diff --git a/examples/vpc_peering_common_dual_stack/example.tfvars b/examples/vpc_peering_common_dual_stack/example.tfvars index 56e13b0..65dc39d 100644 --- a/examples/vpc_peering_common_dual_stack/example.tfvars +++ b/examples/vpc_peering_common_dual_stack/example.tfvars @@ -58,7 +58,7 @@ networks = { firewall_rules = { allow-mgmt-ingress = { name = "allow-mgmt-ingress" - source_ranges = ["1.1.1.1/32"] # Modify this value as per deployment requirements. Replace 1.1.1.1/32 with your own source IP address for management purposes. + source_ranges = ["10.10.10.0/28"] # Set your own management source IP range. priority = "1000" allowed_protocol = "all" allowed_ports = [] diff --git a/examples/vpc_peering_common_dual_stack/files/fw-vmseries-01/config/bootstrap.xml b/examples/vpc_peering_common_dual_stack/files/fw-vmseries-01/config/bootstrap.xml new file mode 100755 index 0000000..8cfa9df --- /dev/null +++ b/examples/vpc_peering_common_dual_stack/files/fw-vmseries-01/config/bootstrap.xml @@ -0,0 +1,858 @@ + + + + + + * + + + yes + + + + + + yes + 8 + + + + + + + + + + + + yes + 5 + + + yes + 5 + + + yes + 5 + + + yes + 10 + + + yes + 5 + + + + yes + + + + 10 + 10 + + 100 + 50 + + + + 10 + 10 + + 100 + 50 + + + + + + 100 + yes + + + + + + + + + + + + yes + + + + + + + no + + + + + + no + + no + + + + + yes + + + + yes + + + + + + yes + 100 + + + + no + + + + no + + + no + + + no + + lb_health_check + + no + + + + + + + yes + + + + + + + no + + + + + + no + + no + + + + + yes + + + + no + + + + + + yes + 100 + + + + no + + + + no + + + no + + + no + + + no + + lb_health_check + + + + + + + + no + + + + + + + yes +
+ + yes + + + yes + +
+
+ lb_health_check +
+
+
+
+ + + + 3 + 5 + wait-recover + + + + + + + + + + + + + yes + + + + + + + + + aes-128-cbc + 3des + + + sha1 + + + group2 + + + 8 + + + + + aes-128-cbc + + + sha256 + + + group19 + + + 8 + + + + + aes-256-cbc + + + sha384 + + + group20 + + + 8 + + + + + + + + aes-128-cbc + 3des + + + sha1 + + + group2 + + 1 + + + + + + aes-128-gcm + + + none + + + group19 + + 1 + + + + + + aes-256-gcm + + + none + + + group20 + + 1 + + + + + + + aes-128-cbc + + + sha1 + + + + + + + + + + + + + real-time + + + high + + + high + + + medium + + + medium + + + low + + + low + + + low + + + + + + + + + + + + no + + + 1.25 + 0.5 + 900 + 300 + 900 + yes + + + + + yes + + + + + no + + + no + + + no + + + + ethernet1/1 + ethernet1/2 + loopback.10 + + + + + + yes + yes + 4 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 35.191.0.0/16 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 35.191.0.0/16 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 209.85.152.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 209.85.152.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 209.85.204.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 209.85.204.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 130.211.0.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 130.211.0.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 0.0.0.0/0 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 192.168.0.0/16 + + + + + + + + + + + fe80::1 + + + None + + ethernet1/1 + 10 + 2600:1901:8001::/48 + + + + + + + fe80::1 + + + None + + ethernet1/2 + 10 + 2600:2d00:1:b029::/64 + + + + + + + fe80::10 + + + None + + ethernet1/2 + 10 + fd20::/20 + + + + + + + + + +
+ + + + + yes + no + no + no + + + updates.paloaltonetworks.com + + + + + wednesday + 01:02 + download-only + + + + + US/Pacific + + yes + yes + + + + 0.us.pool.ntp.org + + + + + + 1.us.pool.ntp.org + + + + + + + + + yes + + + FQDN + + panadmin + + + yes + no + no + no + + + + + + + + + + + + + + + ethernet1/1 + loopback.10 + + + + + + + ethernet1/2 + + + + + + + + + + + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + allow + + + + + + + + + + ethernet1/1 + + + + + public + + + private + + + 192.168.0.0/16 + + + any + + any + + + nptv6 + + private + + + public + + any + any + + fd20::/20 + + + any + + + + 1::/96 + + + no + + + + + + + + ethernet1/1 + ethernet1/2 + loopback.10 + + + + + +
+
+
\ No newline at end of file diff --git a/examples/vpc_peering_common_dual_stack/files/fw-vmseries-02/config/bootstrap.xml b/examples/vpc_peering_common_dual_stack/files/fw-vmseries-02/config/bootstrap.xml new file mode 100755 index 0000000..8cfa9df --- /dev/null +++ b/examples/vpc_peering_common_dual_stack/files/fw-vmseries-02/config/bootstrap.xml @@ -0,0 +1,858 @@ + + + + + + * + + + yes + + + + + + yes + 8 + + + + + + + + + + + + yes + 5 + + + yes + 5 + + + yes + 5 + + + yes + 10 + + + yes + 5 + + + + yes + + + + 10 + 10 + + 100 + 50 + + + + 10 + 10 + + 100 + 50 + + + + + + 100 + yes + + + + + + + + + + + + yes + + + + + + + no + + + + + + no + + no + + + + + yes + + + + yes + + + + + + yes + 100 + + + + no + + + + no + + + no + + + no + + lb_health_check + + no + + + + + + + yes + + + + + + + no + + + + + + no + + no + + + + + yes + + + + no + + + + + + yes + 100 + + + + no + + + + no + + + no + + + no + + + no + + lb_health_check + + + + + + + + no + + + + + + + yes +
+ + yes + + + yes + +
+
+ lb_health_check +
+
+
+
+ + + + 3 + 5 + wait-recover + + + + + + + + + + + + + yes + + + + + + + + + aes-128-cbc + 3des + + + sha1 + + + group2 + + + 8 + + + + + aes-128-cbc + + + sha256 + + + group19 + + + 8 + + + + + aes-256-cbc + + + sha384 + + + group20 + + + 8 + + + + + + + + aes-128-cbc + 3des + + + sha1 + + + group2 + + 1 + + + + + + aes-128-gcm + + + none + + + group19 + + 1 + + + + + + aes-256-gcm + + + none + + + group20 + + 1 + + + + + + + aes-128-cbc + + + sha1 + + + + + + + + + + + + + real-time + + + high + + + high + + + medium + + + medium + + + low + + + low + + + low + + + + + + + + + + + + no + + + 1.25 + 0.5 + 900 + 300 + 900 + yes + + + + + yes + + + + + no + + + no + + + no + + + + ethernet1/1 + ethernet1/2 + loopback.10 + + + + + + yes + yes + 4 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 35.191.0.0/16 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 35.191.0.0/16 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 209.85.152.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 209.85.152.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 209.85.204.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 209.85.204.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 130.211.0.0/22 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 130.211.0.0/22 + + + + + + + 10.10.11.1 + + + None + + + no + any + 2 + + ethernet1/1 + 10 + 0.0.0.0/0 + + + + + + + 10.10.12.1 + + + None + + + no + any + 2 + + ethernet1/2 + 10 + 192.168.0.0/16 + + + + + + + + + + + fe80::1 + + + None + + ethernet1/1 + 10 + 2600:1901:8001::/48 + + + + + + + fe80::1 + + + None + + ethernet1/2 + 10 + 2600:2d00:1:b029::/64 + + + + + + + fe80::10 + + + None + + ethernet1/2 + 10 + fd20::/20 + + + + + + + + + +
+ + + + + yes + no + no + no + + + updates.paloaltonetworks.com + + + + + wednesday + 01:02 + download-only + + + + + US/Pacific + + yes + yes + + + + 0.us.pool.ntp.org + + + + + + 1.us.pool.ntp.org + + + + + + + + + yes + + + FQDN + + panadmin + + + yes + no + no + no + + + + + + + + + + + + + + + ethernet1/1 + loopback.10 + + + + + + + ethernet1/2 + + + + + + + + + + + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + + any + + allow + + + + + + + + + + ethernet1/1 + + + + + public + + + private + + + 192.168.0.0/16 + + + any + + any + + + nptv6 + + private + + + public + + any + any + + fd20::/20 + + + any + + + + 1::/96 + + + no + + + + + + + + ethernet1/1 + ethernet1/2 + loopback.10 + + + + + +
+
+
\ No newline at end of file