fmgr_user_radius_dynamicmapping – Configure RADIUS server entries.¶
New in version 2.10.
Synopsis¶
- This module is able to configure a FortiManager device.
- Examples include all parameters and values need to be adjusted to data sources before usage.
Requirements¶
The below requirements are needed on the host that executes this module.
- ansible>=2.9.0
FortiManager Version Compatibility¶
6.0.0 |
6.2.1 |
6.2.3 |
6.2.5 |
6.4.0 |
6.4.2 |
6.4.5 |
7.0.0 |
7.2.0 |
|
| user_radius_dynamicmapping | yes | yes | yes | yes | yes | yes | yes | yes | yes |
Parameters¶
- enable_log - Enable/Disable logging for task type: bool required: false default: False
- forticloud_access_token - Access token of forticloud managed API users, this option is available with FortiManager later than 6.4.0 type: str required: false
- proposed_method - The overridden method for the underlying Json RPC request type: str required: false choices: set, update, add
- bypass_validation - Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters type: bool required: false default: False
- workspace_locking_adom - Acquire the workspace lock if FortiManager is running in workspace mode type: str required: false choices: global, custom adom including root
- workspace_locking_timeout - The maximum time in seconds to wait for other users to release workspace lock type: integer required: false default: 300
- rc_succeeded - The rc codes list with which the conditions to succeed will be overriden type: list required: false
- rc_failed - The rc codes list with which the conditions to fail will be overriden type: list required: false
- state - The directive to create, update or delete an object type: str required: true choices: present, absent
- adom - The parameter in requested url type: str required: true
- radius - The parameter in requested url type: str required: true
- user_radius_dynamicmapping - no description type: dict
- _scope - No description for the parameter type: array more...
- acct-all-servers - Enable/disable sending of accounting messages to all configured servers (default = disable). type: str choices: [disable, enable] more...
- acct-interim-interval - Time in seconds between each accounting interim update message. type: int more...
- all-usergroup - Enable/disable automatically including this RADIUS server in all user groups. type: str choices: [disable, enable] more...
- auth-type - Authentication methods/protocols permitted for this RADIUS server. type: str choices: [pap, chap, ms_chap, ms_chap_v2, auto] more...
- class - No description for the parameter type: str more...
- dp-carrier-endpoint-attribute - Dp-Carrier-Endpoint-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-carrier-endpoint-block-attribute - Dp-Carrier-Endpoint-Block-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-context-timeout - Dp-Context-Timeout. type: int more...
- dp-flush-ip-session - Dp-Flush-Ip-Session. type: str choices: [disable, enable] more...
- dp-hold-time - Dp-Hold-Time. type: int more...
- dp-http-header - Dp-Http-Header. type: str more...
- dp-http-header-fallback - Dp-Http-Header-Fallback. type: str choices: [ip-header-address, default-profile] more...
- dp-http-header-status - Dp-Http-Header-Status. type: str choices: [disable, enable] more...
- dp-http-header-suppress - Dp-Http-Header-Suppress. type: str choices: [disable, enable] more...
- dp-log-dyn_flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
- dp-log-period - Dp-Log-Period. type: int more...
- dp-mem-percent - Dp-Mem-Percent. type: int more...
- dp-profile-attribute - Dp-Profile-Attribute. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Vendor-Specific, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- dp-profile-attribute-key - Dp-Profile-Attribute-Key. type: str more...
- dp-radius-response - Dp-Radius-Response. type: str choices: [disable, enable] more...
- dp-radius-server-port - Dp-Radius-Server-Port. type: int more...
- dp-secret - No description for the parameter type: str more...
- dp-validate-request-secret - Dp-Validate-Request-Secret. type: str choices: [disable, enable] more...
- dynamic-profile - Dynamic-Profile. type: str choices: [disable, enable] more...
- endpoint-translation - Endpoint-Translation. type: str choices: [disable, enable] more...
- ep-carrier-endpoint-convert-hex - Ep-Carrier-Endpoint-Convert-Hex. type: str choices: [disable, enable] more...
- ep-carrier-endpoint-header - Ep-Carrier-Endpoint-Header. type: str more...
- ep-carrier-endpoint-header-suppress - Ep-Carrier-Endpoint-Header-Suppress. type: str choices: [disable, enable] more...
- ep-carrier-endpoint-prefix - Ep-Carrier-Endpoint-Prefix. type: str choices: [disable, enable] more...
- ep-carrier-endpoint-prefix-range-max - Ep-Carrier-Endpoint-Prefix-Range-Max. type: int more...
- ep-carrier-endpoint-prefix-range-min - Ep-Carrier-Endpoint-Prefix-Range-Min. type: int more...
- ep-carrier-endpoint-prefix-string - Ep-Carrier-Endpoint-Prefix-String. type: str more...
- ep-carrier-endpoint-source - Ep-Carrier-Endpoint-Source. type: str choices: [http-header, cookie] more...
- ep-ip-header - Ep-Ip-Header. type: str more...
- ep-ip-header-suppress - Ep-Ip-Header-Suppress. type: str choices: [disable, enable] more...
- ep-missing-header-fallback - Ep-Missing-Header-Fallback. type: str choices: [session-ip, policy-profile] more...
- ep-profile-query-type - Ep-Profile-Query-Type. type: str choices: [session-ip, extract-ip, extract-carrier-endpoint] more...
- h3c-compatibility - Enable/disable compatibility with the H3C, a mechanism that performs security checking for authentication. type: str choices: [disable, enable] more...
- nas-ip - IP address used to communicate with the RADIUS server and used as NAS-IP-Address and Called-Station-ID attributes. type: str more...
- password-encoding - Password encoding. type: str choices: [ISO-8859-1, auto] more...
- password-renewal - Enable/disable password renewal. type: str choices: [disable, enable] more...
- radius-coa - Enable to allow a mechanism to change the attributes of an authentication, authorization, and accounting session after it is authenticated. type: str choices: [disable, enable] more...
- radius-port - RADIUS service port number. type: int more...
- rsso - Enable/disable RADIUS based single sign on feature. type: str choices: [disable, enable] more...
- rsso-context-timeout - Time in seconds before the logged out user is removed from the "user context list" of logged on users. type: int more...
- rsso-endpoint-attribute - RADIUS attributes used to extract the user end point identifer from the RADIUS Start record. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- rsso-endpoint-block-attribute - RADIUS attributes used to block a user. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- rsso-ep-one-ip-only - Enable/disable the replacement of old IP addresses with new ones for the same endpoint on RADIUS accounting Start messages. type: str choices: [disable, enable] more...
- rsso-flush-ip-session - Enable/disable flushing user IP sessions on RADIUS accounting Stop messages. type: str choices: [disable, enable] more...
- rsso-log-flags - No description for the parameter type: array choices: [none, protocol-error, profile-missing, context-missing, accounting-stop-missed, accounting-event, radiusd-other, endpoint-block] more...
- rsso-log-period - Time interval in seconds that group event log messages will be generated for dynamic profile events. type: int more...
- rsso-radius-response - Enable/disable sending RADIUS response packets after receiving Start and Stop records. type: str choices: [disable, enable] more...
- rsso-radius-server-port - UDP port to listen on for RADIUS Start and Stop records. type: int more...
- rsso-secret - No description for the parameter type: str more...
- rsso-validate-request-secret - Enable/disable validating the RADIUS request shared secret in the Start or End record. type: str choices: [disable, enable] more...
- secondary-secret - No description for the parameter type: str more...
- secondary-server - {<name_str|ip_str>} secondary RADIUS CN domain name or IP. type: str more...
- secret - No description for the parameter type: str more...
- server - Primary RADIUS server CN domain name or IP address. type: str more...
- source-ip - Source IP address for communications to the RADIUS server. type: str more...
- sso-attribute - RADIUS attribute that contains the profile group name to be extracted from the RADIUS Start record. type: str choices: [User-Name, User-Password, CHAP-Password, NAS-IP-Address, NAS-Port, Service-Type, Framed-Protocol, Framed-IP-Address, Framed-IP-Netmask, Framed-Routing, Filter-Id, Framed-MTU, Framed-Compression, Login-IP-Host, Login-Service, Login-TCP-Port, Reply-Message, Callback-Number, Callback-Id, Framed-Route, Framed-IPX-Network, State, Class, Session-Timeout, Idle-Timeout, Termination-Action, Called-Station-Id, Calling-Station-Id, NAS-Identifier, Proxy-State, Login-LAT-Service, Login-LAT-Node, Login-LAT-Group, Framed-AppleTalk-Link, Framed-AppleTalk-Network, Framed-AppleTalk-Zone, Acct-Status-Type, Acct-Delay-Time, Acct-Input-Octets, Acct-Output-Octets, Acct-Session-Id, Acct-Authentic, Acct-Session-Time, Acct-Input-Packets, Acct-Output-Packets, Acct-Terminate-Cause, Acct-Multi-Session-Id, Acct-Link-Count, CHAP-Challenge, NAS-Port-Type, Port-Limit, Login-LAT-Port] more...
- sso-attribute-key - Key prefix for SSO group value in the SSO attribute. type: str more...
- sso-attribute-value-override - Enable/disable override old attribute value with new value for the same endpoint. type: str choices: [disable, enable] more...
- tertiary-secret - No description for the parameter type: str more...
- tertiary-server - {<name_str|ip_str>} tertiary RADIUS CN domain name or IP. type: str more...
- timeout - Time in seconds between re-sending authentication requests. type: int more...
- use-group-for-profile - Use-Group-For-Profile. type: str choices: [disable, enable] more...
- use-management-vdom - Enable/disable using management VDOM to send requests. type: str choices: [disable, enable] more...
- username-case-sensitive - Enable/disable case sensitive user names. type: str choices: [disable, enable] more...
- interface - Specify outgoing interface to reach server. type: str more...
- interface-select-method - Specify how to select outgoing interface to reach server. type: str choices: [auto, sdwan, specify] more...
- group-override-attr-type - Group-Override-Attr-Type. type: str choices: [filter-Id, class] more...
- switch-controller-acct-fast-framedip-detect - Switch-Controller-Acct-Fast-Framedip-Detect. type: int more...
- accounting-server - No description for the parameter type: array
more...
- id - ID (0 - 4294967295). type: int more...
- interface - Specify outgoing interface to reach server. type: str more...
- interface-select-method - Specify how to select outgoing interface to reach server. type: str choices: [auto, sdwan, specify] more...
- port - RADIUS accounting port number. type: int more...
- secret - No description for the parameter type: str more...
- server - {<name_str|ip_str>} Server CN domain name or IP. type: str more...
- source-ip - Source IP address for communications to the RADIUS server. type: str more...
- status - Status. type: str choices: [disable, enable] more...
- switch-controller-service-type - No description for the parameter type: array choices: [login, framed, callback-login, callback-framed, outbound, administrative, nas-prompt, authenticate-only, callback-nas-prompt, call-check, callback-administrative] more...
- delimiter - Configure delimiter to be used for separating profile group names in the SSO attribute (default = plus character "+"). type: str choices: [plus, comma] more...
Notes¶
Note
- Running in workspace locking mode is supported in this FortiManager module, the top level parameters workspace_locking_adom and workspace_locking_timeout help do the work.
- To create or update an object, use state: present directive.
- To delete an object, use state: absent directive
- Normally, running one module can fail when a non-zero rc is returned. you can also override the conditions to fail or succeed with parameters rc_failed and rc_succeeded
Examples¶
- name: gathering fortimanager facts
hosts: fortimanager00
gather_facts: no
connection: httpapi
collections:
- fortinet.fortimanager
vars:
ansible_httpapi_use_ssl: True
ansible_httpapi_validate_certs: False
ansible_httpapi_port: 443
tasks:
- name: retrieve all the dynamic mappings of RADIUS server
fmgr_fact:
facts:
selector: 'user_radius_dynamicmapping'
params:
adom: 'ansible'
radius: 'ansible-test-radius' # name
dynamic_mapping: 'your_value'
- hosts: fortimanager00
collections:
- fortinet.fortimanager
connection: httpapi
vars:
ansible_httpapi_use_ssl: True
ansible_httpapi_validate_certs: False
ansible_httpapi_port: 443
tasks:
- name: Configure dynamic mappings of RADIUS server
fmgr_user_radius_dynamicmapping:
bypass_validation: False
adom: ansible
radius: ansible-test-radius # name
state: present
user_radius_dynamicmapping:
_scope:
-
name: FGT_AWS # need a valid device name
vdom: root # need a valid vdom name under the device
server: ansible
timeout: 100
Return Values¶
Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:
- request_url - The full url requested returned: always type: str sample: /sys/login/user
- response_code - The status of api request returned: always type: int sample: 0
- response_message - The descriptive message of the api response returned: always type: str sample: OK
- response_data - The data body of the api response returned: optional type: list or dict