source: | fortios_application_list.py |
---|---|
orphan: |
fortios_application_list -- Configure application control lists in Fortinet's FortiOS and FortiGate.
.. versionadded:: 2.0.0
- This module is able to configure a FortiGate or FortiOS (FOS) device by allowing the user to set and modify application feature and list category. Examples include all parameters and values need to be adjusted to datasources before usage. Tested with FOS v6.0.0
The below requirements are needed on the host that executes this module.
- ansible>=2.9
Using member operation to add an element to an existing object.
v6.0.0 |
v6.0.5 |
v6.0.11 |
v6.2.0 |
v6.2.3 |
v6.2.5 |
v6.2.7 |
v6.4.0 |
v6.4.1 |
v6.4.4 |
v7.0.0 |
v7.0.1 |
v7.0.2 |
v7.0.3 |
v7.0.4 |
v7.0.5 |
v7.0.6 |
v7.0.7 |
v7.0.8 |
v7.0.12 |
v7.2.0 |
v7.2.1 |
v7.2.2 |
v7.2.4 |
v7.4.0 |
|
fortios_application_list | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes | yes |
- access_token - Token-based authentication. Generated from GUI of Fortigate. type: str required: false
- enable_log - Enable/Disable logging for task. type: bool required: false default: False
- vdom - Virtual domain, among those defined previously. A vdom is a virtual instance of the FortiGate that can be configured and used as a different unit. type: str default: root
- member_path - Member attribute path to operate on. type: str
- member_state - Add or delete a member under specified attribute path. type: str choices: present, absent
- state - Indicates whether to create or remove the object. type: str required: true choices: present, absent
- application_list - Configure application control lists. type: dict
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
application_list yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - app_replacemsg - Enable/disable replacement messages for blocked applications. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
app_replacemsg yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - comment - Comments. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
comment yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - control_default_network_services - Enable/disable enforcement of protocols over selected ports. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
control_default_network_services no no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - deep_app_inspection - Enable/disable deep application inspection. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
deep_app_inspection yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - default_network_services - Default network service entries. type: list member_path: default_network_services:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
default_network_services no no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Entry ID. type: int required: true
more...
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - port - Port number. type: int
more...
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
port yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - services - Network protocols. type: list choices: http, ssh, telnet, ftp, dns, smtp, pop3, imap, snmp, nntp, https
more...
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
services yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [http] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [ssh] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [telnet] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [ftp] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [dns] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [smtp] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [pop3] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [imap] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [snmp] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [nntp] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [https] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - violation_action - Action for protocols not in the allowlist for selected port. type: str choices: pass, monitor, block
more...
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
violation_action yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [pass] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [monitor] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [block] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - enforce_default_app_port - Enable/disable default application port enforcement for allowed applications. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
enforce_default_app_port no no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - entries - Application list entries. type: list member_path: entries:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
entries yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - action - Pass or block traffic, or reset connection for traffic from this application. type: str choices: pass, block, reset
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
action yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [pass] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [block] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [reset] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - application - ID of allowed applications. type: list member_path: entries:id/application:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
application yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Application IDs. type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - behavior - Application behavior filter. type: list
- category - Category ID list. type: list member_path: entries:id/category:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
category yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Application category ID. type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - exclusion - ID of excluded applications. type: list member_path: entries:id/exclusion:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
exclusion no no no no no no yes no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Excluded application IDs. type: int required: true
more...
v6.2.7
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Entry ID. type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - log - Enable/disable logging for this application list. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
log yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - log_packet - Enable/disable packet logging. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
log_packet yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - parameters - Application parameters. type: list member_path: entries:id/parameters:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
parameters yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Parameter tuple ID. type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - members - Parameter tuple members. type: list member_path: entries:id/parameters:id/members:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
members no no no no no no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - id - Parameter. type: int required: true
more...
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
id yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - name - Parameter name. type: str
more...
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
name yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - value - Parameter value. type: str
more...
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
value yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - value - Parameter value. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
value yes yes yes yes yes yes yes - per_ip_shaper - Per-IP traffic shaper. Source firewall.shaper.per-ip-shaper.name. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
per_ip_shaper yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - popularity - Application popularity filter (1 - 5, from least to most popular). type: list choices: 1, 2, 3, 4, 5
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
popularity yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [1] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [2] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [3] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [4] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [5] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - protocols - Application protocol filter. type: list
- quarantine - Quarantine method. type: str choices: none, attacker
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
quarantine yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [none] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [attacker] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - quarantine_expiry - Duration of quarantine. (Format type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
quarantine_expiry yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - quarantine_log - Enable/disable quarantine logging. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
quarantine_log yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - rate_count - Count of the rate. type: int
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
rate_count yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - rate_duration - Duration (sec) of the rate. type: int
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
rate_duration yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - rate_mode - Rate limit mode. type: str choices: periodical, continuous
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
rate_mode yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [periodical] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [continuous] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - rate_track - Track the packet protocol field. type: str choices: none, src-ip, dest-ip, dhcp-client-mac, dns-domain
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
rate_track yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [none] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [src-ip] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [dest-ip] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [dhcp-client-mac] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [dns-domain] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - risk - Risk, or impact, of allowing traffic from this application to occur (1 - 5; Low, Elevated, Medium, High, and Critical). type: list member_path: entries:id/risk:level
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
risk yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - level - Risk, or impact, of allowing traffic from this application to occur (1 - 5; Low, Elevated, Medium, High, and Critical). type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
level yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - session_ttl - Session TTL (0 = default). type: int
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
session_ttl yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - shaper - Traffic shaper. Source firewall.shaper.traffic-shaper.name. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
shaper yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - shaper_reverse - Reverse traffic shaper. Source firewall.shaper.traffic-shaper.name. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
shaper_reverse yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - sub_category - Application Sub-category ID list. type: list member_path: entries:id/sub_category:id
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
sub_category yes yes yes yes yes yes yes - id - Application sub-category ID. type: int required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
id yes yes yes yes yes yes yes - technology - Application technology filter. type: list
- vendor - Application vendor filter. type: list
- extended_log - Enable/disable extended logging. type: str choices: enable, disable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
extended_log yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - force_inclusion_ssl_di_sigs - Enable/disable forced inclusion of SSL deep inspection signatures. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
force_inclusion_ssl_di_sigs no no no yes no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] n/a n/a n/a yes n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] n/a n/a n/a yes n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - name - List name. type: str required: true
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
name yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - options - Basic application protocol signatures allowed by default. type: list choices: allow-dns, allow-icmp, allow-http, allow-ssl, allow-quic
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
options yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [allow-dns] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [allow-icmp] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [allow-http] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [allow-ssl] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [allow-quic] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes n/a n/a - other_application_action - Action for other applications. type: str choices: pass, block
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
other_application_action yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [pass] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [block] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - other_application_log - Enable/disable logging for other applications. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
other_application_log yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - p2p_black_list - P2P applications to be black listed. type: list choices: skype, edonkey, bittorrent
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
p2p_black_list yes yes yes yes yes yes yes yes yes yes [skype] yes yes yes yes yes yes yes yes yes yes [edonkey] yes yes yes yes yes yes yes yes yes yes [bittorrent] yes yes yes yes yes yes yes yes yes yes - p2p_block_list - P2P applications to be block listed. type: list choices: skype, edonkey, bittorrent
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
p2p_block_list no no no no no no no no no no yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [skype] n/a n/a n/a n/a n/a n/a n/a n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [edonkey] n/a n/a n/a n/a n/a n/a n/a n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [bittorrent] n/a n/a n/a n/a n/a n/a n/a n/a n/a n/a yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - replacemsg_group - Replacement message group. Source system.replacemsg-group.name. type: str
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
replacemsg_group yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - unknown_application_action - Pass or block traffic from unknown applications. type: str choices: pass, block
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
unknown_application_action yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [pass] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [block] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes - unknown_application_log - Enable/disable logging for unknown applications. type: str choices: disable, enable
more...
v6.0.0
v6.0.5
v6.0.11
v6.2.0
v6.2.3
v6.2.5
v6.2.7
v6.4.0
v6.4.1
v6.4.4
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.0.12
v7.2.0
v7.2.1
v7.2.2
v7.2.4
v7.4.0
unknown_application_log yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [disable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes [enable] yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes
Note
- Legacy fortiosapi has been deprecated, httpapi is the preferred way to run playbooks
- hosts: fortigates
collections:
- fortinet.fortios
connection: httpapi
vars:
vdom: "root"
ansible_httpapi_use_ssl: yes
ansible_httpapi_validate_certs: no
ansible_httpapi_port: 443
tasks:
- name: Configure application control lists.
fortios_application_list:
vdom: "{{ vdom }}"
state: "present"
access_token: "<your_own_value>"
application_list:
app_replacemsg: "disable"
comment: "Comments."
control_default_network_services: "disable"
deep_app_inspection: "disable"
default_network_services:
-
id: "8"
port: "0"
services: "http"
violation_action: "pass"
enforce_default_app_port: "disable"
entries:
-
action: "pass"
application:
-
id: "16"
behavior: "<your_own_value>"
category:
-
id: "19"
exclusion:
-
id: "21"
id: "22"
log: "disable"
log_packet: "disable"
parameters:
-
id: "26"
members:
-
id: "28"
name: "default_name_29"
value: "<your_own_value>"
value: "<your_own_value>"
per_ip_shaper: "<your_own_value> (source firewall.shaper.per-ip-shaper.name)"
popularity: "1"
protocols: "<your_own_value>"
quarantine: "none"
quarantine_expiry: "<your_own_value>"
quarantine_log: "disable"
rate_count: "0"
rate_duration: "60"
rate_mode: "periodical"
rate_track: "none"
risk:
-
level: "0"
session_ttl: "0"
shaper: "<your_own_value> (source firewall.shaper.traffic-shaper.name)"
shaper_reverse: "<your_own_value> (source firewall.shaper.traffic-shaper.name)"
sub_category:
-
id: "48"
technology: "<your_own_value>"
vendor: "<your_own_value>"
extended_log: "enable"
force_inclusion_ssl_di_sigs: "disable"
name: "default_name_53"
options: "allow-dns"
other_application_action: "pass"
other_application_log: "disable"
p2p_black_list: "skype"
p2p_block_list: "skype"
replacemsg_group: "<your_own_value> (source system.replacemsg-group.name)"
unknown_application_action: "pass"
unknown_application_log: "disable"
Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:
- build - Build number of the fortigate image returned: always type: str sample: 1547
- http_method - Last method used to provision the content into FortiGate returned: always type: str sample: PUT
- http_status - Last result given by FortiGate on last operation applied returned: always type: str sample: 200
- mkey - Master key (id) used in the last call to FortiGate returned: success type: str sample: id
- name - Name of the table used to fulfill the request returned: always type: str sample: urlfilter
- path - Path of the table used to fulfill the request returned: always type: str sample: webfilter
- revision - Internal revision number returned: always type: str sample: 17.0.2.10658
- serial - Serial number of the unit returned: always type: str sample: FGVMEVYYQT3AB5352
- status - Indication of the operation's result returned: always type: str sample: success
- vdom - Virtual domain used returned: always type: str sample: root
- version - Version of the FortiGate returned: always type: str sample: v5.6.3
- This module is not guaranteed to have a backwards compatible interface.
- Link Zheng (@chillancezen)
- Jie Xue (@JieX19)
- Hongbin Lu (@fgtdev-hblu)
- Frank Shen (@frankshen01)
- Miguel Angel Munoz (@mamunozgonzalez)
- Nicolas Thomas (@thomnico)
Hint
If you notice any issues in this documentation, you can create a pull request to improve it.