fortios_system_global – Configure global attributes in Fortinet’s FortiOS and FortiGate.

New in version 2.0.0.

Synopsis

  • This module is able to configure a FortiGate or FortiOS (FOS) device by allowing the user to set and modify system feature and global category. Examples include all parameters and values need to be adjusted to datasources before usage. Tested with FOS v6.0.0

Requirements

The below requirements are needed on the host that executes this module.

  • ansible>=2.15

Tips

Using member operation to add an element to an existing object.

FortiOS Version Compatibility

Supported Version Ranges: v6.0.0 -> 7.4.3

Parameters

  • access_token - Token-based authentication. Generated from GUI of Fortigate. type: str required: false
  • enable_log - Enable/Disable logging for task. type: bool required: false default: False
  • vdom - Virtual domain, among those defined previously. A vdom is a virtual instance of the FortiGate that can be configured and used as a different unit. type: str default: root
  • member_path - Member attribute path to operate on. type: str
  • member_state - Add or delete a member under specified attribute path. type: str choices: present, absent
  • system_global - Configure global attributes. type: dict more...
    • admin_concurrent - Enable/disable concurrent administrator logins. Use policy-auth-concurrent for firewall authenticated users. type: str choices: enable, disable more...
    • admin_console_timeout - Console login timeout that overrides the admin timeout value (15 - 300 seconds). type: int more...
    • admin_forticloud_sso_default_profile - Override access profile. Source system.accprofile.name. type: str more...
    • admin_forticloud_sso_login - Enable/disable FortiCloud admin login via SSO. type: str choices: enable, disable more...
    • admin_host - Administrative host for HTTP and HTTPS. When set, will be used in lieu of the client"s Host header for any redirection. type: str more...
    • admin_hsts_max_age - HTTPS Strict-Transport-Security header max-age in seconds. A value of 0 will reset any HSTS records in the browser.When admin-https-redirect is disabled the header max-age will be 0. type: int more...
    • admin_https_pki_required - Enable/disable admin login method. Enable to force administrators to provide a valid certificate to log in if PKI is enabled. Disable to allow administrators to log in with a certificate or password. type: str choices: enable, disable more...
    • admin_https_redirect - Enable/disable redirection of HTTP administration access to HTTPS. type: str choices: enable, disable more...
    • admin_https_ssl_banned_ciphers - Select one or more cipher technologies that cannot be used in GUI HTTPS negotiations. Only applies to TLS 1.2 and below. type: list choices: RSA, DHE, ECDHE, DSS, ECDSA, AES, AESGCM, CAMELLIA, 3DES, SHA1, SHA256, SHA384, STATIC, CHACHA20, ARIA, AESCCM more...
    • admin_https_ssl_ciphersuites - Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, remove TLS1.3 from admin-https-ssl-versions. type: list choices: TLS-AES-128-GCM-SHA256, TLS-AES-256-GCM-SHA384, TLS-CHACHA20-POLY1305-SHA256, TLS-AES-128-CCM-SHA256, TLS-AES-128-CCM-8-SHA256 more...
    • admin_https_ssl_versions - Allowed TLS versions for web administration. type: list choices: tlsv1-1, tlsv1-2, tlsv1-3, tlsv1-0 more...
    • admin_lockout_duration - Amount of time in seconds that an administrator account is locked out after reaching the admin-lockout-threshold for repeated failed login attempts. type: int more...
    • admin_lockout_threshold - Number of failed login attempts before an administrator account is locked out for the admin-lockout-duration. type: int more...
    • admin_login_max - Maximum number of administrators who can be logged in at the same time (1 - 100). type: int more...
    • admin_maintainer - Enable/disable maintainer administrator login. When enabled, the maintainer account can be used to log in from the console after a hard reboot. The password is "bcpb" followed by the FortiGate unit serial number. You have limited time to complete this login. type: str choices: enable, disable more...
    • admin_port - Administrative access port for HTTP. (1 - 65535). type: int more...
    • admin_restrict_local - Enable/disable local admin authentication restriction when remote authenticator is up and running . type: str choices: enable, disable more...
    • admin_scp - Enable/disable SCP support for system configuration backup, restore, and firmware file upload. type: str choices: enable, disable more...
    • admin_server_cert - Server certificate that the FortiGate uses for HTTPS administrative connections. Source certificate.local.name. type: str more...
    • admin_sport - Administrative access port for HTTPS. (1 - 65535). type: int more...
    • admin_ssh_grace_time - Maximum time in seconds permitted between making an SSH connection to the FortiGate unit and authenticating (10 - 3600 sec (1 hour)). type: int more...
    • admin_ssh_password - Enable/disable password authentication for SSH admin access. type: str choices: enable, disable more...
    • admin_ssh_port - Administrative access port for SSH. (1 - 65535). type: int more...
    • admin_ssh_v1 - Enable/disable SSH v1 compatibility. type: str choices: enable, disable more...
    • admin_telnet - Enable/disable TELNET service. type: str choices: enable, disable more...
    • admin_telnet_port - Administrative access port for TELNET. (1 - 65535). type: int more...
    • admintimeout - Number of minutes before an idle administrator session times out (1 - 480 minutes (8 hours)). A shorter idle timeout is more secure. type: int more...
    • alias - Alias for your FortiGate unit. type: str more...
    • allow_traffic_redirect - Disable to prevent traffic with same local ingress and egress interface from being forwarded without policy check. type: str choices: enable, disable more...
    • anti_replay - Level of checking for packet replay and TCP sequence checking. type: str choices: disable, loose, strict more...
    • arp_max_entry - Maximum number of dynamically learned MAC addresses that can be added to the ARP table (131072 - 2147483647). type: int more...
    • asymroute - Enable/disable asymmetric route. type: str choices: enable, disable more...
    • auth_cert - Server certificate that the FortiGate uses for HTTPS firewall authentication connections. Source certificate.local.name. type: str more...
    • auth_http_port - User authentication HTTP port. (1 - 65535). type: int more...
    • auth_https_port - User authentication HTTPS port. (1 - 65535). type: int more...
    • auth_ike_saml_port - User IKE SAML authentication port (0 - 65535). type: int more...
    • auth_keepalive - Enable to prevent user authentication sessions from timing out when idle. type: str choices: enable, disable more...
    • auth_session_limit - Action to take when the number of allowed user authenticated sessions is reached. type: str choices: block-new, logout-inactive more...
    • auto_auth_extension_device - Enable/disable automatic authorization of dedicated Fortinet extension devices. type: str choices: enable, disable more...
    • autorun_log_fsck - Enable/disable automatic log partition check after ungraceful shutdown. type: str choices: enable, disable more...
    • av_affinity - Affinity setting for AV scanning (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • av_failopen - Set the action to take if the FortiGate is running low on memory or the proxy connection limit has been reached. type: str choices: pass, off, one-shot more...
    • av_failopen_session - When enabled and a proxy for a protocol runs out of room in its session table, that protocol goes into failopen mode and enacts the action specified by av-failopen. type: str choices: enable, disable more...
    • batch_cmdb - Enable/disable batch mode, allowing you to enter a series of CLI commands that will execute as a group once they are loaded. type: str choices: enable, disable more...
    • bfd_affinity - Affinity setting for BFD daemon (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • block_session_timer - Duration in seconds for blocked sessions (1 - 300 sec (5 minutes)). type: int more...
    • br_fdb_max_entry - Maximum number of bridge forwarding database (FDB) entries. type: int more...
    • cert_chain_max - Maximum number of certificates that can be traversed in a certificate chain. type: int more...
    • cfg_revert_timeout - Time-out for reverting to the last saved configuration. (10 - 4294967295 seconds). type: int more...
    • cfg_save - Configuration file save mode for CLI changes. type: str choices: automatic, manual, revert more...
    • check_protocol_header - Level of checking performed on protocol headers. Strict checking is more thorough but may affect performance. Loose checking is OK in most cases. type: str choices: loose, strict more...
    • check_reset_range - Configure ICMP error message verification. You can either apply strict RST range checking or disable it. type: str choices: strict, disable more...
    • cli_audit_log - Enable/disable CLI audit log. type: str choices: enable, disable more...
    • cloud_communication - Enable/disable all cloud communication. type: str choices: enable, disable more...
    • clt_cert_req - Enable/disable requiring administrators to have a client certificate to log into the GUI using HTTPS. type: str choices: enable, disable more...
    • cmdbsvr_affinity - Affinity setting for cmdbsvr (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • compliance_check - Enable/disable global PCI DSS compliance check. type: str choices: enable, disable more...
    • compliance_check_time - Time of day to run scheduled PCI DSS compliance checks. type: str more...
    • cpu_use_threshold - Threshold at which CPU usage is reported (% of total CPU). type: int more...
    • csr_ca_attribute - Enable/disable the CA attribute in certificates. Some CA servers reject CSRs that have the CA attribute. type: str choices: enable, disable more...
    • daily_restart - Enable/disable daily restart of FortiGate unit. Use the restart-time option to set the time of day for the restart. type: str choices: enable, disable more...
    • default_service_source_port - Default service source port range . type: str more...
    • device_identification_active_scan_delay - Number of seconds to passively scan a device before performing an active scan. (20 - 3600 sec, (20 sec to 1 hour)). type: int more...
    • device_idle_timeout - Time in seconds that a device must be idle to automatically log the device user out. (30 - 31536000 sec (30 sec to 1 year)). type: int more...
    • dh_params - Number of bits to use in the Diffie-Hellman exchange for HTTPS/SSH protocols. type: str choices: 1024, 1536, 2048, 3072, 4096, 6144, 8192 more...
    • dnsproxy_worker_count - DNS proxy worker count. For a FortiGate with multiple logical CPUs, you can set the DNS process number from 1 to the number of logical CPUs. type: int more...
    • dst - Enable/disable daylight saving time. type: str choices: enable, disable more...
    • early_tcp_npu_session - Enable/disable early TCP NPU session. type: str choices: enable, disable more...
    • edit_vdom_prompt - Enable/disable edit new VDOM prompt. type: str choices: enable, disable more...
    • endpoint_control_fds_access - Enable/disable access to the FortiGuard network for non-compliant endpoints. type: str choices: enable, disable more...
    • endpoint_control_portal_port - Endpoint control portal port (1 - 65535). type: int more...
    • extender_controller_reserved_network - Configure reserved network subnet for managed LAN extension FortiExtender units. This is available when the FortiExtender daemon is running. type: str more...
    • failtime - Fail-time for server lost. type: int more...
    • faz_disk_buffer_size - Maximum disk buffer size to temporarily store logs destined for FortiAnalyzer. To be used in the event that FortiAnalyzer is unavailable. type: int more...
    • fds_statistics - Enable/disable sending IPS, Application Control, and AntiVirus data to FortiGuard. This data is used to improve FortiGuard services and is not shared with external parties and is protected by Fortinet"s privacy policy. type: str choices: enable, disable more...
    • fds_statistics_period - FortiGuard statistics collection period in minutes. (1 - 1440 min (1 min to 24 hours)). type: int more...
    • fec_port - Local UDP port for Forward Error Correction (49152 - 65535). type: int more...
    • fgd_alert_subscription - Type of alert to retrieve from FortiGuard. type: list choices: advisory, latest-threat, latest-virus, latest-attack, new-antivirus-db, new-attack-db more...
    • forticarrier_bypass - Enable/disable forticarrier-bypass. type: str choices: enable, disable more...
    • forticonverter_config_upload - Enable/disable config upload to FortiConverter. type: str choices: once, disable more...
    • forticonverter_integration - Enable/disable FortiConverter integration service. type: str choices: enable, disable more...
    • fortiextender - Enable/disable FortiExtender. type: str choices: disable, enable more...
    • fortiextender_data_port - FortiExtender data port (1024 - 49150). type: int more...
    • fortiextender_discovery_lockdown - Enable/disable FortiExtender CAPWAP lockdown. type: str choices: disable, enable more...
    • fortiextender_provision_on_authorization - Enable/disable automatic provisioning of latest FortiExtender firmware on authorization. type: str choices: enable, disable more...
    • fortiextender_vlan_mode - Enable/disable FortiExtender VLAN mode. type: str choices: enable, disable more...
    • fortigslb_integration - Enable/disable integration with the FortiGSLB cloud service. type: str choices: disable, enable more...
    • fortiipam_integration - Enable/disable integration with the FortiIPAM cloud service. type: str choices: enable, disable more...
    • fortiservice_port - FortiService port (1 - 65535). Used by FortiClient endpoint compliance. Older versions of FortiClient used a different port. type: int more...
    • fortitoken_cloud - Enable/disable FortiToken Cloud service. type: str choices: enable, disable more...
    • fortitoken_cloud_push_status - Enable/disable FTM push service of FortiToken Cloud. type: str choices: enable, disable more...
    • fortitoken_cloud_sync_interval - Interval in which to clean up remote users in FortiToken Cloud (0 - 336 hours (14 days)). type: int more...
    • gui_allow_default_hostname - Enable/disable the factory default hostname warning on the GUI setup wizard. type: str choices: enable, disable more...
    • gui_allow_incompatible_fabric_fgt - Enable/disable Allow FGT with incompatible firmware to be treated as compatible in security fabric on the GUI. May cause unexpected error. type: str choices: enable, disable more...
    • gui_app_detection_sdwan - Enable/disable Allow app-detection based SD-WAN. type: str choices: enable, disable more...
    • gui_auto_upgrade_setup_warning - Enable/disable the automatic patch upgrade setup prompt on the GUI. type: str choices: enable, disable more...
    • gui_cdn_domain_override - Domain of CDN server. type: str more...
    • gui_cdn_usage - Enable/disable Load GUI static files from a CDN. type: str choices: enable, disable more...
    • gui_certificates - Enable/disable the System > Certificate GUI page, allowing you to add and configure certificates from the GUI. type: str choices: enable, disable more...
    • gui_custom_language - Enable/disable custom languages in GUI. type: str choices: enable, disable more...
    • gui_date_format - Default date format used throughout GUI. type: str choices: yyyy/MM/dd, dd/MM/yyyy, MM/dd/yyyy, yyyy-MM-dd, dd-MM-yyyy, MM-dd-yyyy more...
    • gui_date_time_source - Source from which the FortiGate GUI uses to display date and time entries. type: str choices: system, browser more...
    • gui_device_latitude - Add the latitude of the location of this FortiGate to position it on the Threat Map. type: str more...
    • gui_device_longitude - Add the longitude of the location of this FortiGate to position it on the Threat Map. type: str more...
    • gui_display_hostname - Enable/disable displaying the FortiGate"s hostname on the GUI login page. type: str choices: enable, disable more...
    • gui_firmware_upgrade_warning - Enable/disable the firmware upgrade warning on the GUI. type: str choices: enable, disable more...
    • gui_forticare_registration_setup_warning - Enable/disable the FortiCare registration setup warning on the GUI. type: str choices: enable, disable more...
    • gui_fortigate_cloud_sandbox - Enable/disable displaying FortiGate Cloud Sandbox on the GUI. type: str choices: enable, disable more...
    • gui_fortiguard_resource_fetch - Enable/disable retrieving static GUI resources from FortiGuard. Disabling it will improve GUI load time for air-gapped environments. type: str choices: enable, disable more...
    • gui_fortisandbox_cloud - Enable/disable displaying FortiSandbox Cloud on the GUI. type: str choices: enable, disable more...
    • gui_ipv6 - Enable/disable IPv6 settings on the GUI. type: str choices: enable, disable more...
    • gui_lines_per_page - Number of lines to display per page for web administration. type: int more...
    • gui_local_out - Enable/disable Local-out traffic on the GUI. type: str choices: enable, disable more...
    • gui_replacement_message_groups - Enable/disable replacement message groups on the GUI. type: str choices: enable, disable more...
    • gui_rest_api_cache - Enable/disable REST API result caching on FortiGate. type: str choices: enable, disable more...
    • gui_theme - Color scheme for the administration GUI. type: str choices: jade, neutrino, mariner, graphite, melongene, jet-stream, security-fabric, retro, dark-matter, onyx, eclipse, green, blue, red more...
    • gui_wireless_opensecurity - Enable/disable wireless open security option on the GUI. type: str choices: enable, disable more...
    • gui_workflow_management - Enable/disable Workflow management features on the GUI. type: str choices: enable, disable more...
    • ha_affinity - Affinity setting for HA daemons (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • honor_df - Enable/disable honoring of Don"t-Fragment (DF) flag. type: str choices: enable, disable more...
    • hostname - FortiGate unit"s hostname. Most models will truncate names longer than 24 characters. Some models support hostnames up to 35 characters. type: str more...
    • igmp_state_limit - Maximum number of IGMP memberships (96 - 64000). type: int more...
    • interface_subnet_usage - Enable/disable allowing use of interface-subnet setting in firewall addresses . type: str choices: disable, enable more...
    • internet_service_database - Configure which Internet Service database size to download from FortiGuard and use. type: str choices: mini, standard, full, on-demand more...
    • internet_service_download_list - Configure which on-demand Internet Service IDs are to be downloaded. type: list member_path: internet_service_download_list:id more...
      • id - Internet Service ID. see Notes. Source firewall.internet-service.id. type: int required: true more...
    • interval - Dead gateway detection interval. type: int more...
    • ip_fragment_mem_thresholds - Maximum memory (MB) used to reassemble IPv4/IPv6 fragments. type: int more...
    • ip_src_port_range - IP source port range used for traffic originating from the FortiGate unit. type: str more...
    • ips_affinity - Affinity setting for IPS (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx; allowed CPUs must be less than total number of IPS engine daemons). type: str more...
    • ipsec_asic_offload - Enable/disable ASIC offloading (hardware acceleration) for IPsec VPN traffic. Hardware acceleration can offload IPsec VPN sessions and accelerate encryption and decryption. type: str choices: enable, disable more...
    • ipsec_ha_seqjump_rate - ESP jump ahead rate (1G - 10G pps equivalent). type: int more...
    • ipsec_hmac_offload - Enable/disable offloading (hardware acceleration) of HMAC processing for IPsec VPN. type: str choices: enable, disable more...
    • ipsec_round_robin - Enable/disable round-robin redistribution to multiple CPUs for IPsec VPN traffic. type: str choices: enable, disable more...
    • ipsec_soft_dec_async - Enable/disable software decryption asynchronization (using multiple CPUs to do decryption) for IPsec VPN traffic. type: str choices: enable, disable more...
    • ipv6_accept_dad - Enable/disable acceptance of IPv6 Duplicate Address Detection (DAD). type: int more...
    • ipv6_allow_anycast_probe - Enable/disable IPv6 address probe through Anycast. type: str choices: enable, disable more...
    • ipv6_allow_local_in_slient_drop - Enable/disable silent drop of IPv6 local-in traffic. type: str choices: enable, disable more...
    • ipv6_allow_multicast_probe - Enable/disable IPv6 address probe through Multicast. type: str choices: enable, disable more...
    • ipv6_allow_traffic_redirect - Disable to prevent IPv6 traffic with same local ingress and egress interface from being forwarded without policy check. type: str choices: enable, disable more...
    • irq_time_accounting - Configure CPU IRQ time accounting mode. type: str choices: auto, force more...
    • language - GUI display language. type: str choices: english, french, spanish, portuguese, japanese, trach, simch, korean more...
    • ldapconntimeout - Global timeout for connections with remote LDAP servers in milliseconds (1 - 300000). type: int more...
    • lldp_reception - Enable/disable Link Layer Discovery Protocol (LLDP) reception. type: str choices: enable, disable more...
    • lldp_transmission - Enable/disable Link Layer Discovery Protocol (LLDP) transmission. type: str choices: enable, disable more...
    • log_single_cpu_high - Enable/disable logging the event of a single CPU core reaching CPU usage threshold. type: str choices: enable, disable more...
    • log_ssl_connection - Enable/disable logging of SSL connection events. type: str choices: enable, disable more...
    • log_uuid - Whether UUIDs are added to traffic logs. You can disable UUIDs, add firewall policy UUIDs to traffic logs, or add all UUIDs to traffic logs. type: str choices: disable, policy-only, extended more...
    • log_uuid_address - Enable/disable insertion of address UUIDs to traffic logs. type: str choices: enable, disable more...
    • log_uuid_policy - Enable/disable insertion of policy UUIDs to traffic logs. type: str choices: enable, disable more...
    • login_timestamp - Enable/disable login time recording. type: str choices: enable, disable more...
    • long_vdom_name - Enable/disable long VDOM name support. type: str choices: enable, disable more...
    • management_ip - Management IP address of this FortiGate. Used to log into this FortiGate from another FortiGate in the Security Fabric. type: str more...
    • management_port - Overriding port for management connection (Overrides admin port). type: int more...
    • management_port_use_admin_sport - Enable/disable use of the admin-sport setting for the management port. If disabled, FortiGate will allow user to specify management-port. type: str choices: enable, disable more...
    • management_vdom - Management virtual domain name. Source system.vdom.name. type: str more...
    • max_dlpstat_memory - Maximum DLP stat memory (0 - 4294967295). type: int more...
    • max_route_cache_size - Maximum number of IP route cache entries (0 - 2147483647). type: int more...
    • mc_ttl_notchange - Enable/disable no modification of multicast TTL. type: str choices: enable, disable more...
    • memory_use_threshold_extreme - Threshold at which memory usage is considered extreme (new sessions are dropped) (% of total RAM). type: int more...
    • memory_use_threshold_green - Threshold at which memory usage forces the FortiGate to exit conserve mode (% of total RAM). type: int more...
    • memory_use_threshold_red - Threshold at which memory usage forces the FortiGate to enter conserve mode (% of total RAM). type: int more...
    • miglog_affinity - Affinity setting for logging (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • miglogd_children - Number of logging (miglogd) processes to be allowed to run. Higher number can reduce performance; lower number can slow log processing time. type: int more...
    • multi_factor_authentication - Enforce all login methods to require an additional authentication factor . type: str choices: optional, mandatory more...
    • multicast_forward - Enable/disable multicast forwarding. type: str choices: enable, disable more...
    • ndp_max_entry - Maximum number of NDP table entries (set to 65,536 or higher; if set to 0, kernel holds 65,536 entries). type: int more...
    • per_user_bal - Enable/disable per-user block/allow list filter. type: str choices: enable, disable more...
    • per_user_bwl - Enable/disable per-user black/white list filter. type: str choices: enable, disable more...
    • pmtu_discovery - Enable/disable path MTU discovery. type: str choices: enable, disable more...
    • policy_auth_concurrent - Number of concurrent firewall use logins from the same user (1 - 100). type: int more...
    • post_login_banner - Enable/disable displaying the administrator access disclaimer message after an administrator successfully logs in. type: str choices: disable, enable more...
    • pre_login_banner - Enable/disable displaying the administrator access disclaimer message on the login page before an administrator logs in. type: str choices: enable, disable more...
    • private_data_encryption - Enable/disable private data encryption using an AES 128-bit key or passpharse. type: str choices: disable, enable more...
    • proxy_auth_lifetime - Enable/disable authenticated users lifetime control. This is a cap on the total time a proxy user can be authenticated for after which re-authentication will take place. type: str choices: enable, disable more...
    • proxy_auth_lifetime_timeout - Lifetime timeout in minutes for authenticated users (5 - 65535 min). type: int more...
    • proxy_auth_timeout - Authentication timeout in minutes for authenticated users (1 - 300 min). type: int more...
    • proxy_cert_use_mgmt_vdom - Enable/disable using management VDOM to send requests. type: str choices: enable, disable more...
    • proxy_cipher_hardware_acceleration - Enable/disable using content processor (CP8 or CP9) hardware acceleration to encrypt and decrypt IPsec and SSL traffic. type: str choices: disable, enable more...
    • proxy_hardware_acceleration - Enable/disable email proxy hardware acceleration. type: str choices: disable, enable more...
    • proxy_keep_alive_mode - Control if users must re-authenticate after a session is closed, traffic has been idle, or from the point at which the user was authenticated. type: str choices: session, traffic, re-authentication more...
    • proxy_kxp_hardware_acceleration - Enable/disable using the content processor to accelerate KXP traffic. type: str choices: disable, enable more...
    • proxy_re_authentication_mode - Control if users must re-authenticate after a session is closed, traffic has been idle, or from the point at which the user was first created. type: str choices: session, traffic, absolute more...
    • proxy_re_authentication_time - The time limit that users must re-authenticate if proxy-keep-alive-mode is set to re-authenticate (1 - 86400 sec, default=30s. type: int more...
    • proxy_resource_mode - Enable/disable use of the maximum memory usage on the FortiGate unit"s proxy processing of resources, such as block lists, allow lists, and external resources. type: str choices: enable, disable more...
    • proxy_worker_count - Proxy worker count. type: int more...
    • purdue_level - Purdue Level of this FortiGate. type: str choices: 1, 1.5, 2, 2.5, 3, 3.5, 4, 5, 5.5 more...
    • quic_ack_thresold - Maximum number of unacknowledged packets before sending ACK (2 - 5). type: int more...
    • quic_congestion_control_algo - QUIC congestion control algorithm . type: str choices: cubic, bbr, bbr2, reno more...
    • quic_max_datagram_size - Maximum transmit datagram size (1200 - 1500). type: int more...
    • quic_pmtud - Enable/disable path MTU discovery . type: str choices: enable, disable more...
    • quic_tls_handshake_timeout - Time-to-live (TTL) for TLS handshake in seconds (1 - 60). type: int more...
    • quic_udp_payload_size_shaping_per_cid - Enable/disable UDP payload size shaping per connection ID . type: str choices: enable, disable more...
    • radius_port - RADIUS service port number. type: int more...
    • reboot_upon_config_restore - Enable/disable reboot of system upon restoring configuration. type: str choices: enable, disable more...
    • refresh - Statistics refresh interval second(s) in GUI. type: int more...
    • remoteauthtimeout - Number of seconds that the FortiGate waits for responses from remote RADIUS, LDAP, or TACACS+ authentication servers. (1-300 sec). type: int more...
    • reset_sessionless_tcp - Action to perform if the FortiGate receives a TCP packet but cannot find a corresponding session in its session table. NAT/Route mode only. type: str choices: enable, disable more...
    • restart_time - Daily restart time (hh:mm). type: str more...
    • revision_backup_on_logout - Enable/disable back-up of the latest configuration revision when an administrator logs out of the CLI or GUI. type: str choices: enable, disable more...
    • revision_image_auto_backup - Enable/disable back-up of the latest image revision after the firmware is upgraded. type: str choices: enable, disable more...
    • scanunit_count - Number of scanunits. The range and the default depend on the number of CPUs. Only available on FortiGate units with multiple CPUs. type: int more...
    • security_rating_result_submission - Enable/disable the submission of Security Rating results to FortiGuard. type: str choices: enable, disable more...
    • security_rating_run_on_schedule - Enable/disable scheduled runs of Security Rating. type: str choices: enable, disable more...
    • send_pmtu_icmp - Enable/disable sending of path maximum transmission unit (PMTU) - ICMP destination unreachable packet and to support PMTUD protocol on your network to reduce fragmentation of packets. type: str choices: enable, disable more...
    • sflowd_max_children_num - Maximum number of sflowd child processes allowed to run. type: int more...
    • snat_route_change - Enable/disable the ability to change the source NAT route. type: str choices: enable, disable more...
    • special_file_23_support - Enable/disable detection of those special format files when using Data Leak Prevention. type: str choices: disable, enable more...
    • speedtest_server - Enable/disable speed test server. type: str choices: enable, disable more...
    • speedtestd_ctrl_port - Speedtest server controller port number. type: int more...
    • speedtestd_server_port - Speedtest server port number. type: int more...
    • split_port - Split port(s) to multiple 10Gbps ports. type: list
    • split_port_mode - Configure split port mode of ports. type: list member_path: split_port_mode:interface more...
      • interface - Split port interface. type: str required: true more...
      • split_mode - The configuration mode for the split port interface. type: str choices: disable, 4x10G, 4x25G, 4x50G, 8x25G, 8x50G, 4x100G, 2x200G more...
    • ssd_trim_date - Date within a month to run ssd trim. type: int more...
    • ssd_trim_freq - How often to run SSD Trim . SSD Trim prevents SSD drive data loss by finding and isolating errors. type: str choices: never, hourly, daily, weekly, monthly more...
    • ssd_trim_hour - Hour of the day on which to run SSD Trim (0 - 23). type: int more...
    • ssd_trim_min - Minute of the hour on which to run SSD Trim (0 - 59, 60 for random). type: int more...
    • ssd_trim_weekday - Day of week to run SSD Trim. type: str choices: sunday, monday, tuesday, wednesday, thursday, friday, saturday more...
    • ssh_cbc_cipher - Enable/disable CBC cipher for SSH access. type: str choices: enable, disable more...
    • ssh_enc_algo - Select one or more SSH ciphers. type: list choices: chacha20-poly1305@openssh.com, aes128-ctr, aes192-ctr, aes256-ctr, arcfour256, arcfour128, aes128-cbc, 3des-cbc, blowfish-cbc, cast128-cbc, aes192-cbc, aes256-cbc, arcfour, rijndael-cbc@lysator.liu.se, aes128-gcm@openssh.com, aes256-gcm@openssh.com more...
    • ssh_hmac_md5 - Enable/disable HMAC-MD5 for SSH access. type: str choices: enable, disable more...
    • ssh_hostkey - Config SSH host key. type: str more...
    • ssh_hostkey_algo - Select one or more SSH hostkey algorithms. type: list choices: ssh-rsa, ecdsa-sha2-nistp521, ecdsa-sha2-nistp384, ecdsa-sha2-nistp256, rsa-sha2-256, rsa-sha2-512, ssh-ed25519 more...
    • ssh_hostkey_override - Enable/disable SSH host key override in SSH daemon. type: str choices: disable, enable more...
    • ssh_hostkey_password - Password for ssh-hostkey. type: str more...
    • ssh_kex_algo - Select one or more SSH kex algorithms. type: list choices: diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha1, diffie-hellman-group-exchange-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521 more...
    • ssh_kex_sha1 - Enable/disable SHA1 key exchange for SSH access. type: str choices: enable, disable more...
    • ssh_mac_algo - Select one or more SSH MAC algorithms. type: list choices: hmac-md5, hmac-md5-etm@openssh.com, hmac-md5-96, hmac-md5-96-etm@openssh.com, hmac-sha1, hmac-sha1-etm@openssh.com, hmac-sha2-256, hmac-sha2-256-etm@openssh.com, hmac-sha2-512, hmac-sha2-512-etm@openssh.com, hmac-ripemd160, hmac-ripemd160@openssh.com, hmac-ripemd160-etm@openssh.com, umac-64@openssh.com, umac-128@openssh.com, umac-64-etm@openssh.com, umac-128-etm@openssh.com more...
    • ssh_mac_weak - Enable/disable HMAC-SHA1 and UMAC-64-ETM for SSH access. type: str choices: enable, disable more...
    • ssl_min_proto_version - Minimum supported protocol version for SSL/TLS connections . type: str choices: SSLv3, TLSv1, TLSv1-1, TLSv1-2, TLSv1-3 more...
    • ssl_static_key_ciphers - Enable/disable static key ciphers in SSL/TLS connections (e.g. AES128-SHA, AES256-SHA, AES128-SHA256, AES256-SHA256). type: str choices: enable, disable more...
    • sslvpn_cipher_hardware_acceleration - sslvpn-cipher-hardware-acceleration type: str choices: enable, disable more...
    • sslvpn_ems_sn_check - Enable/disable verification of EMS serial number in SSL-VPN connection. type: str choices: enable, disable more...
    • sslvpn_kxp_hardware_acceleration - sslvpn-kxp-hardware-acceleration type: str choices: enable, disable more...
    • sslvpn_max_worker_count - Maximum number of SSL-VPN processes. Upper limit for this value is the number of CPUs and depends on the model. Default value of zero means the SSLVPN daemon decides the number of worker processes. type: int more...
    • sslvpn_plugin_version_check - sslvpn-plugin-version-check type: str choices: enable, disable more...
    • sslvpn_web_mode - Enable/disable SSL-VPN web mode. type: str choices: enable, disable more...
    • strict_dirty_session_check - Enable to check the session against the original policy when revalidating. This can prevent dropping of redirected sessions when web-filtering and authentication are enabled together. If this option is enabled, the FortiGate unit deletes a session if a routing or policy change causes the session to no longer match the policy that originally allowed the session. type: str choices: enable, disable more...
    • strong_crypto - Enable to use strong encryption and only allow strong ciphers and digest for HTTPS/SSH/TLS/SSL functions. type: str choices: enable, disable more...
    • switch_controller - Enable/disable switch controller feature. Switch controller allows you to manage FortiSwitch from the FortiGate itself. type: str choices: disable, enable more...
    • switch_controller_reserved_network - Configure reserved network subnet for managed switches. This is available when the switch controller is enabled. type: str more...
    • sys_perf_log_interval - Time in minutes between updates of performance statistics logging. (1 - 15 min). type: int more...
    • syslog_affinity - Affinity setting for syslog (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • tcp_halfclose_timer - Number of seconds the FortiGate unit should wait to close a session after one peer has sent a FIN packet but the other has not responded (1 - 86400 sec (1 day)). type: int more...
    • tcp_halfopen_timer - Number of seconds the FortiGate unit should wait to close a session after one peer has sent an open session packet but the other has not responded (1 - 86400 sec (1 day)). type: int more...
    • tcp_option - Enable SACK, timestamp and MSS TCP options. type: str choices: enable, disable more...
    • tcp_rst_timer - Length of the TCP CLOSE state in seconds (5 - 300 sec). type: int more...
    • tcp_timewait_timer - Length of the TCP TIME-WAIT state in seconds (1 - 300 sec). type: int more...
    • tftp - Enable/disable TFTP. type: str choices: enable, disable more...
    • timezone - Timezone database name. Enter ? to view the list of timezone. Source system.timezone.name. type: str more...
    • tp_mc_skip_policy - Enable/disable skip policy check and allow multicast through. type: str choices: enable, disable more...
    • traffic_priority - Choose Type of Service (ToS) or Differentiated Services Code Point (DSCP) for traffic prioritization in traffic shaping. type: str choices: tos, dscp more...
    • traffic_priority_level - Default system-wide level of priority for traffic prioritization. type: str choices: low, medium, high more...
    • two_factor_email_expiry - Email-based two-factor authentication session timeout (30 - 300 seconds (5 minutes)). type: int more...
    • two_factor_fac_expiry - FortiAuthenticator token authentication session timeout (10 - 3600 seconds (1 hour)). type: int more...
    • two_factor_ftk_expiry - FortiToken authentication session timeout (60 - 600 sec (10 minutes)). type: int more...
    • two_factor_ftm_expiry - FortiToken Mobile session timeout (1 - 168 hours (7 days)). type: int more...
    • two_factor_sms_expiry - SMS-based two-factor authentication session timeout (30 - 300 sec). type: int more...
    • udp_idle_timer - UDP connection session timeout. This command can be useful in managing CPU and memory resources (1 - 86400 seconds (1 day)). type: int more...
    • url_filter_affinity - URL filter CPU affinity. type: str more...
    • url_filter_count - URL filter daemon count. type: int more...
    • user_device_store_max_devices - Maximum number of devices allowed in user device store. type: int more...
    • user_device_store_max_unified_mem - Maximum unified memory allowed in user device store. type: int more...
    • user_device_store_max_users - Maximum number of users allowed in user device store. type: int more...
    • user_server_cert - Certificate to use for https user authentication. Source certificate.local.name. type: str more...
    • vdom_admin - vdom-admin type: str choices: enable, disable more...
    • vdom_mode - Enable/disable support for multiple virtual domains (VDOMs). type: str choices: no-vdom, multi-vdom, split-vdom more...
    • vip_arp_range - Controls the number of ARPs that the FortiGate sends for a Virtual IP (VIP) address range. type: str choices: unlimited, restricted more...
    • virtual_server_count - Maximum number of virtual server processes to create. The maximum is the number of CPU cores. This is not available on single-core CPUs. type: int more...
    • virtual_server_hardware_acceleration - Enable/disable virtual server hardware acceleration. type: str choices: disable, enable more...
    • virtual_switch_vlan - Enable/disable virtual switch VLAN. type: str choices: enable, disable more...
    • vpn_ems_sn_check - Enable/disable verification of EMS serial number in SSL-VPN and IPsec VPN connection. type: str choices: enable, disable more...
    • wad_affinity - Affinity setting for wad (hexadecimal value up to 256 bits in the format of xxxxxxxxxxxxxxxx). type: str more...
    • wad_csvc_cs_count - Number of concurrent WAD-cache-service object-cache processes. type: int more...
    • wad_csvc_db_count - Number of concurrent WAD-cache-service byte-cache processes. type: int more...
    • wad_memory_change_granularity - Minimum percentage change in system memory usage detected by the wad daemon prior to adjusting TCP window size for any active connection. type: int more...
    • wad_restart_end_time - WAD workers daily restart end time (hh:mm). type: str more...
    • wad_restart_mode - WAD worker restart mode . type: str choices: none, time, memory more...
    • wad_restart_start_time - WAD workers daily restart time (hh:mm). type: str more...
    • wad_source_affinity - Enable/disable dispatching traffic to WAD workers based on source affinity. type: str choices: disable, enable more...
    • wad_worker_count - Number of explicit proxy WAN optimization daemon (WAD) processes. By default WAN optimization, explicit proxy, and web caching is handled by all of the CPU cores in a FortiGate unit. type: int more...
    • wifi_ca_certificate - CA certificate that verifies the WiFi certificate. Source certificate.ca.name. type: str more...
    • wifi_certificate - Certificate to use for WiFi authentication. Source certificate.local.name. type: str more...
    • wimax_4g_usb - Enable/disable comparability with WiMAX 4G USB devices. type: str choices: enable, disable more...
    • wireless_controller - Enable/disable the wireless controller feature to use the FortiGate unit to manage FortiAPs. type: str choices: enable, disable more...
    • wireless_controller_port - Port used for the control channel in wireless controller mode (wireless-mode is ac). The data channel port is the control channel port number plus one (1024 - 49150). type: int more...

Notes

Note

  • Legacy fortiosapi has been deprecated, httpapi is the preferred way to run playbooks

Examples

- name: Configure global attributes.
  fortinet.fortios.fortios_system_global:
      vdom: "{{ vdom }}"
      system_global:
          admin_concurrent: "enable"
          admin_console_timeout: "0"
          admin_forticloud_sso_default_profile: "<your_own_value> (source system.accprofile.name)"
          admin_forticloud_sso_login: "enable"
          admin_host: "myhostname"
          admin_hsts_max_age: "15552000"
          admin_https_pki_required: "enable"
          admin_https_redirect: "enable"
          admin_https_ssl_banned_ciphers: "RSA"
          admin_https_ssl_ciphersuites: "TLS-AES-128-GCM-SHA256"
          admin_https_ssl_versions: "tlsv1-1"
          admin_lockout_duration: "60"
          admin_lockout_threshold: "3"
          admin_login_max: "100"
          admin_maintainer: "enable"
          admin_port: "80"
          admin_restrict_local: "enable"
          admin_scp: "enable"
          admin_server_cert: "<your_own_value> (source certificate.local.name)"
          admin_sport: "443"
          admin_ssh_grace_time: "120"
          admin_ssh_password: "enable"
          admin_ssh_port: "22"
          admin_ssh_v1: "enable"
          admin_telnet: "enable"
          admin_telnet_port: "23"
          admintimeout: "5"
          alias: "<your_own_value>"
          allow_traffic_redirect: "enable"
          anti_replay: "disable"
          arp_max_entry: "131072"
          asymroute: "enable"
          auth_cert: "<your_own_value> (source certificate.local.name)"
          auth_http_port: "1000"
          auth_https_port: "1003"
          auth_ike_saml_port: "1001"
          auth_keepalive: "enable"
          auth_session_limit: "block-new"
          auto_auth_extension_device: "enable"
          autorun_log_fsck: "enable"
          av_affinity: "<your_own_value>"
          av_failopen: "pass"
          av_failopen_session: "enable"
          batch_cmdb: "enable"
          bfd_affinity: "<your_own_value>"
          block_session_timer: "30"
          br_fdb_max_entry: "8192"
          cert_chain_max: "8"
          cfg_revert_timeout: "600"
          cfg_save: "automatic"
          check_protocol_header: "loose"
          check_reset_range: "strict"
          cli_audit_log: "enable"
          cloud_communication: "enable"
          clt_cert_req: "enable"
          cmdbsvr_affinity: "<your_own_value>"
          compliance_check: "enable"
          compliance_check_time: "<your_own_value>"
          cpu_use_threshold: "90"
          csr_ca_attribute: "enable"
          daily_restart: "enable"
          default_service_source_port: "<your_own_value>"
          device_identification_active_scan_delay: "1800"
          device_idle_timeout: "300"
          dh_params: "1024"
          dnsproxy_worker_count: "1"
          dst: "enable"
          early_tcp_npu_session: "enable"
          edit_vdom_prompt: "enable"
          endpoint_control_fds_access: "enable"
          endpoint_control_portal_port: "32767"
          extender_controller_reserved_network: "<your_own_value>"
          failtime: "5"
          faz_disk_buffer_size: "0"
          fds_statistics: "enable"
          fds_statistics_period: "60"
          fec_port: "50000"
          fgd_alert_subscription: "advisory"
          forticarrier_bypass: "enable"
          forticonverter_config_upload: "once"
          forticonverter_integration: "enable"
          fortiextender: "disable"
          fortiextender_data_port: "25246"
          fortiextender_discovery_lockdown: "disable"
          fortiextender_provision_on_authorization: "enable"
          fortiextender_vlan_mode: "enable"
          fortigslb_integration: "disable"
          fortiipam_integration: "enable"
          fortiservice_port: "8013"
          fortitoken_cloud: "enable"
          fortitoken_cloud_push_status: "enable"
          fortitoken_cloud_sync_interval: "24"
          gui_allow_default_hostname: "enable"
          gui_allow_incompatible_fabric_fgt: "enable"
          gui_app_detection_sdwan: "enable"
          gui_auto_upgrade_setup_warning: "enable"
          gui_cdn_domain_override: "<your_own_value>"
          gui_cdn_usage: "enable"
          gui_certificates: "enable"
          gui_custom_language: "enable"
          gui_date_format: "yyyy/MM/dd"
          gui_date_time_source: "system"
          gui_device_latitude: "<your_own_value>"
          gui_device_longitude: "<your_own_value>"
          gui_display_hostname: "enable"
          gui_firmware_upgrade_warning: "enable"
          gui_forticare_registration_setup_warning: "enable"
          gui_fortigate_cloud_sandbox: "enable"
          gui_fortiguard_resource_fetch: "enable"
          gui_fortisandbox_cloud: "enable"
          gui_ipv6: "enable"
          gui_lines_per_page: "500"
          gui_local_out: "enable"
          gui_replacement_message_groups: "enable"
          gui_rest_api_cache: "enable"
          gui_theme: "jade"
          gui_wireless_opensecurity: "enable"
          gui_workflow_management: "enable"
          ha_affinity: "<your_own_value>"
          honor_df: "enable"
          hostname: "myhostname"
          igmp_state_limit: "3200"
          interface_subnet_usage: "disable"
          internet_service_database: "mini"
          internet_service_download_list:
              -
                  id: "128 (source firewall.internet-service.id)"
          interval: "5"
          ip_fragment_mem_thresholds: "32"
          ip_src_port_range: "<your_own_value>"
          ips_affinity: "<your_own_value>"
          ipsec_asic_offload: "enable"
          ipsec_ha_seqjump_rate: "10"
          ipsec_hmac_offload: "enable"
          ipsec_round_robin: "enable"
          ipsec_soft_dec_async: "enable"
          ipv6_accept_dad: "1"
          ipv6_allow_anycast_probe: "enable"
          ipv6_allow_local_in_slient_drop: "enable"
          ipv6_allow_multicast_probe: "enable"
          ipv6_allow_traffic_redirect: "enable"
          irq_time_accounting: "auto"
          language: "english"
          ldapconntimeout: "500"
          lldp_reception: "enable"
          lldp_transmission: "enable"
          log_single_cpu_high: "enable"
          log_ssl_connection: "enable"
          log_uuid: "disable"
          log_uuid_address: "enable"
          log_uuid_policy: "enable"
          login_timestamp: "enable"
          long_vdom_name: "enable"
          management_ip: "<your_own_value>"
          management_port: "443"
          management_port_use_admin_sport: "enable"
          management_vdom: "<your_own_value> (source system.vdom.name)"
          max_dlpstat_memory: "159"
          max_route_cache_size: "0"
          mc_ttl_notchange: "enable"
          memory_use_threshold_extreme: "95"
          memory_use_threshold_green: "82"
          memory_use_threshold_red: "88"
          miglog_affinity: "<your_own_value>"
          miglogd_children: "0"
          multi_factor_authentication: "optional"
          multicast_forward: "enable"
          ndp_max_entry: "0"
          per_user_bal: "enable"
          per_user_bwl: "enable"
          pmtu_discovery: "enable"
          policy_auth_concurrent: "0"
          post_login_banner: "disable"
          pre_login_banner: "enable"
          private_data_encryption: "disable"
          proxy_auth_lifetime: "enable"
          proxy_auth_lifetime_timeout: "480"
          proxy_auth_timeout: "10"
          proxy_cert_use_mgmt_vdom: "enable"
          proxy_cipher_hardware_acceleration: "disable"
          proxy_hardware_acceleration: "disable"
          proxy_keep_alive_mode: "session"
          proxy_kxp_hardware_acceleration: "disable"
          proxy_re_authentication_mode: "session"
          proxy_re_authentication_time: "30"
          proxy_resource_mode: "enable"
          proxy_worker_count: "0"
          purdue_level: "1"
          quic_ack_thresold: "3"
          quic_congestion_control_algo: "cubic"
          quic_max_datagram_size: "1500"
          quic_pmtud: "enable"
          quic_tls_handshake_timeout: "5"
          quic_udp_payload_size_shaping_per_cid: "enable"
          radius_port: "1812"
          reboot_upon_config_restore: "enable"
          refresh: "0"
          remoteauthtimeout: "5"
          reset_sessionless_tcp: "enable"
          restart_time: "<your_own_value>"
          revision_backup_on_logout: "enable"
          revision_image_auto_backup: "enable"
          scanunit_count: "0"
          security_rating_result_submission: "enable"
          security_rating_run_on_schedule: "enable"
          send_pmtu_icmp: "enable"
          sflowd_max_children_num: "6"
          snat_route_change: "enable"
          special_file_23_support: "disable"
          speedtest_server: "enable"
          speedtestd_ctrl_port: "5200"
          speedtestd_server_port: "5201"
          split_port: "<your_own_value>"
          split_port_mode:
              -
                  interface: "<your_own_value>"
                  split_mode: "disable"
          ssd_trim_date: "1"
          ssd_trim_freq: "never"
          ssd_trim_hour: "1"
          ssd_trim_min: "60"
          ssd_trim_weekday: "sunday"
          ssh_cbc_cipher: "enable"
          ssh_enc_algo: "chacha20-poly1305@openssh.com"
          ssh_hmac_md5: "enable"
          ssh_hostkey: "myhostname"
          ssh_hostkey_algo: "ssh-rsa"
          ssh_hostkey_override: "disable"
          ssh_hostkey_password: "myhostname"
          ssh_kex_algo: "diffie-hellman-group1-sha1"
          ssh_kex_sha1: "enable"
          ssh_mac_algo: "hmac-md5"
          ssh_mac_weak: "enable"
          ssl_min_proto_version: "SSLv3"
          ssl_static_key_ciphers: "enable"
          sslvpn_cipher_hardware_acceleration: "enable"
          sslvpn_ems_sn_check: "enable"
          sslvpn_kxp_hardware_acceleration: "enable"
          sslvpn_max_worker_count: "0"
          sslvpn_plugin_version_check: "enable"
          sslvpn_web_mode: "enable"
          strict_dirty_session_check: "enable"
          strong_crypto: "enable"
          switch_controller: "disable"
          switch_controller_reserved_network: "<your_own_value>"
          sys_perf_log_interval: "5"
          syslog_affinity: "<your_own_value>"
          tcp_halfclose_timer: "120"
          tcp_halfopen_timer: "10"
          tcp_option: "enable"
          tcp_rst_timer: "5"
          tcp_timewait_timer: "1"
          tftp: "enable"
          timezone: "<your_own_value> (source system.timezone.name)"
          tp_mc_skip_policy: "enable"
          traffic_priority: "tos"
          traffic_priority_level: "low"
          two_factor_email_expiry: "60"
          two_factor_fac_expiry: "60"
          two_factor_ftk_expiry: "60"
          two_factor_ftm_expiry: "72"
          two_factor_sms_expiry: "60"
          udp_idle_timer: "180"
          url_filter_affinity: "<your_own_value>"
          url_filter_count: "1"
          user_device_store_max_devices: "20911"
          user_device_store_max_unified_mem: "104558182"
          user_device_store_max_users: "20911"
          user_server_cert: "<your_own_value> (source certificate.local.name)"
          vdom_admin: "enable"
          vdom_mode: "no-vdom"
          vip_arp_range: "unlimited"
          virtual_server_count: "20"
          virtual_server_hardware_acceleration: "disable"
          virtual_switch_vlan: "enable"
          vpn_ems_sn_check: "enable"
          wad_affinity: "<your_own_value>"
          wad_csvc_cs_count: "1"
          wad_csvc_db_count: "0"
          wad_memory_change_granularity: "10"
          wad_restart_end_time: "<your_own_value>"
          wad_restart_mode: "none"
          wad_restart_start_time: "<your_own_value>"
          wad_source_affinity: "disable"
          wad_worker_count: "0"
          wifi_ca_certificate: "<your_own_value> (source certificate.ca.name)"
          wifi_certificate: "<your_own_value> (source certificate.local.name)"
          wimax_4g_usb: "enable"
          wireless_controller: "enable"
          wireless_controller_port: "5246"

Return Values

Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:

  • build - Build number of the fortigate image returned: always type: str sample: 1547
  • http_method - Last method used to provision the content into FortiGate returned: always type: str sample: PUT
  • http_status - Last result given by FortiGate on last operation applied returned: always type: str sample: 200
  • mkey - Master key (id) used in the last call to FortiGate returned: success type: str sample: id
  • name - Name of the table used to fulfill the request returned: always type: str sample: urlfilter
  • path - Path of the table used to fulfill the request returned: always type: str sample: webfilter
  • revision - Internal revision number returned: always type: str sample: 17.0.2.10658
  • serial - Serial number of the unit returned: always type: str sample: FGVMEVYYQT3AB5352
  • status - Indication of the operation's result returned: always type: str sample: success
  • vdom - Virtual domain used returned: always type: str sample: root
  • version - Version of the FortiGate returned: always type: str sample: v5.6.3

Status

  • This module is not guaranteed to have a backwards compatible interface.

Authors

  • Link Zheng (@chillancezen)

  • Jie Xue (@JieX19)

  • Hongbin Lu (@fgtdev-hblu)

  • Frank Shen (@frankshen01)

  • Miguel Angel Munoz (@mamunozgonzalez)

  • Nicolas Thomas (@thomnico)

Hint

If you notice any issues in this documentation, you can create a pull request to improve it.