:source: fortios_firewall_security_policy.py :orphan: .. fortios_firewall_security_policy: fortios_firewall_security_policy -- Configure NGFW IPv4/IPv6 application policies in Fortinet's FortiOS and FortiGate. ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ .. versionadded:: 2.0.0 .. contents:: :local: :depth: 1 Synopsis -------- - This module is able to configure a FortiGate or FortiOS (FOS) device by allowing the user to set and modify firewall feature and security_policy category. Examples include all parameters and values need to be adjusted to datasources before usage. Tested with FOS v6.0.0 Requirements ------------ The below requirements are needed on the host that executes this module. - ansible>=2.16 Tips ---- Using member operation to add an element to an existing object. FortiOS Version Compatibility ----------------------------- Supported Version Ranges: v6.2.0 -> v7.6.6 Parameters ---------- .. raw:: html Notes ----- .. note:: - We highly recommend using your own value as the policyid instead of 0, while '0' is a special placeholder that allows the backend to assign the latest available number for the object, it does have limitations. Please find more details in Q&A. - Legacy fortiosapi has been deprecated, httpapi is the preferred way to run playbooks - The module supports check_mode. Examples -------- .. code-block:: yaml+jinja - name: Configure NGFW IPv4/IPv6 application policies. fortinet.fortios.fortios_firewall_security_policy: vdom: "{{ vdom }}" state: "present" access_token: "" firewall_security_policy: action: "accept" app_category: - id: "5" app_group: - name: "default_name_7 (source application.group.name)" application: - id: "9" application_list: " (source application.list.name)" av_profile: " (source antivirus.profile.name)" casb_profile: " (source casb.profile.name)" cifs_profile: " (source cifs.profile.name)" comments: "" diameter_filter_profile: " (source diameter-filter.profile.name)" dlp_profile: " (source dlp.profile.name)" dlp_sensor: " (source dlp.sensor.name)" dnsfilter_profile: " (source dnsfilter.profile.name)" dstaddr: - name: "default_name_20 (source firewall.address.name firewall.addrgrp.name firewall.vip.name firewall.vipgrp.name system.external-resource .name)" dstaddr_negate: "enable" dstaddr4: - name: "default_name_23 (source firewall.address.name firewall.addrgrp.name firewall.vip.name firewall.vipgrp.name)" dstaddr6: - name: "default_name_25 (source firewall.address6.name firewall.addrgrp6.name firewall.vip6.name firewall.vipgrp6.name system .external-resource.name)" dstaddr6_negate: "enable" dstintf: - name: "default_name_28 (source system.interface.name system.zone.name system.sdwan.zone.name)" emailfilter_profile: " (source emailfilter.profile.name)" enforce_default_app_port: "enable" file_filter_profile: " (source file-filter.profile.name)" fsso_groups: - name: "default_name_33 (source user.adgrp.name)" global_label: "" groups: - name: "default_name_36 (source user.group.name)" icap_profile: " (source icap.profile.name)" internet_service: "enable" internet_service_custom: - name: "default_name_40 (source firewall.internet-service-custom.name)" internet_service_custom_group: - name: "default_name_42 (source firewall.internet-service-custom-group.name)" internet_service_fortiguard: - name: "default_name_44 (source firewall.internet-service-fortiguard.name)" internet_service_group: - name: "default_name_46 (source firewall.internet-service-group.name)" internet_service_id: - id: "48 (source firewall.internet-service.id)" internet_service_name: - name: "default_name_50 (source firewall.internet-service-name.name)" internet_service_negate: "enable" internet_service_src: "enable" internet_service_src_custom: - name: "default_name_54 (source firewall.internet-service-custom.name)" internet_service_src_custom_group: - name: "default_name_56 (source firewall.internet-service-custom-group.name)" internet_service_src_fortiguard: - name: "default_name_58 (source firewall.internet-service-fortiguard.name)" internet_service_src_group: - name: "default_name_60 (source firewall.internet-service-group.name)" internet_service_src_id: - id: "62 (source firewall.internet-service.id)" internet_service_src_name: - name: "default_name_64 (source firewall.internet-service-name.name)" internet_service_src_negate: "enable" internet_service6: "enable" internet_service6_custom: - name: "default_name_68 (source firewall.internet-service-custom.name)" internet_service6_custom_group: - name: "default_name_70 (source firewall.internet-service-custom-group.name)" internet_service6_fortiguard: - name: "default_name_72 (source firewall.internet-service-fortiguard.name)" internet_service6_group: - name: "default_name_74 (source firewall.internet-service-group.name)" internet_service6_name: - name: "default_name_76 (source firewall.internet-service-name.name)" internet_service6_negate: "enable" internet_service6_src: "enable" internet_service6_src_custom: - name: "default_name_80 (source firewall.internet-service-custom.name)" internet_service6_src_custom_group: - name: "default_name_82 (source firewall.internet-service-custom-group.name)" internet_service6_src_fortiguard: - name: "default_name_84 (source firewall.internet-service-fortiguard.name)" internet_service6_src_group: - name: "default_name_86 (source firewall.internet-service-group.name)" internet_service6_src_name: - name: "default_name_88 (source firewall.internet-service-name.name)" internet_service6_src_negate: "enable" ips_sensor: " (source ips.sensor.name)" ips_voip_filter: " (source voip.profile.name)" learning_mode: "enable" logtraffic: "all" logtraffic_start: "enable" mms_profile: " (source firewall.mms-profile.name)" name: "default_name_96" nat46: "enable" nat64: "enable" policyid: "" profile_group: " (source firewall.profile-group.name)" profile_protocol_options: " (source firewall.profile-protocol-options.name)" profile_type: "single" schedule: " (source firewall.schedule.onetime.name firewall.schedule.recurring.name firewall.schedule.group.name)" sctp_filter_profile: " (source sctp-filter.profile.name)" send_deny_packet: "disable" service: - name: "default_name_107 (source firewall.service.custom.name firewall.service.group.name)" service_negate: "enable" srcaddr: - name: "default_name_110 (source firewall.address.name firewall.addrgrp.name system.external-resource.name)" srcaddr_negate: "enable" srcaddr4: - name: "default_name_113 (source firewall.address.name firewall.addrgrp.name)" srcaddr6: - name: "default_name_115 (source firewall.address6.name firewall.addrgrp6.name system.external-resource.name)" srcaddr6_negate: "enable" srcintf: - name: "default_name_118 (source system.interface.name system.zone.name system.sdwan.zone.name)" ssh_filter_profile: " (source ssh-filter.profile.name)" ssl_ssh_profile: " (source firewall.ssl-ssh-profile.name)" status: "enable" telemetry_profile: " (source telemetry-controller.profile.name)" url_category: "" users: - name: "default_name_125 (source user.local.name)" utm_status: "enable" uuid: "" uuid_idx: "2147483647" videofilter_profile: " (source videofilter.profile.name)" virtual_patch_profile: " (source virtual-patch.profile.name)" voip_profile: " (source voip.profile.name)" webfilter_profile: " (source webfilter.profile.name)" Return Values ------------- Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module: .. raw:: html
  • build - Build number of the fortigate image returned: always type: str sample: 1547
  • http_method - Last method used to provision the content into FortiGate returned: always type: str sample: PUT
  • http_status - Last result given by FortiGate on last operation applied returned: always type: str sample: 200
  • mkey - Master key (id) used in the last call to FortiGate returned: success type: str sample: id
  • name - Name of the table used to fulfill the request returned: always type: str sample: urlfilter
  • path - Path of the table used to fulfill the request returned: always type: str sample: webfilter
  • revision - Internal revision number returned: always type: str sample: 17.0.2.10658
  • serial - Serial number of the unit returned: always type: str sample: FGVMEVYYQT3AB5352
  • status - Indication of the operation's result returned: always type: str sample: success
  • vdom - Virtual domain used returned: always type: str sample: root
  • version - Version of the FortiGate returned: always type: str sample: v5.6.3
Status ------ - This module is not guaranteed to have a backwards compatible interface. Authors ------- - Link Zheng (@chillancezen) - Jie Xue (@JieX19) - Hongbin Lu (@fgtdev-hblu) - Frank Shen (@frankshen01) - Miguel Angel Munoz (@mamunozgonzalez) - Nicolas Thomas (@thomnico) .. hint:: If you notice any issues in this documentation, you can create a pull request to improve it.