paloaltonetworks.panos.panos_interface module – Manage data-port network interfaces
Note
This module is part of the paloaltonetworks.panos collection (version 2.21.2).
To install it, use: ansible-galaxy collection install paloaltonetworks.panos
.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: paloaltonetworks.panos.panos_interface
.
New in paloaltonetworks.panos 1.0.0
Synopsis
Manage data-port (DP) network interface. By default DP interfaces are static.
Requirements
The below requirements are needed on the host that executes this module.
pan-python can be obtained from PyPI https://pypi.python.org/pypi/pan-python
pandevice can be obtained from PyPI https://pypi.python.org/pypi/pandevice
pandevice >= 0.8.0
Parameters
Parameter |
Comments |
---|---|
Adjust TCP MSS for layer3 interface. Choices: |
|
Aggregate interface name. |
|
Deprecated Use provider to specify PAN-OS connectivity instead. The API key to use instead of generating it using username / password. |
|
Interface comment. |
|
Deprecated Please use paloaltonetworks.panos.panos_commit_firewall, paloaltonetworks.panos.panos_commit_panorama, paloaltonetworks.panos.panos_commit_push instead. Commit changes after creating object. If ip_address is a Panorama device, and device_group or template are also set, perform a commit to Panorama and a commit-all to the device group/template. Choices: |
|
Whether or not to add default route with router learned via DHCP. Choices: |
|
Metric for the DHCP default route. |
|
Enable DHCP on this interface. Choices: |
|
When state=gathered. An advanced filtering option to filter results returned from PAN-OS. Refer to the guide discussing gathered_filter for more information. |
|
Name of the interface to configure. |
|
List of static IP addresses. |
|
Deprecated Use provider to specify PAN-OS connectivity instead. The IP address or hostname of the PAN-OS device being configured. |
|
(7.1+) TCP MSS adjustment for IPv4. |
|
(7.1+) TCP MSS adjustment for IPv6. |
|
Enable LLDP for layer2 interface. |
|
LLDP profile name for layer2 interface. |
|
Interface management profile name. |
|
MTU for layer3 interface. |
|
Netflow profile for layer3 interface. |
|
Netflow profile name for layer2 interface. |
|
Deprecated Use provider to specify PAN-OS connectivity instead. The password to use for authentication. This is ignored if api_key is specified. |
|
Deprecated Use provider to specify PAN-OS connectivity instead. The port number to connect to the PAN-OS device on. Default: :ansible-option-default:`443` |
|
A dict object containing connection details. |
|
The API key to use instead of generating it using username / password. |
|
The IP address or hostname of the PAN-OS device being configured. |
|
The password to use for authentication. This is ignored if api_key is specified. |
|
The port number to connect to the PAN-OS device on. Default: :ansible-option-default:`443` |
|
The serial number of a firewall to use for targeted commands. If ip_address is not a Panorama PAN-OS device, then this param is ignored. |
|
The username to use for authentication. This is ignored if api_key is specified. Default: :ansible-option-default:`"admin"` |
|
(Panorama only) The template this operation should target. This param is required if the PAN-OS device is Panorama. |
|
Deprecated Use provider to specify PAN-OS connectivity instead. The username to use for authentication. This is ignored if api_key is specified. Default: :ansible-option-default:`"admin"` |
|
The VLAN to put this interface in. If the VLAN does not exist it is created. Only specify this if mode=layer2. |
|
Name of the virtual router; it must already exist. Default: :ansible-option-default:`"default"` |
|
The vsys this object should be imported into. Objects that are imported include interfaces, virtual routers, virtual wires, and VLANs. Interfaces are typically imported into vsys1 if no vsys is specified. |
|
Deprecated Use vsys to specify the vsys instead. Name of the vsys (if firewall) or device group (if panorama) to put this object. |
|
Name of the zone for the interface. If the zone does not exist it is created. If the zone already exists its mode should match mode. |
Notes
Note
Checkmode is supported.
If the PAN-OS device is a firewall and vsys is not specified, then the vsys will default to vsys=vsys1.
PAN-OS connectivity should be specified using provider or the classic PAN-OS connectivity params (ip_address, username, password, api_key, and port). If both are present, then the classic params are ignored.
Examples
# Create ethernet1/1 as DHCP.
- name: enable DHCP client on ethernet1/1 in zone public
paloaltonetworks.panos.panos_interface:
provider: '{{ provider }}'
if_name: "ethernet1/1"
zone_name: "public"
create_default_route: "yes"
# Update ethernet1/2 with a static IP address in zone dmz.
- name: ethernet1/2 as static in zone dmz
paloaltonetworks.panos.panos_interface:
provider: '{{ provider }}'
if_name: "ethernet1/2"
mode: "layer3"
ip: ["10.1.1.1/24"]
enable_dhcp: false
zone_name: "dmz"