stormshield.sns.sns_policy role – Policy configuration
Note
This role is part of the stormshield.sns collection (version 1.0.2).
It is not included in ansible-core
.
To check whether it is installed, run ansible-galaxy collection list
.
To install it use: ansible-galaxy collection install stormshield.sns
.
To use it in a playbook, specify: stormshield.sns.sns_policy
.
Entry point main
– Policy configuration
Synopsis
This role configures filter and NAT policies of Stormshield Network Security appliances.
Parameters
Parameter |
Comments |
---|---|
Activate the slot Choices:
|
|
Slot comment |
|
Filter rules |
|
ACK QID name |
|
Rule action Choices:
|
|
Use antispam analysis Choices:
|
|
Use Antivirus analysis Choices:
|
|
Apply before VPN Choices:
|
|
Rule comment |
|
Choices:
|
|
Destination geo object(<objectgeo[|objectgeo[|…]]]) |
|
Destination host reputation (<0-65535>) |
|
Destination host reputation operator Choices:
|
|
Destination interface (any|<interface name>) |
|
Destination IP reputation (<objectiprep[|objectiprep[|…]]])] |
|
Destination port (any|<objectservice>[,<objectservice>[,<objectservice>[,…]]]) |
|
Destination port operator Choices:
|
|
Destination target (any|[!]<objectname>[,<objectname>[,<objectname>[,…]]]) |
|
Enforce IPsec forward Choices:
|
|
Enforce IPsec reverse routing Choices:
|
|
Use FTP filtering Choices:
|
|
Service Choices:
|
|
ICMP code (“”|<0-255>) |
|
ICMP type (“”|<0-255>) |
|
Inbound Choices:
|
|
Inspection level Choices:
|
|
IP protocol(any|<IP protocol name>) |
|
IP state Choices:
|
|
Rule log level Choices:
|
|
Mail policy index (“”|<0-9>) |
|
Rule name |
|
NAT destination ARP Choices:
|
|
Load balancing algorithm on NAT destination IP Choices:
|
|
NAT destination port (original|<objectservice>|<port range>) |
|
Load balancing algorithm on nat destination port Choices:
|
|
NAT destination port operator Choices:
|
|
NAT destination target (“”|original|<object name>) |
|
NAT source ARP Choices:
|
|
NAT source load balancing algorithm Choices:
|
|
NAT source port (original|<objectservice>|<port range>) |
|
NAT source port loadbalancing algorithm Choices:
|
|
NAT source port operator Choices:
|
|
NAT source target (“”|original|<object name>) |
|
Don’t log the connection all|([disk],[syslog],[ipfix]) |
|
Insert at line N |
|
Application protocol (auto|none|<app protocol name>) |
|
Use cache proxy Choices:
|
|
QoS fairness Choices:
|
|
QID name |
|
(“”|<tcp>,<udp>,<icmp>,<request>) |
|
Use route (“”|\<objrouter\>|<hostname>|<ipaddr>) |
|
Rule name |
|
Use sandboxing analysis Choices:
|
|
Rule scheduling (anytime|<time object>) |
|
Security inspection index (“”|<0-9>) |
|
Set TOS Field (“”|1-254) |
|
Source geo object (<objectgeo[|\<objectgeo\>[|…]]]) |
|
Source host reputation filter (<0-65535>) |
|
Source host reputation operator Choices:
|
|
Source interface (any|<interface name>) |
|
=(<objectiprep[|\<objectiprep\>[|…]]])] |
|
Source port (any|<objectservice>[,<objectservice>[,<objectservice>[,…]]]) |
|
Source port operator Choices:
|
|
Source target (any|[!]<objectname>[,<objectname>[,<objectname>[,…]]]) |
|
Source user (“”|any|unknown|[!]<user>|[!]<usergroup>) |
|
Source user domain (“”|<domain name>) |
|
Source user authentication method Choices:
|
|
Source user type (“”|user|group) |
|
SSL policy index (|<0-9>) |
|
Rule state Choices:
|
|
SYN proxy Choices:
|
|
Filter TOS field (“”|<1-254>) |
|
URL policy index (“”|<0-9>) |
|
Via Choices:
|
|
Web portal exception (“”|urlgroup[,urlgroup[,urlgroup[,…]]]) |
|
Rule add mode Choices:
|
|
NAT rules |
|
ACK QID name |
|
Rule action Choices:
|
|
Use antispam analysis Choices:
|
|
Use Antivirus analysis Choices:
|
|
Apply before VPN Choices:
|
|
Rule comment |
|
Choices:
|
|
Destination geo object(<objectgeo[|objectgeo[|…]]]) |
|
Destination host reputation (<0-65535>) |
|
Destination host reputation operator Choices:
|
|
Destination interface (any|<interface name>) |
|
Destination IP reputation (<objectiprep[|objectiprep[|…]]])] |
|
Destination port (any|<objectservice>[,<objectservice>[,<objectservice>[,…]]]) |
|
Destination port operator Choices:
|
|
Destination target (any|[!]<objectname>[,<objectname>[,<objectname>[,…]]]) |
|
Enforce IPsec forward Choices:
|
|
Enforce IPsec reverse routing Choices:
|
|
Use FTP filtering Choices:
|
|
Service Choices:
|
|
ICMP code (“”|<0-255>) |
|
ICMP type (“”|<0-255>) |
|
Inbound Choices:
|
|
Inspection level Choices:
|
|
IP protocol(any|<IP protocol name>) |
|
IP state Choices:
|
|
Rule log level Choices:
|
|
Mail policy index (“”|<0-9>) |
|
Rule name |
|
NAT destination ARP Choices:
|
|
Load balancing algorithm on NAT destination IP Choices:
|
|
NAT destination port (original|<objectservice>|<port range>) |
|
Load balancing algorithm on nat destination port Choices:
|
|
NAT destination port operator Choices:
|
|
NAT destination target (“”|original|<object name>) |
|
NAT source ARP Choices:
|
|
NAT source load balancing algorithm Choices:
|
|
NAT source port (original|<objectservice>|<port range>) |
|
NAT source port loadbalancing algorithm Choices:
|
|
NAT source port operator Choices:
|
|
NAT source target (“”|original|<object name>) |
|
Don’t log the connection all|([disk],[syslog],[ipfix]) |
|
Insert at line N |
|
Application protocol (auto|none|<app protocol name>) |
|
Use cache proxy Choices:
|
|
QoS fairness Choices:
|
|
QID name |
|
(“”|<tcp>,<udp>,<icmp>,<request>) |
|
Use route (“”|\<objrouter\>|<hostname>|<ipaddr>) |
|
Rule name |
|
Use sandboxing analysis Choices:
|
|
Rule scheduling (anytime|<time object>) |
|
Security inspection index (“”|<0-9>) |
|
Set TOS Field (“”|1-254) |
|
Source geo object (<objectgeo[|\<objectgeo\>[|…]]]) |
|
Source host reputation filter (<0-65535>) |
|
Source host reputation operator Choices:
|
|
Source interface (any|<interface name>) |
|
=(<objectiprep[|\<objectiprep\>[|…]]])] |
|
Source port (any|<objectservice>[,<objectservice>[,<objectservice>[,…]]]) |
|
Source port operator Choices:
|
|
Source target (any|[!]<objectname>[,<objectname>[,<objectname>[,…]]]) |
|
Source user (“”|any|unknown|[!]<user>|[!]<usergroup>) |
|
Source user domain (“”|<domain name>) |
|
Source user authentication method Choices:
|
|
Source user type (“”|user|group) |
|
SSL policy index (|<0-9>) |
|
Rule state Choices:
|
|
SYN proxy Choices:
|
|
Filter TOS field (“”|<1-254>) |
|
URL policy index (“”|<0-9>) |
|
Via Choices:
|
|
Web portal exception (“”|urlgroup[,urlgroup[,urlgroup[,…]]]) |
|
Use local or global slot Choices:
|
|
Slot number |
|
Name of the slot |