FortiOS Firewall Policy64
Resumo
- This module is able to configure a FortiGate or FortiOS (FOS) device by allowing the user to set and modify firewall feature and policy64 category. Examples include all parameters and values need to be adjusted to datasources before usage. Tested with FOS v6.0.5
Requirements
The below requirements are needed on the host that executes this module.
- fortiosapi>=0.9.8
Parameters
ParameterChoices/DefaultsComments | | | | |
|---|---|---|---|---|
firewall_policy64 dictionary | | Configure IPv6 to IPv4 policies. | | |
| action string | | Policy action. | |
| comments string | | Comment. | |
| dstaddr list | | Destination address name. | |
| | name string / required | | Address name. Source firewall.address.name firewall.addrgrp.name firewall.vip64.name firewall.vipgrp64.name. |
| dstintf string | | Destination interface name. Source system.interface.name system.zone.name. | |
| fixedport string | | Enable/disable policy fixed port. | |
| ippool string | | Enable/disable policy64 IP pool. | |
| logtraffic string | | Enable/disable policy log traffic. | |
| per_ip_shaper string | | Per-IP traffic shaper. Source firewall.shaper.per-ip-shaper.name. | |
| permit_any_host string | | Enable/disable permit any host in. | |
| policyid integer / required | | Policy ID. | |
| poolname list | | Policy IP pool names. | |
| | name string / required | | IP pool name. Source firewall.ippool.name. |
| schedule string | | Schedule name. Source firewall.schedule.onetime.name firewall.schedule.recurring.name firewall.schedule.group.name. | |
| service list | | Service name. | |
| | name string / required | | Address name. Source firewall.service.custom.name firewall.service.group.name. |
| srcaddr list | | Source address name. | |
| | name string / required | | Address name. Source firewall.address6.name firewall.addrgrp6.name. |
| srcintf string | | Source interface name. Source system.zone.name system.interface.name. | |
| status string | | Enable/disable policy status. | |
| tcp_mss_receiver integer | | TCP MSS value of receiver. | |
| tcp_mss_sender integer | | TCP MSS value of sender. | |
| traffic_shaper string | | Traffic shaper. Source firewall.shaper.traffic-shaper.name. | |
| traffic_shaper_reverse string | | Reverse traffic shaper. Source firewall.shaper.traffic-shaper.name. | |
| uuid string | | Universally Unique Identifier (UUID; automatically assigned but can be manually reset). | |
host string | | FortiOS or FortiGate IP address. | | |
https boolean | | Indicates if the requests towards FortiGate must use HTTPS protocol. | | |
password string | Default: "" | FortiOS or FortiGate password. | | |
ssl_verify booleanadded in 2.9 | | Ensures FortiGate certificate must be verified by a proper CA. | | |
state stringadded in 2.9 | | Indicates whether to create or remove the object. This attribute was present already in previous version in a deeper level. It has been moved out to this outer level. | | |
username string | | FortiOS or FortiGate username. | | |
vdom string | Default: "root" | Virtual domain, among those defined previously. A vdom is a virtual instance of the FortiGate that can be configured and used as a different unit. | | |
Notes
Note
- Requires fortiosapi library developed by Fortinet
- Run as a local_action in your playbook
Examples
Return Values
Common return values are documented here, the following are the fields unique to this module: