Note
This module is part of the cisco.ise collection (version 2.10.0).
You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install cisco.ise. You need further requirements to be able to use this module, see Requirements for details.
To use it in a playbook, specify: cisco.ise.sg_acl.
Note
The cisco.ise collection is considered unmaintained and will be removed from Ansible 12. Once removed, you can still install the collection manually with ansible-galaxy collection install cisco.ise. See the discussion thread for more information.
New in cisco.ise 1.0.0
Note
This module has a corresponding action plugin.
The below requirements are needed on the host that executes this module.
Parameter | Comments |
|---|---|
aclcontent string | SGACL’s aclcontent. |
description string | SGACL’s description. |
generationId string | SGACL’s generationId. |
id string | SGACL’s id. |
ipVersion string | Allowed values - IPV4, - IPV6, - IP_AGNOSTIC. |
ise_debug boolean | Flag for Identity Services Engine SDK to enable debugging. Choices:
|
ise_hostname string / required | The Identity Services Engine hostname. |
ise_password string / required | The Identity Services Engine password to authenticate. |
ise_single_request_timeout integer added in cisco.ise 3.0.0 | Timeout (in seconds) for RESTful HTTP requests. Default: |
ise_username string / required | The Identity Services Engine username to authenticate. |
ise_uses_api_gateway boolean added in cisco.ise 1.1.0 | Flag that informs the SDK whether to use the Identity Services Engine’s API Gateway to send requests. If it is true, it uses the ISE’s API Gateway and sends requests to https://{{ise_hostname}}. If it is false, it sends the requests to https://{{ise_hostname}}:{{port}}, where the port value depends on the Service used (ERS, Mnt, UI, PxGrid). Choices:
|
ise_uses_csrf_token boolean added in cisco.ise 3.0.0 | Flag that informs the SDK whether we send the CSRF token to ISE’s ERS APIs. If it is True, the SDK assumes that your ISE CSRF Check is enabled. If it is True, it assumes you need the SDK to manage the CSRF token automatically for you. Choices:
|
ise_verify boolean | Flag to enable or disable SSL certificate verification. Choices:
|
ise_version string | Informs the SDK which version of Identity Services Engine to use. Default: |
ise_wait_on_rate_limit boolean | Flag for Identity Services Engine SDK to enable automatic rate-limit handling. Choices:
|
isReadOnly boolean | IsReadOnly flag. Choices:
|
modelledContent dictionary | Modelled content of contract. |
name string | SGACL’s name. |
Note
check_mode
See also
Complete reference of the SecurityGroupsACLs API.
- name: Update by id
cisco.ise.sg_acl:
ise_hostname: "{{ise_hostname}}"
ise_username: "{{ise_username}}"
ise_password: "{{ise_password}}"
ise_verify: "{{ise_verify}}"
state: present
aclcontent: string
description: string
generationId: string
id: string
ipVersion: string
isReadOnly: true
modelledContent: {}
name: string
- name: Delete by id
cisco.ise.sg_acl:
ise_hostname: "{{ise_hostname}}"
ise_username: "{{ise_username}}"
ise_password: "{{ise_password}}"
ise_verify: "{{ise_verify}}"
state: absent
id: string
- name: Create
cisco.ise.sg_acl:
ise_hostname: "{{ise_hostname}}"
ise_username: "{{ise_username}}"
ise_password: "{{ise_password}}"
ise_verify: "{{ise_verify}}"
state: present
aclcontent: string
description: string
generationId: string
ipVersion: string
isReadOnly: true
modelledContent: {}
name: string
Common return values are documented here, the following are the fields unique to this module:
Key | Description |
|---|---|
ise_response dictionary | A dictionary or list with the response returned by the Cisco ISE Python SDK Returned: always Sample: |
ise_update_response dictionary added in cisco.ise 1.1.0 | A dictionary or list with the response returned by the Cisco ISE Python SDK Returned: always Sample: |
© 2012–2018 Michael DeHaan
© 2018–2025 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/cisco/ise/sg_acl_module.html