cisco.catalystcenter.security_service_insertions module -- Resource module for Security Service Insertions

Note

This module is part of the cisco.catalystcenter collection (version 2.11.0).

To install it, use: ansible-galaxy collection install cisco.catalystcenter. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: cisco.catalystcenter.security_service_insertions.

New in cisco.catalystcenter 2.11.0

Synopsis

  • Manage operations create, update and delete of the resource Security Service Insertions.

  • Enables Security Service Insertion SSI on a fabric site within a network.

  • Removes the Security Service Insertion SSI configuration from the fabric.

  • Updates the Security Service Insertion SSI. It allows modifications to the.

Note

This module has a corresponding action plugin.

Requirements

The below requirements are needed on the host that executes this module.

  • catalystcentersdk >= 3.2.3.0.0

  • python >= 3.12

Parameters

Parameter

Comments

catalystcenter_debug

aliases: dnac_debug

boolean

Flag for Cisco Catalyst Center SDK to enable debugging.

Choices:

catalystcenter_host

aliases: dnac_host

string / required

The Cisco Catalyst Center hostname.

catalystcenter_password

aliases: dnac_password

string

The Cisco Catalyst Center password to authenticate.

catalystcenter_port

aliases: dnac_port, catalystcenter_api_port

integer

The Cisco Catalyst Center port.

Default: :ansible-option-default:`443`

catalystcenter_username

aliases: dnac_username, user

string

The Cisco Catalyst Center username to authenticate.

Default: :ansible-option-default:`"admin"`

catalystcenter_verify

aliases: dnac_verify

boolean

Flag to enable or disable SSL certificate verification.

Choices:

catalystcenter_version

aliases: dnac_version

string

Informs the SDK which version of Cisco Catalyst Center to use.

Default: :ansible-option-default:`"3.1.6.0"`

id

string

Id path parameter. The unique identifier of the Security Service Insertion (SSI).

siteId

string

The ID of the fabric site where the service insertion is configured.

validate_response_schema

boolean

Flag for Cisco Catalyst Center SDK to enable the validation of request bodies against a JSON schema.

Choices:

virtualNetworks

list / elements=dictionary

The list of virtual networks which are selected for steering traffic towards the firewall.

devices

list / elements=dictionary

The list of border devices selected per VN for firewall handoff.

id

string

The unique identifier of the network device.

layer3Handoffs

list / elements=dictionary

List containing information regarding the firewall connection and IP addressing.

firewallIpV4AddressWithMask

string

The IPv4 address and subnet mask of the firewall.

name

string

Name of the virtual network associated with the fabric site.

Notes

Note

  • SDK Method used are sda.Sda.create_security_service_insertion_on_a_specific_fabric_site, sda.Sda.delete_security_service_insertion, sda.Sda.update_the_security_service_insertion,

  • Paths used are post /dna/intent/api/v1/securityServiceInsertions, delete /dna/intent/api/v1/securityServiceInsertions/{id}, put /dna/intent/api/v1/securityServiceInsertions/{id},

  • Does not support check_mode

  • The plugin runs on the control node and does not use any ansible connection plugins,

  • but instead uses the embedded connection manager from Cisco CATALYST SDK

  • Requires Python >= 3.10, matching the controller Python versions supported by the collection's minimum ansible-core version (see the collection README for the current ansible-core / Python compatibility range)

See Also

See also

Cisco Catalyst Center documentation for SDA CreateSecurityServiceInsertionOnASpecificFabricSite

Complete reference of the CreateSecurityServiceInsertionOnASpecificFabricSite API.

Cisco Catalyst Center documentation for SDA DeleteSecurityServiceInsertion

Complete reference of the DeleteSecurityServiceInsertion API.

Cisco Catalyst Center documentation for SDA UpdateTheSecurityServiceInsertion

Complete reference of the UpdateTheSecurityServiceInsertion API.

Examples

---
- name: Update by id
  cisco.catalystcenter.security_service_insertions:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: present
    id: string
    siteId: string
    virtualNetworks:
      - devices:
          - id: string
            layer3Handoffs:
              - firewallIpV4AddressWithMask: string
        name: string
- name: Delete by id
  cisco.catalystcenter.security_service_insertions:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: absent
    id: string
- name: Create
  cisco.catalystcenter.security_service_insertions:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    state: present
    siteId: string
    virtualNetworks:
      - devices:
          - id: string
            layer3Handoffs:
              - firewallIpV4AddressWithMask: string
        name: string

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

catalystcenter_response

dictionary

A dictionary or list with the response returned by the Cisco Catalyst Center Python SDK

Returned: always

Sample: :ansible-rv-sample-value:`{"response": {"taskId": "string", "url": "string"}, "version": "string"}`

Authors

  • Bryan Vargas (@bvargasre)