|
无需使用用户名和密码即可访问 FortiManager 的令牌。
|
|
|
|
仅当模块模式与 FortiManager API 结构不同时设置为 True,模块将继续执行而无需验证参数。
选项
|
|
|
|
|
add_nat46_route
别名:add-nat46-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
启用响应此虚拟 IP 地址的 ARP 请求。
选项
|
|
|
|
|
dns_mapping_ttl
别名:dns-mapping-ttl
整数
|
|
dynamic_mapping
列表 / 元素=字典
|
|
|
|
|
|
|
|
add_nat46_route
别名:add-nat46-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
|
|
|
|
|
dns_mapping_ttl
别名:dns-mapping-ttl
整数
|
|
|
|
|
|
|
|
|
|
gratuitous_arp_interval
别名:gratuitous-arp-interval
整数
|
|
gslb_domain_name
别名:gslb-domain-name
字符串
|
|
gslb_hostname
别名:gslb-hostname
字符串
|
在已配置的 FortiGSLB 域中使用的主机名。
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
|
http_ip_header_name
别名: http-ip-header-name
字符串
|
|
http_multiplex
别名: http-multiplex
字符串
|
|
http_multiplex_max_concurrent_request
别名: http-multiplex-max-concurrent-request
整数
|
|
http_multiplex_max_request
别名: http-multiplex-max-request
整数
|
多路复用服务器在断开会话之前可以处理的最大请求数。
|
http_multiplex_ttl
别名: http-multiplex-ttl
整数
|
|
http_redirect
别名: http-redirect
字符串
|
|
http_supported_max_version
别名: http-supported-max-version
字符串
|
|
https_cookie_secure
别名: https-cookie-secure
字符串
|
|
|
|
ipv6_mappedip
别名: ipv6-mappedip
字符串
|
|
ipv6_mappedport
别名: ipv6-mappedport
字符串
|
目标网络上外部端口号范围映射到的 IPv6 端口号范围。
|
ldb_method
别名: ldb-method
字符串
|
负载均衡方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
mapped_addr
别名: mapped-addr
字符串
|
|
|
|
|
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
|
one_click_gslb_server
别名: one-click-gslb-server
字符串
|
启用/禁用一键式 GSLB 服务器与 FortiGSLB 集成。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
|
|
持久性。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
portmapping_type
别名: portmapping-type
字符串
|
|
|
协议。
选项
"tcp"
"udp"
"sctp"
"icmp"
|
|
|
|
|
client_ip
别名: client-ip
任意
|
|
health_check_proto
别名: health-check-proto
字符串
|
|
|
|
holddown_interval
别名: holddown-interval
整数
|
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
|
|
|
|
|
|
状态。
选项
"active"
"standby"
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用将虚拟服务器的主机名/IP 转换为真实服务器。
选项
|
|
|
|
|
server_type
别名: server-type
字符串
|
服务器类型。
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
"ssh"
|
|
|
src_filter
别名: src-filter
任意
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目标。
选项
|
srcintf_filter
别名: srcintf-filter
任意
|
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
启用/禁用用于 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
SSL 算法。
选项
"high"
"medium"
"low"
"custom"
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
|
|
版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
SSL 客户端会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
SSL DH 位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
SSL HPKP。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名:ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名:ssl-hpkp-report-uri
字符串
|
|
|
|
ssl_hsts_age
别名:ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名:ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名:ssl-http-location-conversion
字符串
|
|
ssl_http_match_host
别名:ssl-http-match-host
字符串
|
|
ssl_max_version
别名:ssl-max-version
字符串
|
SSL 最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名:ssl-min-version
字符串
|
SSL 最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
|
|
|
|
ssl_send_empty_frags
别名:ssl-send-empty-frags
字符串
|
|
ssl_server_algorithm
别名:ssl-server-algorithm
字符串
|
SSL 服务器算法。
选项
"high"
"low"
"medium"
"custom"
"客户端"
|
ssl_server_max_version
别名:ssl-server-max-version
字符串
|
SSL 服务器最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_min_version
别名:ssl-server-min-version
字符串
|
SSL 服务器最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_renegotiation
别名:ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名:ssl-server-session-state-max
整数
|
|
ssl_server_session_state_timeout
别名:ssl-server-session-state-timeout
整数
|
|
ssl_server_session_state_type
别名:ssl-server-session-state-type
字符串
|
SSL 服务器会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
|
|
|
类型。
选项
"静态NAT"
"负载均衡"
"服务器负载均衡"
"DNS转换"
"FQDN"
"访问代理"
|
|
|
weblogic_server
别名:weblogic-server
字符串
|
|
websphere_server
别名:websphere-server
字符串
|
|
|
|
|
连接到源网络的接口,接收将转发到目标网络的数据包。
|
|
您要映射到目标网络上的地址或地址范围的外部接口上的IP地址或地址范围。
|
|
您要映射到目标网络上的端口号范围的传入端口号范围。
|
gratuitous_arp_interval
别名:gratuitous-arp-interval
整数
|
启用后,VIP 将发送 gratuitous ARP。
|
gslb_domain_name
别名:gslb-domain-name
字符串
|
|
gslb_hostname
别名:gslb-hostname
字符串
|
在已配置的 FortiGSLB 域中使用的主机名。
|
gslb_public_ips
别名:gslb-public-ips
列表 / 元素=字典
|
|
|
|
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
客户端Web浏览器应保留cookie的时间(以分钟为单位)。
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
启用/禁用使用HTTP中的主机字段的HTTP cookie域名。
选项
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
对于HTTP多路复用,启用此选项可在XForwarded-For HTTP标头中添加原始客户端IP地址。
选项
|
http_ip_header_name
别名: http-ip-header-name
字符串
|
对于HTTP多路复用,输入自定义HTTPS标头名称。
|
http_multiplex
别名: http-multiplex
字符串
|
|
http_multiplex_max_concurrent_request
别名: http-multiplex-max-concurrent-request
整数
|
|
http_multiplex_max_request
别名: http-multiplex-max-request
整数
|
多路复用服务器在断开会话之前可以处理的最大请求数。
|
http_multiplex_ttl
别名: http-multiplex-ttl
整数
|
|
http_redirect
别名: http-redirect
字符串
|
|
http_supported_max_version
别名: http-supported-max-version
字符串
|
|
https_cookie_secure
别名: https-cookie-secure
字符串
|
启用/禁用验证插入的HTTPS cookie是否安全。
选项
|
|
|
ipv6_mappedip
别名: ipv6-mappedip
字符串
|
|
ipv6_mappedport
别名: ipv6-mappedport
字符串
|
目标网络上外部端口号范围映射到的 IPv6 端口号范围。
|
ldb_method
别名: ldb-method
字符串
|
用于将会话分配到真实服务器的方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
mapped_addr
别名: mapped-addr
字符串
|
|
|
(列表) 外部IP地址映射到的目标网络上的IP地址或地址范围。
|
|
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
(列表或字符串) 轮询以确定虚拟服务器连接状态时要使用的健康检查监视器的名称。
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
启用/禁用将源NAT映射的IP强制为所有流量的外部IP。
选项
|
one_click_gslb_server
别名: one-click-gslb-server
字符串
|
启用/禁用一键式 GSLB 服务器与 FortiGSLB 集成。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
启用后,将为Microsoft Outlook Web Access添加Front-End-Https标头。
选项
|
|
配置如何确保客户端每次发出作为同一请求一部分的请求时都连接到同一服务器。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
portmapping_type
别名: portmapping-type
字符串
|
|
|
转发数据包时使用的协议。
选项
"tcp"
"udp"
"sctp"
"icmp"
|
|
|
ack_delay_exponent
别名:ack-delay-exponent
整数
|
|
active_connection_id_limit
别名:active-connection-id-limit
整数
|
|
active_migration
别名:active-migration
字符串
|
|
grease_quic_bit
别名:grease-quic-bit
字符串
|
|
max_ack_delay
别名:max-ack-delay
整数
|
|
max_datagram_frame_size
别名:max-datagram-frame-size
整数
|
|
max_idle_timeout
别名:max-idle-timeout
整数
|
|
max_udp_payload_size
别名:max-udp-payload-size
整数
|
|
|
|
|
|
client_ip
别名: client-ip
任意
|
(列表) 只有在此IP范围内的客户端才能连接到此真实服务器。
|
|
启用后,在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名: holddown-interval
整数
|
健康检查监视器继续监视应处于活动状态的无响应服务器的时间(以秒为单位)。
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
(列表或字符串) 轮询以确定虚拟服务器连接状态时要使用的健康检查监视器的名称。
|
|
|
|
|
|
将真实服务器的状态设置为活动状态,以便它可以接受流量,或者设置为待机或禁用状态,以便没有流量……
选项
"active"
"standby"
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用将虚拟服务器的主机名/IP 转换为真实服务器。
选项
|
|
|
|
|
server_type
别名: server-type
字符串
|
虚拟服务器负载均衡的协议
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
"ssh"
|
|
|
src_filter
别名: src-filter
任意
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目标。
选项
|
srcintf_filter
别名: srcintf-filter
任意
|
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
启用/禁用用于 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
根据加密强度允许的SSL会话加密算法。
选项
"high"
"medium"
"low"
"custom"
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
|
|
密码套件可使用的SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
允许、拒绝或要求安全重新协商客户端会话以符合 RFC 5746。
选项
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
要保留的最大客户端到FortiGate SSL会话状态数。
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
保留客户端到FortiGate SSL会话状态的分钟数。
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
如何使客户端和FortiGate之间SSL连接段的SSL会话过期。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
在用于SSL会话RSA加密的Diffie-Hellman交换中使用的位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
启用/禁用在响应中包含HPKP标头。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名:ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名:ssl-hpkp-report-uri
字符串
|
|
|
|
ssl_hsts_age
别名:ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名:ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名:ssl-http-location-conversion
字符串
|
启用将回复中的Location HTTP标头字段中的HTTP替换为HTTPS。
选项
|
ssl_http_match_host
别名:ssl-http-match-host
字符串
|
|
ssl_max_version
别名:ssl-max-version
字符串
|
从客户端接受的最高SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名:ssl-min-version
字符串
|
从客户端接受的最低SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
|
在客户端和FortiGate之间应用SSL卸载。
选项
|
|
|
ssl_send_empty_frags
别名:ssl-send-empty-frags
字符串
|
启用/禁用发送空片段以避免CBC IV攻击。
选项
|
ssl_server_algorithm
别名:ssl-server-algorithm
字符串
|
根据加密强度允许的SSL完全模式会话服务器端的加密算法。
选项
"high"
"low"
"medium"
"custom"
"客户端"
|
ssl_server_cipher_suites
别名:ssl-server-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
密码套件可使用的SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_server_max_version
别名:ssl-server-max-version
字符串
|
从服务器接受的最高SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_min_version
别名:ssl-server-min-version
字符串
|
从服务器接受的最低SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"客户端"
"tls-1.3"
|
ssl_server_renegotiation
别名:ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名:ssl-server-session-state-max
整数
|
要保留的最大FortiGate到服务器SSL会话状态数。
|
ssl_server_session_state_timeout
别名:ssl-server-session-state-timeout
整数
|
保留FortiGate到服务器SSL会话状态的分钟数。
|
ssl_server_session_state_type
别名:ssl-server-session-state-type
字符串
|
如何使服务器和FortiGate之间SSL连接段的SSL会话过期。
选项
"disable"
"time"
"count"
"both"
|
|
|
|
配置静态NAT、负载均衡、DNS转换或FQDN VIP。
选项
"静态NAT"
"负载均衡"
"服务器负载均衡"
"DNS转换"
"FQDN"
"访问代理"
|
|
|
weblogic_server
别名:weblogic-server
字符串
|
启用添加HTTP标头以指示WebLogic服务器的SSL卸载。
选项
|
websphere_server
别名:websphere-server
字符串
|
启用添加HTTP标头以指示WebSphere服务器的SSL卸载。
选项
|
forticloud_access_token
字符串
|
使用FortiCloud API访问令牌验证Ansible客户端。
|
|
|
|
|
|
|
|
|
workspace_locking_adom
字符串
|
在工作区模式下运行FortiManager时要锁定的ADOM,该值可以是全局的和其他值,包括root。
|
workspace_locking_timeout
整数
|
等待其他用户释放工作区锁的最大时间(秒)。
默认值: 300
|