Documentation

meraki_mr_l3_firewall - Manage MR access point layer 3 firewalls in the Meraki cloud

New in version 2.7.

Synopsis

  • Allows for creation, management, and visibility into layer 3 firewalls implemented on Meraki MR access points.

Parameters

Parameter Choices/Defaults Comments
allow_lan_access
bool
    Choices:
  • no
  • yes ←
Sets whether devices can talk to other devices on the same LAN.
auth_key
Authentication key provided by the dashboard. Required if environmental variable MERAKI_KEY is not set.
host
string
Default:
api.meraki.com
Hostname for Meraki dashboard
Only useful for internal Meraki developers
net_id
ID of network containing access points.
net_name
Name of network containing access points.
number
Number of SSID to apply firewall rule to.

aliases: ssid_number
org_id
ID of organization.
org_name
Name of organization.

aliases: organization
output_level
    Choices:
  • normal ←
  • debug
Set amount of debug output during module execution
rules
List of firewall rules.
policy
    Choices:
  • allow
  • deny
Specifies the action that should be taken when rule is hit.
dest_cidr
Comma separated list of CIDR notation networks to match.
protocol
    Choices:
  • any
  • icmp
  • tcp
  • udp
Specifies protocol to match against.
comment
Optional comment describing the firewall rule.
dest_port
Comma separated list of destination ports to match.
ssid_name
Name of SSID to apply firewall rule to.

aliases: ssid
state
    Choices:
  • present ←
  • query
Create or modify an organization.
timeout
int
Default:
30
Time to timeout for HTTP requests.
use_https
bool
    Choices:
  • no
  • yes ←
If no, it will use HTTP. Otherwise it will use HTTPS.
Only useful for internal Meraki developers
use_proxy
bool
    Choices:
  • no
  • yes
If no, it will not use a proxy, even if one is defined in an environment variable on the target hosts.
validate_certs
bool
    Choices:
  • no
  • yes ←
Whether to validate HTTP certificates.

Notes

Note

Examples

- name: Create single firewall rule
  meraki_mr_l3_firewall:
    auth_key: abc123
    state: present
    org_name: YourOrg
    net_id: 12345
    number: 1
    rules:
      - comment: Integration test rule
        policy: allow
        protocol: tcp
        dest_port: 80
        dest_cidr: 192.0.2.0/24
    allow_lan_access: no
  delegate_to: localhost

- name: Enable local LAN access
  meraki_mr_l3_firewall:
    auth_key: abc123
    state: present
    org_name: YourOrg
    net_id: 123
    number: 1
    rules:
    allow_lan_access: yes
  delegate_to: localhost

- name: Query firewall rules
  meraki_mr_l3_firewall:
    auth_key: abc123
    state: query
    org_name: YourOrg
    net_name: YourNet
    number: 1
  delegate_to: localhost

Status

This module is flagged as preview which means that it is not guaranteed to have a backwards compatible interface.

Maintenance

This module is flagged as community which means that it is maintained by the Ansible Community. See Module Maintenance & Support for more info.

For a list of other modules that are also maintained by the Ansible Community, see here.

Author

  • Kevin Breit (@kbreit)

Hint

If you notice any issues in this documentation you can edit this document to improve it.