fortinet / fortinet.fortimanager / 2.4.0 / module / fmgr_firewall_address Configure IPv4 addresses. | "added in version" 1.0.0 of fortinet.fortimanager" Authors: Xinwei Du (@dux-fortinet), Xing Li (@lix-fortinet), Jie Xue (@JieX19), Link Zheng (@chillancezen), Frank Shen (@fshen01), Hongbin Lu (@fgtdev-hblu) preview | supported by communityfortinet.fortimanager.fmgr_firewall_address (2.4.0) — module
Install with ansible-galaxy collection install fortinet.fortimanager:==2.4.0
collections: - name: fortinet.fortimanager version: 2.4.0
This module is able to configure a FortiManager device.
Examples include all parameters and values which need to be adjusted to data sources before usage.
- name: Example playbook hosts: fortimanagers connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Configure IPv4 addresses. fortinet.fortimanager.fmgr_firewall_address: bypass_validation: false adom: ansible state: present firewall_address: allow-routing: disable associated-interface: any name: "ansible-test1" visibility: disable
- name: Gathering fortimanager facts hosts: fortimanagers gather_facts: false connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Retrieve all the IPv4 addresses fortinet.fortimanager.fmgr_fact: facts: selector: "firewall_address" params: adom: "ansible" address: "your_value"
- name: Example playbook hosts: fortimanagers connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Configure IPv4 addresses. fortinet.fortimanager.fmgr_firewall_address: bypass_validation: false adom: root state: present firewall_address: allow-routing: disable associated-interface: any name: "address-orignal" # visibility: enable - name: Rename the firewall addressobject fortinet.fortimanager.fmgr_rename: rename: selector: "firewall_address" self: adom: "root" address: "address-orignal" target: name: "address-new" - name: Delete renamed object fortinet.fortimanager.fmgr_firewall_address: adom: "root" state: absent firewall_address: name: "address-new"
- name: Example playbook hosts: fortimanagers connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Create IPv4 addresses. fortinet.fortimanager.fmgr_firewall_address: adom: root state: present firewall_address: allow-routing: disable associated-interface: any name: "fooaddress" visibility: disable register: info failed_when: info.rc != 0 - name: Create IPv4 addresses. fortinet.fortimanager.fmgr_firewall_address: adom: root state: present firewall_address: allow-routing: disable associated-interface: any name: "fooaddress" visibility: disable register: info failed_when: info.message != 'Object update skipped!' - name: Delete created address fortinet.fortimanager.fmgr_firewall_address: adom: root state: absent firewall_address: name: "fooaddress"
adom: description: The parameter (adom) in requested url. required: true type: str state: choices: - present - absent description: The directive to create, update or delete an object. required: true type: str rc_failed: description: The rc codes list with which the conditions to fail will be overriden. elements: int type: list enable_log: default: false description: Enable/Disable logging for task. type: bool access_token: description: The token to access FortiManager without using username and password. type: str rc_succeeded: description: The rc codes list with which the conditions to succeed will be overriden. elements: int type: list proposed_method: choices: - update - set - add description: The overridden method for the underlying Json RPC request. type: str firewall_address: description: The top level parameters set. required: false suboptions: _image-base64: description: Deprecated, please rename it to _image_base64. _Image-Base64. type: str allow-routing: choices: - disable - enable description: Deprecated, please rename it to allow_routing. Enable/disable use of this address in the static route configuration. type: str associated-interface: description: Deprecated, please rename it to associated_interface. Network interface associated with address. type: str cache-ttl: description: Deprecated, please rename it to cache_ttl. Defines the minimal TTL of individual IP addresses in FQDN cache measured in se... type: int clearpass-spt: choices: - unknown - healthy - quarantine - checkup - transition - infected - transient description: Deprecated, please rename it to clearpass_spt. SPT type: str color: description: Color of icon on the GUI. type: int comment: description: (dict or str) No description. type: raw country: description: IP addresses associated to a specific country. type: str dirty: choices: - dirty - clean description: To be deleted address. type: str dynamic_mapping: description: Dynamic_Mapping. elements: dict suboptions: _image-base64: description: Deprecated, please rename it to _image_base64. _Image-Base64. type: str _scope: description: _Scope. elements: dict suboptions: name: description: Name. type: str vdom: description: Vdom. type: str type: list allow-routing: choices: - disable - enable description: Deprecated, please rename it to allow_routing. Enable/disable use of this address in the static route configuration. type: str associated-interface: description: Deprecated, please rename it to associated_interface. Network interface associated with address. type: str cache-ttl: description: Deprecated, please rename it to cache_ttl. Defines the minimal TTL of individual IP addresses in FQDN cache measur... type: int clearpass-spt: choices: - unknown - healthy - quarantine - checkup - transition - infected - transient description: Deprecated, please rename it to clearpass_spt. SPT type: str color: description: Color of icon on the GUI. type: int comment: description: (dict or str) No description. type: raw country: description: IP addresses associated to a specific country. type: str dirty: choices: - dirty - clean description: To be deleted address. type: str end-ip: description: Deprecated, please rename it to end_ip. Final IP address type: str end-mac: description: Deprecated, please rename it to end_mac. Last MAC address in the range. type: str epg-name: description: Deprecated, please rename it to epg_name. Endpoint group name. type: str fabric-object: choices: - disable - enable description: Deprecated, please rename it to fabric_object. Security Fabric global object setting. type: str filter: description: Match criteria filter. type: str fqdn: description: Fully Qualified Domain Name address. type: str fsso-group: description: (list or str) Deprecated, please rename it to fsso_group. FSSO group type: raw global-object: description: Deprecated, please rename it to global_object. Global-Object. type: int hw-model: description: Deprecated, please rename it to hw_model. Dynamic address matching hardware model. type: str hw-vendor: description: Deprecated, please rename it to hw_vendor. Dynamic address matching hardware vendor. type: str interface: description: Name of interface whose IP address is to be used. type: str macaddr: description: (list) Macaddr. type: raw node-ip-only: choices: - disable - enable description: Deprecated, please rename it to node_ip_only. Enable/disable collection of node addresses only in Kubernetes. type: str obj-id: description: Deprecated, please rename it to obj_id. Object ID for NSX. type: str obj-tag: description: Deprecated, please rename it to obj_tag. Obj-Tag. type: str obj-type: choices: - ip - mac description: Deprecated, please rename it to obj_type. Obj-Type. type: str organization: description: Organization domain name type: str os: description: Dynamic address matching operating system. type: str pattern-end: description: Deprecated, please rename it to pattern_end. type: int pattern-start: description: Deprecated, please rename it to pattern_start. type: int policy-group: description: Deprecated, please rename it to policy_group. Policy group name. type: str route-tag: description: Deprecated, please rename it to route_tag. Route-tag address. type: int sdn: choices: - aci - aws - nsx - nuage - azure - gcp - oci - openstack description: SDN. type: str sdn-addr-type: choices: - private - public - all description: Deprecated, please rename it to sdn_addr_type. Type of addresses to collect. type: str sdn-tag: description: Deprecated, please rename it to sdn_tag. SDN Tag. type: str start-ip: description: Deprecated, please rename it to start_ip. First IP address type: str start-mac: description: Deprecated, please rename it to start_mac. First MAC address in the range. type: str sub-type: choices: - sdn - clearpass-spt - fsso - ems-tag - swc-tag - fortivoice-tag - fortinac-tag - fortipolicy-tag - device-identification description: Deprecated, please rename it to sub_type. Sub-type of address. type: str subnet: description: IP address and subnet mask of address. type: str subnet-name: description: Deprecated, please rename it to subnet_name. Subnet name. type: str sw-version: description: Deprecated, please rename it to sw_version. Dynamic address matching software version. type: str tag-detection-level: description: Deprecated, please rename it to tag_detection_level. Tag detection level of dynamic address object. type: str tag-type: description: Deprecated, please rename it to tag_type. Tag type of dynamic address object. type: str tags: description: (list or str) Tags. type: raw tenant: description: Tenant. type: str type: choices: - ipmask - iprange - fqdn - wildcard - geography - url - wildcard-fqdn - nsx - aws - dynamic - interface-subnet - mac - fqdn-group - route-tag description: Type of address. type: str url: description: Url. type: str uuid: description: Universally Unique Identifier type: str visibility: choices: - disable - enable description: Enable/disable address visibility in the GUI. type: str wildcard: description: IP address and wildcard netmask. type: str wildcard-fqdn: description: Deprecated, please rename it to wildcard_fqdn. Fully Qualified Domain Name with wildcard characters. type: str type: list end-ip: description: Deprecated, please rename it to end_ip. Final IP address type: str end-mac: description: Deprecated, please rename it to end_mac. Last MAC address in the range. type: str epg-name: description: Deprecated, please rename it to epg_name. Endpoint group name. type: str fabric-object: choices: - disable - enable description: Deprecated, please rename it to fabric_object. Security Fabric global object setting. type: str filter: description: Match criteria filter. type: str fqdn: description: Fully Qualified Domain Name address. type: str fsso-group: description: (list or str) Deprecated, please rename it to fsso_group. FSSO group type: raw global-object: description: Deprecated, please rename it to global_object. Global Object. type: int hw-model: description: Deprecated, please rename it to hw_model. Dynamic address matching hardware model. type: str hw-vendor: description: Deprecated, please rename it to hw_vendor. Dynamic address matching hardware vendor. type: str interface: description: Name of interface whose IP address is to be used. type: str list: description: List. elements: dict suboptions: ip: description: IP. type: str net-id: description: Deprecated, please rename it to net_id. Network ID. type: str obj-id: description: Deprecated, please rename it to obj_id. Object ID. type: str type: list macaddr: description: (list) Multiple MAC address ranges. type: raw name: description: Address name. required: true type: str node-ip-only: choices: - disable - enable description: Deprecated, please rename it to node_ip_only. Enable/disable collection of node addresses only in Kubernetes. type: str obj-id: description: Deprecated, please rename it to obj_id. Object ID for NSX. type: str obj-tag: description: Deprecated, please rename it to obj_tag. Tag of dynamic address object. type: str obj-type: choices: - ip - mac description: Deprecated, please rename it to obj_type. Object type. type: str organization: description: Organization domain name type: str os: description: Dynamic address matching operating system. type: str policy-group: description: Deprecated, please rename it to policy_group. Policy group name. type: str profile-list: description: Deprecated, please rename it to profile_list. elements: dict suboptions: profile-id: description: Deprecated, please rename it to profile_id. NSX service profile ID. type: int type: list route-tag: description: Deprecated, please rename it to route_tag. Route-tag address. type: int sdn: choices: - aci - aws - nsx - nuage - azure - gcp - oci - openstack description: SDN. type: str sdn-addr-type: choices: - private - public - all description: Deprecated, please rename it to sdn_addr_type. Type of addresses to collect. type: str sdn-tag: description: Deprecated, please rename it to sdn_tag. SDN Tag. type: str start-ip: description: Deprecated, please rename it to start_ip. First IP address type: str start-mac: description: Deprecated, please rename it to start_mac. First MAC address in the range. type: str sub-type: choices: - sdn - clearpass-spt - fsso - ems-tag - swc-tag - fortivoice-tag - fortinac-tag - fortipolicy-tag - device-identification description: Deprecated, please rename it to sub_type. Sub-type of address. type: str subnet: description: IP address and subnet mask of address. type: str subnet-name: description: Deprecated, please rename it to subnet_name. Subnet name. type: str sw-version: description: Deprecated, please rename it to sw_version. Dynamic address matching software version. type: str tag-detection-level: description: Deprecated, please rename it to tag_detection_level. Tag detection level of dynamic address object. type: str tag-type: description: Deprecated, please rename it to tag_type. Tag type of dynamic address object. type: str tagging: description: Tagging. elements: dict suboptions: category: description: Tag category. type: str name: description: Tagging entry name. type: str tags: description: (list) Tags. type: raw type: list tags: description: Names of object-tags applied to address. type: str tenant: description: Tenant. type: str type: choices: - ipmask - iprange - fqdn - wildcard - geography - url - wildcard-fqdn - nsx - aws - dynamic - interface-subnet - mac - fqdn-group - route-tag description: Type of address. type: str uuid: description: Universally Unique Identifier type: str visibility: choices: - disable - enable description: Enable/disable address visibility in the GUI. type: str wildcard: description: IP address and wildcard netmask. type: str wildcard-fqdn: description: Deprecated, please rename it to wildcard_fqdn. Fully Qualified Domain Name with wildcard characters. type: str type: dict bypass_validation: default: false description: Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. type: bool workspace_locking_adom: description: The adom to lock for FortiManager running in workspace mode, the value can be global and others including root. type: str forticloud_access_token: description: Authenticate Ansible client with forticloud API access token. type: str workspace_locking_timeout: default: 300 description: The maximum time in seconds to wait for other user to release the workspace lock. type: int
meta: contains: request_url: description: The full url requested. returned: always sample: /sys/login/user type: str response_code: description: The status of api request. returned: always sample: 0 type: int response_data: description: The api response. returned: always type: list response_message: description: The descriptive message of the api response. returned: always sample: OK. type: str system_information: description: The information of the target system. returned: always type: dict description: The result of the request. returned: always type: dict rc: description: The status the request. returned: always sample: 0 type: int version_check_warning: description: Warning if the parameters used in the playbook are not supported by the current FortiManager version. returned: complex type: list