fortinet / fortinet.fortimanager / 2.4.0 / module / fmgr_firewall_vip_dynamicmapping Configure virtual IP for IPv4. | "added in version" 2.0.0 of fortinet.fortimanager" Authors: Xinwei Du (@dux-fortinet), Xing Li (@lix-fortinet), Jie Xue (@JieX19), Link Zheng (@chillancezen), Frank Shen (@fshen01), Hongbin Lu (@fgtdev-hblu) preview | supported by communityfortinet.fortimanager.fmgr_firewall_vip_dynamicmapping (2.4.0) — module
Install with ansible-galaxy collection install fortinet.fortimanager:==2.4.0
collections: - name: fortinet.fortimanager version: 2.4.0
This module is able to configure a FortiManager device.
Examples include all parameters and values which need to be adjusted to data sources before usage.
- name: Example playbook hosts: fortimanagers connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Configure dynamic mappings of virtual IP for IPv4 fortinet.fortimanager.fmgr_firewall_vip_dynamicmapping: bypass_validation: false adom: ansible vip: "ansible-test-vip" # name state: present firewall_vip_dynamicmapping: _scope: # Required - name: FGT_AWS # need a valid device name vdom: root # need a valid vdom name under the device arp-reply: enable color: 2 comment: "ansible-comment" id: 1
- name: Gathering fortimanager facts hosts: fortimanagers gather_facts: false connection: httpapi vars: ansible_httpapi_use_ssl: true ansible_httpapi_validate_certs: false ansible_httpapi_port: 443 tasks: - name: Retrieve all the dynamic mappings of virtual IP for IPv4 fortinet.fortimanager.fmgr_fact: facts: selector: "firewall_vip_dynamicmapping" params: adom: "ansible" vip: "ansible-test-vip" # name dynamic_mapping: "your_value"
vip: description: The parameter (vip) in requested url. required: true type: str adom: description: The parameter (adom) in requested url. required: true type: str state: choices: - present - absent description: The directive to create, update or delete an object. required: true type: str rc_failed: description: The rc codes list with which the conditions to fail will be overriden. elements: int type: list enable_log: default: false description: Enable/Disable logging for task. type: bool access_token: description: The token to access FortiManager without using username and password. type: str rc_succeeded: description: The rc codes list with which the conditions to succeed will be overriden. elements: int type: list proposed_method: choices: - update - set - add description: The overridden method for the underlying Json RPC request. type: str bypass_validation: default: false description: Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. type: bool workspace_locking_adom: description: The adom to lock for FortiManager running in workspace mode, the value can be global and others including root. type: str forticloud_access_token: description: Authenticate Ansible client with forticloud API access token. type: str workspace_locking_timeout: default: 300 description: The maximum time in seconds to wait for other user to release the workspace lock. type: int firewall_vip_dynamicmapping: description: The top level parameters set. required: false suboptions: _scope: description: No description. elements: dict suboptions: name: description: No description. type: str vdom: description: No description. type: str type: list add-nat46-route: choices: - disable - enable description: Deprecated, please rename it to add_nat46_route. Enable/disable adding NAT46 route. type: str arp-reply: choices: - disable - enable description: Deprecated, please rename it to arp_reply. type: str color: description: No description. type: int comment: description: No description. type: str dns-mapping-ttl: description: Deprecated, please rename it to dns_mapping_ttl. type: int extaddr: description: (list or str) No description. type: raw extintf: description: No description. type: str extip: description: No description. type: str extport: description: No description. type: str gratuitous-arp-interval: description: Deprecated, please rename it to gratuitous_arp_interval. type: int gslb-domain-name: description: Deprecated, please rename it to gslb_domain_name. Domain to use when integrating with FortiGSLB. type: str gslb-hostname: description: Deprecated, please rename it to gslb_hostname. Hostname to use within the configured FortiGSLB domain. type: str h2-support: choices: - disable - enable description: Deprecated, please rename it to h2_support. Enable/disable HTTP2 support type: str h3-support: choices: - disable - enable description: Deprecated, please rename it to h3_support. Enable/disable HTTP3/QUIC support type: str http-cookie-age: description: Deprecated, please rename it to http_cookie_age. type: int http-cookie-domain: description: Deprecated, please rename it to http_cookie_domain. type: str http-cookie-domain-from-host: choices: - disable - enable description: Deprecated, please rename it to http_cookie_domain_from_host. type: str http-cookie-generation: description: Deprecated, please rename it to http_cookie_generation. type: int http-cookie-path: description: Deprecated, please rename it to http_cookie_path. type: str http-cookie-share: choices: - disable - same-ip description: Deprecated, please rename it to http_cookie_share. type: str http-ip-header: choices: - disable - enable description: Deprecated, please rename it to http_ip_header. type: str http-ip-header-name: description: Deprecated, please rename it to http_ip_header_name. type: str http-multiplex: choices: - disable - enable description: Deprecated, please rename it to http_multiplex. type: str http-multiplex-max-concurrent-request: description: Deprecated, please rename it to http_multiplex_max_concurrent_request. Maximum number of concurrent requests that a multip... type: int http-multiplex-max-request: description: Deprecated, please rename it to http_multiplex_max_request. Maximum number of requests that a multiplex server can handle ... type: int http-multiplex-ttl: description: Deprecated, please rename it to http_multiplex_ttl. Time-to-live for idle connections to servers. type: int http-redirect: choices: - disable - enable description: Deprecated, please rename it to http_redirect. type: str http-supported-max-version: choices: - http1 - http2 description: Deprecated, please rename it to http_supported_max_version. Maximum supported HTTP versions. type: str https-cookie-secure: choices: - disable - enable description: Deprecated, please rename it to https_cookie_secure. type: str id: description: No description. type: int ipv6-mappedip: description: Deprecated, please rename it to ipv6_mappedip. Range of mapped IPv6 addresses. type: str ipv6-mappedport: description: Deprecated, please rename it to ipv6_mappedport. IPv6 port number range on the destination network to which the external p... type: str ldb-method: choices: - static - round-robin - weighted - least-session - least-rtt - first-alive - http-host description: Deprecated, please rename it to ldb_method. type: str mapped-addr: description: Deprecated, please rename it to mapped_addr. type: str mappedip: description: (list) No description. type: raw mappedport: description: No description. type: str max-embryonic-connections: description: Deprecated, please rename it to max_embryonic_connections. type: int monitor: description: (list or str) No description. type: raw nat-source-vip: choices: - disable - enable description: Deprecated, please rename it to nat_source_vip. type: str nat44: choices: - disable - enable description: Enable/disable NAT44. type: str nat46: choices: - disable - enable description: Enable/disable NAT46. type: str one-click-gslb-server: choices: - disable - enable description: Deprecated, please rename it to one_click_gslb_server. Enable/disable one click GSLB server integration with FortiGSLB. type: str outlook-web-access: choices: - disable - enable description: Deprecated, please rename it to outlook_web_access. type: str persistence: choices: - none - http-cookie - ssl-session-id description: No description. type: str portforward: choices: - disable - enable description: No description. type: str portmapping-type: choices: - 1-to-1 - m-to-n description: Deprecated, please rename it to portmapping_type. type: str protocol: choices: - tcp - udp - sctp - icmp description: No description. type: str realservers: description: No description. elements: dict suboptions: address: description: No description. type: str client-ip: description: (list) Deprecated, please rename it to client_ip. type: raw health-check-proto: choices: - ping - http description: Deprecated, please rename it to health_check_proto. type: str healthcheck: choices: - disable - enable - vip description: No description. type: str holddown-interval: description: Deprecated, please rename it to holddown_interval. type: int http-host: description: Deprecated, please rename it to http_host. type: str id: description: No description. type: int ip: description: No description. type: str max-connections: description: Deprecated, please rename it to max_connections. type: int monitor: description: (list or str) No description. type: raw port: description: No description. type: int seq: description: No description. type: int status: choices: - active - standby - disable description: No description. type: str translate-host: choices: - disable - enable description: Deprecated, please rename it to translate_host. Enable/disable translation of hostname/IP from virtual server to r... type: str type: choices: - ip - address description: No description. type: str weight: description: No description. type: int type: list server-type: choices: - http - https - ssl - tcp - udp - ip - imaps - pop3s - smtps - ssh description: Deprecated, please rename it to server_type. type: str service: description: (list or str) No description. type: raw src-filter: description: (list) Deprecated, please rename it to src_filter. type: raw srcintf-filter: description: (list) Deprecated, please rename it to srcintf_filter. type: raw ssl-accept-ffdhe-groups: choices: - disable - enable description: Deprecated, please rename it to ssl_accept_ffdhe_groups. Enable/disable FFDHE cipher suite for SSL key exchange. type: str ssl-algorithm: choices: - high - medium - low - custom description: Deprecated, please rename it to ssl_algorithm. type: str ssl-certificate: description: Deprecated, please rename it to ssl_certificate. type: str ssl-cipher-suites: description: Deprecated, please rename it to ssl_cipher_suites. elements: dict suboptions: cipher: choices: - TLS-RSA-WITH-RC4-128-MD5 - TLS-RSA-WITH-RC4-128-SHA - TLS-RSA-WITH-DES-CBC-SHA - TLS-RSA-WITH-3DES-EDE-CBC-SHA - TLS-RSA-WITH-AES-128-CBC-SHA - TLS-RSA-WITH-AES-256-CBC-SHA - TLS-RSA-WITH-AES-128-CBC-SHA256 - TLS-RSA-WITH-AES-256-CBC-SHA256 - TLS-RSA-WITH-CAMELLIA-128-CBC-SHA - TLS-RSA-WITH-CAMELLIA-256-CBC-SHA - TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256 - TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256 - TLS-RSA-WITH-SEED-CBC-SHA - TLS-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-DHE-RSA-WITH-DES-CBC-SHA - TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA - TLS-DHE-RSA-WITH-AES-128-CBC-SHA - TLS-DHE-RSA-WITH-AES-256-CBC-SHA - TLS-DHE-RSA-WITH-AES-128-CBC-SHA256 - TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 - TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA - TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA - TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256 - TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256 - TLS-DHE-RSA-WITH-SEED-CBC-SHA - TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-RC4-128-SHA - TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA - TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA - TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA - TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256 - TLS-DHE-RSA-WITH-AES-128-GCM-SHA256 - TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 - TLS-DHE-DSS-WITH-AES-128-CBC-SHA - TLS-DHE-DSS-WITH-AES-256-CBC-SHA - TLS-DHE-DSS-WITH-AES-128-CBC-SHA256 - TLS-DHE-DSS-WITH-AES-128-GCM-SHA256 - TLS-DHE-DSS-WITH-AES-256-CBC-SHA256 - TLS-DHE-DSS-WITH-AES-256-GCM-SHA384 - TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256 - TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256 - TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384 - TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA - TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384 - TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384 - TLS-RSA-WITH-AES-128-GCM-SHA256 - TLS-RSA-WITH-AES-256-GCM-SHA384 - TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA - TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA - TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256 - TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256 - TLS-DHE-DSS-WITH-SEED-CBC-SHA - TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256 - TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256 - TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384 - TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256 - TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384 - TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA - TLS-DHE-DSS-WITH-DES-CBC-SHA - TLS-AES-128-GCM-SHA256 - TLS-AES-256-GCM-SHA384 - TLS-CHACHA20-POLY1305-SHA256 - TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA description: No description. type: str id: description: No description. type: int priority: description: No description. type: int versions: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: No description. elements: str type: list type: list ssl-client-fallback: choices: - disable - enable description: Deprecated, please rename it to ssl_client_fallback. type: str ssl-client-rekey-count: description: Deprecated, please rename it to ssl_client_rekey_count. type: int ssl-client-renegotiation: choices: - deny - allow - secure description: Deprecated, please rename it to ssl_client_renegotiation. type: str ssl-client-session-state-max: description: Deprecated, please rename it to ssl_client_session_state_max. type: int ssl-client-session-state-timeout: description: Deprecated, please rename it to ssl_client_session_state_timeout. type: int ssl-client-session-state-type: choices: - disable - time - count - both description: Deprecated, please rename it to ssl_client_session_state_type. type: str ssl-dh-bits: choices: - '768' - '1024' - '1536' - '2048' - '3072' - '4096' description: Deprecated, please rename it to ssl_dh_bits. type: str ssl-hpkp: choices: - disable - enable - report-only description: Deprecated, please rename it to ssl_hpkp. type: str ssl-hpkp-age: description: Deprecated, please rename it to ssl_hpkp_age. type: int ssl-hpkp-backup: description: Deprecated, please rename it to ssl_hpkp_backup. type: str ssl-hpkp-include-subdomains: choices: - disable - enable description: Deprecated, please rename it to ssl_hpkp_include_subdomains. type: str ssl-hpkp-primary: description: Deprecated, please rename it to ssl_hpkp_primary. type: str ssl-hpkp-report-uri: description: Deprecated, please rename it to ssl_hpkp_report_uri. type: str ssl-hsts: choices: - disable - enable description: Deprecated, please rename it to ssl_hsts. type: str ssl-hsts-age: description: Deprecated, please rename it to ssl_hsts_age. type: int ssl-hsts-include-subdomains: choices: - disable - enable description: Deprecated, please rename it to ssl_hsts_include_subdomains. type: str ssl-http-location-conversion: choices: - disable - enable description: Deprecated, please rename it to ssl_http_location_conversion. type: str ssl-http-match-host: choices: - disable - enable description: Deprecated, please rename it to ssl_http_match_host. type: str ssl-max-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: Deprecated, please rename it to ssl_max_version. type: str ssl-min-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - tls-1.3 description: Deprecated, please rename it to ssl_min_version. type: str ssl-mode: choices: - half - full description: Deprecated, please rename it to ssl_mode. type: str ssl-pfs: choices: - require - deny - allow description: Deprecated, please rename it to ssl_pfs. type: str ssl-send-empty-frags: choices: - disable - enable description: Deprecated, please rename it to ssl_send_empty_frags. type: str ssl-server-algorithm: choices: - high - low - medium - custom - client description: Deprecated, please rename it to ssl_server_algorithm. type: str ssl-server-max-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client - tls-1.3 description: Deprecated, please rename it to ssl_server_max_version. type: str ssl-server-min-version: choices: - ssl-3.0 - tls-1.0 - tls-1.1 - tls-1.2 - client - tls-1.3 description: Deprecated, please rename it to ssl_server_min_version. type: str ssl-server-renegotiation: choices: - disable - enable description: Deprecated, please rename it to ssl_server_renegotiation. Enable/disable secure renegotiation to comply with RFC 5746. type: str ssl-server-session-state-max: description: Deprecated, please rename it to ssl_server_session_state_max. type: int ssl-server-session-state-timeout: description: Deprecated, please rename it to ssl_server_session_state_timeout. type: int ssl-server-session-state-type: choices: - disable - time - count - both description: Deprecated, please rename it to ssl_server_session_state_type. type: str status: choices: - disable - enable description: Enable/disable VIP. type: str type: choices: - static-nat - load-balance - server-load-balance - dns-translation - fqdn - access-proxy description: No description. type: str uuid: description: No description. type: str weblogic-server: choices: - disable - enable description: Deprecated, please rename it to weblogic_server. type: str websphere-server: choices: - disable - enable description: Deprecated, please rename it to websphere_server. type: str type: dict
meta: contains: request_url: description: The full url requested. returned: always sample: /sys/login/user type: str response_code: description: The status of api request. returned: always sample: 0 type: int response_data: description: The api response. returned: always type: list response_message: description: The descriptive message of the api response. returned: always sample: OK. type: str system_information: description: The information of the target system. returned: always type: dict description: The result of the request. returned: always type: dict rc: description: The status the request. returned: always sample: 0 type: int version_check_warning: description: Warning if the parameters used in the playbook are not supported by the current FortiManager version. returned: complex type: list