Note
This module is part of the fortinet.fortimanager collection (version 2.10.0).
You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install fortinet.fortimanager.
To use it in a playbook, specify: fortinet.fortimanager.fmgr_switchcontroller_securitypolicy_8021x.
New in fortinet.fortimanager 2.0.0
Parameter | Comments |
|---|---|
access_token string | The token to access FortiManager without using username and password. |
adom string / required | The parameter (adom) in requested url. |
bypass_validation boolean | Only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters. Choices:
|
enable_log boolean | Enable/Disable logging for task. Choices:
|
forticloud_access_token string | Authenticate Ansible client with forticloud API access token. |
proposed_method string | The overridden method for the underlying Json RPC request. Choices:
|
rc_failed list / elements=integer | The rc codes list with which the conditions to fail will be overriden. |
rc_succeeded list / elements=integer | The rc codes list with which the conditions to succeed will be overriden. |
state string / required | The directive to create, update or delete an object. Choices:
|
switchcontroller_securitypolicy_8021x dictionary | The top level parameters set. |
|
auth_fail_vlan aliases: auth-fail-vlan string |
Enable to allow limited access to clients that cannot authenticate. Choices:
|
|
auth_fail_vlan_id aliases: auth-fail-vlan-id string |
VLAN ID on which authentication failed. |
|
auth_fail_vlanid aliases: auth-fail-vlanid integer |
VLAN ID on which authentication failed. |
|
auth_order aliases: auth-order string |
Configure authentication order. Choices:
|
|
auth_priority aliases: auth-priority string |
Configure authentication priority. Choices:
|
|
authserver_timeout_period aliases: authserver-timeout-period integer |
Authentication server timeout period |
|
authserver_timeout_tagged aliases: authserver-timeout-tagged string |
Configure timeout option for the tagged VLAN which allows limited access when the authentication server is unavailable. Choices:
|
|
authserver_timeout_tagged_vlanid aliases: authserver-timeout-tagged-vlanid any |
(list) Tagged VLAN name for which the timeout option is applied to |
|
authserver_timeout_vlan aliases: authserver-timeout-vlan string |
Enable/disable the authentication server timeout VLAN to allow limited access when RADIUS is unavailable. Choices:
|
|
authserver_timeout_vlanid aliases: authserver-timeout-vlanid string |
Authentication server timeout VLAN name. |
|
dacl string |
Enable/disable dynamic access control list on this interface. Choices:
|
|
eap_auto_untagged_vlans aliases: eap-auto-untagged-vlans string |
Enable/disable automatic inclusion of untagged VLANs. Choices:
|
|
eap_passthru aliases: eap-passthru string |
Enable/disable EAP pass-through mode, allowing protocols Choices:
|
|
framevid_apply aliases: framevid-apply string |
Enable/disable the capability to apply the EAP/MAB frame VLAN to the port native VLAN. Choices:
|
|
guest_auth_delay aliases: guest-auth-delay integer |
Guest authentication delay |
|
guest_vlan aliases: guest-vlan string |
Enable the guest VLAN feature to allow limited access to non-802. Choices:
|
|
guest_vlan_id aliases: guest-vlan-id string |
Guest VLAN name. |
|
guest_vlanid aliases: guest-vlanid integer |
Guest VLAN ID. |
|
mac_auth_bypass aliases: mac-auth-bypass string |
Enable/disable MAB for this policy. Choices:
|
|
name string / required |
Policy name. |
|
open_auth aliases: open-auth string |
Enable/disable open authentication for this policy. Choices:
|
|
policy_type aliases: policy-type string |
Policy type. Choices:
|
|
radius_timeout_overwrite aliases: radius-timeout-overwrite string |
Enable to override the global RADIUS session timeout. Choices:
|
|
security_mode aliases: security-mode string |
Port or MAC based 802. Choices:
|
|
user_group aliases: user-group any |
(list or str) Name of user-group to assign to this MAC Authentication Bypass |
workspace_locking_adom string | The adom to lock for FortiManager running in workspace mode, the value can be global and others including root. |
workspace_locking_timeout integer | The maximum time in seconds to wait for other user to release the workspace lock. Default: |
Note
- name: Example playbook (generated based on argument schema)
hosts: fortimanagers
connection: httpapi
gather_facts: false
vars:
ansible_httpapi_use_ssl: true
ansible_httpapi_validate_certs: false
ansible_httpapi_port: 443
tasks:
- name: Configure 802.
fortinet.fortimanager.fmgr_switchcontroller_securitypolicy_8021x:
# bypass_validation: false
workspace_locking_adom: <value in [global, custom adom including root]>
workspace_locking_timeout: 300
# rc_succeeded: [0, -2, -3, ...]
# rc_failed: [-2, -3, ...]
adom: <your own value>
state: present # <value in [present, absent]>
switchcontroller_securitypolicy_8021x:
name: "your value" # Required variable, string
# auth_fail_vlan: <value in [disable, enable]>
# auth_fail_vlan_id: <string>
# auth_fail_vlanid: <integer>
# eap_passthru: <value in [disable, enable]>
# guest_auth_delay: <integer>
# guest_vlan: <value in [disable, enable]>
# guest_vlan_id: <string>
# guest_vlanid: <integer>
# mac_auth_bypass: <value in [disable, enable]>
# open_auth: <value in [disable, enable]>
# policy_type: <value in [802.1X]>
# radius_timeout_overwrite: <value in [disable, enable]>
# security_mode: <value in [802.1X, 802.1X-mac-based]>
# user_group: <list or string>
# framevid_apply: <value in [disable, enable]>
# eap_auto_untagged_vlans: <value in [disable, enable]>
# authserver_timeout_period: <integer>
# authserver_timeout_vlan: <value in [disable, enable]>
# authserver_timeout_vlanid: <string>
# authserver_timeout_tagged: <value in [static, disable, lldp-voice]>
# authserver_timeout_tagged_vlanid: <list or string>
# dacl: <value in [disable, enable]>
# auth_order: <value in [dot1x-mab, mab-dot1x, mab]>
# auth_priority: <value in [dot1x-mab, mab-dot1x, legacy]>
Common return values are documented here, the following are the fields unique to this module:
Key | Description |
|---|---|
meta dictionary | The result of the request. Returned: always |
|
request_url string |
The full url requested. Returned: always Sample: |
|
response_code integer |
The status of api request. Returned: always Sample: |
|
response_data list / elements=string |
The api response. Returned: always |
|
response_message string |
The descriptive message of the api response. Returned: always Sample: |
|
system_information dictionary |
The information of the target system. Returned: always |
rc integer | The status the request. Returned: always Sample: |
version_check_warning list / elements=string | Warning if the parameters used in the playbook are not supported by the current FortiManager version. Returned: complex |
© 2012–2018 Michael DeHaan
© 2018–2025 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/fortinet/fortimanager/fmgr_switchcontroller_securitypolicy_8021x_module.html