Point of note: Ubuntu targets #
Ansible target hsots need to have either SSH (Linux / network equipment) or WinRM (Windows) enabled. Ubuntu does not have a SSH daemon running by default. You could install one on the target system using the following command:
sudo apt update
sudo apt install openssh-serverVerify ansible inventory consistency #
To check if your Ansible inventory file is valid, you can use the ansible-inventory command with the –list option. This command will attempt to load and parse your inventory file, and display the resulting inventory in JSON format.
Here’s an example of how to use the ansible-inventory command to check if your inventory file is valid:
ansible-inventory -i inventory.ini --listIn this example, the inventory.ini file is the path to your inventory file. If the inventory file is valid, the –list option will display the inventory in JSON format. If the inventory file contains errors, you will see an error message indicating what the problem is.
Visualise ansible inventory #
In addition to the –list option, you can also use the –graph option to display a visual representation of the inventory graph, which can be helpful for understanding the relationships between hosts and groups.
Here’s an example of how to use the ansible-inventory command with the –graph option:
ansible-inventory -i inventory.ini --graphThis command will display a tree-like graph of the inventory, with hosts and groups represented as nodes and edges connecting them. This can be especially helpful for visualizing the structure of your inventory and identifying any issues with the inventory file.
Verify presence of a machine in the inventory file #
You can also query to the ansible inventory file to check if a host is present:
ansible <hostname> --list-hostsSSH to older network devices #
Older network typically support only legacy encryption suites. Typical examples are switches and routers.
To allow ansible to connect to these hosts, you can use the following procedure:
Edit SSH config
sudo nano /etc/ssh/ssh_configIn this inventory file, unquote the following entry:
Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbcAfterwards, add the following line at the bottom of the file:
KexAlgorithms +diffie-hellman-group1-sha1
HostKeyAlgorithms +ssh-rsa
PubkeyAcceptedKeyTypes +ssh-rsaSpecifically for RHEL, it might also be required to add the SHA1 hashing algorithm in the crypto policies. This can be done with the following command:
sudo update-crypto-policies --set DEFAULT:SHA1On Rhel8, you might also need the following command:
sudo update-crypto-policies --set LEGACYFor very old switches #
Some very old switches only support diffiehellman1-group1 negotiations. This is blocked by default on RHEL 8 and RHEL 9 versions.
To enable it, perform the following actions
- Create a file in the SSH client config directory
sudo nano /etc/ssh/ssh_config.d/40-sha1.conf- Enter the following string
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1- Reboot your RHEL VM
reboot- Verify connectivity with SSH using the following command structure: “ssh <username>@<IP address of switch>”. An example is the following
ssh ansible@192.168.100.5Help! I can’t connect to switches and routers with my Ansible controller #
As mentioned before, ansible uses various modules. Additional modules are maintained and centralized in the Ansible Galaxy.
However, many modules are community driven and can contain different SSH packages as their dependancies.
Check if the following Python modules are installed:
- paramiko
- ansible-pylibssh
They can be installed using the following commands:
pip install paramiko
pip install ansible-pylibsshInstall network modules in Ansible #
The following modules are used for cisco switches
ansible-galaxy collection install ansible.network
ansible-galaxy collection install cisco.iosThis will install the latest version of the ansible.network collection, which includes the ios_command, ios_hostname, ios_interface, ios_interface_vlan, ios_static_route, and ios_vlan modules.
The following module set can also be used for other vendors.
Community network edition
RHEL8: SSH connection to devices that have a RSA key generated with less than 1024 bits #
-
On a RHEL7 system, download the packages that are necessary to execute
ssh``` mkdir /tmp/miniroot /tmp/packages yum install --downloadonly --installroot=/tmp/miniroot --releasever=/ --downloaddir=/tmp/packages openssh-clients ```In the example above, the packages will be available in
/tmp/packagesdirectory. -
Copy the packages to the RHEL8 system
scp -r /tmp/packages RHEL8:/root/ -
On the RHEL8 system, create the miniroot
# mkdir /rhel7_miniroot # semanage fcontext -a -e / /rhel7_miniroot # yum install --installroot /rhel7_miniroot ./packages/*.rpmIn the example above, the miniroot for the container will be installed as
/rhel7_miniroot. -
On the RHEL8 system, enter the miniroot to access your legacy device
systemd-nspawn -D /rhel7_miniroot