↓ Naar de hoofdinhoud gaan

Tips & Tricks

·718 woorden·4 mins
Inhoudsopgave

Point of note: Ubuntu targets
#

Ansible target hsots need to have either SSH (Linux / network equipment) or WinRM (Windows) enabled. Ubuntu does not have a SSH daemon running by default. You could install one on the target system using the following command:

sudo apt update
sudo apt install openssh-server

Verify ansible inventory consistency
#

To check if your Ansible inventory file is valid, you can use the ansible-inventory command with the –list option. This command will attempt to load and parse your inventory file, and display the resulting inventory in JSON format.

Here’s an example of how to use the ansible-inventory command to check if your inventory file is valid:

ansible-inventory -i inventory.ini --list

In this example, the inventory.ini file is the path to your inventory file. If the inventory file is valid, the –list option will display the inventory in JSON format. If the inventory file contains errors, you will see an error message indicating what the problem is.

Visualise ansible inventory
#

In addition to the –list option, you can also use the –graph option to display a visual representation of the inventory graph, which can be helpful for understanding the relationships between hosts and groups.

Here’s an example of how to use the ansible-inventory command with the –graph option:

ansible-inventory -i inventory.ini --graph

This command will display a tree-like graph of the inventory, with hosts and groups represented as nodes and edges connecting them. This can be especially helpful for visualizing the structure of your inventory and identifying any issues with the inventory file.

Verify presence of a machine in the inventory file
#

You can also query to the ansible inventory file to check if a host is present:

ansible <hostname> --list-hosts

SSH to older network devices
#

Older network typically support only legacy encryption suites. Typical examples are switches and routers.
To allow ansible to connect to these hosts, you can use the following procedure:

Edit SSH config

sudo nano /etc/ssh/ssh_config

In this inventory file, unquote the following entry:

Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc

Afterwards, add the following line at the bottom of the file:

KexAlgorithms +diffie-hellman-group1-sha1
HostKeyAlgorithms +ssh-rsa
PubkeyAcceptedKeyTypes +ssh-rsa

Specifically for RHEL, it might also be required to add the SHA1 hashing algorithm in the crypto policies. This can be done with the following command:

sudo update-crypto-policies --set DEFAULT:SHA1

On Rhel8, you might also need the following command:

sudo update-crypto-policies --set LEGACY

For very old switches
#

Some very old switches only support diffiehellman1-group1 negotiations. This is blocked by default on RHEL 8 and RHEL 9 versions.
To enable it, perform the following actions

  1. Create a file in the SSH client config directory
sudo nano /etc/ssh/ssh_config.d/40-sha1.conf
  1. Enter the following string
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
  1. Reboot your RHEL VM
reboot
  1. Verify connectivity with SSH using the following command structure: “ssh <username>@<IP address of switch>”. An example is the following
ssh ansible@192.168.100.5

Help! I can’t connect to switches and routers with my Ansible controller
#

As mentioned before, ansible uses various modules. Additional modules are maintained and centralized in the Ansible Galaxy.
However, many modules are community driven and can contain different SSH packages as their dependancies.
Check if the following Python modules are installed:

  • paramiko
  • ansible-pylibssh
    They can be installed using the following commands:
pip install paramiko
pip install ansible-pylibssh

Install network modules in Ansible
#

The following modules are used for cisco switches

ansible-galaxy collection install ansible.network
ansible-galaxy collection install cisco.ios

This will install the latest version of the ansible.network collection, which includes the ios_command, ios_hostname, ios_interface, ios_interface_vlan, ios_static_route, and ios_vlan modules.

The following module set can also be used for other vendors.
Community network edition

RHEL8: SSH connection to devices that have a RSA key generated with less than 1024 bits
#

  1. On a RHEL7 system, download the packages that are necessary to execute ssh

    ``` mkdir /tmp/miniroot /tmp/packages yum install --downloadonly --installroot=/tmp/miniroot --releasever=/ --downloaddir=/tmp/packages openssh-clients ```

    In the example above, the packages will be available in /tmp/packages directory.

  2. Copy the packages to the RHEL8 system

    scp -r /tmp/packages RHEL8:/root/
  3. On the RHEL8 system, create the miniroot

    # mkdir /rhel7_miniroot
    # semanage fcontext -a -e / /rhel7_miniroot
    # yum install --installroot /rhel7_miniroot ./packages/*.rpm

    In the example above, the miniroot for the container will be installed as /rhel7_miniroot.

  4. On the RHEL8 system, enter the miniroot to access your legacy device

    systemd-nspawn -D /rhel7_miniroot

https://access.redhat.com/solutions/6187741