ngine_io.cloudstack.cs_vpn_customer_gateway module – Manages site-to-site VPN customer gateway configurations on Apache CloudStack based clouds.
Note
This module is part of the ngine_io.cloudstack collection (version 2.5.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install ngine_io.cloudstack.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: ngine_io.cloudstack.cs_vpn_customer_gateway.
New in ngine_io.cloudstack 0.1.0
Synopsis
- Create, update and remove VPN customer gateways. 
Requirements
The below requirements are needed on the host that executes this module.
- python >= 2.6 
- cs >= 0.9.0 
Parameters
| Parameter | Comments | 
|---|---|
| Account the VPN customer gateway is related to. | |
| HTTP method used to query the API endpoint. If not given, the  Choices: 
 | |
| API key of the CloudStack API. If not given, the  | |
| Secret key of the CloudStack API. If not set, the  | |
| HTTP timeout in seconds. If not given, the  Default:  | |
| URL of the CloudStack API e.g. https://cloud.example.com/client/api. If not given, the  | |
| Verify CA authority cert file. If not given, the  | |
| List of guest CIDRs behind the gateway. Required if state=present. | |
| Domain the VPN customer gateway is related to. | |
| Enable Dead Peer Detection. Disabled per default by the API on creation if not set. Choices: 
 | |
| Lifetime in seconds of phase 2 VPN connection. Defaulted to 3600 by the API on creation if not set. | |
| ESP policy in the format e.g.  Required if state=present. | |
| Force encapsulation for NAT traversal. Disabled per default by the API on creation if not set. Choices: 
 | |
| Public IP address of the gateway. Required if state=present. | |
| Lifetime in seconds of phase 1 VPN connection. Defaulted to 86400 by the API on creation if not set. | |
| IKE policy in the format e.g.  Required if state=present. | |
| IPsec Preshared-Key. Cannot contain newline or double quotes. Required if state=present. | |
| Name of the gateway. | |
| Poll async jobs until job has finished. Choices: 
 | |
| Name of the project the VPN gateway is related to. | |
| State of the VPN customer gateway. Choices: 
 | |
| If  If not given, the  This should only be used on personally controlled sites using self-signed certificates. Choices: 
 | 
Notes
Note
- A detailed guide about cloudstack modules can be found in the CloudStack Cloud Guide. 
- This module supports check mode. 
Examples
- name: Create a vpn customer gateway
  ngine_io.cloudstack.cs_vpn_customer_gateway:
    name: my vpn customer gateway
    cidrs:
    - 192.168.123.0/24
    - 192.168.124.0/24
    esp_policy: aes256-sha1;modp1536
    gateway: 10.10.1.1
    ike_policy: aes256-sha1;modp1536
    ipsec_psk: "S3cr3Tk3Y"
- name: Remove a vpn customer gateway
  ngine_io.cloudstack.cs_vpn_customer_gateway:
    name: my vpn customer gateway
    state: absent
Return Values
Common return values are documented here, the following are the fields unique to this module:
| Key | Description | 
|---|---|
| Account the VPN customer gateway is related to. Returned: success Sample:  | |
| List of CIDRs of this customer gateway. Returned: success Sample:  | |
| Domain the VPN customer gateway is related to. Returned: success Sample:  | |
| Whether dead pear detection is enabled or not. Returned: success Sample:  | |
| Lifetime in seconds of phase 2 VPN connection. Returned: success Sample:  | |
| IKE policy of the VPN customer gateway. Returned: success Sample:  | |
| Whether encapsulation for NAT traversal is enforced or not. Returned: success Sample:  | |
| IP address of the VPN customer gateway. Returned: success Sample:  | |
| UUID of the VPN customer gateway. Returned: success Sample:  | |
| Lifetime in seconds of phase 1 VPN connection. Returned: success Sample:  | |
| ESP policy of the VPN customer gateway. Returned: success Sample:  | |
| Name of this customer gateway. Returned: success Sample:  | |
| Name of project the VPN customer gateway is related to. Returned: success Sample:  | 
