[WARNING]: Could not match supplied host pattern, ignoring: unprovisioned PLAY [Deploy initial device configuration] ************************************* TASK [Set variables that cannot be set with VARS] ****************************** ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [Find device readiness script] ******************************************** ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [Wait for device to become ready] ***************************************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] included: /home/pipi/net101/tools/netsim/ansible/tasks/readiness-check/routeros7.yml for s1, s2 TASK [Execute local ssh command to check router readiness] ********************* skipping: [s1] skipping: [s2] TASK [Normalize config on bridge-like devices] ********************************* included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for h1, h2, h3, h4, s1, s2 TASK [Figure out whether to deploy the module normalize on current device] ***** ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [Find configuration template for normalize] ******************************* ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [fail] ******************************************************************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] skipping: [s1] skipping: [s2] TASK [Print deployed configuration when running in verbose mode] *************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] skipping: [s1] skipping: [s2] TASK [Find configuration deployment deploy_script for normalize] *************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] skipping: [s1] skipping: [s2] TASK [Deploy normalize configuration] ****************************************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] skipping: [s1] skipping: [s2] TASK [Deploy initial configuration] ******************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for h1, h2, h3, h4, s1, s2 TASK [Figure out whether to deploy the module initial on current device] ******* ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [Find configuration template for initial] ********************************* ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s1] ok: [s2] TASK [fail] ******************************************************************** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] skipping: [s1] skipping: [s2] TASK [Print deployed configuration when running in verbose mode] *************** ok: [h1] => msg: |- initial configuration for h1 ========================================= #!/bin/bash # # This script contains the 'ip' commands needed to set up container # interfaces and route table. It's executed within the container # network namespace on the container host. # # /etc/hosts file is generated as a clab bind. # set -e ### One-Shot configuration (non-Ubuntu VM or container) # # Disable IPv4 and IPv6 forwarding # sysctl -w net.ipv4.ip_forward=0 sysctl -w net.ipv6.conf.all.forwarding=0 # # Interface addressing, create any bond devices # ip link set dev eth1 up set +e ip addr del 172.31.1.1/24 dev eth1 2>/dev/null set -e ip addr add 172.31.1.1/24 dev eth1 ip link set dev eth1 mtu 1500 # # Add static routes (usually IPv4 routes pointing to the first usable gateway) # # # # # Print the final routing table ip route ok: [h2] => msg: |- initial configuration for h2 ========================================= #!/bin/bash # # This script contains the 'ip' commands needed to set up container # interfaces and route table. It's executed within the container # network namespace on the container host. # # /etc/hosts file is generated as a clab bind. # set -e ### One-Shot configuration (non-Ubuntu VM or container) # # Disable IPv4 and IPv6 forwarding # sysctl -w net.ipv4.ip_forward=0 sysctl -w net.ipv6.conf.all.forwarding=0 # # Interface addressing, create any bond devices # ip link set dev eth1 up set +e ip addr del 172.31.1.2/24 dev eth1 2>/dev/null set -e ip addr add 172.31.1.2/24 dev eth1 ip link set dev eth1 mtu 1500 # # Add static routes (usually IPv4 routes pointing to the first usable gateway) # # # # # Print the final routing table ip route ok: [h3] => msg: |- initial configuration for h3 ========================================= #!/bin/bash # # This script contains the 'ip' commands needed to set up container # interfaces and route table. It's executed within the container # network namespace on the container host. # # /etc/hosts file is generated as a clab bind. # set -e ### One-Shot configuration (non-Ubuntu VM or container) # # Disable IPv4 and IPv6 forwarding # sysctl -w net.ipv4.ip_forward=0 sysctl -w net.ipv6.conf.all.forwarding=0 # # Interface addressing, create any bond devices # ip link set dev eth1 up set +e ip addr del 172.31.1.3/24 dev eth1 2>/dev/null set -e ip addr add 172.31.1.3/24 dev eth1 ip link set dev eth1 mtu 1500 # # Add static routes (usually IPv4 routes pointing to the first usable gateway) # # # # # Print the final routing table ip route ok: [h4] => msg: |- initial configuration for h4 ========================================= #!/bin/bash # # This script contains the 'ip' commands needed to set up container # interfaces and route table. It's executed within the container # network namespace on the container host. # # /etc/hosts file is generated as a clab bind. # set -e ### One-Shot configuration (non-Ubuntu VM or container) # # Disable IPv4 and IPv6 forwarding # sysctl -w net.ipv4.ip_forward=0 sysctl -w net.ipv6.conf.all.forwarding=0 # # Interface addressing, create any bond devices # ip link set dev eth1 up set +e ip addr del 172.31.1.4/24 dev eth1 2>/dev/null set -e ip addr add 172.31.1.4/24 dev eth1 ip link set dev eth1 mtu 1500 # # Add static routes (usually IPv4 routes pointing to the first usable gateway) # # # # # Print the final routing table ip route ok: [s1] => msg: |- initial configuration for s1 ========================================= /system identity set name="s1" /interface bridge add name=loopback protocol-mode=none /ip address add interface=loopback address=10.0.0.5/32 /interface/bridge/add name=switch vlan-filtering=yes comment="Global Switch Bridge" /interface/vlan/add name=vlan701 vlan-id=701 interface=switch /interface/vlan/add name=vlan700 vlan-id=700 interface=switch /interface ethernet set comment="s1 -> s2" ether2 /interface ethernet set comment="[Access VLAN red] s1 -> h1" ether3 /interface ethernet set comment="[Access VLAN blue] s1 -> h3" ether4 /interface ethernet set comment="VLAN red (700) -> [s2,h1,h2]" vlan700 /interface ethernet set comment="VLAN blue (701) -> [h3,s2,h4]" vlan701 /ip neighbor discovery-settings set discover-interface-list=all ok: [s2] => msg: |- initial configuration for s2 ========================================= /system identity set name="s2" /interface bridge add name=loopback protocol-mode=none /ip address add interface=loopback address=10.0.0.6/32 /interface/bridge/add name=switch vlan-filtering=yes comment="Global Switch Bridge" /interface/vlan/add name=vlan701 vlan-id=701 interface=switch /interface/vlan/add name=vlan700 vlan-id=700 interface=switch /interface ethernet set comment="s2 -> s1" ether2 /interface ethernet set comment="[Access VLAN red] s2 -> h2" ether3 /interface ethernet set comment="[Access VLAN blue] s2 -> h4" ether4 /interface ethernet set comment="VLAN red (700) -> [s1,h1,h2]" vlan700 /interface ethernet set comment="VLAN blue (701) -> [h3,s1,h4]" vlan701 /ip neighbor discovery-settings set discover-interface-list=all TASK [Find configuration deployment deploy_script for initial] ***************** ok: [h1] ok: [h2] ok: [h3] ok: [h4] ok: [s2] ok: [s1] TASK [Deploy initial configuration] ******************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-config/linux-clab.yml for h1, h2, h3, h4 included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-config/routeros7.yml for s1, s2 TASK [Define script filename and determine whether to execute in netns] ******** ok: [h1] ok: [h2] ok: [h3] ok: [h4] TASK [Create a temporary file for the rendered script] ************************* changed: [h1 -> localhost] changed: [h3 -> localhost] changed: [h4 -> localhost] changed: [h2 -> localhost] TASK [Create container setup script from /home/pipi/net101/tools/netsim/ansible/templates/initial/linux-clab.j2] *** changed: [h1 -> localhost] changed: [h4 -> localhost] changed: [h2 -> localhost] changed: [h3 -> localhost] TASK [Copy script into running container at /tmp/config-h1_initial.sh] ********* skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] TASK [Execute /tmp/config-h1_initial.sh to deploy initial config based on /home/pipi/net101/tools/netsim/ansible/templates/initial/linux-clab.j2] *** skipping: [h1] skipping: [h2] skipping: [h3] skipping: [h4] TASK [Container configuration for initial based on /home/pipi/net101/tools/netsim/ansible/templates/initial/linux-clab.j2 executed in netns] *** changed: [h1 -> localhost] changed: [h4 -> localhost] changed: [h2 -> localhost] changed: [h3 -> localhost] TASK [Remove temporary file /tmp/h1_initial-q2g8it3v.sh] *********************** changed: [h1 -> localhost] changed: [h2 -> localhost] changed: [h3 -> localhost] changed: [h4 -> localhost] TASK [load initial from /home/pipi/net101/tools/netsim/ansible/templates/initial/routeros7.j2] *** ok: [s1] ok: [s2] TASK [Run commands on CHR] ***************************************************** changed: [s2] changed: [s1] PLAY [Deploy module-specific configurations] *********************************** TASK [Set variables that cannot be set with VARS] ****************************** ok: [s1] ok: [s2] TASK [Deploy individual configuration modules] ********************************* included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for s1, s2 => (item=vlan) TASK [Figure out whether to deploy the module vlan on current device] ********** ok: [s1] ok: [s2] TASK [Find configuration template for vlan] ************************************ ok: [s1] ok: [s2] TASK [fail] ******************************************************************** skipping: [s1] skipping: [s2] TASK [Print deployed configuration when running in verbose mode] *************** ok: [s1] => msg: |- vlan configuration for s1 ========================================= /interface/bridge/vlan add bridge=switch vlan-ids=701 tagged=switch /interface/bridge/vlan add bridge=switch vlan-ids=700 tagged=switch /interface/bridge/port add bridge=switch interface=ether2 pvid=700 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=700]],"ether2") [find vlan-ids=700] /interface/bridge/vlan set tagged=([get value-name=tagged [find vlan-ids=700]],"ether2") [find vlan-ids=700] /interface/bridge/vlan set tagged=([get value-name=tagged [find vlan-ids=701]],"ether2") [find vlan-ids=701] /interface/bridge/port add bridge=switch interface=ether3 pvid=700 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=700]],"ether3") [find vlan-ids=700] /interface/bridge/port add bridge=switch interface=ether4 pvid=701 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=701]],"ether4") [find vlan-ids=701] ok: [s2] => msg: |- vlan configuration for s2 ========================================= /interface/bridge/vlan add bridge=switch vlan-ids=701 tagged=switch /interface/bridge/vlan add bridge=switch vlan-ids=700 tagged=switch /interface/bridge/port add bridge=switch interface=ether2 pvid=700 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=700]],"ether2") [find vlan-ids=700] /interface/bridge/vlan set tagged=([get value-name=tagged [find vlan-ids=700]],"ether2") [find vlan-ids=700] /interface/bridge/vlan set tagged=([get value-name=tagged [find vlan-ids=701]],"ether2") [find vlan-ids=701] /interface/bridge/port add bridge=switch interface=ether3 pvid=700 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=700]],"ether3") [find vlan-ids=700] /interface/bridge/port add bridge=switch interface=ether4 pvid=701 /interface/bridge/vlan set untagged=([get value-name=untagged [find vlan-ids=701]],"ether4") [find vlan-ids=701] TASK [Find configuration deployment deploy_script for vlan] ******************** ok: [s1] ok: [s2] TASK [Deploy vlan configuration] *********************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-config/routeros7.yml for s1, s2 TASK [load vlan from /home/pipi/net101/tools/netsim/ansible/templates/vlan/routeros7.j2] *** ok: [s1] ok: [s2] TASK [Run commands on CHR] ***************************************************** changed: [s2] changed: [s1] PLAY [Deploy custom deployment templates] ************************************** skipping: no hosts matched PLAY RECAP ********************************************************************* h1 : ok=16 changed=4 unreachable=0 failed=0 skipped=8 rescued=0 ignored=0 h2 : ok=16 changed=4 unreachable=0 failed=0 skipped=8 rescued=0 ignored=0 h3 : ok=16 changed=4 unreachable=0 failed=0 skipped=8 rescued=0 ignored=0 h4 : ok=16 changed=4 unreachable=0 failed=0 skipped=8 rescued=0 ignored=0 s1 : ok=23 changed=2 unreachable=0 failed=0 skipped=7 rescued=0 ignored=0 s2 : ok=23 changed=2 unreachable=0 failed=0 skipped=7 rescued=0 ignored=0 The devices under test are simple bridges with a VLAN trunk between them. One of the trunk members is a native VLAN. Both VLANs are using the same IP prefix to identify potential inter-VLAN leaking. * h1 and h2 should be able to ping each other * h3 and h4 should be able to ping each other * h1 should not be able to reach h3 Please note it might take a while for the lab to work due to STP learning phase