FortiOS Firewall Vip
Resumo
- Configure o IP virtual para IPv4 no FortiOS e FortiGate.
Parâmetros
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
firewall_vip | dictionary | | Configure o IP virtual para IPv4. |
state | string | Escolhas: - present (default) - absent | Indica se deve criar ou remover o objeto. Use present para criar, ou absent para excluí-lo. |
Subcampos da opção firewall_vip
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
arp_reply | string | Escolhas: - disable - enable | Ative para responder às solicitações ARP para este endereço IP virtual. Ativado por padrão. |
color | integer | | Cor do ícone na GUI. |
comment | string | | Comentário. |
dns_mapping_ttl | integer | | TTL de mapeamento de DNS (defina como zero para usar TTL na resposta de DNS). |
extaddr | list | | Nome do endereço FQDN externo. |
extintf | string | | Interface conectada à rede de origem que recebe os pacotes que serão encaminhados à rede de destino. |
extip | string | | Endereço IP ou intervalo de endereços na interface externa que você deseja mapear para um endereço ou intervalo de endereços na rede de destino. |
extport | string | | Intervalo de número de porta de entrada que você deseja mapear para um intervalo de número de porta na rede de destino. |
gratuitous_arp_interval | integer | | Ative para que o VIP envie ARPs gratuitos. 0 = desativado. Defina de 5 a 8640000 segundos para ativar. |
http_cookie_age | integer | | Tempo em minutos que os navegadores da web do cliente devem manter um cookie. O padrão é 60 segundos. 0 = sem limite de tempo. |
http_cookie_domain | string | | Domínio ao qual a persistência do cookie HTTP deve se aplicar. |
http_cookie_domain_from_host | string | Escolhas: - disable - enable | Habilite/desabilite o uso do domínio do cookie HTTP do campo do host em HTTP. |
http_cookie_generation | integer | | Geração de cookie HTTP à ser aceito. A alteração invalida todos os cookies existentes. |
http_cookie_path | string | | Limita a persistência do cookie HTTP ao caminho especificado. |
http_cookie_share | string | Escolhas: - disable - same-ip | Controle o compartilhamento de cookies em servidores virtuais. Mesmo IP significa que um cookie de um servidor virtual pode ser usado por outro. Desativar interrompe o compartilhamento de cookies. |
http_ip_header | string | Escolhas: - disable - enable | Para multiplexação HTTP, ative para adicionar o endereço IP do cliente original no cabeçalho XForwarded-For HTTP. |
http_ip_header_name | string | | Para multiplexação HTTP, insira um nome de cabeçalho HTTPS customizado. O endereço IP do cliente original é adicionado a este cabeçalho. Se vazio, X-Forwarded-For é usado. |
http_multiplex | string | Escolhas: - disable - enable | Ative / desative a multiplexação HTTP. |
https_cookie_secure | string | Escolhas: - disable - enable | Ative / desative a verificação de que os cookies HTTPS inseridos são seguros. |
id | integer | | ID definido de forma personalizada. |
ldb_method | string | Escolhas: - static - round-robin - weighted - least-session - least-rtt - first-alive - http-host | Método usado para distribuir sessões para servidores reais. |
mapped_addr | string | | Nome do endereço FQDN mapeado. |
mappedip | list | | Endereço IP ou intervalo de endereços na rede de destino, para a qual o endereço IP externo está mapeado. |
mappedport | string | | Intervalo de número de porta na rede de destino, para o qual o intervalo de número de porta externa está mapeado. |
max_embryonic_connections | integer | | Número máximo de conexões incompletas. |
monitor | list | | Nome do monitor de verificação de integridade a ser usado durante a sondagem, para determinar o status de conectividade de um servidor virtual. |
name - required | string | | Nome do IP virtual. |
nat_source_vip | string | Escolhas: - disable - enable | Habilite / desabilite forçando o IP mapeado por NAT de origem para o IP externo para todo o tráfego. |
outlook_web_access | string | Escolhas: - disable - enable | Ative para adicionar o cabeçalho Front-End-Https para o Microsoft Outlook Web Access. |
persistence | string | Escolhas: - none - http-cookie - ssl-session-id | Configure para garantir que os clientes se conectem ao mesmo servidor, sempre que fizerem uma solicitação que faça parte da mesma sessão. |
portforward | string | Escolhas: - disable - enable | Ativar / desativar o encaminhamento de porta. |
portmapping_type | string | Escolhas: - 1-to-1 - m-to-n | Tipo de mapeamento de porta. |
protocol | string | Escolhas: - tcp - udp - sctp - icmp | Protocolo a ser usado ao encaminhar pacotes. |
realservers | list | | Selecione os servidores reais para os quais este VIP de balanceamento de carga de servidor distribuirá o tráfego. |
server_type | string | Escolhas: - http - https - imaps - pop3s - smtps - ssl - tcp - udp - ip | Protocolo a ser balanceado por carga pelo servidor virtual (também chamado de IP virtual de balanceamento de carga do servidor). |
service | list | | Service name. |
src_filter | list | | Source address filter. Each address must be either an IP/subnet (x.x.x.x/n) or a range (x.x.x.x-y.y.y.y). Separate addresses with spaces. |
srcintf_filter | list | | Interfaces to which the VIP applies. Separate the names with spaces. |
ssl_algorithm | string | Escolhas: - high - medium - low - custom | Permitted encryption algorithms for SSL sessions according to encryption strength. |
ssl_certificate | string | | The name of the SSL certificate to use for SSL acceleration. Source vpn.certificate.local.name. |
ssl_cipher_suites | list | | SSL/TLS cipher suites acceptable from a client, ordered by priority. |
ssl_client_fallback | string | Escolhas: - disable - enable | Enable/disable support for preventing Downgrade Attacks on client connections (RFC 7507). |
ssl_client_renegotiation | string | Escolhas: - allow - deny - secure | Allow, deny, or require secure renegotiation of client sessions to comply with RFC 5746. |
ssl_client_session_state_max | integer | | Maximum number of client to FortiGate SSL session states to keep. |
ssl_client_session_state_timeout | integer | | Number of minutes to keep client to FortiGate SSL session state. |
ssl_client_session_state_type | string | Escolhas: - disable - time - count - both | How to expire SSL sessions for the segment of the SSL connection between the client and the FortiGate. |
ssl_dh_bits | string | Escolhas: - 768 - 1024 - 1536 - 2048 - 3072 - 4096 | Number of bits to use in the Diffie-Hellman exchange for RSA encryption of SSL sessions. |
ssl_hpkp | string | Escolhas: - disable - enable - report-only | Enable/disable including HPKP header in response. |
ssl_hpkp_age | integer | | Number of seconds the client should honour the HPKP setting. |
ssl_hpkp_backup | string | | Certificate to generate backup HPKP pin from. Source vpn.certificate.local.name vpn.certificate.ca.name. |
ssl_hpkp_include_subdomains | string | Escolhas: - disable - enable | Indicate that HPKP header applies to all subdomains. |
ssl_hpkp_primary | string | | Certificate to generate primary HPKP pin from. Source vpn.certificate.local.name vpn.certificate.ca.name. |
ssl_hpkp_report_uri | string | | URL to report HPKP violations to. |
ssl_hsts | string | Escolhas: - disable - enable | Enable/disable including HSTS header in response. |
ssl_hsts_age | integer | | Number of seconds the client should honour the HSTS setting. |
ssl_hsts_include_subdomains | string | Escolhas: - disable - enable | Indicate that HSTS header applies to all subdomains. |
ssl_http_location_conversion | string | Escolhas: - disable - enable | Enable to replace HTTP with HTTPS in the reply's Location HTTP header field. |
ssl_http_match_host | string | Escolhas: - disable - enable | Enable/disable HTTP host matching for location conversion. |
ssl_max_version | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 | Highest SSL/TLS version acceptable from a client. |
ssl_min_version | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 | Lowest SSL/TLS version acceptable from a client. |
ssl_mode | string | Escolhas: - half - full | Apply SSL offloading between the client and the FortiGate (half) or from the client to the FortiGate and from the FortiGate to the server (full). |
ssl_pfs | string | Escolhas: - require - deny - allow | Select the cipher suites that can be used for SSL perfect forward secrecy (PFS). Applies to both client and server sessions. |
ssl_send_empty_frags | string | Escolhas: - enable - disable | Enable/disable sending empty fragments to avoid CBC IV attacks (SSL 3.0 & TLS 1.0 only). May need to be disabled for compatibility with older systems. |
ssl_server_algorithm | string | Escolhas: - high - medium - low - custom - client | Permitted encryption algorithms for the server side of SSL full mode sessions according to encryption strength. |
ssl_server_cipher_suites | list | | SSL/TLS cipher suites to offer to a server, ordered by priority. |
ssl_server_max_version | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client | Highest SSL/TLS version acceptable from a server. Use the client setting by default. |
ssl_server_min_version | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client | Lowest SSL/TLS version acceptable from a server. Use the client setting by default. |
ssl_server_session_state_max | integer | | Maximum number of FortiGate to Server SSL session states to keep. |
ssl_server_session_state_timeout | integer | | Number of minutes to keep FortiGate to Server SSL session state. |
ssl_server_session_state_type | string | Escolhas: - disable - time - count - both | How to expire SSL sessions for the segment of the SSL connection between the server and the FortiGate. |
type | string | Escolhas: - static-nat - load-balance - server-load-balance - dns-translation - fqdn | Configure a static NAT, load balance, server load balance, DNS translation, or FQDN VIP. |
uuid | string | | Universally Unique Identifier (UUID; automatically assigned but can be manually reset). |
weblogic_server | string | Escolhas: - disable - enable | Enable to add an HTTP header to indicate SSL offloading for a WebLogic server. |
websphere_server | string | Escolhas: - disable - enable | Enable to add an HTTP header to indicate SSL offloading for a WebSphere server. |
Subcampos da opção extaddr
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
name - required | string | | Address name. Source firewall.address.name firewall.addrgrp.name. |
Subcampos da opção mappedip
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
range - required | string | | Mapped IP range. |
Subcampos da opção monitor
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
name - required | string | | Health monitor name. Source firewall.ldb-monitor.name. |
Subcampos da opção realservers
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
client_ip | string | | Only clients in this IP range can connect to this real server. |
healthcheck | string | Escolhas: - disable - enable - vip | Enable to check the responsiveness of the real server before forwarding traffic. |
holddown_interval | integer | | Time in seconds that the health check monitor continues to monitor and unresponsive server that should be active. |
http_host | string | | HTTP server domain name in HTTP header. |
id - required | integer | | Real server ID. |
ip | string | | IP address of the real server. |
max_connections | integer | | Max number of active connections that can be directed to the real server. When reached, sessions are sent to other real servers. |
monitor | string | | Name of the health check monitor to use when polling to determine a virtual server's connectivity status. Source firewall .ldb-monitor.name. |
port | integer | | Port for communicating with the real server. Required if port forwarding is enabled. |
status | string | Escolhas: - active - standby - disable | Set the status of the real server to active so that it can accept traffic, or on standby or disabled so no traffic is sent. |
weight | integer | | Weight of the real server. If weighted load balancing is enabled, the server with the highest weight gets more connections. |
Subcampos da opção service
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
name - required | string | | Service name. Source firewall.service.custom.name firewall.service.group.name. |
Subcampos da opção src_filter
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
range - required | string | | Source-filter range. |
Subcampos da opção srcintf_filter
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
interface_name | string | | Interface name. Source system.interface.name. |
Subcampos da opção ssl_cipher_suites
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
cipher | string | Escolhas: - TLS-RSA-WITH-3DES-EDE-CBC-SHA - TLS-DHE-RSA-WITH-DES-CBC-SHA - TLS-DHE-DSS-WITH-DES-CBC-SHA | Cipher suite name. |
priority - required | integer | | SSL/TLS cipher suites priority. |
versions | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 | SSL/TLS versions that the cipher suite can be used with. |
Subcampos da opção ssl_server_cipher_suites
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
cipher | string | Escolhas: - TLS-RSA-WITH-3DES-EDE-CBC-SHA - TLS-DHE-RSA-WITH-DES-CBC-SHA - TLS-DHE-DSS-WITH-DES-CBC-SHA | Cipher suite name. |
priority - required | integer | | SSL/TLS cipher suites priority. |
versions | string | Escolhas: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 | SSL/TLS versions that the cipher suite can be used with. |
Exemplos
# Exemplo: Configure virtual IP for IPv4.
- fortios_firewall_vip:
host: "host"
username: "username"
password: "password"
vdom: "vdom"
https: "False"
state: "present"
firewall_vip:
arp_reply: "disable"
color: "4"
comment: "Comment."
dns_mapping_ttl: "6"
extaddr:
- name: "default_name_8 (source firewall.address.name firewall.addrgrp.name)"
extintf: "<your_own_value> (source system.interface.name)"
extip: "<your_own_value>"
extport: "<your_own_value>"
gratuitous_arp_interval: "12"
http_cookie_age: "13"
http_cookie_domain: "<your_own_value>"
http_cookie_domain_from_host: "disable"
http_cookie_generation: "16"
http_cookie_path: "<your_own_value>"
http_cookie_share: "disable"
http_ip_header: "enable"
http_ip_header_name: "<your_own_value>"
http_multiplex: "enable"
https_cookie_secure: "disable"
id: "23"
ldb_method: "static"
mapped_addr: "<your_own_value> (source firewall.address.name)"
mappedip:
- range: "<your_own_value>"
mappedport: "<your_own_value>"
max_embryonic_connections: "29"
monitor:
- name: "default_name_31 (source firewall.ldb-monitor.name)"
name: "default_name_32"
nat_source_vip: "disable"
outlook_web_access: "disable"
persistence: "none"
portforward: "disable"
portmapping_type: "1-to-1"
protocol: "tcp"
realservers:
- client_ip: "<your_own_value>"
healthcheck: "disable"
holddown_interval: "42"
http_host: "myhostname"
id: "44"
ip: "<your_own_value>"
max_connections: "46"
monitor: "<your_own_value> (source firewall.ldb-monitor.name)"
port: "48"
status: "active"
weight: "50"
server_type: "http"
service:
- name: "default_name_53 (source firewall.service.custom.name firewall.service.group.name)"
src_filter:
- range: "<your_own_value>"
srcintf_filter:
- interface_name: "<your_own_value> (source system.interface.name)"
ssl_algorithm: "high"
ssl_certificate: "<your_own_value> (source vpn.certificate.local.name)"
ssl_cipher_suites:
- cipher: "TLS-RSA-WITH-3DES-EDE-CBC-SHA"
priority: "62"
versions: "ssl-3.0"
ssl_client_fallback: "disable"
ssl_client_renegotiation: "allow"
ssl_client_session_state_max: "66"
ssl_client_session_state_timeout: "67"
ssl_client_session_state_type: "disable"
ssl_dh_bits: "768"
ssl_hpkp: "disable"
ssl_hpkp_age: "71"
ssl_hpkp_backup: "<your_own_value> (source vpn.certificate.local.name vpn.certificate.ca.name)"
ssl_hpkp_include_subdomains: "disable"
ssl_hpkp_primary: "<your_own_value> (source vpn.certificate.local.name vpn.certificate.ca.name)"
ssl_hpkp_report_uri: "<your_own_value>"
ssl_hsts: "disable"
ssl_hsts_age: "77"
ssl_hsts_include_subdomains: "disable"
ssl_http_location_conversion: "enable"
ssl_http_match_host: "enable"
ssl_max_version: "ssl-3.0"
ssl_min_version: "ssl-3.0"
ssl_mode: "half"
ssl_pfs: "require"
ssl_send_empty_frags: "enable"
ssl_server_algorithm: "high"
ssl_server_cipher_suites:
- cipher: "TLS-RSA-WITH-3DES-EDE-CBC-SHA"
priority: "89"
versions: "ssl-3.0"
ssl_server_max_version: "ssl-3.0"
ssl_server_min_version: "ssl-3.0"
ssl_server_session_state_max: "93"
ssl_server_session_state_timeout: "94"
ssl_server_session_state_type: "disable"
type: "static-nat"
uuid: "<your_own_value>"
weblogic_server: "disable"
websphere_server: "disable"
Valores retornados
Este módulo extende os mesmos valores retornados do módulo base fortios.