|
无需使用用户名和密码即可访问 FortiManager 的令牌。
|
|
|
|
仅当模块模式与 FortiManager API 结构不同时设置为 True,模块将继续执行而无需验证参数。
选项
|
|
|
|
|
add_nat64_route
别名:add-nat64-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
启用对该虚拟 IP 地址的 ARP 请求的响应。
选项
|
|
|
|
|
dynamic_mapping
列表 / 元素=字典
|
|
|
|
|
|
|
|
add_nat64_route
别名:add-nat64-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
|
|
|
|
|
embedded_ipv4_address
别名:embedded-ipv4-address
字符串
|
启用/禁用将外部 IPv6 地址的低 32 位用作映射的 IPv4 地址。
选项
|
|
|
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
|
http_ip_header_name
别名:http-ip-header-name
字符串
|
|
http_multiplex
别名:http-multiplex
字符串
|
|
http_redirect
别名:http-redirect
字符串
|
|
https_cookie_secure
别名:https-cookie-secure
字符串
|
|
|
|
ipv4_mappedip
别名:ipv4-mappedip
字符串
|
|
ipv4_mappedport
别名:ipv4-mappedport
字符串
|
目标网络上将外部端口号范围映射到的 IPv4 端口号范围。
|
ldb_method
别名:ldb-method
字符串
|
LDB 方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
|
|
|
|
max_embryonic_connections
别名:max-embryonic-connections
整数
|
|
|
|
|
|
|
|
nat_source_vip
别名:nat-source-vip
字符串
|
|
ndp_reply
别名:ndp-reply
字符串
|
启用/禁用此 FortiGate 设备响应此虚拟 IP 地址的 NDP 请求的能力
选项
|
outlook_web_access
别名:outlook-web-access
字符串
|
|
|
持久性。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
|
|
|
|
client_ip
别名:client-ip
字符串
|
只有在此 IP 范围内的客户端才能连接到此真实服务器。
|
|
启用后,在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名:holddown-interval
整数
|
健康检查监控器持续监控无响应服务器的时间(以秒为单位)……
|
http_host
别名:http-host
字符串
|
|
|
|
|
|
max_connections
别名:max-connections
整数
|
|
|
(列表或字符串) 轮询以确定虚拟服务器连接时要使用的健康检查监控器的名称……
|
|
|
|
将真实服务器的状态设置为活动状态,以便它可以接受流量,或者设置为备用或禁用状态,以便不……
选项
"active"
"standby"
"disable"
|
translate_host
别名:translate-host
字符串
|
启用/禁用从虚拟服务器到真实服务器的主机名/IP 地址转换。
选项
|
|
|
server_type
别名:server-type
字符串
|
服务器类型。
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
|
src_filter
别名:src-filter
任意
|
|
src_vip_filter
别名:src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目标。
选项
|
ssl_accept_ffdhe_groups
别名:ssl-accept-ffdhe-groups
字符串
|
启用/禁用 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名:ssl-algorithm
字符串
|
SSL 算法。
选项
"high"
"low"
"medium"
"custom"
|
ssl_certificate
别名:ssl-certificate
字符串
|
|
ssl_cipher_suites
别名:ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名:ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名:ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名:ssl-client-renegotiation
字符串
|
|
ssl_client_session_state_max
别名:ssl-client-session-state-max
整数
|
|
ssl_client_session_state_timeout
别名:ssl-client-session-state-timeout
整数
|
|
ssl_client_session_state_type
别名:ssl-client-session-state-type
字符串
|
SSL 客户端会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名:ssl-dh-bits
字符串
|
SSL DH 比特数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
|
SSL HPKP。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名:ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名:ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名:ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名:ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名:ssl-hpkp-report-uri
字符串
|
|
|
|
ssl_hsts_age
别名:ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名:ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名:ssl-http-location-conversion
字符串
|
|
ssl_http_match_host
别名:ssl-http-match-host
字符串
|
|
ssl_max_version
别名:ssl-max-version
字符串
|
SSL 最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名:ssl-min-version
字符串
|
SSL 最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
|
|
|
|
ssl_send_empty_frags
别名:ssl-send-empty-frags
字符串
|
|
ssl_server_algorithm
别名:ssl-server-algorithm
字符串
|
SSL 服务器算法。
选项
"high"
"low"
"medium"
"custom"
"client"
|
ssl_server_max_version
别名:ssl-server-max-version
字符串
|
SSL 服务器最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_min_version
别名:ssl-server-min-version
字符串
|
SSL 服务器最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_renegotiation
别名:ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名:ssl-server-session-state-max
整数
|
|
ssl_server_session_state_timeout
别名:ssl-server-session-state-timeout
整数
|
|
ssl_server_session_state_type
别名:ssl-server-session-state-type
字符串
|
SSL 服务器会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
|
类型。
选项
"static-nat"
"server-load-balance"
"access-proxy"
|
|
|
weblogic_server
别名:weblogic-server
字符串
|
|
websphere_server
别名:websphere-server
字符串
|
|
embedded_ipv4_address
别名:embedded-ipv4-address
字符串
|
启用/禁用将外部 IPv6 地址的低 32 位用作映射的 IPv4 地址。
选项
|
|
您想要映射到目标地址或地址范围的外部接口上的 IP 地址或地址范围……
|
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
客户端Web浏览器应保留Cookie的时间(以分钟为单位)。
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
启用/禁用使用HTTP中的主机字段中的HTTP Cookie域。
选项
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
对于HTTP多路复用,启用此选项可在XForwarded-For HTTP标头中添加原始客户端IP地址。
选项
|
http_ip_header_name
别名:http-ip-header-name
字符串
|
对于HTTP多路复用,输入自定义HTTPS标头名称。
|
http_multiplex
别名:http-multiplex
字符串
|
|
http_redirect
别名:http-redirect
字符串
|
|
https_cookie_secure
别名:https-cookie-secure
字符串
|
启用/禁用验证插入的HTTPS Cookie是否安全。
选项
|
|
|
ipv4_mappedip
别名:ipv4-mappedip
字符串
|
|
ipv4_mappedport
别名:ipv4-mappedport
字符串
|
目标网络上将外部端口号范围映射到的 IPv4 端口号范围。
|
ldb_method
别名:ldb-method
字符串
|
用于将会话分发到真实服务器的方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
|
映射的IP地址范围,格式为startIP-endIP。
|
|
目标网络上的端口号范围,外部端口号范围将映射到该范围。
|
max_embryonic_connections
别名:max-embryonic-connections
整数
|
|
|
(列表或字符串)轮询以确定虚拟服务器连接状态时要使用的运行状况检查监视器的名称。
|
|
|
|
|
|
|
nat_source_vip
别名:nat-source-vip
字符串
|
启用此选项可在所有出站接口上对来自mappedip到extip的流量执行SNAT。
选项
|
ndp_reply
别名:ndp-reply
字符串
|
启用/禁用此 FortiGate 设备响应此虚拟 IP 地址的 NDP 请求的能力
选项
|
outlook_web_access
别名:outlook-web-access
字符串
|
启用此选项可为Microsoft Outlook Web Access添加Front-End-Https标头。
选项
|
|
配置如何确保客户端每次发出属于同一…的请求时都连接到同一服务器。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
|
|
|
|
ack_delay_exponent
别名:ack-delay-exponent
整数
|
|
active_connection_id_limit
别名:active-connection-id-limit
整数
|
|
active_migration
别名:active-migration
字符串
|
|
grease_quic_bit
别名:grease-quic-bit
字符串
|
|
max_ack_delay
别名:max-ack-delay
整数
|
|
max_datagram_frame_size
别名:max-datagram-frame-size
整数
|
|
max_idle_timeout
别名:max-idle-timeout
整数
|
|
max_udp_payload_size
别名:max-udp-payload-size
整数
|
|
|
|
client_ip
别名:client-ip
字符串
|
只有在此 IP 范围内的客户端才能连接到此真实服务器。
|
|
启用后,在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名:holddown-interval
整数
|
运行状况检查监视器继续监视应处于活动状态的无响应服务器的时间(以秒为单位)。
|
http_host
别名:http-host
字符串
|
|
|
|
|
|
max_connections
别名:max-connections
整数
|
|
|
(列表或字符串)轮询以确定虚拟服务器连接状态时要使用的运行状况检查监视器的名称。
|
|
|
|
将真实服务器的状态设置为活动状态,以便它可以接受流量,或者设置为待机状态或禁用状态,以便没有流量…
选项
"active"
"standby"
"disable"
|
translate_host
别名:translate-host
字符串
|
启用/禁用从虚拟服务器到真实服务器的主机名/IP 地址转换。
选项
|
|
|
server_type
别名:server-type
字符串
|
虚拟服务器要负载均衡的协议
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
|
src_filter
别名:src-filter
任意
|
|
src_vip_filter
别名:src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目标。
选项
|
ssl_accept_ffdhe_groups
别名:ssl-accept-ffdhe-groups
字符串
|
启用/禁用 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名:ssl-algorithm
字符串
|
根据加密强度允许的SSL会话加密算法。
选项
"high"
"low"
"medium"
"custom"
|
ssl_certificate
别名:ssl-certificate
字符串
|
|
ssl_cipher_suites
别名:ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名:ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名:ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名:ssl-client-renegotiation
字符串
|
允许、拒绝或要求安全重新协商客户端会话以符合RFC 5746。
选项
|
ssl_client_session_state_max
别名:ssl-client-session-state-max
整数
|
要保留的客户端到FortiGate SSL会话状态的最大数量。
|
ssl_client_session_state_timeout
别名:ssl-client-session-state-timeout
整数
|
保留客户端到FortiGate SSL会话状态的分钟数。
|
ssl_client_session_state_type
别名:ssl-client-session-state-type
字符串
|
如何使客户端与FortiGate之间的SSL连接段的SSL会话过期。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名:ssl-dh-bits
字符串
|
在用于RSA加密SSL会话的Diffie-Hellman交换中使用的位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
|
启用/禁用在响应中包含HPKP标头。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名:ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名:ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名:ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名:ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名:ssl-hpkp-report-uri
字符串
|
|
|
|
ssl_hsts_age
别名:ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名:ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名:ssl-http-location-conversion
字符串
|
启用此选项可在回复的Location HTTP标头字段中将HTTP替换为HTTPS。
选项
|
ssl_http_match_host
别名:ssl-http-match-host
字符串
|
|
ssl_max_version
别名:ssl-max-version
字符串
|
客户端可接受的最高SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名:ssl-min-version
字符串
|
客户端可接受的最低SSL/TLS版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
|
在客户端和FortiGate之间应用SSL卸载。
选项
|
|
|
ssl_send_empty_frags
别名:ssl-send-empty-frags
字符串
|
启用/禁用发送空片段以避免 CBC IV 攻击
选项
|
ssl_server_algorithm
别名:ssl-server-algorithm
字符串
|
根据加密强度,允许用于 SSL 全模式会话服务器端的加密算法。
选项
"high"
"low"
"medium"
"custom"
"client"
|
ssl_server_cipher_suites
别名:ssl-server-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
密码套件可使用的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_server_max_version
别名:ssl-server-max-version
字符串
|
服务器可接受的最高 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_min_version
别名:ssl-server-min-version
字符串
|
服务器可接受的最低 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_renegotiation
别名:ssl-server-renegotiation
字符串
|
启用/禁用安全重新协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名:ssl-server-session-state-max
整数
|
FortiGate 与服务器之间需要保持的最大 SSL 会话状态数。
|
ssl_server_session_state_timeout
别名:ssl-server-session-state-timeout
整数
|
保持 FortiGate 与服务器之间 SSL 会话状态的分钟数。
|
ssl_server_session_state_type
别名:ssl-server-session-state-type
字符串
|
如何使服务器和 FortiGate 之间 SSL 连接段的 SSL 会话过期。
选项
"disable"
"time"
"count"
"both"
|
|
配置静态 NAT VIP。
选项
"static-nat"
"server-load-balance"
"access-proxy"
|
|
|
weblogic_server
别名:weblogic-server
字符串
|
启用后,将添加 HTTP 头以指示 WebLogic 服务器的 SSL 卸载。
选项
|
websphere_server
别名:websphere-server
字符串
|
启用后,将添加 HTTP 头以指示 WebSphere 服务器的 SSL 卸载。
选项
|
forticloud_access_token
字符串
|
使用 FortiCloud API 访问令牌验证 Ansible 客户端。
|
|
|
|
|
|
|
|
|
workspace_locking_adom
字符串
|
在工作区模式下运行 FortiManager 时需要锁定的 ADOM,值可以是 global 和其他值,包括 root。
|
workspace_locking_timeout
整数
|
等待其他用户释放工作区锁定的最大时间(秒)。
默认值: 300
|