commands": [ - # "delete service ntp allow-clients", - # "delete service ntp listen-address", - # "delete service ntp server serv", - # "delete service ntp server server1", - # "delete service ntp server server2" - # - # ] - - # After state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - - # # ------------------- - # # 6. Using rendered - # # ------------------- - - # # Before state: - # # ------------- - # vyos@vyos:~$ show configuration commands | grep ntp - # set service ntp server time1.vyos.net - # set service ntp server time2.vyos.net - # set service ntp server time3.vyos.net - # vyos@vyos:~$ - - # Task - # ------------- - - name: Render ntp config - vyos.vyos.vyos_ntp_global: + # Using replaced + - name: Replace NAT config + vyos.vyos.vyos_nat: config: - allow_clients: - - 10.7.7.0/24 - - 10.8.8.0/24 - listen_addresses: - - 10.7.9.1 - servers: - - server: server7 - - server: server45 - options: - - noselect - - prefer - - pool - - server: time1.vyos.net - - server: time2.vyos.net - - server: time3.vyos.net - state: rendered - - # # Task output: - # # ------------- - # "rendered": [ - # "set service ntp allow-clients address 10.7.7.0/24", - # "set service ntp allow-clients address 10.8.8.0/24", - # "set service ntp listen-address 10.7.9.1", - # "set service ntp server server7", - # "set service ntp server server45 noselect", - # "set service ntp server server45 prefer", - # "set service ntp server server45 pool", - # "set service ntp server time1.vyos.net", - # "set service ntp server time2.vyos.net", - # "set service ntp server time3.vyos.net" - # ] - - - # # ------------------- - # # 7. Using parsed - # # ------------------- - - # # sample_config.cfg: - # # ------------- - # "set service ntp allow-clients address 10.7.7.0/24", - # "set service ntp listen-address 10.7.9.1", - # "set service ntp server server45 noselect", - # "set service ntp allow-clients addres 10.8.6.0/24", - # "set service ntp listen-address 10.5.4.1", - # "set service ntp server server45 dynamic", - # "set service ntp server time1.vyos.net", - # "set service ntp server time2.vyos.net", - # "set service ntp server time3.vyos.net" + source: + rule: + - id: 100 + description: "Replaced rule" + state: replaced - # Task: - # ------------- - - name: Parse externally provided ntp configuration - vyos.vyos.vyos_ntp_global: - running_config: "{{ lookup('file', './sample_config.cfg') }}" + # Using parsed + - name: Parse NAT config + vyos.vyos.vyos_nat: + running_config: "{{ lookup('file', './nat_config.cfg') }}" state: parsed - # # Task output: - # # ------------- - # parsed = { - # "allow_clients": [ - # "10.7.7.0/24", - # "10.8.6.0/24 - # ], - # "listen_addresses": [ - # "10.5.4.1", - # "10.7.9.1" - # ], - # "servers": [ - # { - # "server": "server45", - # "options": [ - # "noselect", - # "dynamic" - # - # ] - # }, - # { - # "server": "time1.vyos.net" - # }, - # { - # "server": "time2.vyos.net" - # }, - # { - # "server": "time3.vyos.net" - # } - # - # ] - # } + # Using rendered + - name: Render NAT config offline + vyos.vyos.vyos_nat: + config: + source: + rule: + - id: 100 + description: "Rendered rule" + state: rendered Return Values ------------- Common return values are documented `here `_, the following are the fields unique to this module: .. raw:: html
Key Returned Description
after
dictionary
when changed
The resulting configuration after module execution.

Sample:
This output will always be in the same format as the module argspec.
before
dictionary
when state is merged, replaced, overridden, deleted or purged
The configuration prior to the module execution.

Sample:
This output will always be in the same format as the module argspec.
commands
list
when state is merged, replaced, overridden, deleted or purged
The set of commands pushed to the remote device.

Sample:
-
['set system ntp server server1 dynamic', 'set system ntp server server1 prefer', 'set system ntp server server2 noselect', 'set system ntp server server2 preempt', 'set system ntp server server_add preempt']
+
["set nat source rule 100 description 'Outbound masquerade'"]
gathered
- list + dictionary
when state is gathered
Facts about the network resource gathered from the remote device as structured data.

Sample:
This output will always be in the same format as the module argspec.
parsed
- list + dictionary
when state is parsed
The device native config provided in running_config option parsed into structured data as per module argspec.

Sample:
This output will always be in the same format as the module argspec.
rendered
list
when state is rendered
The provided configuration in the task rendered in device-native format (offline).

Sample:
-
['set system ntp server server1 dynamic', 'set system ntp server server1 prefer', 'set system ntp server server2 noselect', 'set system ntp server server2 preempt', 'set system ntp server server_add preempt']
+
["set nat source rule 100 description 'Rendered rule'"]


Status ------ Authors ~~~~~~~ - Evgeny Molotkov (@omnom62) diff --git a/plugins/module_utils/network/vyos/argspec/nat/nat.py b/plugins/module_utils/network/vyos/argspec/nat/nat.py index 88ed9fad..6ff5b579 100644 --- a/plugins/module_utils/network/vyos/argspec/nat/nat.py +++ b/plugins/module_utils/network/vyos/argspec/nat/nat.py @@ -1,304 +1,304 @@ # -*- coding: utf-8 -*- # Copyright 2024 Red Hat # GNU General Public License v3.0+ # (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) from __future__ import absolute_import, division, print_function __metaclass__ = type ############################################# # WARNING # ############################################# # # This file is auto generated by the # cli_rm_builder. # # Manually editing this file is not advised. # # To update the argspec make the desired changes # in the module docstring and re-run # cli_rm_builder. # ############################################# """ The arg spec for the vyos_nat module """ class NatArgs(object): # pylint: disable=R0903 """The arg spec for the vyos_nat module""" argument_spec = { "config": { "type": "dict", "options": { "cgnat": { "type": "dict", "options": { "log_allocation": { "type": "bool", }, "pool": { "type": "dict", "options": { "external": { "type": "list", "elements": "dict", "options": { "name": { "type": "str", "required": True, }, "external_port_range": { "type": "str", }, "per_user_limit": { "type": "dict", "options": { "port": { "type": "int", }, }, }, "range": { "type": "list", "elements": "str", }, }, }, "internal": { "type": "list", "elements": "dict", "options": { "name": { "type": "str", "required": True, }, "range": { "type": "list", "elements": "str", }, }, }, }, }, "rule": { "type": "list", "elements": "dict", "options": { "id": { "type": "int", "required": True, }, "source": { "type": "dict", "options": { "pool": { "type": "str", }, }, }, "translation": { "type": "dict", "options": { "pool": { "type": "str", }, }, }, }, }, }, }, "destination": { "type": "dict", "options": { "rule": { "type": "list", "elements": "dict", "options": { "id": { "type": "int", "required": True, }, "description": { "type": "str", }, "destination": { "type": "dict", "options": { "address": { "type": "str", }, "fqdn": { "type": "str", }, "group": { "type": "dict", "options": { - "address-group": { + "address_group": { "type": "str", }, - "domain-group": { + "domain_group": { "type": "str", }, - "mac-group": { + "mac_group": { "type": "str", }, - "network-group": { + "network_group": { "type": "str", }, - "port-group": { + "port_group": { "type": "str", }, }, }, "port": { "type": "str", }, "protocol": { "type": "str", }, "exclude": { "type": "bool", }, "log": { "type": "bool", }, "disable": { "type": "bool", }, }, }, }, }, }, }, "source": { "type": "dict", "options": { "rule": { "type": "list", "elements": "dict", "options": { "id": { "type": "int", "required": True, }, "description": { "type": "str", }, "destination": { "type": "dict", "options": { "address": { "type": "str", }, "fqdn": { "type": "str", }, "group": { "type": "dict", "options": { - "address-group": { + "address_group": { "type": "str", }, - "domain-group": { + "domain_group": { "type": "str", }, - "mac-group": { + "mac_group": { "type": "str", }, - "network-group": { + "network_group": { "type": "str", }, - "port-group": { + "port_group": { "type": "str", }, }, }, "port": { "type": "str", }, "protocol": { "type": "str", }, "exclude": { "type": "bool", }, "log": { "type": "bool", }, "disable": { "type": "bool", }, }, }, }, }, }, }, "static": { "type": "dict", "options": { "rule": { "type": "list", "elements": "dict", "options": { "id": { "type": "int", "required": True, }, "description": { "type": "str", }, "destination": { "type": "dict", "options": { "address": { "type": "str", }, }, }, "inbound_interface": { "type": "list", "elements": "str", }, "log": { "type": "bool", }, "disable": { "type": "bool", }, "translation": { "type": "dict", "options": { "address": { "type": "str", }, }, }, }, }, }, }, }, }, "running_config": {"type": "str"}, "state": { "type": "str", "choices": [ "deleted", "merged", "overridden", "replaced", "gathered", "rendered", "parsed", ], "default": "merged", }, } # pylint: disable=C0301 diff --git a/plugins/modules/vyos_nat.py b/plugins/modules/vyos_nat.py index f3c31f35..fec94c7a 100644 --- a/plugins/modules/vyos_nat.py +++ b/plugins/modules/vyos_nat.py @@ -1,935 +1,414 @@ #!/usr/bin/python # -*- coding: utf-8 -*- # Copyright 2024 Red Hat # GNU General Public License v3.0+ # (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt) """ The module file for vyos_nat """ from __future__ import absolute_import, division, print_function __metaclass__ = type DOCUMENTATION = """ module: vyos_nat version_added: 1.0.0 short_description: NAT resource module description: - This module manages NAT configuration on devices running Vyos author: - Evgeny Molotkov (@omnom62) notes: - Tested against VyOS 1.3.8, 1.4.2, the upcoming 1.5, and the rolling release of spring 2025 - This module works with connection C(network_cli). options: config: description: - The desired configuration for the NAT resource represented as a dictionary. type: dict suboptions: cgnat: type: dict description: Configuration for Carrier Grade NAT (CGNAT). suboptions: log_allocation: type: bool description: Whether to log CGNAT address allocations. pool: type: dict description: Configuration for CGNAT pools. suboptions: external: type: list elements: dict description: List of external NAT pools for CGNAT. suboptions: name: type: str required: true description: Name of the external NAT pool. external_port_range: type: str description: Port range to use for NAT translations in this external pool. - per_user_limit_port: - type: int - description: Maximum number of ports allocated per user. - ranges: + per_user_limit: + type: dict + description: Per-user limit configuration for the external pool. + suboptions: + port: + type: int + description: Maximum number of ports allocated per user. + range: type: list elements: str description: List of external IP addresses or prefixes in the pool. internal: type: list elements: dict description: List of internal NAT pools for CGNAT. suboptions: name: type: str required: true description: Name of the internal NAT pool. - ranges: + range: type: list elements: str description: List of internal IP addresses or prefixes in the pool. rule: type: list elements: dict description: List of CGNAT rules. suboptions: id: type: int required: true description: Rule number for CGNAT. source: type: dict description: Source configuration for CGNAT translation. suboptions: pool: type: str description: Source pool to use for CGNAT translation. translation: type: dict description: Translation configuration for CGNAT. suboptions: pool: type: str description: Translation pool to use for CGNAT translation. destination: type: dict description: Configuration for destination NAT rules. suboptions: rule: type: list elements: dict description: List of destination NAT rules. suboptions: id: type: int required: true description: Rule number for destination NAT. description: type: str description: User-friendly description of the destination NAT rule. destination: type: dict description: Match criteria for destination NAT. suboptions: address: type: str description: IP address, subnet, or range to match for destination NAT. fqdn: type: str description: Fully qualified domain name to match for destination NAT. + group: + type: dict + description: Address/network/port group to match for destination NAT. + suboptions: + address_group: + type: str + description: Address group name to match. + domain_group: + type: str + description: Domain group name to match. + mac_group: + type: str + description: MAC address group name to match. + network_group: + type: str + description: Network group name to match. + port_group: + type: str + description: Port group name to match. port: type: str - description: Port number or range for destination NAT, can include named ports or comma-separated lists. + description: Port number or range for destination NAT. protocol: type: str description: Protocol to match (TCP, UDP, ICMP, etc.). exclude: type: bool description: Exclude packets matching this rule from NAT. log: type: bool description: Log packets hitting this destination NAT rule. disable: type: bool description: Disable this destination NAT rule. source: type: dict description: Configuration for source NAT rules. suboptions: rule: type: list elements: dict description: List of source NAT rules. suboptions: id: type: int required: true description: Rule number for source NAT. description: type: str description: User-friendly description of the source NAT rule. destination: type: dict description: Match criteria for source NAT. suboptions: address: type: str description: IP address, subnet, or range to match for source NAT. + fqdn: + type: str + description: Fully qualified domain name to match for source NAT. + group: + type: dict + description: Address/network/port group to match for source NAT. + suboptions: + address_group: + type: str + description: Address group name to match. + domain_group: + type: str + description: Domain group name to match. + mac_group: + type: str + description: MAC address group name to match. + network_group: + type: str + description: Network group name to match. + port_group: + type: str + description: Port group name to match. + port: + type: str + description: Port number or range for source NAT. + protocol: + type: str + description: Protocol to match (TCP, UDP, ICMP, etc.). + exclude: + type: bool + description: Exclude packets matching this rule from NAT. + log: + type: bool + description: Log packets hitting this source NAT rule. + disable: + type: bool + description: Disable this source NAT rule. static: type: dict description: Configuration for static NAT rules. suboptions: rule: type: list elements: dict description: List of static NAT rules. suboptions: id: type: int required: true description: Rule number for static NAT (one-to-one). + destination: + type: dict + description: Match criteria for static NAT. + suboptions: + address: + type: str + description: IP address, subnet, or range to match for static NAT. + log: + type: bool + description: Log packets hitting this static NAT rule. + disable: + type: bool + description: Disable this static NAT rule. description: type: str description: User-friendly description of the static NAT rule. inbound_interface: type: list elements: str description: List of inbound interfaces that this static NAT rule applies to. translation: type: dict description: Translation configuration for static NAT. suboptions: address: type: str - description: IP address or prefix to translate to (destination of the static NAT). + description: IP address or prefix to translate to. running_config: description: - This option is used only with state I(parsed). - The value of this option should be the output received from the VYOS device by - executing the command B(show configuration commands | grep ntp). + executing the command B(show configuration commands | grep nat). - The states I(replaced) and I(overridden) have identical behaviour for this module. - - The state I(parsed) reads the configuration from C(show configuration commands | grep ntp) option and + - The state I(parsed) reads the configuration from C(show configuration commands | grep nat) option and transforms it into Ansible structured data as per the resource module's argspec and the value is then returned in the I(parsed) key within the result. type: str state: description: - The state the configuration should be left in. type: str choices: - deleted - merged - overridden - replaced - gathered - rendered - parsed default: merged """ EXAMPLES = """ -# # ------------------- -# # 1. Using merged -# # ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# # Task -# # ------------- -- name: Replace the existing ntp config with the new config - vyos.vyos.vyos_ntp_global: - config: - allow_clients: - - 10.6.6.0/24 - listen_addresses: - - 10.1.3.1 - servers: - - server: 203.0.113.0 - options: - - prefer - - -# Task output: -# ------------- -# "after": { -# "allow_clients": [ -# "10.6.6.0/24" -# ], -# "listen_addresses": [ -# "10.1.3.1" -# ], -# "servers": [ -# { -# "server": "ser", -# "options": [ -# "prefer" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "before": { -# }, -# "changed": true, -# "commands": [ -# "set service ntp allow-clients address 10.6.6.0/24", -# "set service ntp listen-address 10.1.3.1", -# "set service ntp server 203.0.113.0 prefer" -# ] - -# After state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.6.6.0/24' -# set service ntp listen-address '10.1.3.1' -# set service ntp server 203.0.113.0 prefer, -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - - -# # ------------------- -# # 2. Using replaced -# # ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.4.9.0/24' -# set service ntp allow-clients address '10.4.7.0/24' -# set service ntp allow-clients address '10.1.2.0/24' -# set service ntp allow-clients address '10.2.3.0/24' -# set service ntp listen-address '10.1.9.16' -# set service ntp listen-address '10.5.3.2' -# set service ntp listen-address '10.7.9.21' -# set service ntp listen-address '10.8.9.4' -# set service ntp listen-address '10.4.5.1' -# set service ntp server 10.3.6.5 noselect -# set service ntp server 10.3.6.5 dynamic -# set service ntp server 10.3.6.5 preempt -# set service ntp server 10.3.6.5 prefer -# set service ntp server server4 noselect -# set service ntp server server4 dynamic -# set service ntp server server5 -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# # Task -# # ------------- -- name: Replace the existing ntp config with the new config - vyos.vyos.vyos_ntp_global: - config: - allow_clients: - - 10.6.6.0/24 - listen_addresses: - - 10.1.3.1 - servers: - - server: 203.0.113.0 - options: - - prefer - state: replaced - - -# # Task output: -# # ------------- -# "after": { -# "allow_clients": [ -# "10.6.6.0/24" -# ], -# "listen_addresses": [ -# "10.1.3.1" -# ], -# "servers": [ -# { -# "server": "ser", -# "options": [ -# "prefer" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "before": { -# "allow_clients": [ -# "10.4.7.0/24", -# "10.2.3.0/24", -# "10.1.2.0/24", -# "10.4.9.0/24" -# ], -# "listen_addresses": [ -# "10.7.9.21", -# "10.4.5.1", -# "10.5.3.2", -# "10.8.9.4", -# "10.1.9.16" -# ], -# "servers": [ -# { -# "server": "10.3.6.5", -# "options": [ -# "noselect", -# "dynamic", -# "preempt", -# "prefer" -# ] -# }, -# { -# "server": "server4", -# "options": [ -# "noselect", -# "dynamic" -# ] -# }, -# { -# "server": "server5" -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "changed": true, -# "commands": [ -# "delete service ntp allow-clients address 10.4.7.0/24", -# "delete service ntp allow-clients address 10.2.3.0/24", -# "delete service ntp allow-clients address 10.1.2.0/24", -# "delete service ntp allow-clients address 10.4.9.0/24", -# "delete service ntp listen-address 10.7.9.21", -# "delete service ntp listen-address 10.4.5.1", -# "delete service ntp listen-address 10.5.3.2", -# "delete service ntp listen-address 10.8.9.4", -# "delete service ntp listen-address 10.1.9.16", -# "delete service ntp server 10.3.6.5", -# "delete service ntp server server4", -# "delete service ntp server server5", -# "set service ntp allow-clients address 10.6.6.0/24", -# "set service ntp listen-address 10.1.3.1", -# "set service ntp server 203.0.113.0 prefer" -# ] - -# After state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.6.6.0/24' -# set service ntp listen-address '10.1.3.1' -# set service ntp server 203.0.113.0 prefer, -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# # ------------------- -# # 3. Using overridden -# # ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.6.6.0/24' -# set service ntp listen-address '10.1.3.1' -# set service ntp server 203.0.113.0 prefer, -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# Task -# ------------- -- name: Override ntp config - vyos.vyos.vyos_ntp_global: +# Using merged +- name: Merge NAT source rule + vyos.vyos.vyos_nat: config: - allow_clients: - - 10.3.3.0/24 - listen_addresses: - - 10.7.8.1 - servers: - - server: server1 - options: - - dynamic - - prefer - - - server: server2 - options: - - noselect - - preempt - - - server: serv - state: overridden - -# # Task output: -# # ------------- -# "after": { -# "allow_clients": [ -# "10.3.3.0/24" -# ], -# "listen_addresses": [ -# "10.7.8.1" -# ], -# "servers": [ -# { -# "server": "serv" -# }, -# { -# "server": "server1", -# "options": [ -# "dynamic", -# "prefer" -# ] -# }, -# { -# "server": "server2", -# "options": [ -# "noselect", -# "preempt" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "before": { -# "allow_clients": [ -# "10.6.6.0/24" -# ], -# "listen_addresses": [ -# "10.1.3.1" -# ], -# "servers": [ -# { -# "server": "ser", -# "options": [ -# "prefer" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "changed": true, -# "commands": [ -# "delete service ntp allow-clients address 10.6.6.0/24", -# "delete service ntp listen-address 10.1.3.1", -# "delete service ntp server ser", -# "set service ntp allow-clients address 10.3.3.0/24", -# "set service ntp listen-address 10.7.8.1", -# "set service ntp server server1 dynamic", -# "set service ntp server server1 prefer", -# "set service ntp server server2 noselect", -# "set service ntp server server2 preempt", -# "set service ntp server serv" -# ] - -# After state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.3.3.0/24' -# set service ntp listen-address '10.7.8.1' -# set service ntp server serv -# set service ntp server server1 dynamic -# set service ntp server server1 prefer -# set service ntp server server2 noselect -# set service ntp server server2 preempt -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# 4. Using gathered -# ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.3.3.0/24' -# set service ntp listen-address '10.7.8.1' -# set service ntp server serv -# set service ntp server server1 dynamic -# set service ntp server server1 prefer -# set service ntp server server2 noselect -# set service ntp server server2 preempt -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# Task -# ------------- -- name: Gather ntp config - vyos.vyos.vyos_ntp_global: + source: + rule: + - id: 100 + description: "Outbound masquerade" + state: merged + +# Using gathered +- name: Gather NAT config + vyos.vyos.vyos_nat: state: gathered -# # Task output: -# # ------------- -# "gathered": { -# "allow_clients": [ -# "10.3.3.0/24" -# ], -# "listen_addresses": [ -# "10.7.8.1" -# ], -# "servers": [ -# { -# "server": "serv" -# }, -# { -# "server": "server1", -# "options": [ -# "dynamic", -# "prefer" -# ] -# }, -# { -# "server": "server2", -# "options": [ -# "noselect", -# "preempt" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# } - -# After state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.3.3.0/24' -# set service ntp listen-address '10.7.8.1' -# set service ntp server serv -# set service ntp server server1 dynamic -# set service ntp server server1 prefer -# set service ntp server server2 noselect -# set service ntp server server2 preempt -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - - -# # ------------------- -# # 5. Using deleted -# # ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp allow-clients address '10.3.3.0/24' -# set service ntp listen-address '10.7.8.1' -# set service ntp server serv -# set service ntp server server1 dynamic -# set service ntp server server1 prefer -# set service ntp server server2 noselect -# set service ntp server server2 preempt -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# # Task -# # ------------- -- name: Delete ntp config - vyos.vyos.vyos_ntp_global: +# Using deleted +- name: Delete NAT config + vyos.vyos.vyos_nat: state: deleted - -# # Task output: -# # ------------- -# "after": { -# "servers": [ -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "before": { -# "allow_clients": [ -# "10.3.3.0/24" -# ], -# "listen_addresses": [ -# "10.7.8.1" -# ], -# "servers": [ -# { -# "server": "serv" -# }, -# { -# "server": "server1", -# "options": [ -# "dynamic", -# "prefer" -# ] -# }, -# { -# "server": "server2", -# "options": [ -# "noselect", -# "preempt" -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# ] -# }, -# "changed": true, -# "commands": [ -# "delete service ntp allow-clients", -# "delete service ntp listen-address", -# "delete service ntp server serv", -# "delete service ntp server server1", -# "delete service ntp server server2" -# -# ] - -# After state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - - -# # ------------------- -# # 6. Using rendered -# # ------------------- - -# # Before state: -# # ------------- -# vyos@vyos:~$ show configuration commands | grep ntp -# set service ntp server time1.vyos.net -# set service ntp server time2.vyos.net -# set service ntp server time3.vyos.net -# vyos@vyos:~$ - -# Task -# ------------- -- name: Render ntp config - vyos.vyos.vyos_ntp_global: +# Using replaced +- name: Replace NAT config + vyos.vyos.vyos_nat: config: - allow_clients: - - 10.7.7.0/24 - - 10.8.8.0/24 - listen_addresses: - - 10.7.9.1 - servers: - - server: server7 - - server: server45 - options: - - noselect - - prefer - - pool - - server: time1.vyos.net - - server: time2.vyos.net - - server: time3.vyos.net - state: rendered - -# # Task output: -# # ------------- -# "rendered": [ -# "set service ntp allow-clients address 10.7.7.0/24", -# "set service ntp allow-clients address 10.8.8.0/24", -# "set service ntp listen-address 10.7.9.1", -# "set service ntp server server7", -# "set service ntp server server45 noselect", -# "set service ntp server server45 prefer", -# "set service ntp server server45 pool", -# "set service ntp server time1.vyos.net", -# "set service ntp server time2.vyos.net", -# "set service ntp server time3.vyos.net" -# ] - - -# # ------------------- -# # 7. Using parsed -# # ------------------- - -# # sample_config.cfg: -# # ------------- -# "set service ntp allow-clients address 10.7.7.0/24", -# "set service ntp listen-address 10.7.9.1", -# "set service ntp server server45 noselect", -# "set service ntp allow-clients addres 10.8.6.0/24", -# "set service ntp listen-address 10.5.4.1", -# "set service ntp server server45 dynamic", -# "set service ntp server time1.vyos.net", -# "set service ntp server time2.vyos.net", -# "set service ntp server time3.vyos.net" + source: + rule: + - id: 100 + description: "Replaced rule" + state: replaced -# Task: -# ------------- -- name: Parse externally provided ntp configuration - vyos.vyos.vyos_ntp_global: - running_config: "{{ lookup('file', './sample_config.cfg') }}" +# Using parsed +- name: Parse NAT config + vyos.vyos.vyos_nat: + running_config: "{{ lookup('file', './nat_config.cfg') }}" state: parsed -# # Task output: -# # ------------- -# parsed = { -# "allow_clients": [ -# "10.7.7.0/24", -# "10.8.6.0/24 -# ], -# "listen_addresses": [ -# "10.5.4.1", -# "10.7.9.1" -# ], -# "servers": [ -# { -# "server": "server45", -# "options": [ -# "noselect", -# "dynamic" -# -# ] -# }, -# { -# "server": "time1.vyos.net" -# }, -# { -# "server": "time2.vyos.net" -# }, -# { -# "server": "time3.vyos.net" -# } -# -# ] -# } +# Using rendered +- name: Render NAT config offline + vyos.vyos.vyos_nat: + config: + source: + rule: + - id: 100 + description: "Rendered rule" + state: rendered """ RETURN = """ before: description: The configuration prior to the module execution. returned: when I(state) is C(merged), C(replaced), C(overridden), C(deleted) or C(purged) type: dict sample: > This output will always be in the same format as the module argspec. after: description: The resulting configuration after module execution. returned: when changed type: dict sample: > This output will always be in the same format as the module argspec. commands: description: The set of commands pushed to the remote device. returned: when I(state) is C(merged), C(replaced), C(overridden), C(deleted) or C(purged) type: list sample: - - set system ntp server server1 dynamic - - set system ntp server server1 prefer - - set system ntp server server2 noselect - - set system ntp server server2 preempt - - set system ntp server server_add preempt + - set nat source rule 100 description 'Outbound masquerade' rendered: description: The provided configuration in the task rendered in device-native format (offline). returned: when I(state) is C(rendered) type: list sample: - - set system ntp server server1 dynamic - - set system ntp server server1 prefer - - set system ntp server server2 noselect - - set system ntp server server2 preempt - - set system ntp server server_add preempt + - set nat source rule 100 description 'Rendered rule' gathered: description: Facts about the network resource gathered from the remote device as structured data. returned: when I(state) is C(gathered) - type: list + type: dict sample: > This output will always be in the same format as the module argspec. parsed: description: The device native config provided in I(running_config) option parsed into structured data as per module argspec. returned: when I(state) is C(parsed) - type: list + type: dict sample: > This output will always be in the same format as the module argspec. """ from ansible.module_utils.basic import AnsibleModule from ansible_collections.vyos.vyos.plugins.module_utils.network.vyos.argspec.nat.nat import ( NatArgs, ) from ansible_collections.vyos.vyos.plugins.module_utils.network.vyos.config.nat.nat import ( Nat, ) def main(): """ Main entry point for module execution :returns: the result form module invocation """ module = AnsibleModule( argument_spec=NatArgs.argument_spec, mutually_exclusive=[["config", "running_config"]], required_if=[ ["state", "merged", ["config"]], ["state", "replaced", ["config"]], ["state", "overridden", ["config"]], ["state", "rendered", ["config"]], ["state", "parsed", ["running_config"]], ], supports_check_mode=True, ) result = Nat(module).execute_module() module.exit_json(**result) if __name__ == "__main__": main()