Creating Device configuration snippets [CREATED] h1: initial,routing [CREATED] h2: initial,routing [CREATED] srv: initial,routing [CREATED] dut: initial,vrf Checking Are lab devices ready to be configured? [INFO] Checking lab devices with an Ansible playbook [WARNING]: Could not match supplied host pattern, ignoring: netlab_ready_ssh [WARNING]: Found variable using reserved name: hosts PLAY [Wait for SSH servers] **************************************************** skipping: no hosts matched PLAY [Wait for device-specific conditions] ************************************* TASK [Set variables that cannot be set with VARS] ****************************** ok: [dut] TASK [Find device readiness script] ******************************************** ok: [dut] TASK [Wait for device to become ready] ***************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/readiness-check/junos.yml for dut TASK [set_fact] **************************************************************** ok: [dut] TASK [Wait for first interface (et-0/0/0)] ************************************* ok: [dut] PLAY RECAP ********************************************************************* dut : ok=5 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 Config Deploying device configurations [INFO] Executing initial configuration for node h1 (namespace clab- ml-85-h1) [INFO] Executing initial configuration for node h2 (namespace clab- ml-85-h2) [INFO] Executing initial configuration for node srv (namespace clab- ml-85-srv) [INFO] Executing routing configuration for node h1 (namespace clab- ml-85-h1) [INFO] Executing routing configuration for node h2 (namespace clab- ml-85-h2) [INFO] Executing routing configuration for node srv (namespace clab- ml-85-srv) [INFO] Starting Ansible playbook to deploy the rest of the configurations [WARNING]: Found variable using reserved name: hosts PLAY [Deploy initial device configuration] ************************************* TASK [Set variables that cannot be set with VARS] ****************************** ok: [dut] TASK [Normalize config on bridge-like devices] ********************************* included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for dut TASK [Figure out whether to deploy the module normalize on current device] ***** ok: [dut] TASK [Find configuration template for normalize] ******************************* ok: [dut] TASK [fail] ******************************************************************** skipping: [dut] TASK [Find configuration deployment deploy_script for normalize] *************** ok: [dut] TASK [Print deployed configuration when running in verbose mode] *************** skipping: [dut] TASK [Deploy normalize configuration] ****************************************** skipping: [dut] TASK [Deploy initial configuration] ******************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for dut TASK [Figure out whether to deploy the module initial on current device] ******* ok: [dut] TASK [Find configuration template for initial] ********************************* ok: [dut] TASK [fail] ******************************************************************** skipping: [dut] TASK [Find configuration deployment deploy_script for initial] ***************** ok: [dut] TASK [Print deployed configuration when running in verbose mode] *************** ok: [dut] => { "msg": "initial configuration for dut\n=========================================\nsystem {\n host-name dut;\n static-host-mapping {\n h1 inet 172.16.0.1;\n h2 inet 172.16.1.2;\n srv inet 172.16.2.3;\n }\n}\n\n\n\n\npolicy-options {\n community tg_65000_1 members target:65000:1;\n community tg_65000_3 members target:65000:3;\n community tg_65000_2 members target:65000:2;\n}\n\n\n\npolicy-options {\n policy-statement vrf-red-rt-export {\n term 1 {\n then {\n community add tg_65000_1;\n accept;\n }\n }\n }\n\n\n policy-statement vrf-red-rt-import {\n term 1 {\n from community [ tg_65000_1 tg_65000_3 ];\n then accept;\n }\n term default {\n then reject;\n }\n }\n policy-statement vrf-blue-rt-export {\n term 1 {\n then {\n community add tg_65000_2;\n accept;\n }\n }\n }\n\n\n policy-statement vrf-blue-rt-import {\n term 1 {\n from community [ tg_65000_2 tg_65000_3 ];\n then accept;\n }\n term default {\n then reject;\n }\n }\n policy-statement vrf-common-rt-export {\n term 1 {\n then {\n community add tg_65000_3;\n accept;\n }\n }\n }\n\n\n policy-statement vrf-common-rt-import {\n term 1 {\n from community [ tg_65000_1 tg_65000_2 tg_65000_3 ];\n then accept;\n }\n term default {\n then reject;\n }\n }\n}\n\nrouting-instances {\n\n red {\n instance-type vrf;\n route-distinguisher 65000:1;\n\n vrf-import vrf-red-rt-import;\n vrf-export vrf-red-rt-export;\n\n routing-options {\n auto-export;\n }\n\n interface et-0/0/0.0;\n\n }\n\n\n blue {\n instance-type vrf;\n route-distinguisher 65000:2;\n\n vrf-import vrf-blue-rt-import;\n vrf-export vrf-blue-rt-export;\n\n routing-options {\n auto-export;\n }\n\n interface et-0/0/1.0;\n\n }\n\n\n common {\n instance-type vrf;\n route-distinguisher 65000:3;\n\n vrf-import vrf-common-rt-import;\n vrf-export vrf-common-rt-export;\n\n routing-options {\n auto-export;\n }\n\n interface et-0/0/2.0;\n\n }\n\n}\ninterfaces {\n\n lo0.0 {\n \n family inet {\n address 10.0.0.4/32;\n }\n family inet6 {\n address 2001:db8:1:4::1/64;\n }\n \n }\n et-0/0/0.0 {\n description \"dut -> h1 [stub]\";\n \n family inet {\n address 172.16.0.4/24;\n }\n family inet6 {\n address 2001:db8:2::4/64;\n }\n \n }\n et-0/0/1.0 {\n description \"dut -> h2 [stub]\";\n \n family inet {\n address 172.16.1.4/24;\n }\n family inet6 {\n address 2001:db8:2:1::4/64;\n }\n \n }\n et-0/0/2.0 {\n description \"dut -> srv [stub]\";\n \n family inet {\n address 172.16.2.4/24;\n }\n family inet6 {\n address 2001:db8:2:2::4/64;\n }\n \n }\n}\nprotocols {\n lldp {\n interface re0:mgmt-0 {\n disable;\n }\n interface all;\n }\n router-advertisement {\n interface et-0/0/0.0;\n interface et-0/0/1.0;\n interface et-0/0/2.0;\n }\n}\n" } TASK [Deploy initial configuration] ******************************************** included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-config/junos.yml for dut TASK [junos_config: deploying initial from /work/netlab_cicd/other_vm/node_files/dut/initial] *** changed: [dut] PLAY [Deploy module-specific configurations] *********************************** TASK [Set variables that cannot be set with VARS] ****************************** ok: [dut] TASK [Deploy individual configuration modules] ********************************* included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for dut => (item=vrf) included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-module.yml for dut => (item=routing) TASK [Figure out whether to deploy the module vrf on current device] *********** ok: [dut] TASK [Find configuration template for vrf] ************************************* ok: [dut] TASK [fail] ******************************************************************** skipping: [dut] TASK [Find configuration deployment deploy_script for vrf] ********************* ok: [dut] TASK [Print deployed configuration when running in verbose mode] *************** ok: [dut] => { "msg": "vrf configuration for dut\n=========================================\n\n\npolicy-options {\n delete: policy-statement bgp-red-redistribute;\n delete: route-filter-list bgp-red-announce-ipv4;\n delete: route-filter-list bgp-red-announce-ipv6;\n\n community x-route-permit-mark members large:65535:0:65536;\n\n policy-statement bgp-final {\n term final-option {\n from community x-route-permit-mark;\n then {\n community delete x-route-permit-mark;\n accept;\n }\n }\n term default-reject {\n then reject;\n }\n }\n\n\n policy-statement bgp-red-redistribute {\n\n term redis_bgp {\n from protocol bgp;\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n term redist_connected {\n from {\n protocol direct;\n }\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n\n term default {\n then reject;\n }\n }\n\n\n delete: policy-statement bgp-blue-redistribute;\n delete: route-filter-list bgp-blue-announce-ipv4;\n delete: route-filter-list bgp-blue-announce-ipv6;\n\n community x-route-permit-mark members large:65535:0:65536;\n\n policy-statement bgp-final {\n term final-option {\n from community x-route-permit-mark;\n then {\n community delete x-route-permit-mark;\n accept;\n }\n }\n term default-reject {\n then reject;\n }\n }\n\n\n policy-statement bgp-blue-redistribute {\n\n term redis_bgp {\n from protocol bgp;\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n term redist_connected {\n from {\n protocol direct;\n }\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n\n term default {\n then reject;\n }\n }\n\n\n delete: policy-statement bgp-common-redistribute;\n delete: route-filter-list bgp-common-announce-ipv4;\n delete: route-filter-list bgp-common-announce-ipv6;\n\n community x-route-permit-mark members large:65535:0:65536;\n\n policy-statement bgp-final {\n term final-option {\n from community x-route-permit-mark;\n then {\n community delete x-route-permit-mark;\n accept;\n }\n }\n term default-reject {\n then reject;\n }\n }\n\n\n policy-statement bgp-common-redistribute {\n\n term redis_bgp {\n from protocol bgp;\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n term redist_connected {\n from {\n protocol direct;\n }\n then {\n community add x-route-permit-mark;\n next policy;\n }\n }\n\n term default {\n then reject;\n }\n }\n\n\n}\n\n\nrouting-instances {\n\n red {\n routing-options {\n autonomous-system 65000;\n router-id 10.0.0.4\n }\n\n protocols {\n bgp {\n\n group ebgp-peers {\n export [ ];\n advertise-inactive;\n }\n }\n }\n }\n\n\n blue {\n routing-options {\n autonomous-system 65000;\n router-id 10.0.0.4\n }\n\n protocols {\n bgp {\n\n group ebgp-peers {\n export [ ];\n advertise-inactive;\n }\n }\n }\n }\n\n\n common {\n routing-options {\n autonomous-system 65000;\n router-id 10.0.0.4\n }\n\n protocols {\n bgp {\n\n group ebgp-peers {\n export [ ];\n advertise-inactive;\n }\n }\n }\n }\n\n}\n" } TASK [Deploy vrf configuration] ************************************************ included: /home/pipi/net101/tools/netsim/ansible/tasks/deploy-config/junos.yml for dut TASK [junos_config: deploying vrf from /work/netlab_cicd/other_vm/node_files/dut/vrf] *** [WARNING]: statement not found changed: [dut] TASK [Figure out whether to deploy the module routing on current device] ******* ok: [dut] TASK [Find configuration template for routing] ********************************* skipping: [dut] TASK [fail] ******************************************************************** skipping: [dut] TASK [Find configuration deployment deploy_script for routing] ***************** skipping: [dut] TASK [Print deployed configuration when running in verbose mode] *************** skipping: [dut] TASK [Deploy routing configuration] ******************************************** skipping: [dut] PLAY [Deploy custom deployment templates] ************************************** skipping: no hosts matched PLAY RECAP ********************************************************************* dut : ok=22 changed=2 unreachable=0 failed=0 skipped=10 rescued=0 ignored=0 Results of configuration script deployments ================================================================================ h1 Script: initial,routing h2 Script: initial,routing srv Script: initial,routing The device under test has two user VRFs and a common services VRF. The lab tests inter-VRF route leaking between common VRF and other VRFs * h1 and h2 should be able to ping srv but not each other