From 9c968e9da8f177297d595f881cdd1ad49824079f Mon Sep 17 00:00:00 2001 From: Kurt Bales Date: Tue, 7 Apr 2015 10:43:51 -0700 Subject: [PATCH] Update VPN ansible examples to insert pod_id for st0 unit number --- ansible/playbooks/vpn_config.yml | 2 +- ansible/playbooks/vpn_ospf_config.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/ansible/playbooks/vpn_config.yml b/ansible/playbooks/vpn_config.yml index 4af3a28..74b23ca 100644 --- a/ansible/playbooks/vpn_config.yml +++ b/ansible/playbooks/vpn_config.yml @@ -9,7 +9,7 @@ build_dir: "/tmp/" mss_entries: [ {'protocol': 'ipsec-vpn', 'mss': '1350'} ] interfaces: [ - {'interface': 'st0', 'unit': '1', 'family': 'inet', 'addr_type': 'address', 'addr': '10.255.{{pod_id}}.2/30', 'zone':'vpn', 'hit_protocols': ['ospf', 'bgp'], 'hit_services': ['ping', 'traceroute']}, + {'interface': 'st0', 'unit': '{{pod_id}}', 'family': 'inet', 'addr_type': 'address', 'addr': '10.255.{{pod_id}}.2/30', 'zone':'vpn', 'hit_protocols': ['ospf', 'bgp'], 'hit_services': ['ping', 'traceroute']}, {'interface': 'ge-0/0/2', 'unit': '0', 'family': 'inet', 'addr_type': 'dhcp', 'zone':'untrust', 'hit_services': ['ike','ping','ssh','netconf']} ] ike: [ {'ike_name': 'ike-vpn', 'gateway_ip': '10.10.0.5', 'ext_interface': 'ge-0/0/2.0', 'ike_policy_name': 'ike-policy1', 'ike_policy_mode': 'main', 'ike_policy_proposal': 'standard', 'shared_secret': 'AwesomePassword123'} ] diff --git a/ansible/playbooks/vpn_ospf_config.yml b/ansible/playbooks/vpn_ospf_config.yml index a4d5dac..a881bed 100644 --- a/ansible/playbooks/vpn_ospf_config.yml +++ b/ansible/playbooks/vpn_ospf_config.yml @@ -8,7 +8,7 @@ junos_password: "Juniper" build_dir: "/tmp/" interfaces: [ - {'interface': 'st0', 'unit': '1', 'family': 'inet', 'addr_type': 'address', 'addr': '10.255.{{pod_id}}.2/30', 'zone':'vpn', 'hit_protocols': ['ospf', 'bgp'], 'hit_services': ['ping', 'traceroute'],'ospf': {'area': '0'}}, + {'interface': 'st0', 'unit': '{{pod_id}}', 'family': 'inet', 'addr_type': 'address', 'addr': '10.255.{{pod_id}}.2/30', 'zone':'vpn', 'hit_protocols': ['ospf', 'bgp'], 'hit_services': ['ping', 'traceroute'],'ospf': {'area': '0'}}, {'interface': 'lo0', 'unit': '0', 'family': 'inet', 'addr_type': 'address', 'addr': '10.255.255.{{pod_id}}/32', 'zone':'trust', 'ospf': {'area': '0', 'passive': True}} ]