fortinet / fortinet.fortimanager / 2.4.0 / module / fmgr_firewall_vip6_dynamicmapping Configure virtual IP for IPv6. | "added in version" 2.0.0 of fortinet.fortimanager" Authors: Xinwei Du (@dux-fortinet), Xing Li (@lix-fortinet), Jie Xue (@JieX19), Link Zheng (@chillancezen), Frank Shen (@fshen01), Hongbin Lu (@fgtdev-hblu) preview | supported by communityfortinet.fortimanager.fmgr_firewall_vip6_dynamicmapping (2.4.0) — module
Install with ansible-galaxy collection install fortinet.fortimanager:==2.4.0
collections: - name: fortinet.fortimanager version: 2.4.0
This module is able to configure a FortiManager device.
Examples include all parameters and values which need to be adjusted to data sources before usage.
- name: Example playbook hosts: fortimanagers connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Configure dynamic mappings of virtual IP for IPv6 fortinet.fortimanager.fmgr_firewall_vip6_dynamicmapping: bypass_validation: false adom: ansible vip6: "ansible-test-vip6" # name state: present firewall_vip6_dynamicmapping: _scope: - name: FGT_AWS # need a valid device name vdom: root # need a valid vdom name under the device arp-reply: disable color: 1 comment: "ansible-comment" id: 1
- name: Gathering fortimanager facts hosts: fortimanagers gather_facts: false connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Retrieve all the dynamic mappings of virtual IP for IPv6 fortinet.fortimanager.fmgr_fact: facts: selector: "firewall_vip6_dynamicmapping" params: adom: "ansible" vip6: "ansible-test-vip6" # name dynamic_mapping: "your_value"
adom: description: The parameter (adom) in requested url. required: true type: str vip6: description: The parameter (vip6) in requested url. required: true type: str state: choices: - present - absent description: The directive to create, update or delete an object. required: true type: str rc_failed: description: The rc codes list with which the conditions to fail will be overriden. elements: int type: list enable_log: default: false description: Enable/Disable logging for task. type: bool access_token: description: The token to access FortiManager without using username and password. type: str rc_succeeded: description: The rc codes list with which the conditions to succeed will be overriden. elements: int type: list proposed_method: choices: - update - set - add description: The overridden method for the underlying Json RPC request. type: str bypass_validation: default: false description: Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. type: bool workspace_locking_adom: description: The adom to lock for FortiManager running in workspace mode, the value can be global and others including root. type: str forticloud_access_token: description: Authenticate Ansible client with forticloud API access token. type: str workspace_locking_timeout: default: 300 description: The maximum time in seconds to wait for other user to release the workspace lock. type: int firewall_vip6_dynamicmapping: description: The top level parameters set. required: false suboptions: _scope: description: No description. elements: dict suboptions: name: description: No description. type: str vdom: description: No description. type: str type: list add-nat64-route: choices: - disable - enable description: Deprecated, please rename it to add_nat64_route. Enable/disable adding NAT64 route. type: str arp-reply: choices: - disable - enable description: Deprecated, please rename it to arp_reply. type: str color: description: No description. type: int comment: description: No description. type: str embedded-ipv4-address: choices: - disable - enable description: Deprecated, please rename it to embedded_ipv4_address. Enable/disable use of the lower 32 bits of the external IPv6 addres... type: str extip: description: No description. type: str extport: description: No description. type: str h2-support: choices: - disable - enable description: Deprecated, please rename it to h2_support. Enable/disable HTTP2 support type: str h3-support: choices: - disable - enable description: Deprecated, please rename it to h3_support. Enable/disable HTTP3/QUIC support type: str http-cookie-age: description: Deprecated, please rename it to http_cookie_age. type: int http-cookie-domain: description: Deprecated, please rename it to http_cookie_domain. type: str http-cookie-domain-from-host: choices: - disable - enable description: Deprecated, please rename it to http_cookie_domain_from_host. type: str http-cookie-generation: description: Deprecated, please rename it to http_cookie_generation. type: int http-cookie-path: description: Deprecated, please rename it to http_cookie_path. type: str http-cookie-share: choices: - disable - same-ip description: Deprecated, please rename it to http_cookie_share. type: str http-ip-header: choices: - disable - enable description: Deprecated, please rename it to http_ip_header. type: str http-ip-header-name: description: Deprecated, please rename it to http_ip_header_name. type: str http-multiplex: choices: - disable - enable description: Deprecated, please rename it to http_multiplex. type: str http-redirect: choices: - disable - enable description: Deprecated, please rename it to http_redirect. type: str https-cookie-secure: choices: - disable - enable description: Deprecated, please rename it to https_cookie_secure. type: str id: description: No description. type: int ipv4-mappedip: description: Deprecated, please rename it to ipv4_mappedip. Range of mapped IP addresses. type: str ipv4-mappedport: description: Deprecated, please rename it to ipv4_mappedport. IPv4 port number range on the destination network to which the external p... type: str ldb-method: choices: - static - round-robin - weighted - least-session - least-rtt - first-alive - http-host description: Deprecated, please rename it to ldb_method. type: str mappedip: description: No description. type: str mappedport: description: No description. type: str max-embryonic-connections: description: Deprecated, please rename it to max_embryonic_connections. type: int monitor: description: (list or str) No description. type: raw nat-source-vip: choices: - disable - enable description: Deprecated, please rename it to nat_source_vip. type: str nat64: choices: - disable - enable description: Enable/disable DNAT64. type: str nat66: choices: - disable - enable description: Enable/disable DNAT66. type: str ndp-reply: choices: - disable - enable description: Deprecated, please rename it to ndp_reply. Enable/disable this FortiGate units ability to respond to NDP requests for this... type: str outlook-web-access: choices: - disable - enable description: Deprecated, please rename it to outlook_web_access. type: str persistence: choices: - none - http-cookie - ssl-session-id description: No description. type: str portforward: choices: - disable - enable description: No description. type: str protocol: choices: - tcp - udp - sctp description: No description. type: str realservers: description: No description. elements: dict suboptions: client-ip: description: Deprecated, please rename it to client_ip. Only clients in this IP range can connect to this real server. type: str healthcheck: choices: - disable - enable - vip description: Enable to check the responsiveness of the real server before forwarding traffic. type: str holddown-interval: description: Deprecated, please rename it to holddown_interval. Time in seconds that the health check monitor continues to moni... type: int http-host: description: Deprecated, please rename it to http_host. HTTP server domain name in HTTP header. type: str id: description: Real server ID. type: int ip: description: IP address of the real server. type: str max-connections: description: Deprecated, please rename it to max_connections. Max number of active connections that can directed to the real se... type: int monitor: description: (list or str) No description. type: raw port: description: Port for communicating with the real server. type: int status: choices: - active - standby - disable description: Set the status of the real server to active so that it can accept traffic, or on standby or disabled so no traffic... type: str translate-host: choices: - disable - enable description: Deprecated, please rename it to translate_host. Enable/disable translation of hostname/IP from virtual server to r... type: str weight: description: Weight of the real server. type: int type: list server-type: choices: - http - https - ssl - tcp - udp - ip - imaps - pop3s - smtps description: Deprecated, please rename it to server_type. type: str src-filter: description: (list) Deprecated, please rename it to src_filter. type: raw ssl-accept-ffdhe-groups: choices: - disable - enable description: Deprecated, please rename it to ssl_accept_ffdhe_groups. Enable/disable FFDHE cipher suite for SSL key exchange. type: str ssl-algorithm: choices: - high - low - medium - custom description: Deprecated, please rename it to ssl_algorithm. type: str ssl-certificate: description: Deprecated, please rename it to ssl_certificate. type: str ssl-cipher-suites: description: Deprecated, please rename it to ssl_cipher_suites. elements: dict suboptions: cipher: choices: - TLS-RSA-WITH-RC4-128-MD5 - TLS-RSA-WITH-RC4-128-SHA - TLS-RSA-WITH-DES-CBC-SHA - TLS-RSA-WITH-3DES-EDE-CBC-SHA - TLS-RSA-WITH-AES-128-CBC-SHA - TLS-RSA-WITH-AES-256-CBC-SHA - TLS-RSA-WITH-AES-128-CBC-SHA256 - TLS-RSA-WITH-AES-256-CBC-SHA256 - TLS-RSA-WITH-CAMELLIA-128-CBC-SHA - TLS-RSA-WITH-CAMELLIA-256-CBC-SHA - TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256 - TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256 - TLS-RSA-WITH-SEED-CBC-SHA - TLS-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-DHE-RSA-WITH-DES-CBC-SHA - TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA - TLS-DHE-RSA-WITH-AES-128-CBC-SHA - TLS-DHE-RSA-WITH-AES-256-CBC-SHA - TLS-DHE-RSA-WITH-AES-128-CBC-SHA256 - TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 - TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA - TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA - TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256 - TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256 - TLS-DHE-RSA-WITH-SEED-CBC-SHA - TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-RC4-128-SHA - TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA - TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA - TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA - TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-DHE-RSA-WITH-AES-128-GCM-SHA256 - TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 - TLS-DHE-DSS-WITH-AES-128-CBC-SHA - TLS-DHE-DSS-WITH-AES-256-CBC-SHA - TLS-DHE-DSS-WITH-AES-128-CBC-SHA256 - TLS-DHE-DSS-WITH-AES-128-GCM-SHA256 - TLS-DHE-DSS-WITH-AES-256-CBC-SHA256 - TLS-DHE-DSS-WITH-AES-256-GCM-SHA384 - TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256 - TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256 - TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384 - TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA - TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384 - TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384 - TLS-RSA-WITH-AES-128-GCM-SHA256 - TLS-RSA-WITH-AES-256-GCM-SHA384 - TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA - TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA - TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256 - TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256 - TLS-DHE-DSS-WITH-SEED-CBC-SHA - TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256 - TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256 - TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384 - TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA - TLS-DHE-DSS-WITH-DES-CBC-SHA - TLS-AES-128-GCM-SHA256 - TLS-AES-256-GCM-SHA384 - TLS-CHACHA20-POLY1305-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA description: Cipher suite name. type: str priority: description: SSL/TLS cipher suites priority. type: int versions: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: No description. elements: str type: list type: list ssl-client-fallback: choices: - disable - enable description: Deprecated, please rename it to ssl_client_fallback. type: str ssl-client-rekey-count: description: Deprecated, please rename it to ssl_client_rekey_count. type: int ssl-client-renegotiation: choices: - deny - allow - secure description: Deprecated, please rename it to ssl_client_renegotiation. type: str ssl-client-session-state-max: description: Deprecated, please rename it to ssl_client_session_state_max. type: int ssl-client-session-state-timeout: description: Deprecated, please rename it to ssl_client_session_state_timeout. type: int ssl-client-session-state-type: choices: - disable - time - count - both description: Deprecated, please rename it to ssl_client_session_state_type. type: str ssl-dh-bits: choices: - '768' - '1024' - '1536' - '2048' - '3072' - '4096' description: Deprecated, please rename it to ssl_dh_bits. type: str ssl-hpkp: choices: - disable - enable - report-only description: Deprecated, please rename it to ssl_hpkp. type: str ssl-hpkp-age: description: Deprecated, please rename it to ssl_hpkp_age. type: int ssl-hpkp-backup: description: Deprecated, please rename it to ssl_hpkp_backup. type: str ssl-hpkp-include-subdomains: choices: - disable - enable description: Deprecated, please rename it to ssl_hpkp_include_subdomains. type: str ssl-hpkp-primary: description: Deprecated, please rename it to ssl_hpkp_primary. type: str ssl-hpkp-report-uri: description: Deprecated, please rename it to ssl_hpkp_report_uri. type: str ssl-hsts: choices: - disable - enable description: Deprecated, please rename it to ssl_hsts. type: str ssl-hsts-age: description: Deprecated, please rename it to ssl_hsts_age. type: int ssl-hsts-include-subdomains: choices: - disable - enable description: Deprecated, please rename it to ssl_hsts_include_subdomains. type: str ssl-http-location-conversion: choices: - disable - enable description: Deprecated, please rename it to ssl_http_location_conversion. type: str ssl-http-match-host: choices: - disable - enable description: Deprecated, please rename it to ssl_http_match_host. type: str ssl-max-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: Deprecated, please rename it to ssl_max_version. type: str ssl-min-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: Deprecated, please rename it to ssl_min_version. type: str ssl-mode: choices: - half - full description: Deprecated, please rename it to ssl_mode. type: str ssl-pfs: choices: - require - deny - allow description: Deprecated, please rename it to ssl_pfs. type: str ssl-send-empty-frags: choices: - disable - enable description: Deprecated, please rename it to ssl_send_empty_frags. type: str ssl-server-algorithm: choices: - high - low - medium - custom - client description: Deprecated, please rename it to ssl_server_algorithm. type: str ssl-server-max-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client - tls-1.3 description: Deprecated, please rename it to ssl_server_max_version. type: str ssl-server-min-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client - tls-1.3 description: Deprecated, please rename it to ssl_server_min_version. type: str ssl-server-renegotiation: choices: - disable - enable description: Deprecated, please rename it to ssl_server_renegotiation. Enable/disable secure renegotiation to comply with RFC 5746. type: str ssl-server-session-state-max: description: Deprecated, please rename it to ssl_server_session_state_max. type: int ssl-server-session-state-timeout: description: Deprecated, please rename it to ssl_server_session_state_timeout. type: int ssl-server-session-state-type: choices: - disable - time - count - both description: Deprecated, please rename it to ssl_server_session_state_type. type: str type: choices: - static-nat - server-load-balance - access-proxy description: No description. type: str uuid: description: No description. type: str weblogic-server: choices: - disable - enable description: Deprecated, please rename it to weblogic_server. type: str websphere-server: choices: - disable - enable description: Deprecated, please rename it to websphere_server. type: str type: dict
meta: contains: request_url: description: The full url requested. returned: always sample: /sys/login/user type: str response_code: description: The status of api request. returned: always sample: 0 type: int response_data: description: The api response. returned: always type: list response_message: description: The descriptive message of the api response. returned: always sample: OK. type: str system_information: description: The information of the target system. returned: always type: dict description: The result of the request. returned: always type: dict rc: description: The status the request. returned: always sample: 0 type: int version_check_warning: description: Warning if the parameters used in the playbook are not supported by the current FortiManager version. returned: complex type: list