New in version 2.8.
The below requirements are needed on the host that executes this module.
Parameter | Choices/Defaults | Comments | ||
---|---|---|---|---|
firewall_profile_protocol_options dictionary | Default: null | Configure protocol options. | ||
comment string | Optional comments. | |||
dns dictionary | Configure DNS protocol options. | |||
ports integer | Ports to scan for content (1 - 65535). | |||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
ftp dictionary | Configure FTP protocol options. | |||
comfort_amount integer | Amount of data to send in a transmission for client comforting (1 - 10240 bytes). | |||
comfort_interval integer | Period of time between start, or last transmission, and the next client comfort transmission of data (1 - 900 sec). | |||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
http dictionary | Configure HTTP protocol options. | |||
block_page_status_code integer | Code number returned for blocked HTTP pages (non-FortiGuard only) (100 - 599). | |||
comfort_amount integer | Amount of data to send in a transmission for client comforting (1 - 10240 bytes). | |||
comfort_interval integer | Period of time between start, or last transmission, and the next client comfort transmission of data (1 - 900 sec). | |||
fortinet_bar string |
| Enable/disable Fortinet bar on HTML content. | ||
fortinet_bar_port integer | Port for use by Fortinet Bar (1 - 65535). | |||
http_policy string |
| Enable/disable HTTP policy check. | ||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
post_lang string |
| ID codes for character sets to be used to convert to UTF-8 for banned words and DLP on HTTP posts (maximum of 5 character sets). | ||
range_block string |
| Enable/disable blocking of partial downloads. | ||
retry_count integer | Number of attempts to retry HTTP connection (0 - 100). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
streaming_content_bypass string |
| Enable/disable bypassing of streaming content from buffering. | ||
strip_x_forwarded_for string |
| Enable/disable stripping of HTTP X-Forwarded-For header. | ||
switching_protocols string |
| Bypass from scanning, or block a connection that attempts to switch protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
imap dictionary | Configure IMAP protocol options. | |||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
mail_signature dictionary | Configure Mail signature. | |||
signature string | Email signature to be added to outgoing email (if the signature contains spaces, enclose with quotation marks). | |||
status string |
| Enable/disable adding an email signature to SMTP email messages as they pass through the FortiGate. | ||
mapi dictionary | Configure MAPI protocol options. | |||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
name string / required | Name. | |||
nntp dictionary | Configure NNTP protocol options. | |||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
oversize_log string |
| Enable/disable logging for antivirus oversize file blocking. | ||
pop3 dictionary | Configure POP3 protocol options. | |||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
replacemsg_group string | Name of the replacement message group to be used Source system.replacemsg-group.name. | |||
rpc_over_http string |
| Enable/disable inspection of RPC over HTTP. | ||
smtp dictionary | Configure SMTP protocol options. | |||
inspect_all string |
| Enable/disable the inspection of all ports for the protocol. | ||
options string |
| One or more options that can be applied to the session. | ||
oversize_limit integer | Maximum in-memory file size that can be scanned (1 - 383 MB). | |||
ports integer | Ports to scan for content (1 - 65535). | |||
scan_bzip2 string |
| Enable/disable scanning of BZip2 compressed files. | ||
server_busy string |
| Enable/disable SMTP server busy when server not available. | ||
status string |
| Enable/disable the active status of scanning for this protocol. | ||
uncompressed_nest_limit integer | Maximum nested levels of compression that can be uncompressed and scanned (2 - 100). | |||
uncompressed_oversize_limit integer | Maximum in-memory uncompressed file size that can be scanned (0 - 383 MB, 0 = unlimited). | |||
state string |
| Deprecated Starting with Ansible 2.9 we recommend using the top-level 'state' parameter. Indicates whether to create or remove the object. | ||
switching_protocols_log string |
| Enable/disable logging for HTTP/HTTPS switching protocols. | ||
host string | FortiOS or FortiGate IP address. | |||
https boolean |
| Indicates if the requests towards FortiGate must use HTTPS protocol. | ||
password string | Default: "" | FortiOS or FortiGate password. | ||
ssl_verify boolean added in 2.9 |
| Ensures FortiGate certificate must be verified by a proper CA. | ||
state string added in 2.9 |
| Indicates whether to create or remove the object. This attribute was present already in previous version in a deeper level. It has been moved out to this outer level. | ||
username string | FortiOS or FortiGate username. | |||
vdom string | Default: "root" | Virtual domain, among those defined previously. A vdom is a virtual instance of the FortiGate that can be configured and used as a different unit. |
Note
- hosts: localhost vars: host: "192.168.122.40" username: "admin" password: "" vdom: "root" ssl_verify: "False" tasks: - name: Configure protocol options. fortios_firewall_profile_protocol_options: host: "{{ host }}" username: "{{ username }}" password: "{{ password }}" vdom: "{{ vdom }}" https: "False" state: "present" firewall_profile_protocol_options: comment: "Optional comments." dns: ports: "5" status: "enable" ftp: comfort_amount: "8" comfort_interval: "9" inspect_all: "enable" options: "clientcomfort" oversize_limit: "12" ports: "13" scan_bzip2: "enable" status: "enable" uncompressed_nest_limit: "16" uncompressed_oversize_limit: "17" http: block_page_status_code: "19" comfort_amount: "20" comfort_interval: "21" fortinet_bar: "enable" fortinet_bar_port: "23" http_policy: "disable" inspect_all: "enable" options: "clientcomfort" oversize_limit: "27" ports: "28" post_lang: "jisx0201" range_block: "disable" retry_count: "31" scan_bzip2: "enable" status: "enable" streaming_content_bypass: "enable" strip_x_forwarded_for: "disable" switching_protocols: "bypass" uncompressed_nest_limit: "37" uncompressed_oversize_limit: "38" imap: inspect_all: "enable" options: "fragmail" oversize_limit: "42" ports: "43" scan_bzip2: "enable" status: "enable" uncompressed_nest_limit: "46" uncompressed_oversize_limit: "47" mail_signature: signature: "<your_own_value>" status: "disable" mapi: options: "fragmail" oversize_limit: "53" ports: "54" scan_bzip2: "enable" status: "enable" uncompressed_nest_limit: "57" uncompressed_oversize_limit: "58" name: "default_name_59" nntp: inspect_all: "enable" options: "oversize" oversize_limit: "63" ports: "64" scan_bzip2: "enable" status: "enable" uncompressed_nest_limit: "67" uncompressed_oversize_limit: "68" oversize_log: "disable" pop3: inspect_all: "enable" options: "fragmail" oversize_limit: "73" ports: "74" scan_bzip2: "enable" status: "enable" uncompressed_nest_limit: "77" uncompressed_oversize_limit: "78" replacemsg_group: "<your_own_value> (source system.replacemsg-group.name)" rpc_over_http: "enable" smtp: inspect_all: "enable" options: "fragmail" oversize_limit: "84" ports: "85" scan_bzip2: "enable" server_busy: "enable" status: "enable" uncompressed_nest_limit: "89" uncompressed_oversize_limit: "90" switching_protocols_log: "disable"
Common return values are documented here, the following are the fields unique to this module:
Key | Returned | Description |
---|---|---|
build string | always | Build number of the fortigate image Sample: 1547 |
http_method string | always | Last method used to provision the content into FortiGate Sample: PUT |
http_status string | always | Last result given by FortiGate on last operation applied Sample: 200 |
mkey string | success | Master key (id) used in the last call to FortiGate Sample: id |
name string | always | Name of the table used to fulfill the request Sample: urlfilter |
path string | always | Path of the table used to fulfill the request Sample: webfilter |
revision string | always | Internal revision number Sample: 17.0.2.10658 |
serial string | always | Serial number of the unit Sample: FGVMEVYYQT3AB5352 |
status string | always | Indication of the operation's result Sample: success |
vdom string | always | Virtual domain used Sample: root |
version string | always | Version of the FortiGate Sample: v5.6.3 |
Hint
If you notice any issues in this documentation, you can edit this document to improve it.
© 2012–2018 Michael DeHaan
© 2018–2019 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/2.9/modules/fortios_firewall_profile_protocol_options_module.html