New in version 2.8.
The below requirements are needed on the host that executes this module.
| Parameter | Choices/Defaults | Comments | |
|---|---|---|---|
|   host    string    |    FortiOS or FortiGate IP address.   |  ||
|   https    boolean    |   
  |    Indicates if the requests towards FortiGate must use HTTPS protocol.   |  |
|   password    string    |   Default: ""   |    FortiOS or FortiGate password.   |  |
|   ssl_verify    boolean   added in 2.9   |   
  |    Ensures FortiGate certificate must be verified by a proper CA.   |  |
|   state    string   added in 2.9   |   
  |    Indicates whether to create or remove the object. This attribute was present already in previous version in a deeper level. It has been moved out to this outer level.   |  |
|   username    string    |    FortiOS or FortiGate username.   |  ||
|   vdom    string    |   Default: "root"   |    Virtual domain, among those defined previously. A vdom is a virtual instance of the FortiGate that can be configured and used as a different unit.   |  |
|   vpn_ipsec_phase2_interface    dictionary    |   Default: null   |    Configure VPN autokey tunnel.   |  |
|   add_route    string    |   
  |    Enable/disable automatic route addition.   |  |
|   auto_discovery_forwarder    string    |   
  |    Enable/disable forwarding short-cut messages.   |  |
|   auto_discovery_sender    string    |   
  |    Enable/disable sending short-cut messages.   |  |
|   auto_negotiate    string    |   
  |    Enable/disable IPsec SA auto-negotiation.   |  |
|   comments    string    |    Comment.   |  ||
|   dhcp_ipsec    string    |   
  |    Enable/disable DHCP-IPsec.   |  |
|   dhgrp    string    |   
  |    Phase2 DH group.   |  |
|   dst_addr_type    string    |   
  |    Remote proxy ID type.   |  |
|   dst_end_ip    string    |    Remote proxy ID IPv4 end.   |  ||
|   dst_end_ip6    string    |    Remote proxy ID IPv6 end.   |  ||
|   dst_name    string    |    Remote proxy ID name. Source firewall.address.name firewall.addrgrp.name.   |  ||
|   dst_name6    string    |    Remote proxy ID name. Source firewall.address6.name firewall.addrgrp6.name.   |  ||
|   dst_port    integer    |    Quick mode destination port (1 - 65535 or 0 for all).   |  ||
|   dst_start_ip    string    |    Remote proxy ID IPv4 start.   |  ||
|   dst_start_ip6    string    |    Remote proxy ID IPv6 start.   |  ||
|   dst_subnet    string    |    Remote proxy ID IPv4 subnet.   |  ||
|   dst_subnet6    string    |    Remote proxy ID IPv6 subnet.   |  ||
|   encapsulation    string    |   
  |    ESP encapsulation mode.   |  |
|   keepalive    string    |   
  |    Enable/disable keep alive.   |  |
|   keylife_type    string    |   
  |    Keylife type.   |  |
|   keylifekbs    integer    |    Phase2 key life in number of bytes of traffic (5120 - 4294967295).   |  ||
|   keylifeseconds    integer    |    Phase2 key life in time in seconds (120 - 172800).   |  ||
|   l2tp    string    |   
  |    Enable/disable L2TP over IPsec.   |  |
|   name    string / required    |    IPsec tunnel name.   |  ||
|   pfs    string    |   
  |    Enable/disable PFS feature.   |  |
|   phase1name    string    |    Phase 1 determines the options required for phase 2. Source vpn.ipsec.phase1-interface.name.   |  ||
|   proposal    string    |   
  |    Phase2 proposal.   |  |
|   protocol    integer    |    Quick mode protocol selector (1 - 255 or 0 for all).   |  ||
|   replay    string    |   
  |    Enable/disable replay detection.   |  |
|   route_overlap    string    |   
  |    Action for overlapping routes.   |  |
|   single_source    string    |   
  |    Enable/disable single source IP restriction.   |  |
|   src_addr_type    string    |   
  |    Local proxy ID type.   |  |
|   src_end_ip    string    |    Local proxy ID end.   |  ||
|   src_end_ip6    string    |    Local proxy ID IPv6 end.   |  ||
|   src_name    string    |    Local proxy ID name. Source firewall.address.name firewall.addrgrp.name.   |  ||
|   src_name6    string    |    Local proxy ID name. Source firewall.address6.name firewall.addrgrp6.name.   |  ||
|   src_port    integer    |    Quick mode source port (1 - 65535 or 0 for all).   |  ||
|   src_start_ip    string    |    Local proxy ID start.   |  ||
|   src_start_ip6    string    |    Local proxy ID IPv6 start.   |  ||
|   src_subnet    string    |    Local proxy ID subnet.   |  ||
|   src_subnet6    string    |    Local proxy ID IPv6 subnet.   |  ||
|   state    string    |   
  |    Deprecated  Starting with Ansible 2.9 we recommend using the top-level 'state' parameter.   Indicates whether to create or remove the object.   |  |
Note
- hosts: localhost
  vars:
   host: "192.168.122.40"
   username: "admin"
   password: ""
   vdom: "root"
   ssl_verify: "False"
  tasks:
  - name: Configure VPN autokey tunnel.
    fortios_vpn_ipsec_phase2_interface:
      host:  "{{ host }}"
      username: "{{ username }}"
      password: "{{ password }}"
      vdom:  "{{ vdom }}"
      https: "False"
      state: "present"
      vpn_ipsec_phase2_interface:
        add_route: "phase1"
        auto_discovery_forwarder: "phase1"
        auto_discovery_sender: "phase1"
        auto_negotiate: "enable"
        comments: "<your_own_value>"
        dhcp_ipsec: "enable"
        dhgrp: "1"
        dst_addr_type: "subnet"
        dst_end_ip: "<your_own_value>"
        dst_end_ip6: "<your_own_value>"
        dst_name: "<your_own_value> (source firewall.address.name firewall.addrgrp.name)"
        dst_name6: "<your_own_value> (source firewall.address6.name firewall.addrgrp6.name)"
        dst_port: "15"
        dst_start_ip: "<your_own_value>"
        dst_start_ip6: "<your_own_value>"
        dst_subnet: "<your_own_value>"
        dst_subnet6: "<your_own_value>"
        encapsulation: "tunnel-mode"
        keepalive: "enable"
        keylife_type: "seconds"
        keylifekbs: "23"
        keylifeseconds: "24"
        l2tp: "enable"
        name: "default_name_26"
        pfs: "enable"
        phase1name: "<your_own_value> (source vpn.ipsec.phase1-interface.name)"
        proposal: "null-md5"
        protocol: "30"
        replay: "enable"
        route_overlap: "use-old"
        single_source: "enable"
        src_addr_type: "subnet"
        src_end_ip: "<your_own_value>"
        src_end_ip6: "<your_own_value>"
        src_name: "<your_own_value> (source firewall.address.name firewall.addrgrp.name)"
        src_name6: "<your_own_value> (source firewall.address6.name firewall.addrgrp6.name)"
        src_port: "39"
        src_start_ip: "<your_own_value>"
        src_start_ip6: "<your_own_value>"
        src_subnet: "<your_own_value>"
        src_subnet6: "<your_own_value>"
   Common return values are documented here, the following are the fields unique to this module:
| Key | Returned | Description | 
|---|---|---|
|   build    string    |  always |   Build number of the fortigate image  Sample:  1547   |  
|   http_method    string    |  always |   Last method used to provision the content into FortiGate  Sample:  PUT   |  
|   http_status    string    |  always |   Last result given by FortiGate on last operation applied  Sample:  200   |  
|   mkey    string    |  success |   Master key (id) used in the last call to FortiGate  Sample:  id   |  
|   name    string    |  always |   Name of the table used to fulfill the request  Sample:  urlfilter   |  
|   path    string    |  always |   Path of the table used to fulfill the request  Sample:  webfilter   |  
|   revision    string    |  always |   Internal revision number  Sample:  17.0.2.10658   |  
|   serial    string    |  always |   Serial number of the unit  Sample:  FGVMEVYYQT3AB5352   |  
|   status    string    |  always |   Indication of the operation's result  Sample:  success   |  
|   vdom    string    |  always |   Virtual domain used  Sample:  root   |  
|   version    string    |  always |   Version of the FortiGate  Sample:  v5.6.3   |  
Hint
If you notice any issues in this documentation, you can edit this document to improve it.
    © 2012–2018 Michael DeHaan
© 2018–2019 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
    https://docs.ansible.com/ansible/2.9/modules/fortios_vpn_ipsec_phase2_interface_module.html