fmgr_user_radius_dynamicmapping – Configure RADIUS server entries.¶
New in version 2.0.0.
Synopsis¶
- This module is able to configure a FortiManager device.
- Examples include all parameters and values need to be adjusted to data sources before usage.
- Tested with FortiManager v6.x and v7.x.
Requirements¶
The below requirements are needed on the host that executes this module.
- ansible>=2.9.0
FortiManager Version Compatibility¶
6.0.0 |
||||||||||||
| True | ||||||||||||
6.2.0 |
6.2.1 |
6.2.2 |
6.2.3 |
6.2.5 |
6.2.6 |
6.2.7 |
6.2.8 |
6.2.9 |
6.2.10 |
6.2.11 |
||
| True | True | True | True | True | True | True | True | True | True | True | ||
6.4.0 |
6.4.1 |
6.4.2 |
6.4.3 |
6.4.4 |
6.4.5 |
6.4.6 |
6.4.7 |
6.4.8 |
6.4.9 |
6.4.10 |
6.4.11 |
6.4.12 |
| True | True | True | True | True | True | True | True | True | True | True | True | True |
7.0.0 |
7.0.1 |
7.0.2 |
7.0.3 |
7.0.4 |
7.0.5 |
7.0.6 |
7.0.7 |
7.0.8 |
||||
| True | True | True | True | True | True | True | True | True | ||||
7.2.0 |
7.2.1 |
7.2.2 |
7.2.3 |
|||||||||
| True | True | True | True | |||||||||
7.4.0 |
||||||||||||
| True |
Parameters¶
- access_token -The token to access FortiManager without using username and password. type: str required: false
- bypass_validation - Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. type: bool required: false default: False
- enable_log - Enable/Disable logging for task. type: bool required: false default: False
- forticloud_access_token - Access token of forticloud managed API users, this option is available with FortiManager later than 6.4.0. type: str required: false
- proposed_method - The overridden method for the underlying Json RPC request. type: str required: false choices: set, update, add
- rc_succeeded - The rc codes list with which the conditions to succeed will be overriden. type: list required: false
- rc_failed - The rc codes list with which the conditions to fail will be overriden. type: list required: false
- state - The directive to create, update or delete an object type: str required: true choices: present, absent
- workspace_locking_adom - Acquire the workspace lock if FortiManager is running in workspace mode. type: str required: false choices: global, custom adom including root
- workspace_locking_timeout - The maximum time in seconds to wait for other users to release workspace lock. type: integer required: false default: 300
- adom - The parameter in requested url type: str required: true
- radius - The parameter in requested url type: str required: true
- user_radius_dynamicmapping - Configure RADIUS server entries. type: dict
- _scope - No description for the parameter type: array more...
- acct-all-servers - No description for the parameter type: str choices: [disable, enable] more...
- acct-interim-interval - No description for the parameter type: int more...
- all-usergroup - No description for the parameter type: str choices: [disable, enable] more...
- auth-type - No description for the parameter type: str choices: [pap, chap, ms_chap, ms_chap_v2, auto] more...
- class - No description for the parameter type: str more...
- dp-carrier-endpoint-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-carrier-endpoint-block-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-context-timeout - No description for the parameter type: int more...
- dp-flush-ip-session - No description for the parameter type: str choices: [disable, enable] more...
- dp-hold-time - No description for the parameter type: int more...
- dp-http-header - No description for the parameter type: str more...
- dp-http-header-fallback - No description for the parameter type: str choices: [ip-header-address, default-profile] more...
- dp-http-header-status - No description for the parameter type: str choices: [disable, enable] more...
- dp-http-header-suppress - No description for the parameter type: str choices: [disable, enable] more...
- dp-log-dyn_flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
- dp-log-period - No description for the parameter type: int more...
- dp-mem-percent - No description for the parameter type: int more...
- dp-profile-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-profile-attribute-key - No description for the parameter type: str more...
- dp-radius-response - No description for the parameter type: str choices: [disable, enable] more...
- dp-radius-server-port - No description for the parameter type: int more...
- dp-secret - No description for the parameter type: str more...
- dp-validate-request-secret - No description for the parameter type: str choices: [disable, enable] more...
- dynamic-profile - No description for the parameter type: str choices: [disable, enable] more...
- endpoint-translation - No description for the parameter type: str choices: [disable, enable] more...
- ep-carrier-endpoint-convert-hex - No description for the parameter type: str choices: [disable, enable] more...
- ep-carrier-endpoint-header - No description for the parameter type: str more...
- ep-carrier-endpoint-header-suppress - No description for the parameter type: str choices: [disable, enable] more...
- ep-carrier-endpoint-prefix - No description for the parameter type: str choices: [disable, enable] more...
- ep-carrier-endpoint-prefix-range-max - No description for the parameter type: int more...
- ep-carrier-endpoint-prefix-range-min - No description for the parameter type: int more...
- ep-carrier-endpoint-prefix-string - No description for the parameter type: str more...
- ep-carrier-endpoint-source - No description for the parameter type: str choices: [http-header, cookie] more...
- ep-ip-header - No description for the parameter type: str more...
- ep-ip-header-suppress - No description for the parameter type: str choices: [disable, enable] more...
- ep-missing-header-fallback - No description for the parameter type: str choices: [session-ip, policy-profile] more...
- ep-profile-query-type - No description for the parameter type: str choices: [session-ip, extract-ip, extract-carrier-endpoint] more...
- h3c-compatibility - No description for the parameter type: str choices: [disable, enable] more...
- nas-ip - No description for the parameter type: str more...
- password-encoding - No description for the parameter type: str choices: [ISO-8859-1, auto] more...
- password-renewal - No description for the parameter type: str choices: [disable, enable] more...
- radius-coa - No description for the parameter type: str choices: [disable, enable] more...
- radius-port - No description for the parameter type: int more...
- rsso - No description for the parameter type: str choices: [disable, enable] more...
- rsso-context-timeout - No description for the parameter type: int more...
- rsso-endpoint-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- rsso-endpoint-block-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- rsso-ep-one-ip-only - No description for the parameter type: str choices: [disable, enable] more...
- rsso-flush-ip-session - No description for the parameter type: str choices: [disable, enable] more...
- rsso-log-flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
- rsso-log-period - No description for the parameter type: int more...
- rsso-radius-response - No description for the parameter type: str choices: [disable, enable] more...
- rsso-radius-server-port - No description for the parameter type: int more...
- rsso-secret - No description for the parameter type: str more...
- rsso-validate-request-secret - No description for the parameter type: str choices: [disable, enable] more...
- secondary-secret - No description for the parameter type: str more...
- secondary-server - No description for the parameter type: str more...
- secret - No description for the parameter type: str more...
- server - No description for the parameter type: str more...
- source-ip - No description for the parameter type: str more...
- sso-attribute - No description for the parameter type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- sso-attribute-key - No description for the parameter type: str more...
- sso-attribute-value-override - No description for the parameter type: str choices: [disable, enable] more...
- tertiary-secret - No description for the parameter type: str more...
- tertiary-server - No description for the parameter type: str more...
- timeout - No description for the parameter type: int more...
- use-group-for-profile - No description for the parameter type: str choices: [disable, enable] more...
- use-management-vdom - No description for the parameter type: str choices: [disable, enable] more...
- username-case-sensitive - No description for the parameter type: str choices: [disable, enable] more...
- interface - No description for the parameter type: str more...
- interface-select-method - No description for the parameter type: str choices: [auto, sdwan, specify] more...
- group-override-attr-type - No description for the parameter type: str choices: [filter-Id, class] more...
- switch-controller-acct-fast-framedip-detect - No description for the parameter type: int more...
- accounting-server - No description for the parameter type: array
more...
- id - No description for the parameter type: int more...
- interface - No description for the parameter type: str more...
- interface-select-method - No description for the parameter type: str choices: [auto, sdwan, specify] more...
- port - No description for the parameter type: int more...
- secret - No description for the parameter type: str more...
- server - No description for the parameter type: str more...
- source-ip - No description for the parameter type: str more...
- status - No description for the parameter type: str choices: [disable, enable] more...
- switch-controller-service-type - No description for the parameter type: array choices: [login, framed, callback-login, callback-framed, outbound, administrative, nas-prompt, authenticate-only, callback-nas-prompt, call-check, callback-administrative] more...
- delimiter - Configure delimiter to be used for separating profile group names in the SSO attribute (default = plus character +). type: str choices: [plus, comma] more...
- mac-case - MAC authentication case (default = lowercase). type: str choices: [uppercase, lowercase] more...
- mac-password-delimiter - MAC authentication password delimiter (default = hyphen). type: str choices: [hyphen, single-hyphen, colon, none] more...
- mac-username-delimiter - MAC authentication username delimiter (default = hyphen). type: str choices: [hyphen, single-hyphen, colon, none] more...
- nas-id - Custom NAS identifier. type: str more...
- nas-id-type - NAS identifier type configuration (default = legacy). type: str choices: [legacy, custom, hostname] more...
- ca-cert - CA of server to trust under TLS. type: str more...
- client-cert - Client certificate to use under TLS. type: str more...
- server-identity-check - Enable/disable RADIUS server identity check (verify server domain name/IP address against the server certificate). type: str choices: [disable, enable] more...
- status-ttl - Time for which server reachability is cached so that when a server is unreachable, it will not be retried for at least this period of time (0 = cache disabled, default = 300). type: int more...
- tls-min-proto-version - Minimum supported protocol version for TLS connections (default is to follow system global setting). type: str choices: [default, TLSv1, TLSv1-1, TLSv1-2, SSLv3] more...
- transport-protocol - Transport protocol to be used (default = udp). type: str choices: [udp, tcp, tls] more...
Notes¶
Note
- Running in workspace locking mode is supported in this FortiManager module, the top level parameters workspace_locking_adom and workspace_locking_timeout help do the work.
- To create or update an object, use state: present directive.
- To delete an object, use state: absent directive
- Normally, running one module can fail when a non-zero rc is returned. you can also override the conditions to fail or succeed with parameters rc_failed and rc_succeeded
Examples¶
- hosts: fortimanager00
collections:
- fortinet.fortimanager
connection: httpapi
vars:
ansible_httpapi_use_ssl: True
ansible_httpapi_validate_certs: False
ansible_httpapi_port: 443
tasks:
- name: Configure dynamic mappings of RADIUS server
fmgr_user_radius_dynamicmapping:
bypass_validation: False
adom: ansible
radius: ansible-test-radius # name
state: present
user_radius_dynamicmapping:
_scope:
-
name: FGT_AWS # need a valid device name
vdom: root # need a valid vdom name under the device
server: ansible
timeout: 100
- name: gathering fortimanager facts
hosts: fortimanager00
gather_facts: no
connection: httpapi
collections:
- fortinet.fortimanager
vars:
ansible_httpapi_use_ssl: True
ansible_httpapi_validate_certs: False
ansible_httpapi_port: 443
tasks:
- name: retrieve all the dynamic mappings of RADIUS server
fmgr_fact:
facts:
selector: 'user_radius_dynamicmapping'
params:
adom: 'ansible'
radius: 'ansible-test-radius' # name
dynamic_mapping: 'your_value'
Return Values¶
Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:
- meta - The result of the request.returned: always type: dict
- request_url - The full url requested. returned: always type: str sample: /sys/login/user
- response_code - The status of api request. returned: always type: int sample: 0
- response_data - The data body of the api response. returned: optional type: list or dict
- response_message - The descriptive message of the api response. returned: always type: str sample: OK
- system_information - The information of the target system. returned: always type: dict
- rc - The status the request. returned: always type: int 0
- version_check_warning - Warning if the parameters used in the playbook are not supported by the current FortiManager version. returned: if at least on parameter mpt supported by the current FortiManager version type: list 0