Fortios v0.0.6 published on Tuesday, Jul 9, 2024 by pulumiverse
fortios.vpn/ssl.getSettings
Explore with Pulumi AI
Use this data source to get information on fortios vpnssl settings
Using getSettings
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getSettings(args: GetSettingsArgs, opts?: InvokeOptions): Promise<GetSettingsResult>
function getSettingsOutput(args: GetSettingsOutputArgs, opts?: InvokeOptions): Output<GetSettingsResult>
def get_settings(vdomparam: Optional[str] = None,
opts: Optional[InvokeOptions] = None) -> GetSettingsResult
def get_settings_output(vdomparam: Optional[pulumi.Input[str]] = None,
opts: Optional[InvokeOptions] = None) -> Output[GetSettingsResult]
func LookupSettings(ctx *Context, args *LookupSettingsArgs, opts ...InvokeOption) (*LookupSettingsResult, error)
func LookupSettingsOutput(ctx *Context, args *LookupSettingsOutputArgs, opts ...InvokeOption) LookupSettingsResultOutput
> Note: This function is named LookupSettings
in the Go SDK.
public static class GetSettings
{
public static Task<GetSettingsResult> InvokeAsync(GetSettingsArgs args, InvokeOptions? opts = null)
public static Output<GetSettingsResult> Invoke(GetSettingsInvokeArgs args, InvokeOptions? opts = null)
}
public static CompletableFuture<GetSettingsResult> getSettings(GetSettingsArgs args, InvokeOptions options)
// Output-based functions aren't available in Java yet
fn::invoke:
function: fortios:vpn/ssl/getSettings:getSettings
arguments:
# arguments dictionary
The following arguments are supported:
- Vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- Vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- vdomparam String
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- vdomparam str
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- vdomparam String
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
getSettings Result
The following output properties are available:
- Algorithm string
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- Auth
Session stringCheck Source Ip - Enable/disable checking of source IP for authentication session.
- Auth
Timeout int - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- Authentication
Rules List<Pulumiverse.Fortios. Vpn. Ssl. Outputs. Get Settings Authentication Rule> - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - Auto
Tunnel stringStatic Route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- Banned
Cipher string - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- Browser
Language stringDetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- Check
Referer string - Enable/disable verification of referer field in HTTP request header.
- Ciphersuite string
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- Client
Sigalgs string - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- Default
Portal string - Default SSL VPN portal.
- Deflate
Compression intLevel - Compression level (0~9).
- Deflate
Min intData Size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- Dns
Server1 string - DNS server 1.
- Dns
Server2 string - DNS server 2.
- Dns
Suffix string - DNS suffix used for SSL-VPN clients.
- Dtls
Heartbeat intFail Count - Number of missing heartbeats before the connection is considered dropped.
- Dtls
Heartbeat intIdle Timeout - Idle timeout before DTLS heartbeat is sent.
- Dtls
Heartbeat intInterval - Interval between DTLS heartbeat.
- Dtls
Hello intTimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- Dtls
Max stringProto Ver - DTLS maximum protocol version.
- Dtls
Min stringProto Ver - DTLS minimum protocol version.
- Dtls
Tunnel string - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- Dual
Stack stringMode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- Encode2f
Sequence string - Encode \2F sequence to forward slash in URLs.
- Encrypt
And stringStore Password - Encrypt and store user passwords for SSL-VPN web sessions.
- Force
Two stringFactor Auth - Enable to force two-factor authentication for all SSL-VPNs.
- Header
XForwarded stringFor - Forward the same, add, or remove HTTP header.
- Hsts
Include stringSubdomains - Add HSTS includeSubDomains response header.
- Http
Compression string - Enable to allow HTTP compression over SSL-VPN tunnels.
- string
- Enable/disable SSL-VPN support for HttpOnly cookies.
- Http
Request intBody Timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- Http
Request intHeader Timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- Https
Redirect string - Enable/disable redirect of port 80 to SSL-VPN port.
- Id string
- The provider-assigned unique ID for this managed resource.
- Idle
Timeout int - SSL VPN disconnects if idle for specified time in seconds.
- Ipv6Dns
Server1 string - IPv6 DNS server 1.
- Ipv6Dns
Server2 string - IPv6 DNS server 2.
- Ipv6Wins
Server1 string - IPv6 WINS server 1.
- Ipv6Wins
Server2 string - IPv6 WINS server 2.
- Login
Attempt intLimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- Login
Block intTime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- Login
Timeout int - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- Port int
- SSL-VPN access port (1 - 65535).
- Port
Precedence string - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- Reqclientcert string
- Enable to require client certificates for all SSL-VPN users.
- Route
Source stringInterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- Saml
Redirect intPort - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- Server
Hostname string - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- Servercert string
- Name of the server certificate to be used for SSL-VPNs.
- Source
Address6Negate string - Enable/disable negated source IPv6 address match.
- Source
Address6s List<Pulumiverse.Fortios. Vpn. Ssl. Outputs. Get Settings Source Address6> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - Source
Address stringNegate - Enable/disable negated source address match.
- Source
Addresses List<Pulumiverse.Fortios. Vpn. Ssl. Outputs. Get Settings Source Address> - Source address of incoming traffic. The structure of
source_address
block is documented below. - Source
Interfaces List<Pulumiverse.Fortios. Vpn. Ssl. Outputs. Get Settings Source Interface> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - Ssl
Client stringRenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- Ssl
Insert stringEmpty Fragment - Enable/disable insertion of empty fragment.
- Ssl
Max stringProto Ver - SSL maximum protocol version.
- Ssl
Min stringProto Ver - SSL minimum protocol version.
- Status string
- Enable/disable SSL-VPN.
- Tlsv10 string
- Enable/disable TLSv1.0.
- Tlsv11 string
- Enable/disable TLSv1.1.
- Tlsv12 string
- Enable/disable TLSv1.2.
- Tlsv13 string
- Enable/disable TLSv1.3.
- Transform
Backward stringSlashes - Transform backward slashes to forward slashes in URLs.
- Tunnel
Addr stringAssigned Method - Method used for assigning address for tunnel.
- Tunnel
Connect stringWithout Reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- Tunnel
Ip List<Pulumiverse.Pools Fortios. Vpn. Ssl. Outputs. Get Settings Tunnel Ip Pool> - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - Tunnel
Ipv6Pools List<Pulumiverse.Fortios. Vpn. Ssl. Outputs. Get Settings Tunnel Ipv6Pool> - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - Tunnel
User intSession Timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- Unsafe
Legacy stringRenegotiation - Enable/disable unsafe legacy re-negotiation.
- Url
Obscuration string - Enable to obscure the host name of the URL of the web browser display.
- User
Peer string - Name of user peer.
- Web
Mode stringSnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- Wins
Server1 string - WINS server 1.
- Wins
Server2 string - WINS server 2.
- XContent
Type stringOptions - Add HTTP X-Content-Type-Options header.
- Ztna
Trusted stringClient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- Vdomparam string
- Algorithm string
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- Auth
Session stringCheck Source Ip - Enable/disable checking of source IP for authentication session.
- Auth
Timeout int - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- Authentication
Rules []GetSettings Authentication Rule - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - Auto
Tunnel stringStatic Route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- Banned
Cipher string - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- Browser
Language stringDetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- Check
Referer string - Enable/disable verification of referer field in HTTP request header.
- Ciphersuite string
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- Client
Sigalgs string - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- Default
Portal string - Default SSL VPN portal.
- Deflate
Compression intLevel - Compression level (0~9).
- Deflate
Min intData Size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- Dns
Server1 string - DNS server 1.
- Dns
Server2 string - DNS server 2.
- Dns
Suffix string - DNS suffix used for SSL-VPN clients.
- Dtls
Heartbeat intFail Count - Number of missing heartbeats before the connection is considered dropped.
- Dtls
Heartbeat intIdle Timeout - Idle timeout before DTLS heartbeat is sent.
- Dtls
Heartbeat intInterval - Interval between DTLS heartbeat.
- Dtls
Hello intTimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- Dtls
Max stringProto Ver - DTLS maximum protocol version.
- Dtls
Min stringProto Ver - DTLS minimum protocol version.
- Dtls
Tunnel string - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- Dual
Stack stringMode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- Encode2f
Sequence string - Encode \2F sequence to forward slash in URLs.
- Encrypt
And stringStore Password - Encrypt and store user passwords for SSL-VPN web sessions.
- Force
Two stringFactor Auth - Enable to force two-factor authentication for all SSL-VPNs.
- Header
XForwarded stringFor - Forward the same, add, or remove HTTP header.
- Hsts
Include stringSubdomains - Add HSTS includeSubDomains response header.
- Http
Compression string - Enable to allow HTTP compression over SSL-VPN tunnels.
- string
- Enable/disable SSL-VPN support for HttpOnly cookies.
- Http
Request intBody Timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- Http
Request intHeader Timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- Https
Redirect string - Enable/disable redirect of port 80 to SSL-VPN port.
- Id string
- The provider-assigned unique ID for this managed resource.
- Idle
Timeout int - SSL VPN disconnects if idle for specified time in seconds.
- Ipv6Dns
Server1 string - IPv6 DNS server 1.
- Ipv6Dns
Server2 string - IPv6 DNS server 2.
- Ipv6Wins
Server1 string - IPv6 WINS server 1.
- Ipv6Wins
Server2 string - IPv6 WINS server 2.
- Login
Attempt intLimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- Login
Block intTime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- Login
Timeout int - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- Port int
- SSL-VPN access port (1 - 65535).
- Port
Precedence string - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- Reqclientcert string
- Enable to require client certificates for all SSL-VPN users.
- Route
Source stringInterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- Saml
Redirect intPort - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- Server
Hostname string - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- Servercert string
- Name of the server certificate to be used for SSL-VPNs.
- Source
Address6Negate string - Enable/disable negated source IPv6 address match.
- Source
Address6s []GetSettings Source Address6 - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - Source
Address stringNegate - Enable/disable negated source address match.
- Source
Addresses []GetSettings Source Address - Source address of incoming traffic. The structure of
source_address
block is documented below. - Source
Interfaces []GetSettings Source Interface - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - Ssl
Client stringRenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- Ssl
Insert stringEmpty Fragment - Enable/disable insertion of empty fragment.
- Ssl
Max stringProto Ver - SSL maximum protocol version.
- Ssl
Min stringProto Ver - SSL minimum protocol version.
- Status string
- Enable/disable SSL-VPN.
- Tlsv10 string
- Enable/disable TLSv1.0.
- Tlsv11 string
- Enable/disable TLSv1.1.
- Tlsv12 string
- Enable/disable TLSv1.2.
- Tlsv13 string
- Enable/disable TLSv1.3.
- Transform
Backward stringSlashes - Transform backward slashes to forward slashes in URLs.
- Tunnel
Addr stringAssigned Method - Method used for assigning address for tunnel.
- Tunnel
Connect stringWithout Reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- Tunnel
Ip []GetPools Settings Tunnel Ip Pool - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - Tunnel
Ipv6Pools []GetSettings Tunnel Ipv6Pool - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - Tunnel
User intSession Timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- Unsafe
Legacy stringRenegotiation - Enable/disable unsafe legacy re-negotiation.
- Url
Obscuration string - Enable to obscure the host name of the URL of the web browser display.
- User
Peer string - Name of user peer.
- Web
Mode stringSnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- Wins
Server1 string - WINS server 1.
- Wins
Server2 string - WINS server 2.
- XContent
Type stringOptions - Add HTTP X-Content-Type-Options header.
- Ztna
Trusted stringClient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- Vdomparam string
- algorithm String
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- auth
Session StringCheck Source Ip - Enable/disable checking of source IP for authentication session.
- auth
Timeout Integer - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- authentication
Rules List<GetSettings Authentication Rule> - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - auto
Tunnel StringStatic Route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- banned
Cipher String - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- browser
Language StringDetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- check
Referer String - Enable/disable verification of referer field in HTTP request header.
- ciphersuite String
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- client
Sigalgs String - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- default
Portal String - Default SSL VPN portal.
- deflate
Compression IntegerLevel - Compression level (0~9).
- deflate
Min IntegerData Size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- dns
Server1 String - DNS server 1.
- dns
Server2 String - DNS server 2.
- dns
Suffix String - DNS suffix used for SSL-VPN clients.
- dtls
Heartbeat IntegerFail Count - Number of missing heartbeats before the connection is considered dropped.
- dtls
Heartbeat IntegerIdle Timeout - Idle timeout before DTLS heartbeat is sent.
- dtls
Heartbeat IntegerInterval - Interval between DTLS heartbeat.
- dtls
Hello IntegerTimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- dtls
Max StringProto Ver - DTLS maximum protocol version.
- dtls
Min StringProto Ver - DTLS minimum protocol version.
- dtls
Tunnel String - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- dual
Stack StringMode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- encode2f
Sequence String - Encode \2F sequence to forward slash in URLs.
- encrypt
And StringStore Password - Encrypt and store user passwords for SSL-VPN web sessions.
- force
Two StringFactor Auth - Enable to force two-factor authentication for all SSL-VPNs.
- header
XForwarded StringFor - Forward the same, add, or remove HTTP header.
- hsts
Include StringSubdomains - Add HSTS includeSubDomains response header.
- http
Compression String - Enable to allow HTTP compression over SSL-VPN tunnels.
- String
- Enable/disable SSL-VPN support for HttpOnly cookies.
- http
Request IntegerBody Timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- http
Request IntegerHeader Timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- https
Redirect String - Enable/disable redirect of port 80 to SSL-VPN port.
- id String
- The provider-assigned unique ID for this managed resource.
- idle
Timeout Integer - SSL VPN disconnects if idle for specified time in seconds.
- ipv6Dns
Server1 String - IPv6 DNS server 1.
- ipv6Dns
Server2 String - IPv6 DNS server 2.
- ipv6Wins
Server1 String - IPv6 WINS server 1.
- ipv6Wins
Server2 String - IPv6 WINS server 2.
- login
Attempt IntegerLimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- login
Block IntegerTime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- login
Timeout Integer - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- port Integer
- SSL-VPN access port (1 - 65535).
- port
Precedence String - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- reqclientcert String
- Enable to require client certificates for all SSL-VPN users.
- route
Source StringInterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- saml
Redirect IntegerPort - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- server
Hostname String - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- servercert String
- Name of the server certificate to be used for SSL-VPNs.
- source
Address6Negate String - Enable/disable negated source IPv6 address match.
- source
Address6s List<GetSettings Source Address6> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address StringNegate - Enable/disable negated source address match.
- source
Addresses List<GetSettings Source Address> - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces List<GetSettings Source Interface> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - ssl
Client StringRenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- ssl
Insert StringEmpty Fragment - Enable/disable insertion of empty fragment.
- ssl
Max StringProto Ver - SSL maximum protocol version.
- ssl
Min StringProto Ver - SSL minimum protocol version.
- status String
- Enable/disable SSL-VPN.
- tlsv10 String
- Enable/disable TLSv1.0.
- tlsv11 String
- Enable/disable TLSv1.1.
- tlsv12 String
- Enable/disable TLSv1.2.
- tlsv13 String
- Enable/disable TLSv1.3.
- transform
Backward StringSlashes - Transform backward slashes to forward slashes in URLs.
- tunnel
Addr StringAssigned Method - Method used for assigning address for tunnel.
- tunnel
Connect StringWithout Reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- tunnel
Ip List<GetPools Settings Tunnel Ip Pool> - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - tunnel
Ipv6Pools List<GetSettings Tunnel Ipv6Pool> - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - tunnel
User IntegerSession Timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- unsafe
Legacy StringRenegotiation - Enable/disable unsafe legacy re-negotiation.
- url
Obscuration String - Enable to obscure the host name of the URL of the web browser display.
- user
Peer String - Name of user peer.
- web
Mode StringSnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- wins
Server1 String - WINS server 1.
- wins
Server2 String - WINS server 2.
- x
Content StringType Options - Add HTTP X-Content-Type-Options header.
- ztna
Trusted StringClient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- vdomparam String
- algorithm string
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- auth
Session stringCheck Source Ip - Enable/disable checking of source IP for authentication session.
- auth
Timeout number - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- authentication
Rules GetSettings Authentication Rule[] - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - auto
Tunnel stringStatic Route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- banned
Cipher string - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- browser
Language stringDetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- check
Referer string - Enable/disable verification of referer field in HTTP request header.
- ciphersuite string
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- client
Sigalgs string - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- default
Portal string - Default SSL VPN portal.
- deflate
Compression numberLevel - Compression level (0~9).
- deflate
Min numberData Size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- dns
Server1 string - DNS server 1.
- dns
Server2 string - DNS server 2.
- dns
Suffix string - DNS suffix used for SSL-VPN clients.
- dtls
Heartbeat numberFail Count - Number of missing heartbeats before the connection is considered dropped.
- dtls
Heartbeat numberIdle Timeout - Idle timeout before DTLS heartbeat is sent.
- dtls
Heartbeat numberInterval - Interval between DTLS heartbeat.
- dtls
Hello numberTimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- dtls
Max stringProto Ver - DTLS maximum protocol version.
- dtls
Min stringProto Ver - DTLS minimum protocol version.
- dtls
Tunnel string - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- dual
Stack stringMode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- encode2f
Sequence string - Encode \2F sequence to forward slash in URLs.
- encrypt
And stringStore Password - Encrypt and store user passwords for SSL-VPN web sessions.
- force
Two stringFactor Auth - Enable to force two-factor authentication for all SSL-VPNs.
- header
XForwarded stringFor - Forward the same, add, or remove HTTP header.
- hsts
Include stringSubdomains - Add HSTS includeSubDomains response header.
- http
Compression string - Enable to allow HTTP compression over SSL-VPN tunnels.
- string
- Enable/disable SSL-VPN support for HttpOnly cookies.
- http
Request numberBody Timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- http
Request numberHeader Timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- https
Redirect string - Enable/disable redirect of port 80 to SSL-VPN port.
- id string
- The provider-assigned unique ID for this managed resource.
- idle
Timeout number - SSL VPN disconnects if idle for specified time in seconds.
- ipv6Dns
Server1 string - IPv6 DNS server 1.
- ipv6Dns
Server2 string - IPv6 DNS server 2.
- ipv6Wins
Server1 string - IPv6 WINS server 1.
- ipv6Wins
Server2 string - IPv6 WINS server 2.
- login
Attempt numberLimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- login
Block numberTime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- login
Timeout number - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- port number
- SSL-VPN access port (1 - 65535).
- port
Precedence string - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- reqclientcert string
- Enable to require client certificates for all SSL-VPN users.
- route
Source stringInterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- saml
Redirect numberPort - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- server
Hostname string - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- servercert string
- Name of the server certificate to be used for SSL-VPNs.
- source
Address6Negate string - Enable/disable negated source IPv6 address match.
- source
Address6s GetSettings Source Address6[] - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address stringNegate - Enable/disable negated source address match.
- source
Addresses GetSettings Source Address[] - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces GetSettings Source Interface[] - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - ssl
Client stringRenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- ssl
Insert stringEmpty Fragment - Enable/disable insertion of empty fragment.
- ssl
Max stringProto Ver - SSL maximum protocol version.
- ssl
Min stringProto Ver - SSL minimum protocol version.
- status string
- Enable/disable SSL-VPN.
- tlsv10 string
- Enable/disable TLSv1.0.
- tlsv11 string
- Enable/disable TLSv1.1.
- tlsv12 string
- Enable/disable TLSv1.2.
- tlsv13 string
- Enable/disable TLSv1.3.
- transform
Backward stringSlashes - Transform backward slashes to forward slashes in URLs.
- tunnel
Addr stringAssigned Method - Method used for assigning address for tunnel.
- tunnel
Connect stringWithout Reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- tunnel
Ip GetPools Settings Tunnel Ip Pool[] - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - tunnel
Ipv6Pools GetSettings Tunnel Ipv6Pool[] - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - tunnel
User numberSession Timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- unsafe
Legacy stringRenegotiation - Enable/disable unsafe legacy re-negotiation.
- url
Obscuration string - Enable to obscure the host name of the URL of the web browser display.
- user
Peer string - Name of user peer.
- web
Mode stringSnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- wins
Server1 string - WINS server 1.
- wins
Server2 string - WINS server 2.
- x
Content stringType Options - Add HTTP X-Content-Type-Options header.
- ztna
Trusted stringClient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- vdomparam string
- algorithm str
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- auth_
session_ strcheck_ source_ ip - Enable/disable checking of source IP for authentication session.
- auth_
timeout int - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- authentication_
rules Sequence[GetSettings Authentication Rule] - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - auto_
tunnel_ strstatic_ route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- banned_
cipher str - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- browser_
language_ strdetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- check_
referer str - Enable/disable verification of referer field in HTTP request header.
- ciphersuite str
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- client_
sigalgs str - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- default_
portal str - Default SSL VPN portal.
- deflate_
compression_ intlevel - Compression level (0~9).
- deflate_
min_ intdata_ size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- dns_
server1 str - DNS server 1.
- dns_
server2 str - DNS server 2.
- dns_
suffix str - DNS suffix used for SSL-VPN clients.
- dtls_
heartbeat_ intfail_ count - Number of missing heartbeats before the connection is considered dropped.
- dtls_
heartbeat_ intidle_ timeout - Idle timeout before DTLS heartbeat is sent.
- dtls_
heartbeat_ intinterval - Interval between DTLS heartbeat.
- dtls_
hello_ inttimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- dtls_
max_ strproto_ ver - DTLS maximum protocol version.
- dtls_
min_ strproto_ ver - DTLS minimum protocol version.
- dtls_
tunnel str - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- dual_
stack_ strmode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- encode2f_
sequence str - Encode \2F sequence to forward slash in URLs.
- encrypt_
and_ strstore_ password - Encrypt and store user passwords for SSL-VPN web sessions.
- force_
two_ strfactor_ auth - Enable to force two-factor authentication for all SSL-VPNs.
- header_
x_ strforwarded_ for - Forward the same, add, or remove HTTP header.
- hsts_
include_ strsubdomains - Add HSTS includeSubDomains response header.
- http_
compression str - Enable to allow HTTP compression over SSL-VPN tunnels.
- str
- Enable/disable SSL-VPN support for HttpOnly cookies.
- http_
request_ intbody_ timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- http_
request_ intheader_ timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- https_
redirect str - Enable/disable redirect of port 80 to SSL-VPN port.
- id str
- The provider-assigned unique ID for this managed resource.
- idle_
timeout int - SSL VPN disconnects if idle for specified time in seconds.
- ipv6_
dns_ strserver1 - IPv6 DNS server 1.
- ipv6_
dns_ strserver2 - IPv6 DNS server 2.
- ipv6_
wins_ strserver1 - IPv6 WINS server 1.
- ipv6_
wins_ strserver2 - IPv6 WINS server 2.
- login_
attempt_ intlimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- login_
block_ inttime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- login_
timeout int - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- port int
- SSL-VPN access port (1 - 65535).
- port_
precedence str - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- reqclientcert str
- Enable to require client certificates for all SSL-VPN users.
- route_
source_ strinterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- saml_
redirect_ intport - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- server_
hostname str - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- servercert str
- Name of the server certificate to be used for SSL-VPNs.
- source_
address6_ strnegate - Enable/disable negated source IPv6 address match.
- source_
address6s Sequence[GetSettings Source Address6] - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source_
address_ strnegate - Enable/disable negated source address match.
- source_
addresses Sequence[GetSettings Source Address] - Source address of incoming traffic. The structure of
source_address
block is documented below. - source_
interfaces Sequence[GetSettings Source Interface] - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - ssl_
client_ strrenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- ssl_
insert_ strempty_ fragment - Enable/disable insertion of empty fragment.
- ssl_
max_ strproto_ ver - SSL maximum protocol version.
- ssl_
min_ strproto_ ver - SSL minimum protocol version.
- status str
- Enable/disable SSL-VPN.
- tlsv10 str
- Enable/disable TLSv1.0.
- tlsv11 str
- Enable/disable TLSv1.1.
- tlsv12 str
- Enable/disable TLSv1.2.
- tlsv13 str
- Enable/disable TLSv1.3.
- transform_
backward_ strslashes - Transform backward slashes to forward slashes in URLs.
- tunnel_
addr_ strassigned_ method - Method used for assigning address for tunnel.
- tunnel_
connect_ strwithout_ reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- tunnel_
ip_ Sequence[Getpools Settings Tunnel Ip Pool] - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - tunnel_
ipv6_ Sequence[Getpools Settings Tunnel Ipv6Pool] - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - tunnel_
user_ intsession_ timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- unsafe_
legacy_ strrenegotiation - Enable/disable unsafe legacy re-negotiation.
- url_
obscuration str - Enable to obscure the host name of the URL of the web browser display.
- user_
peer str - Name of user peer.
- web_
mode_ strsnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- wins_
server1 str - WINS server 1.
- wins_
server2 str - WINS server 2.
- x_
content_ strtype_ options - Add HTTP X-Content-Type-Options header.
- ztna_
trusted_ strclient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- vdomparam str
- algorithm String
- Force the SSL-VPN security level. High allows only high. Medium allows medium and high. Low allows any.
- auth
Session StringCheck Source Ip - Enable/disable checking of source IP for authentication session.
- auth
Timeout Number - SSL-VPN authentication timeout (1 - 259200 sec (3 days), 0 for no timeout).
- authentication
Rules List<Property Map> - Authentication rule for SSL VPN. The structure of
authentication_rule
block is documented below. - auto
Tunnel StringStatic Route - Enable to auto-create static routes for the SSL-VPN tunnel IP addresses.
- banned
Cipher String - Select one or more cipher technologies that cannot be used in SSL-VPN negotiations.
- browser
Language StringDetection - Enable/disable overriding the configured system language based on the preferred language of the browser.
- check
Referer String - Enable/disable verification of referer field in HTTP request header.
- ciphersuite String
- Select one or more TLS 1.3 ciphersuites to enable. Does not affect ciphers in TLS 1.2 and below. At least one must be enabled. To disable all, set ssl-max-proto-ver to tls1-2 or below.
- client
Sigalgs String - Set signature algorithms related to client authentication. Affects TLS version <= 1.2 only.
- default
Portal String - Default SSL VPN portal.
- deflate
Compression NumberLevel - Compression level (0~9).
- deflate
Min NumberData Size - Minimum amount of data that triggers compression (200 - 65535 bytes).
- dns
Server1 String - DNS server 1.
- dns
Server2 String - DNS server 2.
- dns
Suffix String - DNS suffix used for SSL-VPN clients.
- dtls
Heartbeat NumberFail Count - Number of missing heartbeats before the connection is considered dropped.
- dtls
Heartbeat NumberIdle Timeout - Idle timeout before DTLS heartbeat is sent.
- dtls
Heartbeat NumberInterval - Interval between DTLS heartbeat.
- dtls
Hello NumberTimeout - SSLVPN maximum DTLS hello timeout (10 - 60 sec, default = 10).
- dtls
Max StringProto Ver - DTLS maximum protocol version.
- dtls
Min StringProto Ver - DTLS minimum protocol version.
- dtls
Tunnel String - Enable DTLS to prevent eavesdropping, tampering, or message forgery.
- dual
Stack StringMode - Tunnel mode: enable parallel IPv4 and IPv6 tunnel. Web mode: support IPv4 and IPv6 bookmarks in the portal.
- encode2f
Sequence String - Encode \2F sequence to forward slash in URLs.
- encrypt
And StringStore Password - Encrypt and store user passwords for SSL-VPN web sessions.
- force
Two StringFactor Auth - Enable to force two-factor authentication for all SSL-VPNs.
- header
XForwarded StringFor - Forward the same, add, or remove HTTP header.
- hsts
Include StringSubdomains - Add HSTS includeSubDomains response header.
- http
Compression String - Enable to allow HTTP compression over SSL-VPN tunnels.
- String
- Enable/disable SSL-VPN support for HttpOnly cookies.
- http
Request NumberBody Timeout - SSL-VPN session is disconnected if an HTTP request body is not received within this time (1 - 60 sec, default = 20).
- http
Request NumberHeader Timeout - SSL-VPN session is disconnected if an HTTP request header is not received within this time (1 - 60 sec, default = 20).
- https
Redirect String - Enable/disable redirect of port 80 to SSL-VPN port.
- id String
- The provider-assigned unique ID for this managed resource.
- idle
Timeout Number - SSL VPN disconnects if idle for specified time in seconds.
- ipv6Dns
Server1 String - IPv6 DNS server 1.
- ipv6Dns
Server2 String - IPv6 DNS server 2.
- ipv6Wins
Server1 String - IPv6 WINS server 1.
- ipv6Wins
Server2 String - IPv6 WINS server 2.
- login
Attempt NumberLimit - SSL VPN maximum login attempt times before block (0 - 10, default = 2, 0 = no limit).
- login
Block NumberTime - Time for which a user is blocked from logging in after too many failed login attempts (0 - 86400 sec, default = 60).
- login
Timeout Number - SSLVPN maximum login timeout (10 - 180 sec, default = 30).
- port Number
- SSL-VPN access port (1 - 65535).
- port
Precedence String - Enable means that if SSL-VPN connections are allowed on an interface admin GUI connections are blocked on that interface.
- reqclientcert String
- Enable to require client certificates for all SSL-VPN users.
- route
Source StringInterface - Enable to allow SSL-VPN sessions to bypass routing and bind to the incoming interface.
- saml
Redirect NumberPort - SAML local redirect port in the machine running FCT (0 - 65535). 0 is to disable redirection on FGT side.
- server
Hostname String - Server hostname for HTTPS. When set, will be used for SSL VPN web proxy host header for any redirection.
- servercert String
- Name of the server certificate to be used for SSL-VPNs.
- source
Address6Negate String - Enable/disable negated source IPv6 address match.
- source
Address6s List<Property Map> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address StringNegate - Enable/disable negated source address match.
- source
Addresses List<Property Map> - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces List<Property Map> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - ssl
Client StringRenegotiation - Enable to allow client renegotiation by the server if the tunnel goes down.
- ssl
Insert StringEmpty Fragment - Enable/disable insertion of empty fragment.
- ssl
Max StringProto Ver - SSL maximum protocol version.
- ssl
Min StringProto Ver - SSL minimum protocol version.
- status String
- Enable/disable SSL-VPN.
- tlsv10 String
- Enable/disable TLSv1.0.
- tlsv11 String
- Enable/disable TLSv1.1.
- tlsv12 String
- Enable/disable TLSv1.2.
- tlsv13 String
- Enable/disable TLSv1.3.
- transform
Backward StringSlashes - Transform backward slashes to forward slashes in URLs.
- tunnel
Addr StringAssigned Method - Method used for assigning address for tunnel.
- tunnel
Connect StringWithout Reauth - Enable/disable tunnel connection without re-authorization if previous connection dropped.
- tunnel
Ip List<Property Map>Pools - Names of the IPv4 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ip_pools
block is documented below. - tunnel
Ipv6Pools List<Property Map> - Names of the IPv6 IP Pool firewall objects that define the IP addresses reserved for remote clients. The structure of
tunnel_ipv6_pools
block is documented below. - tunnel
User NumberSession Timeout - Time out value to clean up user session after tunnel connection is dropped (1 - 255 sec, default=30).
- unsafe
Legacy StringRenegotiation - Enable/disable unsafe legacy re-negotiation.
- url
Obscuration String - Enable to obscure the host name of the URL of the web browser display.
- user
Peer String - Name of user peer.
- web
Mode StringSnat - Enable/disable use of IP pools defined in firewall policy while using web-mode.
- wins
Server1 String - WINS server 1.
- wins
Server2 String - WINS server 2.
- x
Content StringType Options - Add HTTP X-Content-Type-Options header.
- ztna
Trusted StringClient - Enable/disable verification of device certificate for SSLVPN ZTNA session.
- vdomparam String
Supporting Types
GetSettingsAuthenticationRule
- Auth string
- SSL VPN authentication method restriction.
- Cipher string
- SSL VPN cipher strength.
- Client
Cert string - Enable/disable SSL VPN client certificate restrictive.
- Groups
List<Pulumiverse.
Fortios. Vpn. Ssl. Inputs. Get Settings Authentication Rule Group> - User groups. The structure of
groups
block is documented below. - Id int
- ID (0 - 4294967295).
- Portal string
- SSL VPN portal.
- Realm string
- SSL VPN realm.
- Source
Address6Negate string - Enable/disable negated source IPv6 address match.
- Source
Address6s List<Pulumiverse.Fortios. Vpn. Ssl. Inputs. Get Settings Authentication Rule Source Address6> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - Source
Address stringNegate - Enable/disable negated source address match.
- Source
Addresses List<Pulumiverse.Fortios. Vpn. Ssl. Inputs. Get Settings Authentication Rule Source Address> - Source address of incoming traffic. The structure of
source_address
block is documented below. - Source
Interfaces List<Pulumiverse.Fortios. Vpn. Ssl. Inputs. Get Settings Authentication Rule Source Interface> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - User
Peer string - Name of user peer.
- Users
List<Pulumiverse.
Fortios. Vpn. Ssl. Inputs. Get Settings Authentication Rule User> - User name. The structure of
users
block is documented below.
- Auth string
- SSL VPN authentication method restriction.
- Cipher string
- SSL VPN cipher strength.
- Client
Cert string - Enable/disable SSL VPN client certificate restrictive.
- Groups
[]Get
Settings Authentication Rule Group - User groups. The structure of
groups
block is documented below. - Id int
- ID (0 - 4294967295).
- Portal string
- SSL VPN portal.
- Realm string
- SSL VPN realm.
- Source
Address6Negate string - Enable/disable negated source IPv6 address match.
- Source
Address6s []GetSettings Authentication Rule Source Address6 - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - Source
Address stringNegate - Enable/disable negated source address match.
- Source
Addresses []GetSettings Authentication Rule Source Address - Source address of incoming traffic. The structure of
source_address
block is documented below. - Source
Interfaces []GetSettings Authentication Rule Source Interface - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - User
Peer string - Name of user peer.
- Users
[]Get
Settings Authentication Rule User - User name. The structure of
users
block is documented below.
- auth String
- SSL VPN authentication method restriction.
- cipher String
- SSL VPN cipher strength.
- client
Cert String - Enable/disable SSL VPN client certificate restrictive.
- groups
List<Get
Settings Authentication Rule Group> - User groups. The structure of
groups
block is documented below. - id Integer
- ID (0 - 4294967295).
- portal String
- SSL VPN portal.
- realm String
- SSL VPN realm.
- source
Address6Negate String - Enable/disable negated source IPv6 address match.
- source
Address6s List<GetSettings Authentication Rule Source Address6> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address StringNegate - Enable/disable negated source address match.
- source
Addresses List<GetSettings Authentication Rule Source Address> - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces List<GetSettings Authentication Rule Source Interface> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - user
Peer String - Name of user peer.
- users
List<Get
Settings Authentication Rule User> - User name. The structure of
users
block is documented below.
- auth string
- SSL VPN authentication method restriction.
- cipher string
- SSL VPN cipher strength.
- client
Cert string - Enable/disable SSL VPN client certificate restrictive.
- groups
Get
Settings Authentication Rule Group[] - User groups. The structure of
groups
block is documented below. - id number
- ID (0 - 4294967295).
- portal string
- SSL VPN portal.
- realm string
- SSL VPN realm.
- source
Address6Negate string - Enable/disable negated source IPv6 address match.
- source
Address6s GetSettings Authentication Rule Source Address6[] - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address stringNegate - Enable/disable negated source address match.
- source
Addresses GetSettings Authentication Rule Source Address[] - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces GetSettings Authentication Rule Source Interface[] - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - user
Peer string - Name of user peer.
- users
Get
Settings Authentication Rule User[] - User name. The structure of
users
block is documented below.
- auth str
- SSL VPN authentication method restriction.
- cipher str
- SSL VPN cipher strength.
- client_
cert str - Enable/disable SSL VPN client certificate restrictive.
- groups
Sequence[Get
Settings Authentication Rule Group] - User groups. The structure of
groups
block is documented below. - id int
- ID (0 - 4294967295).
- portal str
- SSL VPN portal.
- realm str
- SSL VPN realm.
- source_
address6_ strnegate - Enable/disable negated source IPv6 address match.
- source_
address6s Sequence[GetSettings Authentication Rule Source Address6] - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source_
address_ strnegate - Enable/disable negated source address match.
- source_
addresses Sequence[GetSettings Authentication Rule Source Address] - Source address of incoming traffic. The structure of
source_address
block is documented below. - source_
interfaces Sequence[GetSettings Authentication Rule Source Interface] - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - user_
peer str - Name of user peer.
- users
Sequence[Get
Settings Authentication Rule User] - User name. The structure of
users
block is documented below.
- auth String
- SSL VPN authentication method restriction.
- cipher String
- SSL VPN cipher strength.
- client
Cert String - Enable/disable SSL VPN client certificate restrictive.
- groups List<Property Map>
- User groups. The structure of
groups
block is documented below. - id Number
- ID (0 - 4294967295).
- portal String
- SSL VPN portal.
- realm String
- SSL VPN realm.
- source
Address6Negate String - Enable/disable negated source IPv6 address match.
- source
Address6s List<Property Map> - IPv6 source address of incoming traffic. The structure of
source_address6
block is documented below. - source
Address StringNegate - Enable/disable negated source address match.
- source
Addresses List<Property Map> - Source address of incoming traffic. The structure of
source_address
block is documented below. - source
Interfaces List<Property Map> - SSL VPN source interface of incoming traffic. The structure of
source_interface
block is documented below. - user
Peer String - Name of user peer.
- users List<Property Map>
- User name. The structure of
users
block is documented below.
GetSettingsAuthenticationRuleGroup
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsAuthenticationRuleSourceAddress
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsAuthenticationRuleSourceAddress6
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsAuthenticationRuleSourceInterface
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsAuthenticationRuleUser
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsSourceAddress
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsSourceAddress6
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsSourceInterface
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsTunnelIpPool
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
GetSettingsTunnelIpv6Pool
- Name string
- Group name.
- Name string
- Group name.
- name String
- Group name.
- name string
- Group name.
- name str
- Group name.
- name String
- Group name.
Package Details
- Repository
- fortios pulumiverse/pulumi-fortios
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
fortios
Terraform Provider.