|
无需使用用户名和密码即可访问 FortiManager 的令牌。
|
|
|
|
仅当模块架构与 FortiManager API 结构不同时才设置为 True,模块将继续执行而不验证参数。
选项
|
|
|
|
|
add_nat46_route
别名:add-nat46-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
启用以响应此虚拟 IP 地址的 ARP 请求。
选项
|
|
|
|
|
dns_mapping_ttl
别名:dns-mapping-ttl
整数
|
|
dynamic_mapping
列表 / 元素=字典
|
|
|
|
|
|
|
|
add_nat46_route
别名:add-nat46-route
字符串
|
|
arp_reply
别名:arp-reply
字符串
|
|
|
|
|
|
dns_mapping_ttl
别名:dns-mapping-ttl
整数
|
|
|
|
|
|
|
|
|
|
gratuitous_arp_interval
别名:gratuitous-arp-interval
整数
|
|
gslb_domain_name
别名:gslb-domain-name
字符串
|
|
gslb_hostname
别名:gslb-hostname
字符串
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
|
http_ip_header_name
别名: http-ip-header-name
字符串
|
|
http_multiplex
别名: http-multiplex
字符串
|
|
http_multiplex_max_concurrent_request
别名: http-multiplex-max-concurrent-request
整数
|
|
http_multiplex_max_request
别名: http-multiplex-max-request
整数
|
多路复用服务器在断开会话之前可以处理的最大请求数。
|
http_multiplex_ttl
别名: http-multiplex-ttl
整数
|
|
http_redirect
别名: http-redirect
字符串
|
|
http_supported_max_version
别名: http-supported-max-version
字符串
|
|
https_cookie_secure
别名: https-cookie-secure
字符串
|
|
|
|
ipv6_mappedip
别名: ipv6-mappedip
字符串
|
|
ipv6_mappedport
别名: ipv6-mappedport
字符串
|
目标网络上的 IPv6 端口号范围,外部端口号范围映射到该范围。
|
ldb_method
别名: ldb-method
字符串
|
LDB 方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
mapped_addr
别名: mapped-addr
字符串
|
|
|
|
|
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
|
one_click_gslb_server
别名: one-click-gslb-server
字符串
|
启用/禁用与 FortiGSLB 的一键式 GSLB 服务器集成。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
|
|
持久性。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
portmapping_type
别名: portmapping-type
字符串
|
|
|
协议。
选项
"tcp"
"udp"
"sctp"
"icmp"
|
|
|
|
|
client_ip
别名: client-ip
任意
|
|
health_check_proto
别名: health-check-proto
字符串
|
|
|
|
holddown_interval
别名: holddown-interval
整数
|
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
|
|
|
|
|
|
状态。
选项
"active"
"standby"
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用从虚拟服务器到真实服务器的主机名/IP 转换。
选项
|
|
|
|
|
server_type
别名: server-type
字符串
|
服务器类型。
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
"ssh"
|
|
|
src_filter
别名: src-filter
任意
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目的地。
选项
|
srcintf_filter
别名: srcintf-filter
任意
|
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
启用/禁用用于 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
SSL 算法。
选项
"high"
"medium"
"low"
"custom"
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
|
|
版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
SSL客户端会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
SSL DH 位数。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
SSL HPKP。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名: ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名: ssl-hpkp-report-uri
字符串
|
|
ssl_hsts
别名: ssl-hsts
字符串
|
|
ssl_hsts_age
别名: ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名: ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名: ssl-http-location-conversion
字符串
|
|
ssl_http_match_host
别名: ssl-http-match-host
字符串
|
|
ssl_max_version
别名: ssl-max-version
字符串
|
SSL 最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名: ssl-min-version
字符串
|
SSL 最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_mode
别名: ssl-mode
字符串
|
|
|
|
ssl_send_empty_frags
别名: ssl-send-empty-frags
字符串
|
|
ssl_server_algorithm
别名: ssl-server-algorithm
字符串
|
SSL 服务器算法。
选项
"high"
"low"
"medium"
"custom"
"client"
|
ssl_server_max_version
别名: ssl-server-max-version
字符串
|
SSL 服务器最大版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_min_version
别名: ssl-server-min-version
字符串
|
SSL 服务器最小版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_renegotiation
别名: ssl-server-renegotiation
字符串
|
启用/禁用安全重协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名: ssl-server-session-state-max
整数
|
|
ssl_server_session_state_timeout
别名: ssl-server-session-state-timeout
整数
|
|
ssl_server_session_state_type
别名: ssl-server-session-state-type
字符串
|
SSL 服务器会话状态类型。
选项
"disable"
"time"
"count"
"both"
|
|
|
|
类型。
选项
"static-nat"
"load-balance"
"server-load-balance"
"dns-translation"
"fqdn"
"access-proxy"
|
|
|
weblogic_server
别名: weblogic-server
字符串
|
|
websphere_server
别名: websphere-server
字符串
|
|
|
|
|
连接到源网络的接口,该接口接收将转发到目标网络的数据包。
|
|
外部接口上的 IP 地址或地址范围,您希望将其映射到目标上的地址或地址范围。
|
|
传入端口号范围,您希望将其映射到目标网络上的端口号范围。
|
gratuitous_arp_interval
别名:gratuitous-arp-interval
整数
|
|
gslb_domain_name
别名:gslb-domain-name
字符串
|
|
gslb_hostname
别名:gslb-hostname
字符串
|
|
gslb_public_ips
别名: gslb-public-ips
列表 / 元素=字典
|
|
|
|
|
|
h2_support
别名:h2-support
字符串
|
|
h3_support
别名:h3-support
字符串
|
|
http_cookie_age
别名:http-cookie-age
整数
|
客户端 Web 浏览器应保留 cookie 的分钟数。
|
http_cookie_domain
别名:http-cookie-domain
字符串
|
|
http_cookie_domain_from_host
别名:http-cookie-domain-from-host
字符串
|
启用/禁用从 HTTP 中的主机字段使用 HTTP cookie 域。
选项
|
http_cookie_generation
别名:http-cookie-generation
整数
|
|
http_cookie_path
别名:http-cookie-path
字符串
|
将 HTTP cookie 持久性限制为指定的路径。
|
http_cookie_share
别名:http-cookie-share
字符串
|
|
http_ip_header
别名:http-ip-header
字符串
|
对于 HTTP 多路复用,启用此选项以在 XForwarded-For HTTP 标头中添加原始客户端 IP 地址。
选项
|
http_ip_header_name
别名: http-ip-header-name
字符串
|
对于 HTTP 多路复用,请输入自定义 HTTPS 标头名称。
|
http_multiplex
别名: http-multiplex
字符串
|
|
http_multiplex_max_concurrent_request
别名: http-multiplex-max-concurrent-request
整数
|
|
http_multiplex_max_request
别名: http-multiplex-max-request
整数
|
多路复用服务器在断开会话之前可以处理的最大请求数。
|
http_multiplex_ttl
别名: http-multiplex-ttl
整数
|
|
http_redirect
别名: http-redirect
字符串
|
启用/禁用将 HTTP 重定向到 HTTPS
选项
|
http_supported_max_version
别名: http-supported-max-version
字符串
|
|
https_cookie_secure
别名: https-cookie-secure
字符串
|
启用/禁用对插入的 HTTPS cookie 是否安全的验证。
选项
|
|
|
ipv6_mappedip
别名: ipv6-mappedip
字符串
|
|
ipv6_mappedport
别名: ipv6-mappedport
字符串
|
目标网络上的 IPv6 端口号范围,外部端口号范围映射到该范围。
|
ldb_method
别名: ldb-method
字符串
|
用于将会话分配给真实服务器的方法。
选项
"static"
"round-robin"
"weighted"
"least-session"
"least-rtt"
"first-alive"
"http-host"
|
mapped_addr
别名: mapped-addr
字符串
|
|
|
(列表)目标网络上外部 IP 地址映射到的 IP 地址或地址范围。
|
|
目标网络上的端口号范围,外部端口号范围映射到该范围。
|
max_embryonic_connections
别名: max-embryonic-connections
整数
|
|
|
(列表或字符串)用于轮询以确定虚拟服务器连接状态的运行状况检查监视器的名称。
|
|
|
|
|
|
|
nat_source_vip
别名: nat-source-vip
字符串
|
启用/禁用强制将所有流量的源 NAT 映射 IP 设置为外部 IP。
选项
|
one_click_gslb_server
别名: one-click-gslb-server
字符串
|
启用/禁用与 FortiGSLB 的一键式 GSLB 服务器集成。
选项
|
outlook_web_access
别名: outlook-web-access
字符串
|
启用此选项可为 Microsoft Outlook Web Access 添加 Front-End-Https 标头。
选项
|
|
配置如何确保客户端每次发出同一会话的一部分的请求时都连接到同一服务器。
选项
"none"
"http-cookie"
"ssl-session-id"
|
|
|
portmapping_type
别名: portmapping-type
字符串
|
|
|
转发数据包时使用的协议。
选项
"tcp"
"udp"
"sctp"
"icmp"
|
|
|
ack_delay_exponent
别名: ack-delay-exponent
整数
|
|
active_connection_id_limit
别名: active-connection-id-limit
整数
|
|
active_migration
别名: active-migration
字符串
|
|
grease_quic_bit
别名: grease-quic-bit
字符串
|
|
max_ack_delay
别名: max-ack-delay
整数
|
|
max_datagram_frame_size
别名: max-datagram-frame-size
整数
|
|
max_idle_timeout
别名: max-idle-timeout
整数
|
|
max_udp_payload_size
别名: max-udp-payload-size
整数
|
|
|
|
|
|
client_ip
别名: client-ip
任意
|
(列表) 只有此 IP 范围内的客户端才能连接到此真实服务器。
|
|
启用以在转发流量之前检查真实服务器的响应能力。
选项
|
holddown_interval
别名: holddown-interval
整数
|
运行状况检查监视器继续监视应处于活动状态的无响应服务器的秒数。
|
http_host
别名: http-host
字符串
|
|
|
|
|
|
max_connections
别名: max-connections
整数
|
|
|
(列表或字符串)用于轮询以确定虚拟服务器连接状态的运行状况检查监视器的名称。
|
|
|
|
|
|
将真实服务器的状态设置为活动,以便它可以接受流量,或者设置为备用或禁用,以便不接受流量...
选项
"active"
"standby"
"disable"
|
translate_host
别名: translate-host
字符串
|
启用/禁用从虚拟服务器到真实服务器的主机名/IP 转换。
选项
|
|
|
|
|
server_type
别名: server-type
字符串
|
虚拟服务器要进行负载平衡的协议
选项
"http"
"https"
"ssl"
"tcp"
"udp"
"ip"
"imaps"
"pop3s"
"smtps"
"ssh"
|
|
|
src_filter
别名: src-filter
任意
|
|
src_vip_filter
别名: src-vip-filter
字符串
|
启用/禁用使用 src-filter 来匹配反向 SNAT 规则的目的地。
选项
|
srcintf_filter
别名: srcintf-filter
任意
|
|
ssl_accept_ffdhe_groups
别名: ssl-accept-ffdhe-groups
字符串
|
启用/禁用用于 SSL 密钥交换的 FFDHE 密码套件。
选项
|
ssl_algorithm
别名: ssl-algorithm
字符串
|
根据加密强度,允许用于 SSL 会话的加密算法。
选项
"high"
"medium"
"low"
"custom"
|
ssl_certificate
别名: ssl-certificate
字符串
|
|
ssl_cipher_suites
别名: ssl-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
|
|
可以使用密码套件的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_client_fallback
别名: ssl-client-fallback
字符串
|
|
ssl_client_rekey_count
别名: ssl-client-rekey-count
整数
|
|
ssl_client_renegotiation
别名: ssl-client-renegotiation
字符串
|
允许、拒绝或要求安全地重新协商客户端会话以符合 RFC 5746。
选项
|
ssl_client_session_state_max
别名: ssl-client-session-state-max
整数
|
要保留的客户端到 FortiGate SSL 会话状态的最大数量。
|
ssl_client_session_state_timeout
别名: ssl-client-session-state-timeout
整数
|
保持客户端到 FortiGate SSL 会话状态的分钟数。
|
ssl_client_session_state_type
别名: ssl-client-session-state-type
字符串
|
如何为客户端和 FortiGate 之间的 SSL 连接段过期 SSL 会话。
选项
"disable"
"time"
"count"
"both"
|
ssl_dh_bits
别名: ssl-dh-bits
字符串
|
在 Diffie-Hellman 交换中使用多少位用于 SSL 会话的 RSA 加密。
选项
"768"
"1024"
"1536"
"2048"
"3072"
"4096"
|
ssl_hpkp
别名: ssl-hpkp
字符串
|
启用/禁用在响应中包含 HPKP 标头。
选项
"disable"
"enable"
"report-only"
|
ssl_hpkp_age
别名: ssl-hpkp-age
整数
|
|
ssl_hpkp_backup
别名: ssl-hpkp-backup
字符串
|
|
ssl_hpkp_include_subdomains
别名: ssl-hpkp-include-subdomains
字符串
|
|
ssl_hpkp_primary
别名: ssl-hpkp-primary
字符串
|
|
ssl_hpkp_report_uri
别名: ssl-hpkp-report-uri
字符串
|
|
ssl_hsts
别名: ssl-hsts
字符串
|
|
ssl_hsts_age
别名: ssl-hsts-age
整数
|
|
ssl_hsts_include_subdomains
别名: ssl-hsts-include-subdomains
字符串
|
|
ssl_http_location_conversion
别名: ssl-http-location-conversion
字符串
|
启用以将回复的位置 HTTP 标头字段中的 HTTP 替换为 HTTPS。
选项
|
ssl_http_match_host
别名: ssl-http-match-host
字符串
|
启用/禁用用于位置转换的 HTTP 主机匹配。
选项
|
ssl_max_version
别名: ssl-max-version
字符串
|
客户端可接受的最高 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_min_version
别名: ssl-min-version
字符串
|
客户端可接受的最低 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_mode
别名: ssl-mode
字符串
|
在客户端和 FortiGate 之间应用 SSL 卸载
选项
|
|
|
ssl_send_empty_frags
别名: ssl-send-empty-frags
字符串
|
启用/禁用发送空片段以避免 CBC IV 攻击
选项
|
ssl_server_algorithm
别名: ssl-server-algorithm
字符串
|
根据加密强度,允许用于 SSL 完全模式会话的服务器端的加密算法。
选项
"high"
"low"
"medium"
"custom"
"client"
|
ssl_server_cipher_suites
别名: ssl-server-cipher-suites
列表 / 元素=字典
|
|
|
密码套件名称。
选项
"TLS-RSA-WITH-RC4-128-MD5"
"TLS-RSA-WITH-RC4-128-SHA"
"TLS-RSA-WITH-DES-CBC-SHA"
"TLS-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA"
"TLS-RSA-WITH-AES-256-CBC-SHA"
"TLS-RSA-WITH-AES-128-CBC-SHA256"
"TLS-RSA-WITH-AES-256-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-RSA-WITH-SEED-CBC-SHA"
"TLS-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-RSA-WITH-DES-CBC-SHA"
"TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-DHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-RSA-WITH-SEED-CBC-SHA"
"TLS-DHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-RC4-128-SHA"
"TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA"
"TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256"
"TLS-DHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-DHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA"
"TLS-DHE-DSS-WITH-AES-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-128-GCM-SHA256"
"TLS-DHE-DSS-WITH-AES-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA"
"TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
"TLS-RSA-WITH-AES-128-GCM-SHA256"
"TLS-RSA-WITH-AES-256-GCM-SHA384"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA"
"TLS-DHE-DSS-WITH-CAMELLIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-CAMELLIA-256-CBC-SHA256"
"TLS-DHE-DSS-WITH-SEED-CBC-SHA"
"TLS-DHE-DSS-WITH-ARIA-128-CBC-SHA256"
"TLS-DHE-DSS-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-RSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-RSA-WITH-ARIA-256-CBC-SHA384"
"TLS-ECDHE-ECDSA-WITH-ARIA-128-CBC-SHA256"
"TLS-ECDHE-ECDSA-WITH-ARIA-256-CBC-SHA384"
"TLS-DHE-DSS-WITH-3DES-EDE-CBC-SHA"
"TLS-DHE-DSS-WITH-DES-CBC-SHA"
"TLS-AES-128-GCM-SHA256"
"TLS-AES-256-GCM-SHA384"
"TLS-CHACHA20-POLY1305-SHA256"
"TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA"
|
|
|
|
可以使用密码套件的 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"tls-1.3"
|
ssl_server_max_version
别名: ssl-server-max-version
字符串
|
服务器可接受的最高 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_min_version
别名: ssl-server-min-version
字符串
|
服务器可接受的最低 SSL/TLS 版本。
选项
"ssl-3.0"
"tls-1.0"
"tls-1.1"
"tls-1.2"
"client"
"tls-1.3"
|
ssl_server_renegotiation
别名: ssl-server-renegotiation
字符串
|
启用/禁用安全重协商以符合 RFC 5746。
选项
|
ssl_server_session_state_max
别名: ssl-server-session-state-max
整数
|
要保留的 FortiGate 到服务器 SSL 会话状态的最大数量。
|
ssl_server_session_state_timeout
别名: ssl-server-session-state-timeout
整数
|
保持 FortiGate 到服务器 SSL 会话状态的分钟数。
|
ssl_server_session_state_type
别名: ssl-server-session-state-type
字符串
|
如何为服务器和 FortiGate 之间的 SSL 连接段过期 SSL 会话。
选项
"disable"
"time"
"count"
"both"
|
|
|
|
配置静态 NAT、负载平衡、DNS 转换或 FQDN VIP。
选项
"static-nat"
"load-balance"
"server-load-balance"
"dns-translation"
"fqdn"
"access-proxy"
|
|
|
weblogic_server
别名: weblogic-server
字符串
|
启用以添加 HTTP 标头,指示 WebLogic 服务器的 SSL 卸载。
选项
|
websphere_server
别名: websphere-server
字符串
|
启用以添加 HTTP 标头,指示 WebSphere 服务器的 SSL 卸载。
选项
|
forticloud_access_token
字符串
|
使用 forticloud API 访问令牌验证 Ansible 客户端。
|
|
|
rc_failed
list / elements=integer
|
|
rc_succeeded
list / elements=integer
|
|
|
|
workspace_locking_adom
字符串
|
要在工作区模式下运行的 FortiManager 中锁定的 adom,值可以是全局的和其他的,包括 root。
|
workspace_locking_timeout
整数
|
等待其他用户释放工作区锁定的最长时间(秒)。
默认值: 300
|