|
无需使用用户名和密码即可访问 FortiManager 的令牌。
|
|
|
|
仅当模块模式与 FortiManager API 结构不同时设置为 True,模块将继续执行而不验证参数。
选项
|
|
|
|
|
add_nat64_route
别名:add-nat64-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
启用以响应此虚拟 IP 地址的 ARP 请求。
选项
|
|
|
|
|
dynamic_mapping
列表 / 元素=字典
|
|
|
|
|
|
|
|
add_nat64_route
别名:add-nat64-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
|
|
|
|
|
embedded_ipv4_address
别名:embedded-ipv4-address
字符串
|
启用/禁用使用外部 IPv6 地址的低 32 位作为映射的 IPv4 地址。
选项
|
|
|
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
|
http_ip_header_name
别名:http-ip-header-name
字符串
|
|
http_multiplex
别名:http-multiplex
字符串
|
|
http_redirect
别名:http-redirect
字符串
|
|
https_cookie_secure
别名:https-cookie-secure
字符串
|
|
|
|
ipv4_mappedip
别名: ipv4-mappedip
字符串
|
|
ipv4_mappedport
别名: ipv4-mappedport
字符串
|
目标网络上外部端口号范围映射到的 IPv4 端口号范围。
|
ldb_method
别名: ldb-method
字符串
|
Ldb 方法。
选项
"static"(静态)
"round-robin"(轮询)
"weighted"(加权)
"least-session"(最少会话)
"least-rtt"(最少 RTT)
"first-alive"(首个活跃)
"http-host"(HTTP 主机)
|
|
|
|
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
|
ndp_reply
别名: ndp-reply
字符串
|
启用/禁用此 FortiGate 设备响应此虚拟 IP 地址的 NDP 请求的能力。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
|
|
|
|
|
|
|
|
|
client_ip
别名: client-ip
字符串
|
只有此 IP 范围内的客户端才能连接到此真实服务器。
|
|
启用以在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名: holddown-interval
整数
|
运行状况检查监视器在应该重新上线的不响应服务器上继续监视的时间(以秒为单位)……
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
(列表或字符串)用于轮询以确定虚拟服务器连接性的运行状况检查监视器的名称……
|
|
|
|
将真实服务器的状态设置为活动,以便它可以接受流量,或者设置为备用或禁用,以便不……
选项
"active"(活动)
"standby"(备用)
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用将主机名/IP 从虚拟服务器转换为真实服务器。
选项
|
|
|
server_type
别名: server-type
字符串
|
服务器类型。
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
|
src_filter
别名: src-filter
any
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用源过滤器来匹配反向 SNAT 规则的目标。
选项
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
为 SSL 密钥交换启用/禁用 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
SSL 算法。
选项
"high"(高)
"low"(低)
"medium"(中)
"custom"(自定义)
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
versions
list / elements=string
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
SSL 客户端重新协商。
选项
"deny"(拒绝)
"allow"(允许)
"secure"(安全)
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
SSL 客户端会话状态类型。
选项
"disable"
"time"(时间)
"count"(计数)
"both"(两者)
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
SSL DH 位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
SSL HPKP。
选项
"disable"
"enable"
"report-only"(仅报告)
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名: ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名: ssl-hpkp-report-uri
字符串
|
|
ssl_hsts
别名: ssl-hsts
字符串
|
|
ssl_hsts_age
别名: ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名: ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名: ssl-http-location-conversion
字符串
|
|
ssl_http_match_host
别名: ssl-http-match-host
字符串
|
|
ssl_max_version
别名: ssl-max-version
字符串
|
SSL 最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名: ssl-min-version
字符串
|
SSL 最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_mode
别名: ssl-mode
字符串
|
|
|
Ssl pfs.
选项
"需要"
"deny"(拒绝)
"allow"(允许)
|
ssl_send_empty_frags
别名: ssl-send-empty-frags
字符串
|
|
ssl_server_algorithm
别名: ssl-server-algorithm
字符串
|
Ssl 服务器算法。
选项
"high"(高)
"low"(低)
"medium"(中)
"custom"(自定义)
"客户端"
|
ssl_server_max_version
别名: ssl-server-max-version
字符串
|
Ssl 服务器最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_min_version
别名: ssl-server-min-version
字符串
|
Ssl 服务器最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_renegotiation
别名: ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名: ssl-server-session-state-max
整数
|
|
ssl_server_session_state_timeout
别名: ssl-server-session-state-timeout
整数
|
|
ssl_server_session_state_type
别名: ssl-server-session-state-type
字符串
|
Ssl 服务器会话状态类型。
选项
"disable"
"time"(时间)
"count"(计数)
"both"(两者)
|
|
类型。
选项
"静态-NAT"
"服务器负载均衡"
"访问代理"
|
|
|
weblogic_server
别名: weblogic-server
字符串
|
|
websphere_server
别名: websphere-server
字符串
|
|
embedded_ipv4_address
别名:embedded-ipv4-address
字符串
|
启用/禁用使用外部 IPv6 地址的低 32 位作为映射的 IPv4 地址。
选项
|
|
您要映射到目标地址或地址范围的外部接口上的 IP 地址或地址范围...
|
|
您要映射到目标网络上的端口号范围的传入端口号范围。
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
客户端 Web 浏览器应保留 cookie 的分钟数。
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
启用/禁用 HTTP 中使用来自主机字段的 HTTP cookie 域。
选项
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
将 HTTP cookie 持久性限制为指定的路径。
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
对于 HTTP 多路复用,启用以在 XForwarded-For HTTP 标头中添加原始客户端 IP 地址。
选项
|
http_ip_header_name
别名:http-ip-header-name
字符串
|
对于 HTTP 多路复用,输入自定义 HTTPS 标头名称。
|
http_multiplex
别名:http-multiplex
字符串
|
|
http_redirect
别名:http-redirect
字符串
|
|
https_cookie_secure
别名:https-cookie-secure
字符串
|
启用/禁用验证插入的 HTTPS cookie 是否安全。
选项
|
|
|
ipv4_mappedip
别名: ipv4-mappedip
字符串
|
|
ipv4_mappedport
别名: ipv4-mappedport
字符串
|
目标网络上外部端口号范围映射到的 IPv4 端口号范围。
|
ldb_method
别名: ldb-method
字符串
|
用于将会话分配到真实服务器的方法。
选项
"static"(静态)
"round-robin"(轮询)
"weighted"(加权)
"least-session"(最少会话)
"least-rtt"(最少 RTT)
"first-alive"(首个活跃)
"http-host"(HTTP 主机)
|
|
格式为 startIP-endIP 的映射 IP 地址范围。
|
|
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
(列表或字符串)在轮询以确定虚拟服务器的连接状态时要使用的运行状况检查监视器的名称。
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
启用以对来自 mappedip 的流量执行 SNAT 到所有出口接口的 extip。
选项
|
ndp_reply
别名: ndp-reply
字符串
|
启用/禁用此 FortiGate 设备响应此虚拟 IP 地址的 NDP 请求的能力。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
启用以添加 Microsoft Outlook Web Access 的 Front-End-Https 标头。
选项
|
|
配置如何确保客户端每次发出请求(属于同一部分)时都连接到同一服务器...
选项
|
|
|
|
|
|
|
ack_delay_exponent
别名: ack-delay-exponent
整数
|
|
active_connection_id_limit
别名: active-connection-id-limit
整数
|
|
active_migration
别名: active-migration
字符串
|
|
grease_quic_bit
别名: grease-quic-bit
字符串
|
|
max_ack_delay
别名: max-ack-delay
整数
|
|
max_datagram_frame_size
别名: max-datagram-frame-size
整数
|
|
max_idle_timeout
别名: max-idle-timeout
整数
|
|
max_udp_payload_size
别名: max-udp-payload-size
整数
|
|
|
|
client_ip
别名: client-ip
字符串
|
只有此 IP 范围内的客户端才能连接到此真实服务器。
|
|
启用以在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名: holddown-interval
整数
|
运行状况检查监视器继续监视应处于活动状态的无响应服务器的秒数。
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
(列表或字符串)在轮询以确定虚拟服务器的连接状态时要使用的运行状况检查监视器的名称。
|
|
|
|
将真实服务器的状态设置为活动,以便它可以接受流量,或者设置为待机或禁用,以便没有流量...
选项
"active"(活动)
"standby"(备用)
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用将主机名/IP 从虚拟服务器转换为真实服务器。
选项
|
|
|
server_type
别名: server-type
字符串
|
虚拟服务器要负载平衡的协议
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
|
src_filter
别名: src-filter
any
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用源过滤器来匹配反向 SNAT 规则的目标。
选项
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
为 SSL 密钥交换启用/禁用 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
根据加密强度允许用于 SSL 会话的加密算法。
选项
"high"(高)
"low"(低)
"medium"(中)
"custom"(自定义)
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
versions
list / elements=string
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
在触发客户端重新密钥之前的数据最大长度(以 MB 为单位)
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
允许、拒绝或要求客户端会话的安全重新协商以符合 RFC 5746。
选项
"deny"(拒绝)
"allow"(允许)
"secure"(安全)
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
要保留的客户端到 FortiGate SSL 会话状态的最大数量。
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
保留客户端到 FortiGate SSL 会话状态的分钟数。
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
如何使客户端和 FortiGate 之间的 SSL 连接段的 SSL 会话过期。
选项
"disable"
"time"(时间)
"count"(计数)
"both"(两者)
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
在 SSL 会话的 RSA 加密的 Diffie-Hellman 交换中使用的位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
启用/禁用在响应中包含 HPKP 标头。
选项
"disable"
"enable"
"report-only"(仅报告)
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名: ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名: ssl-hpkp-report-uri
字符串
|
|
ssl_hsts
别名: ssl-hsts
字符串
|
|
ssl_hsts_age
别名: ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名: ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名: ssl-http-location-conversion
字符串
|
启用以在回复的 Location HTTP 标头字段中将 HTTP 替换为 HTTPS。
选项
|
ssl_http_match_host
别名: ssl-http-match-host
字符串
|
启用/禁用 HTTP 主机匹配以进行位置转换。
选项
|
ssl_max_version
别名: ssl-max-version
字符串
|
客户端可接受的最高 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名: ssl-min-version
字符串
|
客户端可接受的最低 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_mode
别名: ssl-mode
字符串
|
在客户端和 FortiGate 之间应用 SSL 卸载。
选项
|
|
选择可用于 SSL 完全前向保密的密码套件。
选项
"需要"
"deny"(拒绝)
"allow"(允许)
|
ssl_send_empty_frags
别名: ssl-send-empty-frags
字符串
|
启用/禁用发送空分片以避免 CBC IV 攻击。
选项
|
ssl_server_algorithm
别名: ssl-server-algorithm
字符串
|
根据加密强度,允许用于 SSL 完全模式会话服务器端的加密算法。
选项
"high"(高)
"low"(低)
"medium"(中)
"custom"(自定义)
"客户端"
|
ssl_server_cipher_suites
别名:ssl-server-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
versions
list / elements=string
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_server_max_version
别名: ssl-server-max-version
字符串
|
服务器可接受的最高 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_min_version
别名: ssl-server-min-version
字符串
|
服务器可接受的最低 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_renegotiation
别名: ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名: ssl-server-session-state-max
整数
|
要保留的 FortiGate 到服务器 SSL 会话状态的最大数量。
|
ssl_server_session_state_timeout
别名: ssl-server-session-state-timeout
整数
|
保留 FortiGate 到服务器 SSL 会话状态的分钟数。
|
ssl_server_session_state_type
别名: ssl-server-session-state-type
字符串
|
如何使服务器和 FortiGate 之间的 SSL 连接段的 SSL 会话过期。
选项
"disable"
"time"(时间)
"count"(计数)
"both"(两者)
|
|
配置静态 NAT VIP。
选项
"静态-NAT"
"服务器负载均衡"
"访问代理"
|
|
|
weblogic_server
别名: weblogic-server
字符串
|
启用后,添加 HTTP 标头以指示 WebLogic 服务器的 SSL 卸载。
选项
|
websphere_server
别名: websphere-server
字符串
|
启用后,添加 HTTP 标头以指示 WebSphere 服务器的 SSL 卸载。
选项
|
forticloud_access_token
字符串
|
使用 forticloud API 访问令牌验证 Ansible 客户端。
|
|
|
rc_failed
list / elements=integer
|
|
rc_succeeded
list / elements=integer
|
|
|
|
workspace_locking_adom
字符串
|
在工作区模式下运行的 FortiManager 的要锁定的 ADOM,该值可以是 global 和其他包括 root。
|
workspace_locking_timeout
整数
|
等待其他用户释放工作区锁定的最长时间(以秒为单位)。
默认值: 300
|