fmgr_user_radius_dynamicmapping – Configure RADIUS server entries.

New in version 2.10.

Synopsis

  • This module is able to configure a FortiManager device.
  • Examples include all parameters and values need to be adjusted to data sources before usage.

Requirements

The below requirements are needed on the host that executes this module.

  • ansible>=2.9.0

FortiManager Version Compatibility


6.0.0 6.2.1 6.2.3 6.2.5 6.4.0 6.4.2 6.4.5 7.0.0 7.2.0
user_radius_dynamicmapping yes yes yes yes yes yes yes yes yes

Parameters

  • enable_log - Enable/Disable logging for task type: bool required: false default: False
  • forticloud_access_token - Access token of forticloud managed API users, this option is available with FortiManager later than 6.4.0 type: str required: false
  • proposed_method - The overridden method for the underlying Json RPC request type: str required: false choices: set, update, add
  • bypass_validation - Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters type: bool required: false default: False
  • workspace_locking_adom - Acquire the workspace lock if FortiManager is running in workspace mode type: str required: false choices: global, custom adom including root
  • workspace_locking_timeout - The maximum time in seconds to wait for other users to release workspace lock type: integer required: false default: 300
  • rc_succeeded - The rc codes list with which the conditions to succeed will be overriden type: list required: false
  • rc_failed - The rc codes list with which the conditions to fail will be overriden type: list required: false
  • state - The directive to create, update or delete an object type: str required: true choices: present, absent
  • adom - The parameter in requested url type: str required: true
  • radius - The parameter in requested url type: str required: true
  • user_radius_dynamicmapping - no description type: dict
    • _scope - No description for the parameter type: array more...
      • name - Name. type: str more...
      • vdom - Vdom. type: str more...
    • acct-all-servers - Enable/disable sending of accounting messages to all configured servers (default = disable). type: str choices: [disable, enable] more...
    • acct-interim-interval - Time in seconds between each accounting interim update message. type: int more...
    • all-usergroup - Enable/disable automatically including this RADIUS server in all user groups. type: str choices: [disable, enable] more...
    • auth-type - Authentication methods/protocols permitted for this RADIUS server. type: str choices: [pap, chap, ms_chap, ms_chap_v2, auto] more...
    • class - No description for the parameter type: str more...
    • dp-carrier-endpoint-attribute - Dp-Carrier-Endpoint-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • dp-carrier-endpoint-block-attribute - Dp-Carrier-Endpoint-Block-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • dp-context-timeout - Dp-Context-Timeout. type: int more...
    • dp-flush-ip-session - Dp-Flush-Ip-Session. type: str choices: [disable, enable] more...
    • dp-hold-time - Dp-Hold-Time. type: int more...
    • dp-http-header - Dp-Http-Header. type: str more...
    • dp-http-header-fallback - Dp-Http-Header-Fallback. type: str choices: [ip-header-address, default-profile] more...
    • dp-http-header-status - Dp-Http-Header-Status. type: str choices: [disable, enable] more...
    • dp-http-header-suppress - Dp-Http-Header-Suppress. type: str choices: [disable, enable] more...
    • dp-log-dyn_flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
    • dp-log-period - Dp-Log-Period. type: int more...
    • dp-mem-percent - Dp-Mem-Percent. type: int more...
    • dp-profile-attribute - Dp-Profile-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • dp-profile-attribute-key - Dp-Profile-Attribute-Key. type: str more...
    • dp-radius-response - Dp-Radius-Response. type: str choices: [disable, enable] more...
    • dp-radius-server-port - Dp-Radius-Server-Port. type: int more...
    • dp-secret - No description for the parameter type: str more...
    • dp-validate-request-secret - Dp-Validate-Request-Secret. type: str choices: [disable, enable] more...
    • dynamic-profile - Dynamic-Profile. type: str choices: [disable, enable] more...
    • endpoint-translation - Endpoint-Translation. type: str choices: [disable, enable] more...
    • ep-carrier-endpoint-convert-hex - Ep-Carrier-Endpoint-Convert-Hex. type: str choices: [disable, enable] more...
    • ep-carrier-endpoint-header - Ep-Carrier-Endpoint-Header. type: str more...
    • ep-carrier-endpoint-header-suppress - Ep-Carrier-Endpoint-Header-Suppress. type: str choices: [disable, enable] more...
    • ep-carrier-endpoint-prefix - Ep-Carrier-Endpoint-Prefix. type: str choices: [disable, enable] more...
    • ep-carrier-endpoint-prefix-range-max - Ep-Carrier-Endpoint-Prefix-Range-Max. type: int more...
    • ep-carrier-endpoint-prefix-range-min - Ep-Carrier-Endpoint-Prefix-Range-Min. type: int more...
    • ep-carrier-endpoint-prefix-string - Ep-Carrier-Endpoint-Prefix-String. type: str more...
    • ep-carrier-endpoint-source - Ep-Carrier-Endpoint-Source. type: str choices: [http-header, cookie] more...
    • ep-ip-header - Ep-Ip-Header. type: str more...
    • ep-ip-header-suppress - Ep-Ip-Header-Suppress. type: str choices: [disable, enable] more...
    • ep-missing-header-fallback - Ep-Missing-Header-Fallback. type: str choices: [session-ip, policy-profile] more...
    • ep-profile-query-type - Ep-Profile-Query-Type. type: str choices: [session-ip, extract-ip, extract-carrier-endpoint] more...
    • h3c-compatibility - Enable/disable compatibility with the H3C, a mechanism that performs security checking for authentication. type: str choices: [disable, enable] more...
    • nas-ip - IP address used to communicate with the RADIUS server and used as NAS-IP-Address and Called-Station-ID attributes. type: str more...
    • password-encoding - Password encoding. type: str choices: [ISO-8859-1, auto] more...
    • password-renewal - Enable/disable password renewal. type: str choices: [disable, enable] more...
    • radius-coa - Enable to allow a mechanism to change the attributes of an authentication, authorization, and accounting session after it is authenticated. type: str choices: [disable, enable] more...
    • radius-port - RADIUS service port number. type: int more...
    • rsso - Enable/disable RADIUS based single sign on feature. type: str choices: [disable, enable] more...
    • rsso-context-timeout - Time in seconds before the logged out user is removed from the "user context list" of logged on users. type: int more...
    • rsso-endpoint-attribute - RADIUS attributes used to extract the user end point identifer from the RADIUS Start record. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • rsso-endpoint-block-attribute - RADIUS attributes used to block a user. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • rsso-ep-one-ip-only - Enable/disable the replacement of old IP addresses with new ones for the same endpoint on RADIUS accounting Start messages. type: str choices: [disable, enable] more...
    • rsso-flush-ip-session - Enable/disable flushing user IP sessions on RADIUS accounting Stop messages. type: str choices: [disable, enable] more...
    • rsso-log-flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
    • rsso-log-period - Time interval in seconds that group event log messages will be generated for dynamic profile events. type: int more...
    • rsso-radius-response - Enable/disable sending RADIUS response packets after receiving Start and Stop records. type: str choices: [disable, enable] more...
    • rsso-radius-server-port - UDP port to listen on for RADIUS Start and Stop records. type: int more...
    • rsso-secret - No description for the parameter type: str more...
    • rsso-validate-request-secret - Enable/disable validating the RADIUS request shared secret in the Start or End record. type: str choices: [disable, enable] more...
    • secondary-secret - No description for the parameter type: str more...
    • secondary-server - {<name_str|ip_str>} secondary RADIUS CN domain name or IP. type: str more...
    • secret - No description for the parameter type: str more...
    • server - Primary RADIUS server CN domain name or IP address. type: str more...
    • source-ip - Source IP address for communications to the RADIUS server. type: str more...
    • sso-attribute - RADIUS attribute that contains the profile group name to be extracted from the RADIUS Start record. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
    • sso-attribute-key - Key prefix for SSO group value in the SSO attribute. type: str more...
    • sso-attribute-value-override - Enable/disable override old attribute value with new value for the same endpoint. type: str choices: [disable, enable] more...
    • tertiary-secret - No description for the parameter type: str more...
    • tertiary-server - {<name_str|ip_str>} tertiary RADIUS CN domain name or IP. type: str more...
    • timeout - Time in seconds between re-sending authentication requests. type: int more...
    • use-group-for-profile - Use-Group-For-Profile. type: str choices: [disable, enable] more...
    • use-management-vdom - Enable/disable using management VDOM to send requests. type: str choices: [disable, enable] more...
    • username-case-sensitive - Enable/disable case sensitive user names. type: str choices: [disable, enable] more...
    • interface - Specify outgoing interface to reach server. type: str more...
    • interface-select-method - Specify how to select outgoing interface to reach server. type: str choices: [auto, sdwan, specify] more...
    • group-override-attr-type - Group-Override-Attr-Type. type: str choices: [filter-Id, class] more...
    • switch-controller-acct-fast-framedip-detect - Switch-Controller-Acct-Fast-Framedip-Detect. type: int more...
    • accounting-server - No description for the parameter type: array more...
      • id - ID (0 - 4294967295). type: int more...
      • interface - Specify outgoing interface to reach server. type: str more...
      • interface-select-method - Specify how to select outgoing interface to reach server. type: str choices: [auto, sdwan, specify] more...
      • port - RADIUS accounting port number. type: int more...
      • secret - No description for the parameter type: str more...
      • server - {<name_str|ip_str>} Server CN domain name or IP. type: str more...
      • source-ip - Source IP address for communications to the RADIUS server. type: str more...
      • status - Status. type: str choices: [disable, enable] more...
    • switch-controller-service-type - No description for the parameter type: array choices: [login, framed, callback-login, callback-framed, outbound, administrative, nas-prompt, authenticate-only, callback-nas-prompt, call-check, callback-administrative] more...
    • delimiter - Configure delimiter to be used for separating profile group names in the SSO attribute (default = plus character "+"). type: str choices: [plus, comma] more...

Notes

Note

  • Running in workspace locking mode is supported in this FortiManager module, the top level parameters workspace_locking_adom and workspace_locking_timeout help do the work.
  • To create or update an object, use state: present directive.
  • To delete an object, use state: absent directive
  • Normally, running one module can fail when a non-zero rc is returned. you can also override the conditions to fail or succeed with parameters rc_failed and rc_succeeded

Examples

- name: gathering fortimanager facts
  hosts: fortimanager00
  gather_facts: no
  connection: httpapi
  collections:
    - fortinet.fortimanager
  vars:
    ansible_httpapi_use_ssl: True
    ansible_httpapi_validate_certs: False
    ansible_httpapi_port: 443
  tasks:
   - name: retrieve all the dynamic mappings of RADIUS server
     fmgr_fact:
       facts:
           selector: 'user_radius_dynamicmapping'
           params:
               adom: 'ansible'
               radius: 'ansible-test-radius' # name
               dynamic_mapping: 'your_value'

- hosts: fortimanager00
  collections:
    - fortinet.fortimanager
  connection: httpapi
  vars:
     ansible_httpapi_use_ssl: True
     ansible_httpapi_validate_certs: False
     ansible_httpapi_port: 443
  tasks:
   - name: Configure dynamic mappings of RADIUS server
     fmgr_user_radius_dynamicmapping:
        bypass_validation: False
        adom: ansible
        radius: ansible-test-radius # name
        state: present
        user_radius_dynamicmapping:
           _scope:
             -
                 name: FGT_AWS # need a valid device name
                 vdom: root # need a valid vdom name under the device
           server: ansible
           timeout: 100

Return Values

Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:

  • request_url - The full url requested returned: always type: str sample: /sys/login/user
  • response_code - The status of api request returned: always type: int sample: 0
  • response_message - The descriptive message of the api response returned: always type: str sample: OK
  • response_data - The data body of the api response returned: optional type: list or dict

Status

  • This module is not guaranteed to have a backwards compatible interface.

Authors

  • Link Zheng (@chillancezen)
  • Jie Xue (@JieX19)
  • Frank Shen (@fshen01)
  • Hongbin Lu (@fgtdev-hblu)

Hint

If you notice any issues in this documentation, you can create a pull request to improve it.