fortinet.fortimanager.fmgr_vpnsslweb_portal module – Portal.

Note

This module is part of the fortinet.fortimanager collection (version 2.4.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install fortinet.fortimanager.

To use it in a playbook, specify: fortinet.fortimanager.fmgr_vpnsslweb_portal.

New in fortinet.fortimanager 2.0.0

Synopsis

  • This module is able to configure a FortiManager device.

  • Examples include all parameters and values which need to be adjusted to data sources before usage.

Parameters

Parameter

Comments

access_token

string

The token to access FortiManager without using username and password.

adom

string / required

The parameter (adom) in requested url.

bypass_validation

boolean

Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters.

Choices:

  • false ← (default)

  • true

enable_log

boolean

Enable/Disable logging for task.

Choices:

  • false ← (default)

  • true

forticloud_access_token

string

Authenticate Ansible client with forticloud API access token.

proposed_method

string

The overridden method for the underlying Json RPC request.

Choices:

  • "update"

  • "set"

  • "add"

rc_failed

list / elements=integer

The rc codes list with which the conditions to fail will be overriden.

rc_succeeded

list / elements=integer

The rc codes list with which the conditions to succeed will be overriden.

state

string / required

The directive to create, update or delete an object.

Choices:

  • "present"

  • "absent"

vpnsslweb_portal

dictionary

The top level parameters set.

allow-user-access

list / elements=string

Deprecated, please rename it to allow_user_access. Allow user access to SSL-VPN applications.

Choices:

  • "web"

  • "ftp"

  • "telnet"

  • "smb"

  • "vnc"

  • "rdp"

  • "ssh"

  • "ping"

  • "citrix"

  • "portforward"

  • "sftp"

auto-connect

string

Deprecated, please rename it to auto_connect. Enable/disable automatic connect by client when system is up.

Choices:

  • "disable"

  • "enable"

bookmark-group

list / elements=dictionary

Deprecated, please rename it to bookmark_group. Bookmark-Group.

bookmarks

list / elements=dictionary

Bookmarks.

additional-params

string

Deprecated, please rename it to additional_params. Additional parameters.

apptype

string

Application type.

Choices:

  • "web"

  • "telnet"

  • "ssh"

  • "ftp"

  • "smb"

  • "vnc"

  • "rdp"

  • "citrix"

  • "rdpnative"

  • "portforward"

  • "sftp"

color-depth

string

Deprecated, please rename it to color_depth. Color depth per pixel.

Choices:

  • "8"

  • "16"

  • "32"

description

string

Description.

domain

string

Login domain.

folder

string

Network shared file folder parameter.

form-data

list / elements=dictionary

Deprecated, please rename it to form_data. Form-Data.

name

string

Name.

value

string

Value.

height

integer

Screen height

host

string

Host name/IP parameter.

keyboard-layout

string

Deprecated, please rename it to keyboard_layout. Keyboard layout.

Choices:

  • "ar"

  • "da"

  • "de"

  • "de-ch"

  • "en-gb"

  • "en-uk"

  • "en-us"

  • "es"

  • "fi"

  • "fr"

  • "fr-be"

  • "fr-ca"

  • "fr-ch"

  • "hr"

  • "hu"

  • "it"

  • "ja"

  • "lt"

  • "lv"

  • "mk"

  • "no"

  • "pl"

  • "pt"

  • "pt-br"

  • "ru"

  • "sl"

  • "sv"

  • "tk"

  • "tr"

  • "fr-ca-m"

  • "wg"

  • "ar-101"

  • "ar-102"

  • "ar-102-azerty"

  • "can-mul"

  • "cz"

  • "cz-qwerty"

  • "cz-pr"

  • "nl"

  • "de-ibm"

  • "en-uk-ext"

  • "en-us-dvorak"

  • "es-var"

  • "fi-sami"

  • "hu-101"

  • "it-142"

  • "ko"

  • "lt-ibm"

  • "lt-std"

  • "lav-std"

  • "lav-leg"

  • "mk-std"

  • "no-sami"

  • "pol-214"

  • "pol-pr"

  • "pt-br-abnt2"

  • "ru-mne"

  • "ru-t"

  • "sv-sami"

  • "tuk"

  • "tur-f"

  • "tur-q"

  • "zh-sym-sg-us"

  • "zh-sym-us"

  • "zh-tr-hk"

  • "zh-tr-mo"

  • "zh-tr-us"

  • "fr-apple"

  • "la-am"

  • "ja-106"

listening-port

integer

Deprecated, please rename it to listening_port. Listening port

load-balancing-info

string

Deprecated, please rename it to load_balancing_info. The load balancing information or cookie which should…

logon-password

any

(list) Deprecated, please rename it to logon_password. Logon password.

logon-user

string

Deprecated, please rename it to logon_user. Logon user.

name

string

Bookmark name.

port

integer

Remote port.

preconnection-blob

string

Deprecated, please rename it to preconnection_blob. An arbitrary string which identifies the RDP source.

preconnection-id

integer

Deprecated, please rename it to preconnection_id. The numeric ID of the RDP source

remote-port

integer

Deprecated, please rename it to remote_port. Remote port

restricted-admin

string

Deprecated, please rename it to restricted_admin. Enable/disable restricted admin mode for RDP.

Choices:

  • "disable"

  • "enable"

security

string

Security mode for RDP connection.

Choices:

  • "rdp"

  • "nla"

  • "tls"

  • "any"

send-preconnection-id

string

Deprecated, please rename it to send_preconnection_id. Enable/disable sending of preconnection ID.

Choices:

  • "disable"

  • "enable"

server-layout

string

Deprecated, please rename it to server_layout. Server side keyboard layout.

Choices:

  • "en-us-qwerty"

  • "de-de-qwertz"

  • "fr-fr-azerty"

  • "it-it-qwerty"

  • "sv-se-qwerty"

  • "failsafe"

  • "en-gb-qwerty"

  • "es-es-qwerty"

  • "fr-ch-qwertz"

  • "ja-jp-qwerty"

  • "pt-br-qwerty"

  • "tr-tr-qwerty"

  • "fr-ca-qwerty"

show-status-window

string

Deprecated, please rename it to show_status_window. Enable/disable showing of status window.

Choices:

  • "disable"

  • "enable"

sso

string

Single Sign-On.

Choices:

  • "disable"

  • "static"

  • "auto"

sso-credential

string

Deprecated, please rename it to sso_credential. Single sign-on credentials.

Choices:

  • "sslvpn-login"

  • "alternative"

sso-credential-sent-once

string

Deprecated, please rename it to sso_credential_sent_once. Single sign-on credentials are only sent once to…

Choices:

  • "disable"

  • "enable"

sso-password

any

(list) Deprecated, please rename it to sso_password. SSO password.

sso-username

string

Deprecated, please rename it to sso_username. SSO user name.

url

string

URL parameter.

vnc-keyboard-layout

string

Deprecated, please rename it to vnc_keyboard_layout. Keyboard layout.

Choices:

  • "da"

  • "de"

  • "de-ch"

  • "en-uk"

  • "es"

  • "fi"

  • "fr"

  • "fr-be"

  • "it"

  • "no"

  • "pt"

  • "sv"

  • "nl"

  • "en-uk-ext"

  • "it-142"

  • "pt-br-abnt2"

  • "default"

  • "fr-ca-mul"

  • "gd"

  • "us-intl"

width

integer

Screen width

name

string

Bookmark group name.

client-src-range

string

Deprecated, please rename it to client_src_range. Allow client to add source range for the tunnel traffic.

Choices:

  • "disable"

  • "enable"

clipboard

string

Enable to support RDP/VPC clipboard functionality.

Choices:

  • "disable"

  • "enable"

custom-lang

string

Deprecated, please rename it to custom_lang. Change the web portal display language.

customize-forticlient-download-url

string

Deprecated, please rename it to customize_forticlient_download_url. Enable support of customized download URL for FortiClient.

Choices:

  • "disable"

  • "enable"

default-protocol

string

Deprecated, please rename it to default_protocol. Application type that is set by default.

Choices:

  • "web"

  • "ftp"

  • "telnet"

  • "smb"

  • "vnc"

  • "rdp"

  • "ssh"

  • "sftp"

default-window-height

integer

Deprecated, please rename it to default_window_height. Screen height

default-window-width

integer

Deprecated, please rename it to default_window_width. Screen width

dhcp-ip-overlap

string

Deprecated, please rename it to dhcp_ip_overlap. Configure overlapping DHCP IP allocation assignment.

Choices:

  • "use-old"

  • "use-new"

dhcp-ra-giaddr

string

Deprecated, please rename it to dhcp_ra_giaddr. Relay agent gateway IP address to use in the giaddr field of DHCP requests.

dhcp6-ra-linkaddr

string

Deprecated, please rename it to dhcp6_ra_linkaddr. Relay agent IPv6 link address to use in DHCP6 requests.

display-bookmark

string

Deprecated, please rename it to display_bookmark. Enable to display the web portal bookmark widget.

Choices:

  • "disable"

  • "enable"

display-connection-tools

string

Deprecated, please rename it to display_connection_tools. Enable to display the web portal connection tools widget.

Choices:

  • "disable"

  • "enable"

display-history

string

Deprecated, please rename it to display_history. Enable to display the web portal user login history widget.

Choices:

  • "disable"

  • "enable"

display-status

string

Deprecated, please rename it to display_status. Enable to display the web portal status widget.

Choices:

  • "disable"

  • "enable"

dns-server1

string

Deprecated, please rename it to dns_server1. IPv4 DNS server 1.

dns-server2

string

Deprecated, please rename it to dns_server2. IPv4 DNS server 2.

dns-suffix

string

Deprecated, please rename it to dns_suffix. DNS suffix.

exclusive-routing

string

Deprecated, please rename it to exclusive_routing. Enable/disable all traffic go through tunnel only.

Choices:

  • "disable"

  • "enable"

focus-bookmark

string

Deprecated, please rename it to focus_bookmark. Enable to prioritize the placement of the bookmark section over the quick-…

Choices:

  • "disable"

  • "enable"

forticlient-download

string

Deprecated, please rename it to forticlient_download. Enable/disable download option for FortiClient.

Choices:

  • "disable"

  • "enable"

forticlient-download-method

string

Deprecated, please rename it to forticlient_download_method. FortiClient download method.

Choices:

  • "direct"

  • "ssl-vpn"

heading

string

Web portal heading message.

hide-sso-credential

string

Deprecated, please rename it to hide_sso_credential. Enable to prevent SSO credential being sent to client.

Choices:

  • "disable"

  • "enable"

host-check

string

Deprecated, please rename it to host_check. Type of host checking performed on endpoints.

Choices:

  • "none"

  • "av"

  • "fw"

  • "av-fw"

  • "custom"

host-check-interval

integer

Deprecated, please rename it to host_check_interval. Periodic host check interval.

host-check-policy

any

(list or str) Deprecated, please rename it to host_check_policy. One or more policies to require the endpoint to have spec…

ip-mode

string

Deprecated, please rename it to ip_mode. Method by which users of this SSL-VPN tunnel obtain IP addresses.

Choices:

  • "range"

  • "user-group"

  • "dhcp"

  • "no-ip"

ip-pools

any

(list or str) Deprecated, please rename it to ip_pools. IPv4 firewall source address objects reserved for SSL-VPN tunnel m…

ipv6-dns-server1

string

Deprecated, please rename it to ipv6_dns_server1. IPv6 DNS server 1.

ipv6-dns-server2

string

Deprecated, please rename it to ipv6_dns_server2. IPv6 DNS server 2.

ipv6-exclusive-routing

string

Deprecated, please rename it to ipv6_exclusive_routing. Enable/disable all IPv6 traffic go through tunnel only.

Choices:

  • "disable"

  • "enable"

ipv6-pools

any

(list or str) Deprecated, please rename it to ipv6_pools. IPv4 firewall source address objects reserved for SSL-VPN tunnel…

ipv6-service-restriction

string

Deprecated, please rename it to ipv6_service_restriction. Enable/disable IPv6 tunnel service restriction.

Choices:

  • "disable"

  • "enable"

ipv6-split-tunneling

string

Deprecated, please rename it to ipv6_split_tunneling. Enable/disable IPv6 split tunneling.

Choices:

  • "disable"

  • "enable"

ipv6-split-tunneling-routing-address

any

(list or str) Deprecated, please rename it to ipv6_split_tunneling_routing_address. IPv6 SSL-VPN tunnel mode firewall addr…

ipv6-split-tunneling-routing-negate

string

Deprecated, please rename it to ipv6_split_tunneling_routing_negate. Enable to negate IPv6 split tunneling routing address.

Choices:

  • "disable"

  • "enable"

ipv6-tunnel-mode

string

Deprecated, please rename it to ipv6_tunnel_mode. Enable/disable IPv6 SSL-VPN tunnel mode.

Choices:

  • "disable"

  • "enable"

ipv6-wins-server1

string

Deprecated, please rename it to ipv6_wins_server1. IPv6 WINS server 1.

ipv6-wins-server2

string

Deprecated, please rename it to ipv6_wins_server2. IPv6 WINS server 2.

keep-alive

string

Deprecated, please rename it to keep_alive. Enable/disable automatic reconnect for FortiClient connections.

Choices:

  • "disable"

  • "enable"

landing-page

dictionary

Deprecated, please rename it to landing_page.

form-data

list / elements=dictionary

Deprecated, please rename it to form_data.

name

string

Name.

value

string

Value.

logout-url

string

Deprecated, please rename it to logout_url. Landing page log out URL.

sso

string

Single sign-on.

Choices:

  • "disable"

  • "static"

  • "auto"

sso-credential

string

Deprecated, please rename it to sso_credential. Single sign-on credentials.

Choices:

  • "sslvpn-login"

  • "alternative"

sso-password

any

(list) Deprecated, please rename it to sso_password.

sso-username

string

Deprecated, please rename it to sso_username. SSO user name.

url

string

Landing page URL.

landing-page-mode

string

Deprecated, please rename it to landing_page_mode. Enable/disable SSL-VPN landing page mode.

Choices:

  • "disable"

  • "enable"

limit-user-logins

string

Deprecated, please rename it to limit_user_logins. Enable to limit each user to one SSL-VPN session at a time.

Choices:

  • "disable"

  • "enable"

mac-addr-action

string

Deprecated, please rename it to mac_addr_action. Client MAC address action.

Choices:

  • "deny"

  • "allow"

mac-addr-check

string

Deprecated, please rename it to mac_addr_check. Enable/disable MAC address host checking.

Choices:

  • "disable"

  • "enable"

mac-addr-check-rule

list / elements=dictionary

Deprecated, please rename it to mac_addr_check_rule. Mac-Addr-Check-Rule.

mac-addr-list

any

(list) Deprecated, please rename it to mac_addr_list. Client MAC address list.

mac-addr-mask

integer

Deprecated, please rename it to mac_addr_mask. Client MAC address mask.

name

string

Client MAC address check rule name.

macos-forticlient-download-url

string

Deprecated, please rename it to macos_forticlient_download_url. Download URL for Mac FortiClient.

name

string / required

Portal name.

os-check

string

Deprecated, please rename it to os_check. Enable to let the FortiGate decide action based on client OS.

Choices:

  • "disable"

  • "enable"

os-check-list

dictionary

Deprecated, please rename it to os_check_list.

action

string

OS check options.

Choices:

  • "allow"

  • "check-up-to-date"

  • "deny"

latest-patch-level

string

Deprecated, please rename it to latest_patch_level. Latest OS patch level.

name

string

Name.

tolerance

integer

OS patch level tolerance.

prefer-ipv6-dns

string

Deprecated, please rename it to prefer_ipv6_dns. Prefer to query IPv6 dns first if enabled.

Choices:

  • "disable"

  • "enable"

redir-url

string

Deprecated, please rename it to redir_url. Client login redirect URL.

rewrite-ip-uri-ui

string

Deprecated, please rename it to rewrite_ip_uri_ui. Rewrite contents for URI contains IP and /ui/.

Choices:

  • "disable"

  • "enable"

save-password

string

Deprecated, please rename it to save_password. Enable/disable FortiClient saving the users password.

Choices:

  • "disable"

  • "enable"

service-restriction

string

Deprecated, please rename it to service_restriction. Enable/disable tunnel service restriction.

Choices:

  • "disable"

  • "enable"

skip-check-for-browser

string

Deprecated, please rename it to skip_check_for_browser. Enable to skip host check for browser support.

Choices:

  • "disable"

  • "enable"

skip-check-for-unsupported-browser

string

Deprecated, please rename it to skip_check_for_unsupported_browser. Enable to skip host check if browser does not support it.

Choices:

  • "disable"

  • "enable"

skip-check-for-unsupported-os

string

Deprecated, please rename it to skip_check_for_unsupported_os. Enable to skip host check if client OS does not support it.

Choices:

  • "disable"

  • "enable"

smb-max-version

string

Deprecated, please rename it to smb_max_version. SMB maximum client protocol version.

Choices:

  • "smbv1"

  • "smbv2"

  • "smbv3"

smb-min-version

string

Deprecated, please rename it to smb_min_version. SMB minimum client protocol version.

Choices:

  • "smbv1"

  • "smbv2"

  • "smbv3"

smb-ntlmv1-auth

string

Deprecated, please rename it to smb_ntlmv1_auth. Enable support of NTLMv1 for Samba authentication.

Choices:

  • "disable"

  • "enable"

smbv1

string

Enable/disable support of SMBv1 for Samba.

Choices:

  • "disable"

  • "enable"

split-dns

list / elements=dictionary

Deprecated, please rename it to split_dns. Split-Dns.

dns-server1

string

Deprecated, please rename it to dns_server1. DNS server 1.

dns-server2

string

Deprecated, please rename it to dns_server2. DNS server 2.

domains

string

Split DNS domains used for SSL-VPN clients separated by comma

id

integer

ID.

ipv6-dns-server1

string

Deprecated, please rename it to ipv6_dns_server1. IPv6 DNS server 1.

ipv6-dns-server2

string

Deprecated, please rename it to ipv6_dns_server2. IPv6 DNS server 2.

split-tunneling

string

Deprecated, please rename it to split_tunneling. Enable/disable IPv4 split tunneling.

Choices:

  • "disable"

  • "enable"

split-tunneling-routing-address

any

(list or str) Deprecated, please rename it to split_tunneling_routing_address. IPv4 SSL-VPN tunnel mode firewall address o…

split-tunneling-routing-negate

string

Deprecated, please rename it to split_tunneling_routing_negate. Enable to negate split tunneling routing address.

Choices:

  • "disable"

  • "enable"

theme

string

Web portal color scheme.

Choices:

  • "gray"

  • "blue"

  • "orange"

  • "crimson"

  • "steelblue"

  • "darkgrey"

  • "green"

  • "melongene"

  • "red"

  • "mariner"

  • "neutrino"

  • "jade"

  • "graphite"

  • "dark-matter"

  • "onyx"

  • "eclipse"

  • "jet-stream"

  • "security-fabric"

transform-backward-slashes

string

Deprecated, please rename it to transform_backward_slashes. Transform backward slashes to forward slashes in URLs.

Choices:

  • "disable"

  • "enable"

tunnel-mode

string

Deprecated, please rename it to tunnel_mode. Enable/disable IPv4 SSL-VPN tunnel mode.

Choices:

  • "disable"

  • "enable"

use-sdwan

string

Deprecated, please rename it to use_sdwan. Use SD-WAN rules to get output interface.

Choices:

  • "disable"

  • "enable"

user-bookmark

string

Deprecated, please rename it to user_bookmark. Enable to allow web portal users to create their own bookmarks.

Choices:

  • "disable"

  • "enable"

user-group-bookmark

string

Deprecated, please rename it to user_group_bookmark. Enable to allow web portal users to create bookmarks for all users in…

Choices:

  • "disable"

  • "enable"

virtual-desktop

string

Deprecated, please rename it to virtual_desktop. Enable/disable SSL VPN virtual desktop.

Choices:

  • "disable"

  • "enable"

virtual-desktop-app-list

string

Deprecated, please rename it to virtual_desktop_app_list. Virtual desktop application list.

virtual-desktop-clipboard-share

string

Deprecated, please rename it to virtual_desktop_clipboard_share. Enable/disable sharing of clipboard in virtual desktop.

Choices:

  • "disable"

  • "enable"

virtual-desktop-desktop-switch

string

Deprecated, please rename it to virtual_desktop_desktop_switch. Enable/disable switch to virtual desktop.

Choices:

  • "disable"

  • "enable"

virtual-desktop-logout-when-browser-close

string

Deprecated, please rename it to virtual_desktop_logout_when_browser_close. Enable/disable logout when browser is close in …

Choices:

  • "disable"

  • "enable"

virtual-desktop-network-share-access

string

Deprecated, please rename it to virtual_desktop_network_share_access. Enable/disable network share access in virtual desktop.

Choices:

  • "disable"

  • "enable"

virtual-desktop-printing

string

Deprecated, please rename it to virtual_desktop_printing. Enable/disable printing in virtual desktop.

Choices:

  • "disable"

  • "enable"

virtual-desktop-removable-media-access

string

Deprecated, please rename it to virtual_desktop_removable_media_access. Enable/disable access to removable media in virtua…

Choices:

  • "disable"

  • "enable"

web-mode

string

Deprecated, please rename it to web_mode. Enable/disable SSL VPN web mode.

Choices:

  • "disable"

  • "enable"

windows-forticlient-download-url

string

Deprecated, please rename it to windows_forticlient_download_url. Download URL for Windows FortiClient.

wins-server1

string

Deprecated, please rename it to wins_server1. IPv4 WINS server 1.

wins-server2

string

Deprecated, please rename it to wins_server2. IPv4 WINS server 1.

workspace_locking_adom

string

The adom to lock for FortiManager running in workspace mode, the value can be global and others including root.

workspace_locking_timeout

integer

The maximum time in seconds to wait for other user to release the workspace lock.

Default: 300

Notes

Note

  • Starting in version 2.4.0, all input arguments are named using the underscore naming convention (snake_case). Please change the arguments such as “var-name” to “var_name”. Old argument names are still available yet you will receive deprecation warnings. You can ignore this warning by setting deprecation_warnings=False in ansible.cfg.

  • Running in workspace locking mode is supported in this FortiManager module, the top level parameters workspace_locking_adom and workspace_locking_timeout help do the work.

  • To create or update an object, use state present directive.

  • To delete an object, use state absent directive.

  • Normally, running one module can fail when a non-zero rc is returned. you can also override the conditions to fail or succeed with parameters rc_failed and rc_succeeded

Examples

- name: Example playbook (generated based on argument schema)
  hosts: fortimanagers
  connection: httpapi
  vars:
    ansible_httpapi_use_ssl: true
    ansible_httpapi_validate_certs: false
    ansible_httpapi_port: 443
  tasks:
    - name: Portal.
      fortinet.fortimanager.fmgr_vpnsslweb_portal:
        # bypass_validation: false
        workspace_locking_adom: <value in [global, custom adom including root]>
        workspace_locking_timeout: 300
        # rc_succeeded: [0, -2, -3, ...]
        # rc_failed: [-2, -3, ...]
        adom: <your own value>
        state: present # <value in [present, absent]>
        vpnsslweb_portal:
          allow_user_access:
            - web
            - ftp
            - telnet
            - smb
            - vnc
            - rdp
            - ssh
            - ping
            - citrix
            - portforward
            - sftp
          auto_connect: <value in [disable, enable]>
          bookmark_group:
            -
              bookmarks:
                -
                  additional_params: <string>
                  apptype: <value in [web, telnet, ssh, ...]>
                  description: <string>
                  folder: <string>
                  form_data:
                    -
                      name: <string>
                      value: <string>
                  host: <string>
                  listening_port: <integer>
                  load_balancing_info: <string>
                  logon_password: <list or string>
                  logon_user: <string>
                  name: <string>
                  port: <integer>
                  preconnection_blob: <string>
                  preconnection_id: <integer>
                  remote_port: <integer>
                  security: <value in [rdp, nla, tls, ...]>
                  server_layout: <value in [en-us-qwerty, de-de-qwertz, fr-fr-azerty, ...]>
                  show_status_window: <value in [disable, enable]>
                  sso: <value in [disable, static, auto]>
                  sso_credential: <value in [sslvpn-login, alternative]>
                  sso_credential_sent_once: <value in [disable, enable]>
                  sso_password: <list or string>
                  sso_username: <string>
                  url: <string>
                  domain: <string>
                  color_depth: <value in [8, 16, 32]>
                  height: <integer>
                  keyboard_layout: <value in [ar, da, de, ...]>
                  restricted_admin: <value in [disable, enable]>
                  send_preconnection_id: <value in [disable, enable]>
                  width: <integer>
                  vnc_keyboard_layout: <value in [da, de, de-ch, ...]>
              name: <string>
          custom_lang: <string>
          customize_forticlient_download_url: <value in [disable, enable]>
          display_bookmark: <value in [disable, enable]>
          display_connection_tools: <value in [disable, enable]>
          display_history: <value in [disable, enable]>
          display_status: <value in [disable, enable]>
          dns_server1: <string>
          dns_server2: <string>
          dns_suffix: <string>
          exclusive_routing: <value in [disable, enable]>
          forticlient_download: <value in [disable, enable]>
          forticlient_download_method: <value in [direct, ssl-vpn]>
          heading: <string>
          hide_sso_credential: <value in [disable, enable]>
          host_check: <value in [none, av, fw, ...]>
          host_check_interval: <integer>
          host_check_policy: <list or string>
          ip_mode: <value in [range, user-group, dhcp, ...]>
          ip_pools: <list or string>
          ipv6_dns_server1: <string>
          ipv6_dns_server2: <string>
          ipv6_exclusive_routing: <value in [disable, enable]>
          ipv6_pools: <list or string>
          ipv6_service_restriction: <value in [disable, enable]>
          ipv6_split_tunneling: <value in [disable, enable]>
          ipv6_split_tunneling_routing_address: <list or string>
          ipv6_tunnel_mode: <value in [disable, enable]>
          ipv6_wins_server1: <string>
          ipv6_wins_server2: <string>
          keep_alive: <value in [disable, enable]>
          limit_user_logins: <value in [disable, enable]>
          mac_addr_action: <value in [deny, allow]>
          mac_addr_check: <value in [disable, enable]>
          mac_addr_check_rule:
            -
              mac_addr_list: <list or string>
              mac_addr_mask: <integer>
              name: <string>
          macos_forticlient_download_url: <string>
          name: <string>
          os_check: <value in [disable, enable]>
          redir_url: <string>
          save_password: <value in [disable, enable]>
          service_restriction: <value in [disable, enable]>
          skip_check_for_unsupported_browser: <value in [disable, enable]>
          skip_check_for_unsupported_os: <value in [disable, enable]>
          smb_ntlmv1_auth: <value in [disable, enable]>
          smbv1: <value in [disable, enable]>
          split_dns:
            -
              dns_server1: <string>
              dns_server2: <string>
              domains: <string>
              id: <integer>
              ipv6_dns_server1: <string>
              ipv6_dns_server2: <string>
          split_tunneling: <value in [disable, enable]>
          split_tunneling_routing_address: <list or string>
          theme: <value in [gray, blue, orange, ...]>
          tunnel_mode: <value in [disable, enable]>
          user_bookmark: <value in [disable, enable]>
          user_group_bookmark: <value in [disable, enable]>
          web_mode: <value in [disable, enable]>
          windows_forticlient_download_url: <string>
          wins_server1: <string>
          wins_server2: <string>
          skip_check_for_browser: <value in [disable, enable]>
          smb_max_version: <value in [smbv1, smbv2, smbv3]>
          smb_min_version: <value in [smbv1, smbv2, smbv3]>
          virtual_desktop_logout_when_browser_close: <value in [disable, enable]>
          virtual_desktop_clipboard_share: <value in [disable, enable]>
          virtual_desktop_desktop_switch: <value in [disable, enable]>
          virtual_desktop: <value in [disable, enable]>
          virtual_desktop_network_share_access: <value in [disable, enable]>
          virtual_desktop_printing: <value in [disable, enable]>
          virtual_desktop_app_list: <string>
          virtual_desktop_removable_media_access: <value in [disable, enable]>
          transform_backward_slashes: <value in [disable, enable]>
          ipv6_split_tunneling_routing_negate: <value in [disable, enable]>
          split_tunneling_routing_negate: <value in [disable, enable]>
          os_check_list:
            action: <value in [allow, check-up-to-date, deny]>
            latest_patch_level: <string>
            name: <string>
            tolerance: <integer>
          use_sdwan: <value in [disable, enable]>
          prefer_ipv6_dns: <value in [disable, enable]>
          rewrite_ip_uri_ui: <value in [disable, enable]>
          clipboard: <value in [disable, enable]>
          default_window_height: <integer>
          default_window_width: <integer>
          dhcp_ip_overlap: <value in [use-old, use-new]>
          client_src_range: <value in [disable, enable]>
          dhcp_ra_giaddr: <string>
          dhcp6_ra_linkaddr: <string>
          landing_page:
            form_data:
              -
                name: <string>
                value: <string>
            logout_url: <string>
            sso: <value in [disable, static, auto]>
            sso_credential: <value in [sslvpn-login, alternative]>
            sso_password: <list or string>
            sso_username: <string>
            url: <string>
          landing_page_mode: <value in [disable, enable]>
          default_protocol: <value in [web, ftp, telnet, ...]>
          focus_bookmark: <value in [disable, enable]>

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

meta

dictionary

The result of the request.

Returned: always

request_url

string

The full url requested.

Returned: always

Sample: "/sys/login/user"

response_code

integer

The status of api request.

Returned: always

Sample: 0

response_data

list / elements=string

The api response.

Returned: always

response_message

string

The descriptive message of the api response.

Returned: always

Sample: "OK."

system_information

dictionary

The information of the target system.

Returned: always

rc

integer

The status the request.

Returned: always

Sample: 0

version_check_warning

list / elements=string

Warning if the parameters used in the playbook are not supported by the current FortiManager version.

Returned: complex

Authors

  • Xinwei Du (@dux-fortinet)

  • Xing Li (@lix-fortinet)

  • Jie Xue (@JieX19)

  • Link Zheng (@chillancezen)

  • Frank Shen (@fshen01)

  • Hongbin Lu (@fgtdev-hblu)