fortinet.fortimanager.fmgr_vpnsslweb_portal module – Portal.
Note
This module is part of the fortinet.fortimanager collection (version 2.7.0).
You might already have this collection installed if you are using the ansible
package.
It is not included in ansible-core
.
To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install fortinet.fortimanager
.
To use it in a playbook, specify: fortinet.fortimanager.fmgr_vpnsslweb_portal
.
New in fortinet.fortimanager 2.0.0
Synopsis
This module is able to configure a FortiManager device.
Examples include all parameters and values which need to be adjusted to data sources before usage.
Parameters
Parameter |
Comments |
---|---|
The token to access FortiManager without using username and password. |
|
The parameter (adom) in requested url. |
|
Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. Choices:
|
|
Enable/Disable logging for task. Choices:
|
|
Authenticate Ansible client with forticloud API access token. |
|
The overridden method for the underlying Json RPC request. Choices:
|
|
The rc codes list with which the conditions to fail will be overriden. |
|
The rc codes list with which the conditions to succeed will be overriden. |
|
The directive to create, update or delete an object. Choices:
|
|
The top level parameters set. |
|
Deprecated, please rename it to allow_user_access. Allow user access to SSL-VPN applications. Choices:
|
|
Deprecated, please rename it to auto_connect. Enable/disable automatic connect by client when system is up. Choices:
|
|
Deprecated, please rename it to bookmark_group. Bookmark group. |
|
Bookmarks. |
|
Deprecated, please rename it to additional_params. Additional parameters. |
|
Application type. Choices:
|
|
Deprecated, please rename it to color_depth. Color depth per pixel. Choices:
|
|
Description. |
|
Login domain. |
|
Network shared file folder parameter. |
|
Deprecated, please rename it to form_data. Form data. |
|
Name. |
|
Value. |
|
Screen height |
|
Host name/IP parameter. |
|
Deprecated, please rename it to keyboard_layout. Keyboard layout. Choices:
|
|
Deprecated, please rename it to listening_port. Listening port |
|
Deprecated, please rename it to load_balancing_info. The load balancing information or cookie which should… |
|
(list) Deprecated, please rename it to logon_password. Logon password. |
|
Deprecated, please rename it to logon_user. Logon user. |
|
Bookmark name. |
|
Remote port. |
|
Deprecated, please rename it to preconnection_blob. An arbitrary string which identifies the RDP source. |
|
Deprecated, please rename it to preconnection_id. The numeric ID of the RDP source |
|
Deprecated, please rename it to remote_port. Remote port |
|
Deprecated, please rename it to restricted_admin. Enable/disable restricted admin mode for RDP. Choices:
|
|
Security mode for RDP connection. Choices:
|
|
Deprecated, please rename it to send_preconnection_id. Enable/disable sending of preconnection ID. Choices:
|
|
Deprecated, please rename it to server_layout. Server side keyboard layout. Choices:
|
|
Deprecated, please rename it to show_status_window. Enable/disable showing of status window. Choices:
|
|
Single Sign-On. Choices:
|
|
Deprecated, please rename it to sso_credential. Single sign-on credentials. Choices:
|
|
Deprecated, please rename it to sso_credential_sent_once. Single sign-on credentials are only sent once to… Choices:
|
|
(list) Deprecated, please rename it to sso_password. SSO password. |
|
Deprecated, please rename it to sso_username. SSO user name. |
|
URL parameter. |
|
Deprecated, please rename it to vnc_keyboard_layout. Keyboard layout. Choices:
|
|
Screen width |
|
Bookmark group name. |
|
Deprecated, please rename it to client_src_range. Allow client to add source range for the tunnel traffic. Choices:
|
|
Enable to support RDP/VPC clipboard functionality. Choices:
|
|
Deprecated, please rename it to custom_lang. Change the web portal display language. |
|
Deprecated, please rename it to customize_forticlient_download_url. Enable support of customized download URL for FortiClient. Choices:
|
|
Deprecated, please rename it to default_protocol. Application type that is set by default. Choices:
|
|
Deprecated, please rename it to default_window_height. Screen height |
|
Deprecated, please rename it to default_window_width. Screen width |
|
Deprecated, please rename it to dhcp_ip_overlap. Configure overlapping DHCP IP allocation assignment. Choices:
|
|
Deprecated, please rename it to dhcp_ra_giaddr. Relay agent gateway IP address to use in the giaddr field of DHCP requests. |
|
Deprecated, please rename it to dhcp_reservation. Enable/disable dhcp reservation. Choices:
|
|
Deprecated, please rename it to dhcp6_ra_linkaddr. Relay agent IPv6 link address to use in DHCP6 requests. |
|
Deprecated, please rename it to display_bookmark. Enable to display the web portal bookmark widget. Choices:
|
|
Deprecated, please rename it to display_connection_tools. Enable to display the web portal connection tools widget. Choices:
|
|
Deprecated, please rename it to display_history. Enable to display the web portal user login history widget. Choices:
|
|
Deprecated, please rename it to display_status. Enable to display the web portal status widget. Choices:
|
|
Deprecated, please rename it to dns_server1. IPv4 DNS server 1. |
|
Deprecated, please rename it to dns_server2. IPv4 DNS server 2. |
|
Deprecated, please rename it to dns_suffix. DNS suffix. |
|
Deprecated, please rename it to exclusive_routing. Enable/disable all traffic go through tunnel only. Choices:
|
|
Deprecated, please rename it to focus_bookmark. Enable to prioritize the placement of the bookmark section over the quick-… Choices:
|
|
Deprecated, please rename it to forticlient_download. Enable/disable download option for FortiClient. Choices:
|
|
Deprecated, please rename it to forticlient_download_method. FortiClient download method. Choices:
|
|
Web portal heading message. |
|
Deprecated, please rename it to hide_sso_credential. Enable to prevent SSO credential being sent to client. Choices:
|
|
Deprecated, please rename it to host_check. Type of host checking performed on endpoints. Choices:
|
|
Deprecated, please rename it to host_check_interval. Periodic host check interval. |
|
(list or str) Deprecated, please rename it to host_check_policy. One or more policies to require the endpoint to have spec… |
|
Deprecated, please rename it to ip_mode. Method by which users of this SSL-VPN tunnel obtain IP addresses. Choices:
|
|
(list or str) Deprecated, please rename it to ip_pools. IPv4 firewall source address objects reserved for SSL-VPN tunnel m… |
|
Deprecated, please rename it to ipv6_dns_server1. IPv6 DNS server 1. |
|
Deprecated, please rename it to ipv6_dns_server2. IPv6 DNS server 2. |
|
Deprecated, please rename it to ipv6_exclusive_routing. Enable/disable all IPv6 traffic go through tunnel only. Choices:
|
|
(list or str) Deprecated, please rename it to ipv6_pools. IPv4 firewall source address objects reserved for SSL-VPN tunnel… |
|
Deprecated, please rename it to ipv6_service_restriction. Enable/disable IPv6 tunnel service restriction. Choices:
|
|
Deprecated, please rename it to ipv6_split_tunneling. Enable/disable IPv6 split tunneling. Choices:
|
|
(list or str) Deprecated, please rename it to ipv6_split_tunneling_routing_address. IPv6 SSL-VPN tunnel mode firewall addr… |
|
Deprecated, please rename it to ipv6_split_tunneling_routing_negate. Enable to negate IPv6 split tunneling routing address. Choices:
|
|
Deprecated, please rename it to ipv6_tunnel_mode. Enable/disable IPv6 SSL-VPN tunnel mode. Choices:
|
|
Deprecated, please rename it to ipv6_wins_server1. IPv6 WINS server 1. |
|
Deprecated, please rename it to ipv6_wins_server2. IPv6 WINS server 2. |
|
Deprecated, please rename it to keep_alive. Enable/disable automatic reconnect for FortiClient connections. Choices:
|
|
Deprecated, please rename it to landing_page. Landing page. |
|
Deprecated, please rename it to form_data. Form data. |
|
Name. |
|
Value. |
|
Deprecated, please rename it to logout_url. Landing page log out URL. |
|
Single sign-on. Choices:
|
|
Deprecated, please rename it to sso_credential. Single sign-on credentials. Choices:
|
|
(list) Deprecated, please rename it to sso_password. SSO password. |
|
Deprecated, please rename it to sso_username. SSO user name. |
|
Landing page URL. |
|
Deprecated, please rename it to landing_page_mode. Enable/disable SSL-VPN landing page mode. Choices:
|
|
Deprecated, please rename it to limit_user_logins. Enable to limit each user to one SSL-VPN session at a time. Choices:
|
|
Deprecated, please rename it to mac_addr_action. Client MAC address action. Choices:
|
|
Deprecated, please rename it to mac_addr_check. Enable/disable MAC address host checking. Choices:
|
|
Deprecated, please rename it to mac_addr_check_rule. Mac addr check rule. |
|
(list) Deprecated, please rename it to mac_addr_list. Client MAC address list. |
|
Deprecated, please rename it to mac_addr_mask. Client MAC address mask. |
|
Client MAC address check rule name. |
|
Deprecated, please rename it to macos_forticlient_download_url. Download URL for Mac FortiClient. |
|
Portal name. |
|
Deprecated, please rename it to os_check. Enable to let the FortiGate decide action based on client OS. Choices:
|
|
Deprecated, please rename it to os_check_list. Os check list. |
|
OS check options. Choices:
|
|
Deprecated, please rename it to latest_patch_level. Latest OS patch level. |
|
Deprecated, please rename it to minor_version. Minor version number. |
|
Name. |
|
OS patch level tolerance. |
|
Deprecated, please rename it to prefer_ipv6_dns. Prefer to query IPv6 dns first if enabled. Choices:
|
|
Deprecated, please rename it to redir_url. Client login redirect URL. |
|
Deprecated, please rename it to rewrite_ip_uri_ui. Rewrite contents for URI contains IP and /ui/. Choices:
|
|
Deprecated, please rename it to save_password. Enable/disable FortiClient saving the users password. Choices:
|
|
Deprecated, please rename it to service_restriction. Enable/disable tunnel service restriction. Choices:
|
|
Deprecated, please rename it to skip_check_for_browser. Enable to skip host check for browser support. Choices:
|
|
Deprecated, please rename it to skip_check_for_unsupported_browser. Enable to skip host check if browser does not support it. Choices:
|
|
Deprecated, please rename it to skip_check_for_unsupported_os. Enable to skip host check if client OS does not support it. Choices:
|
|
Deprecated, please rename it to smb_max_version. SMB maximum client protocol version. Choices:
|
|
Deprecated, please rename it to smb_min_version. SMB minimum client protocol version. Choices:
|
|
Deprecated, please rename it to smb_ntlmv1_auth. Enable support of NTLMv1 for Samba authentication. Choices:
|
|
Enable/disable support of SMBv1 for Samba. Choices:
|
|
Deprecated, please rename it to split_dns. Split dns. |
|
Deprecated, please rename it to dns_server1. DNS server 1. |
|
Deprecated, please rename it to dns_server2. DNS server 2. |
|
Split DNS domains used for SSL-VPN clients separated by comma |
|
ID. |
|
Deprecated, please rename it to ipv6_dns_server1. IPv6 DNS server 1. |
|
Deprecated, please rename it to ipv6_dns_server2. IPv6 DNS server 2. |
|
Deprecated, please rename it to split_tunneling. Enable/disable IPv4 split tunneling. Choices:
|
|
(list or str) Deprecated, please rename it to split_tunneling_routing_address. IPv4 SSL-VPN tunnel mode firewall address o… |
|
Deprecated, please rename it to split_tunneling_routing_negate. Enable to negate split tunneling routing address. Choices:
|
|
Web portal color scheme. Choices:
|
|
Deprecated, please rename it to transform_backward_slashes. Transform backward slashes to forward slashes in URLs. Choices:
|
|
Deprecated, please rename it to tunnel_mode. Enable/disable IPv4 SSL-VPN tunnel mode. Choices:
|
|
Deprecated, please rename it to use_sdwan. Use SD-WAN rules to get output interface. Choices:
|
|
Deprecated, please rename it to user_bookmark. Enable to allow web portal users to create their own bookmarks. Choices:
|
|
Deprecated, please rename it to user_group_bookmark. Enable to allow web portal users to create bookmarks for all users in… Choices:
|
|
Deprecated, please rename it to virtual_desktop. Enable/disable SSL VPN virtual desktop. Choices:
|
|
Deprecated, please rename it to virtual_desktop_app_list. Virtual desktop application list. |
|
Deprecated, please rename it to virtual_desktop_clipboard_share. Enable/disable sharing of clipboard in virtual desktop. Choices:
|
|
Deprecated, please rename it to virtual_desktop_desktop_switch. Enable/disable switch to virtual desktop. Choices:
|
|
Deprecated, please rename it to virtual_desktop_logout_when_browser_close. Enable/disable logout when browser is close in … Choices:
|
|
Deprecated, please rename it to virtual_desktop_network_share_access. Enable/disable network share access in virtual desktop. Choices:
|
|
Deprecated, please rename it to virtual_desktop_printing. Enable/disable printing in virtual desktop. Choices:
|
|
Deprecated, please rename it to virtual_desktop_removable_media_access. Enable/disable access to removable media in virtua… Choices:
|
|
Deprecated, please rename it to web_mode. Enable/disable SSL VPN web mode. Choices:
|
|
Deprecated, please rename it to windows_forticlient_download_url. Download URL for Windows FortiClient. |
|
Deprecated, please rename it to wins_server1. IPv4 WINS server 1. |
|
Deprecated, please rename it to wins_server2. IPv4 WINS server 1. |
|
The adom to lock for FortiManager running in workspace mode, the value can be global and others including root. |
|
The maximum time in seconds to wait for other user to release the workspace lock. Default: |
Notes
Note
Starting in version 2.4.0, all input arguments are named using the underscore naming convention (snake_case). Please change the arguments such as “var-name” to “var_name”. Old argument names are still available yet you will receive deprecation warnings. You can ignore this warning by setting deprecation_warnings=False in ansible.cfg.
Running in workspace locking mode is supported in this FortiManager module, the top level parameters workspace_locking_adom and workspace_locking_timeout help do the work.
To create or update an object, use state present directive.
To delete an object, use state absent directive.
Normally, running one module can fail when a non-zero rc is returned. you can also override the conditions to fail or succeed with parameters rc_failed and rc_succeeded
Examples
- name: Example playbook (generated based on argument schema)
hosts: fortimanagers
connection: httpapi
vars:
ansible_httpapi_use_ssl: true
ansible_httpapi_validate_certs: false
ansible_httpapi_port: 443
tasks:
- name: Portal.
fortinet.fortimanager.fmgr_vpnsslweb_portal:
# bypass_validation: false
workspace_locking_adom: <value in [global, custom adom including root]>
workspace_locking_timeout: 300
# rc_succeeded: [0, -2, -3, ...]
# rc_failed: [-2, -3, ...]
adom: <your own value>
state: present # <value in [present, absent]>
vpnsslweb_portal:
allow_user_access:
- web
- ftp
- telnet
- smb
- vnc
- rdp
- ssh
- ping
- citrix
- portforward
- sftp
auto_connect: <value in [disable, enable]>
bookmark_group:
-
bookmarks:
-
additional_params: <string>
apptype: <value in [web, telnet, ssh, ...]>
description: <string>
folder: <string>
form_data:
-
name: <string>
value: <string>
host: <string>
listening_port: <integer>
load_balancing_info: <string>
logon_password: <list or string>
logon_user: <string>
name: <string>
port: <integer>
preconnection_blob: <string>
preconnection_id: <integer>
remote_port: <integer>
security: <value in [rdp, nla, tls, ...]>
server_layout: <value in [en-us-qwerty, de-de-qwertz, fr-fr-azerty, ...]>
show_status_window: <value in [disable, enable]>
sso: <value in [disable, static, auto]>
sso_credential: <value in [sslvpn-login, alternative]>
sso_credential_sent_once: <value in [disable, enable]>
sso_password: <list or string>
sso_username: <string>
url: <string>
domain: <string>
color_depth: <value in [8, 16, 32]>
height: <integer>
keyboard_layout: <value in [ar, da, de, ...]>
restricted_admin: <value in [disable, enable]>
send_preconnection_id: <value in [disable, enable]>
width: <integer>
vnc_keyboard_layout: <value in [da, de, de-ch, ...]>
name: <string>
custom_lang: <string>
customize_forticlient_download_url: <value in [disable, enable]>
display_bookmark: <value in [disable, enable]>
display_connection_tools: <value in [disable, enable]>
display_history: <value in [disable, enable]>
display_status: <value in [disable, enable]>
dns_server1: <string>
dns_server2: <string>
dns_suffix: <string>
exclusive_routing: <value in [disable, enable]>
forticlient_download: <value in [disable, enable]>
forticlient_download_method: <value in [direct, ssl-vpn]>
heading: <string>
hide_sso_credential: <value in [disable, enable]>
host_check: <value in [none, av, fw, ...]>
host_check_interval: <integer>
host_check_policy: <list or string>
ip_mode: <value in [range, user-group, dhcp, ...]>
ip_pools: <list or string>
ipv6_dns_server1: <string>
ipv6_dns_server2: <string>
ipv6_exclusive_routing: <value in [disable, enable]>
ipv6_pools: <list or string>
ipv6_service_restriction: <value in [disable, enable]>
ipv6_split_tunneling: <value in [disable, enable]>
ipv6_split_tunneling_routing_address: <list or string>
ipv6_tunnel_mode: <value in [disable, enable]>
ipv6_wins_server1: <string>
ipv6_wins_server2: <string>
keep_alive: <value in [disable, enable]>
limit_user_logins: <value in [disable, enable]>
mac_addr_action: <value in [deny, allow]>
mac_addr_check: <value in [disable, enable]>
mac_addr_check_rule:
-
mac_addr_list: <list or string>
mac_addr_mask: <integer>
name: <string>
macos_forticlient_download_url: <string>
name: <string>
os_check: <value in [disable, enable]>
redir_url: <string>
save_password: <value in [disable, enable]>
service_restriction: <value in [disable, enable]>
skip_check_for_unsupported_browser: <value in [disable, enable]>
skip_check_for_unsupported_os: <value in [disable, enable]>
smb_ntlmv1_auth: <value in [disable, enable]>
smbv1: <value in [disable, enable]>
split_dns:
-
dns_server1: <string>
dns_server2: <string>
domains: <string>
id: <integer>
ipv6_dns_server1: <string>
ipv6_dns_server2: <string>
split_tunneling: <value in [disable, enable]>
split_tunneling_routing_address: <list or string>
theme: <value in [gray, blue, orange, ...]>
tunnel_mode: <value in [disable, enable]>
user_bookmark: <value in [disable, enable]>
user_group_bookmark: <value in [disable, enable]>
web_mode: <value in [disable, enable]>
windows_forticlient_download_url: <string>
wins_server1: <string>
wins_server2: <string>
skip_check_for_browser: <value in [disable, enable]>
smb_max_version: <value in [smbv1, smbv2, smbv3]>
smb_min_version: <value in [smbv1, smbv2, smbv3]>
virtual_desktop_logout_when_browser_close: <value in [disable, enable]>
virtual_desktop_clipboard_share: <value in [disable, enable]>
virtual_desktop_desktop_switch: <value in [disable, enable]>
virtual_desktop: <value in [disable, enable]>
virtual_desktop_network_share_access: <value in [disable, enable]>
virtual_desktop_printing: <value in [disable, enable]>
virtual_desktop_app_list: <string>
virtual_desktop_removable_media_access: <value in [disable, enable]>
transform_backward_slashes: <value in [disable, enable]>
ipv6_split_tunneling_routing_negate: <value in [disable, enable]>
split_tunneling_routing_negate: <value in [disable, enable]>
os_check_list:
action: <value in [allow, check-up-to-date, deny]>
latest_patch_level: <string>
name: <string>
tolerance: <integer>
minor_version: <integer>
use_sdwan: <value in [disable, enable]>
prefer_ipv6_dns: <value in [disable, enable]>
rewrite_ip_uri_ui: <value in [disable, enable]>
clipboard: <value in [disable, enable]>
default_window_height: <integer>
default_window_width: <integer>
dhcp_ip_overlap: <value in [use-old, use-new]>
client_src_range: <value in [disable, enable]>
dhcp_ra_giaddr: <string>
dhcp6_ra_linkaddr: <string>
landing_page:
form_data:
-
name: <string>
value: <string>
logout_url: <string>
sso: <value in [disable, static, auto]>
sso_credential: <value in [sslvpn-login, alternative]>
sso_password: <list or string>
sso_username: <string>
url: <string>
landing_page_mode: <value in [disable, enable]>
default_protocol: <value in [web, ftp, telnet, ...]>
focus_bookmark: <value in [disable, enable]>
dhcp_reservation: <value in [disable, enable]>
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
---|---|
The result of the request. Returned: always |
|
The full url requested. Returned: always Sample: |
|
The status of api request. Returned: always Sample: |
|
The api response. Returned: always |
|
The descriptive message of the api response. Returned: always Sample: |
|
The information of the target system. Returned: always |
|
The status the request. Returned: always Sample: |
|
Warning if the parameters used in the playbook are not supported by the current FortiManager version. Returned: complex |