diff --git a/changelogs/fragments/T8321_vpn_ipsec.yml b/changelogs/fragments/T8321_vpn_ipsec.yml new file mode 100644 index 00000000..2fc5abb6 --- /dev/null +++ b/changelogs/fragments/T8321_vpn_ipsec.yml @@ -0,0 +1,3 @@ +--- +minor_changes: + - vyos_vrf - Add VRF support for the collection. diff --git a/plugins/modules/vyos_vpn_ipsec.yaml b/plugins/modules/vyos_vpn_ipsec.yaml new file mode 100644 index 00000000..928544ca --- /dev/null +++ b/plugins/modules/vyos_vpn_ipsec.yaml @@ -0,0 +1,480 @@ +module: vyos_vpn_ipsec +short_description: Manages global IPsec (ike-group, esp-group, profile, authentication, options) attributes of VyOS network devices. +description: This module manages global VPN IPsec configuration on VyOS devices — IKE groups, ESP groups, PSK/PPK authentication, IPsec profiles, and global options. Site-to-site peers and IKEv2 remote-access connections are handled by separate modules. +version_added: 6.2.0 +author: Evgeny (@omnom62) +notes: + - Tested against VyOS 1.4 and 1.5. + - "Source of truth for field types/choices: device node.def templates under /opt/vyatta/share/vyatta-cfg/templates/vpn/ipsec/." +options: + config: + description: IPsec global configuration. + type: dict + suboptions: + ike_group: + description: List of IKE groups. + type: list + elements: dict + suboptions: + name: + description: The name of the IKE group. + type: str + required: true + close_action: + description: Action to take if a child SA is unexpectedly closed. + type: str + choices: [none, trap, start] + dead_peer_detection: + description: Dead Peer Detection (DPD). + type: dict + suboptions: + action: + description: Keep-alive failure action. + type: str + choices: [trap, clear, restart] + interval: + description: Keep-alive interval in seconds. + type: int + timeout: + description: Dead Peer Detection keep-alive timeout (IKEv1 only), in seconds. + type: int + disable_mobike: + description: Disable MOBIKE support (IKEv2 only). + type: bool + ikev2_reauth: + description: Re-authentication of the remote peer during an IKE re-key (IKEv2 only). + type: bool + key_exchange: + description: IKE version. + type: str + choices: [ikev1, ikev2] + lifetime: + description: IKE lifetime in seconds. + type: int + mode: + description: IKEv1 phase 1 mode. + type: str + choices: [main, aggressive] + proposal: + description: List of IKE proposals. + type: list + elements: dict + suboptions: + proposal_id: + description: The proposal identifier. + type: int + dh_group: + description: Diffie-Hellman group. + type: int + choices: + [ + 1, + 2, + 5, + 14, + 15, + 16, + 17, + 18, + 19, + 20, + 21, + 22, + 23, + 24, + 25, + 26, + 27, + 28, + 29, + 30, + 31, + 32, + ] + encryption: + description: Encryption algorithm. + type: str + choices: + - "null" + - aes128 + - aes192 + - aes256 + - aes128ctr + - aes192ctr + - aes256ctr + - aes128ccm64 + - aes192ccm64 + - aes256ccm64 + - aes128ccm96 + - aes192ccm96 + - aes256ccm96 + - aes128ccm128 + - aes192ccm128 + - aes256ccm128 + - aes128gcm64 + - aes192gcm64 + - aes256gcm64 + - aes128gcm96 + - aes192gcm96 + - aes256gcm96 + - aes128gcm128 + - aes192gcm128 + - aes256gcm128 + - aes128gmac + - aes192gmac + - aes256gmac + - 3des + - blowfish128 + - blowfish192 + - blowfish256 + - camellia128 + - camellia192 + - camellia256 + - camellia128ctr + - camellia192ctr + - camellia256ctr + - camellia128ccm64 + - camellia192ccm64 + - camellia256ccm64 + - camellia128ccm96 + - camellia192ccm96 + - camellia256ccm96 + - camellia128ccm128 + - camellia192ccm128 + - camellia256ccm128 + - serpent128 + - serpent192 + - serpent256 + - twofish128 + - twofish192 + - twofish256 + - cast128 + - chacha20poly1305 + hash: + description: Hash algorithm. + type: str + choices: + [ + md5, + md5_128, + sha1, + sha1_160, + sha256, + sha256_96, + sha384, + sha512, + aesxcbc, + aescmac, + aes128gmac, + aes192gmac, + aes256gmac, + ] + prf: + description: Pseudo-Random Function. + type: str + choices: + [ + prfmd5, + prfsha1, + prfaesxcbc, + prfaescmac, + prfsha256, + prfsha384, + prfsha512, + ] + esp_group: + description: List of ESP groups. + type: list + elements: dict + suboptions: + name: + description: The name of the ESP group. + type: str + required: true + compression: + description: Enable ESP compression. + type: bool + disable_rekey: + description: Do not locally initiate a re-key of the SA; remote peer must re-key before expiration. + type: bool + life_bytes: + description: Security Association byte count to expire. + type: int + life_packets: + description: Security Association packet count to expire. + type: int + lifetime: + description: Security Association time to expire, in seconds. + type: int + mode: + description: ESP mode. + type: str + choices: [tunnel, transport] + pfs: + description: ESP Perfect Forward Secrecy. + type: str + choices: + - enable + - disable + - dh-group1 + - dh-group2 + - dh-group5 + - dh-group14 + - dh-group15 + - dh-group16 + - dh-group17 + - dh-group18 + - dh-group19 + - dh-group20 + - dh-group21 + - dh-group22 + - dh-group23 + - dh-group24 + - dh-group25 + - dh-group26 + - dh-group27 + - dh-group28 + - dh-group29 + - dh-group30 + - dh-group31 + - dh-group32 + proposal: + description: List of ESP proposals. + type: list + elements: dict + suboptions: + proposal_id: + description: The proposal identifier. + type: int + encryption: + description: Encryption algorithm. + type: str + choices: + - "null" + - aes128 + - aes192 + - aes256 + - aes128ctr + - aes192ctr + - aes256ctr + - aes128ccm64 + - aes192ccm64 + - aes256ccm64 + - aes128ccm96 + - aes192ccm96 + - aes256ccm96 + - aes128ccm128 + - aes192ccm128 + - aes256ccm128 + - aes128gcm64 + - aes192gcm64 + - aes256gcm64 + - aes128gcm96 + - aes192gcm96 + - aes256gcm96 + - aes128gcm128 + - aes192gcm128 + - aes256gcm128 + - aes128gmac + - aes192gmac + - aes256gmac + - 3des + - blowfish128 + - blowfish192 + - blowfish256 + - camellia128 + - camellia192 + - camellia256 + - camellia128ctr + - camellia192ctr + - camellia256ctr + - camellia128ccm64 + - camellia192ccm64 + - camellia256ccm64 + - camellia128ccm96 + - camellia192ccm96 + - camellia256ccm96 + - camellia128ccm128 + - camellia192ccm128 + - camellia256ccm128 + - serpent128 + - serpent192 + - serpent256 + - twofish128 + - twofish192 + - twofish256 + - cast128 + - chacha20poly1305 + hash: + description: Hash algorithm. + type: str + choices: + [ + md5, + md5_128, + sha1, + sha1_160, + sha256, + sha256_96, + sha384, + sha512, + aesxcbc, + aescmac, + aes128gmac, + aes192gmac, + aes256gmac, + ] + authentication: + description: Global pre-shared-key and post-quantum pre-shared-key definitions. + type: dict + suboptions: + psk: + description: List of pre-shared keys. + type: list + elements: dict + suboptions: + name: + description: Pre-shared key name. + type: str + required: true + id: + description: ID(s) for authentication. + type: list + elements: str + dhcp_interface: + description: DHCP interface(s) supplying next-hop IP address. + type: list + elements: str + secret: + description: IKE pre-shared secret key. + type: str + no_log: true + secret_type: + description: Secret encoding type. + type: str + choices: [base64, hex, plaintext] + ppk: + description: List of post-quantum pre-shared keys. + type: list + elements: dict + suboptions: + name: + description: Post-quantum pre-shared key name. + type: str + required: true + id: + description: ID(s) for PPK. + type: list + elements: str + secret: + description: Post-quantum pre-shared secret key. + type: str + no_log: true + secret_type: + description: Secret encoding type. + type: str + choices: [base64, hex, plaintext] + profile: + description: List of VPN IPsec profiles (used for e.g. DMVPN/GRE tunnel binding). + type: list + elements: dict + suboptions: + name: + description: Profile name. + type: str + required: true + authentication: + type: dict + suboptions: + mode: + description: Authentication mode. + type: str + choices: [pre-shared-secret] + pre_shared_secret: + description: Pre-shared secret key. + type: str + no_log: true + bind_tunnel: + description: Tunnel interface(s) associated with this profile. + type: list + elements: str + disable: + description: Disable this profile. + type: bool + esp_group: + description: ESP group name to use for this profile. + type: str + ike_group: + description: IKE group name to use for this profile. + type: str + interface: + description: Interface(s) IPsec listens on. If omitted, listens on all interfaces. + type: list + elements: str + log: + type: dict + suboptions: + level: + description: Global IPsec logging level. + type: int + choices: [0, 1, 2] + subsystem: + description: Per-subsystem logging levels to enable. + type: list + elements: str + choices: + [ + dmn, + mgr, + ike, + chd, + job, + cfg, + knl, + net, + asn, + enc, + lib, + esp, + tls, + tnc, + imc, + imv, + pts, + any, + ] + options: + type: dict + suboptions: + disable_route_autoinstall: + description: Do not automatically install routes to remote networks. + type: bool + flexvpn: + description: Allow FlexVPN vendor ID payload (IKEv2 only). + type: bool + interface: + description: Single interface for IPsec options scope (distinct from top-level interface list). + type: str + retransmission: + type: dict + suboptions: + attempts: + description: Maximum number of retransmissions. + type: int + base: + description: Base of exponential backoff. + type: float + timeout: + description: Timeout in seconds before the first retransmission. + type: int + virtual_ip: + description: Allow install of virtual-ip addresses. + type: bool + disable_uniqreqids: + description: Disable requirement for unique IDs in the Security Database. + type: bool + state: + description: The state the configuration should be left in. + type: str + choices: [merged, replaced, overridden, deleted, gathered, rendered, parsed] + default: merged