cisco.catalystcenter.sites_site_id_wireless_settings_ssids_id_update module -- Resource module for Sites Site Id Wireless Settings Ssids Id Update
Note
This module is part of the cisco.catalystcenter collection (version 2.11.0).
To install it, use: ansible-galaxy collection install cisco.catalystcenter.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: cisco.catalystcenter.sites_site_id_wireless_settings_ssids_id_update.
New in cisco.catalystcenter 2.0.0
Synopsis
Manage operation create of the resource Sites Site Id Wireless Settings Ssids Id Update.
This API allows to either update SSID at global `siteId` or override SSID at non-global `siteId`.
Note
This module has a corresponding action plugin.
Requirements
The below requirements are needed on the host that executes this module.
catalystcentersdk >= 3.2.3.0.0
python >= 3.12
Parameters
Parameter |
Comments |
|---|---|
Activate the AAA Override feature when set to true. Choices: |
|
List of Accounting server IpAddresses. |
|
Pre-Auth Access Control List (ACL) Name. |
|
Authentication Server, Mandatory for Guest SSIDs with wlanType=Guest and l3AuthType=web_auth. |
|
List of Authentication/Authorization server IpAddresses. |
|
L2 Authentication Type (If authType is not open , then atleast one RSN Cipher Suite and corresponding valid AKM must be enabled). |
|
This refers to the duration of inactivity, measured in seconds, before a client connected to the Basic Service Set is considered idle and timed out. Default is Basic ServiceSet ClientIdle Timeout if exists else 300. If it needs to be disabled , pass 0 as its value else valid range is 15 to 100000. |
|
Activate the maximum idle feature for the Basic Service Set. Choices: |
|
Flag for Cisco Catalyst Center SDK to enable debugging. Choices: |
|
The Cisco Catalyst Center hostname. |
|
The Cisco Catalyst Center password to authenticate. |
|
The Cisco Catalyst Center port. Default: :ansible-option-default:`443` |
|
The Cisco Catalyst Center username to authenticate. Default: :ansible-option-default:`"admin"` |
|
Flag to enable or disable SSL certificate verification. Choices: |
|
Informs the SDK which version of Cisco Catalyst Center to use. Default: :ansible-option-default:`"3.1.6.0"` |
|
CCKM Timestamp Tolerance(in milliseconds). |
|
Activate the feature that allows for the exclusion of clients. Choices: |
|
This refers to the length of time, in seconds, a client is excluded or blocked from accessing the network after a specified number of unsuccessful attempts. |
|
This pertains to the maximum data transfer rate, specified in bits per second, that a client is permitted to achieve. |
|
Activate Coverage Hole Detection feature when set to true. Choices: |
|
The Directed Multicast Service feature becomes operational when it is set to true. Choices: |
|
Egress QOS. |
|
External WebAuth URL (Mandatory for Guest SSIDs with wlanType = Guest , l3AuthType = web_auth and authServer = auth_external). |
|
Fast Transition. |
|
Enable Fast Transition over the Distributed System when set to true. Choices: |
|
2.4 Ghz Band Policy value. Allowed only when 2.4 Radio Band is enabled in ssidRadioType. |
|
True if 6 GHz Policy Client Steering is enabled, else False. Choices: |
|
SSID ID. |
|
Ingress QOS. |
|
Name of the group ssid is inherited from. |
|
UUID of the site from which the SSID is inherited from. - An empty inheritedSiteUUID signifies that the SSID configuration is not inherited and is defined at the specified site level. - A non-empty inheritedSiteUUID indicates that the SSID configuration is inherited from either the immediate parent site with an override or from the global site level, if no such parent exists. - Example -Given the site hierarchy as Global/Area/BGL-1/FLR-1 and an SSID (SSID-1) that is overridden at BGL-1 - If ${siteId} is the Global Site Identifier, the API will return SSID data associated with the Global Site Identifier, and inheritedSiteUUID will be an empty string. - If ${siteId} is the Area Site Identifier, the API will return SSID data associated with the Area Site Identifier, and inheritedSiteUUID will contain the Global Site Identifier. - If ${siteId} is the BGL-1 Site Identifier, the API will return SSID data that has been overridden at the BGL-1 Site Identifier level, and inheritedSiteUUID will be an empty string. - If ${siteId} is the FLR-1 Site Identifier, the API will return SSID data that has been overridden at the BGL-1 Site Identifier level, and inheritedSiteUUID will contain the BGL-1 Site Identifier. |
|
Pre-Auth IPv6 Access Control List (ACL) Name. |
|
When set to true, the Access Point (AP) Beacon Protection feature is activated, enhancing the security of the network. Choices: |
|
When set to true, the 802.1X authentication key is in use. Choices: |
|
When set to true, the feature that enables 802.1X authentication using the SHA256 algorithm is turned on. Choices: |
|
When set to true, the 802.1X-Plus-FT authentication key is in use. Choices: |
|
When set to true, the feature that enables the use of Easy Pre-shared Key (PSK) authentication is activated. Choices: |
|
When set to true, the Opportunistic Wireless Encryption (OWE) authentication key feature is turned on. Choices: |
|
When set to true, the Pre-shared Key (PSK) authentication feature is enabled. Choices: |
|
When set to true, the feature that enables the combination of Pre-shared Key (PSK) and Fast Transition (FT) authentication keys is activated. Choices: |
|
The feature that allows the use of Pre-shared Key (PSK) authentication with the SHA256 algorithm is enabled when it is set to true. Choices: |
|
When set to true, the feature enabling the Simultaneous Authentication of Equals (SAE) authentication key is activated. Choices: |
|
When set to true, the Simultaneous Authentication of Equals (SAE) Extended Authentication key feature is turned on. Choices: |
|
When set to true, the Simultaneous Authentication of Equals (SAE) combined with Fast Transition (FT) Authentication Key feature is enabled. Choices: |
|
Activating this setting by switching it to true turns on the authentication key feature that supports both Simultaneous Authentication of Equals (SAE) and Fast Transition (FT). Choices: |
|
When set to true, the SuiteB192-1x authentication key feature is enabled. Choices: |
|
When activated by setting it to true, the SuiteB-1x authentication key feature is engaged. Choices: |
|
When activated by setting it to true, the Broadcast SSID feature will make the SSID publicly visible to wireless devices searching for available networks. Choices: |
|
True if CCKM is enabled, else False. Choices: |
|
Set to true if Custom NAS ID Options provided. Choices: |
|
Set SSID's admin status as 'Enabled' when set to true. Choices: |
|
True if FastLane is enabled, else False. Choices: |
|
True if passphrase is in Hex format, else False. Choices: |
|
Load Balancing config for the Radius Server group will be enabled when set to true. Can be enabled only when more that one acctServers configured. Choices: |
|
Load Balancing config for the Radius Server group will be enabled when set to true. Can be enabled only when more that one authServers configured. Choices: |
|
When set to true, MAC Filtering will be activated, allowing control over network access based on the MAC address of the device. Choices: |
|
Applicable only for Enterprise SSIDs. When set to True, Posturing will enabled. Required to be set to True if ACL needs to be mapped for Enterprise SSID. Choices: |
|
'true' if Radius profiling needs to be enabled, defaults to 'false' if not specified. At least one AAA/PSN server is required to enable Radius Profiling. Choices: |
|
Deny clients using randomized MAC addresses when set to true. Choices: |
|
L3 Authentication Type. |
|
Management Frame Protection Client. |
|
Multi PSK Settings (Only applicable for SSID with PERSONAL auth type and PSK). |
|
Passphrase needs to be between 8 and 63 characters for ASCII type. HEX passphrase needs to be 64 characters. |
|
Passphrase Type. |
|
Priority. |
|
Pre-Defined NAS Options AP ETH Mac Address, AP IP address, AP Location , AP MAC Address, AP Name, AP Policy Tag, AP Site Tag, SSID, System IP Address, System MAC Address, System Name. |
|
The Neighbor List feature is enabled when it is set to true. Choices: |
|
Open SSID which is already created in the design and not associated to any other OPEN-SECURED SSID. |
|
Passphrase (Only applicable for SSID with PERSONAL security level). |
|
Policy Profile Name. If 'policyProfileName' is not provided, the value of 'profileName' will be assigned to it. If 'profileName' is also not provided, an autogenerated name will be used. Autogenerated name is generated by appending 'ssid' field's value with '_profile' (Example If 'ssid' = 'ExampleSsid', then autogenerated name will be 'ExampleSsid_profile'). |
|
WLAN Profile Name , if not passed autogenerated profile name will be assigned. |
|
(REQUIRED is applicable for authType WPA3_PERSONAL, WPA3_ENTERPRISE, OPEN_SECURED) and (OPTIONAL/REQUIRED is applicable for authType WPA2_WPA3_PERSONAL and WPA2_WPA3_ENTERPRISE). |
|
When set to true, the Robust Security Network (RSN) Cipher Suite CCMP128 encryption protocol is activated. Choices: |
|
When set to true, the Robust Security Network (RSN) Cipher Suite CCMP256 encryption protocol is activated. Choices: |
|
When set to true, the Robust Security Network (RSN) Cipher Suite GCMP128 encryption protocol is activated. Choices: |
|
When set to true, the Robust Security Network (RSN) Cipher Suite GCMP256 encryption protocol is activated. Choices: |
|
This denotes the allotted time span, expressed in seconds, before a session is automatically terminated due to inactivity. |
|
Turn on the feature that imposes a time limit on user sessions. Choices: |
|
SiteId path parameter. Site UUID. |
|
When set to true, this will activate the timeout settings that apply to clients in sleep mode. Choices: |
|
This refers to the amount of time, measured in minutes, before a sleeping (inactive) client is timed out of the network. |
|
Name of the SSID. |
|
Radio Policy Enum (default Triple band operation(2.4GHz, 5GHz and 6GHz)). |
|
Pre-Auth URL Access Control List (ACL) Name. |
|
Flag for Cisco Catalyst Center SDK to enable the validation of request bodies against a JSON schema. Choices: |
|
When set to true, the Web-Passthrough feature will be activated for the Guest SSID, allowing guests to bypass certain login requirements. Choices: |
|
Band select is allowed only when band options selected contains at least 2.4 GHz and 5 GHz band. Choices: |
|
WLAN type. |
Notes
Note
SDK Method used are wireless.Wireless.update_or_overridessid,
Paths used are post /dna/intent/api/v1/sites/{siteId}/wirelessSettings/ssids/{id}/update,
Does not support
check_modeThe plugin runs on the control node and does not use any ansible connection plugins,
but instead uses the embedded connection manager from Cisco CATALYST SDK
Requires Python >= 3.10, matching the controller Python versions supported by the collection's minimum ansible-core version (see the collection README for the current ansible-core / Python compatibility range)
See Also
See also
- Cisco Catalyst Center documentation for Wireless UpdateOrOverrideSSID
Complete reference of the UpdateOrOverrideSSID API.
Examples
---
- name: Create
cisco.catalystcenter.sites_site_id_wireless_settings_ssids_id_update:
catalystcenter_host: "{{catalystcenter_host}}"
catalystcenter_username: "{{catalystcenter_username}}"
catalystcenter_password: "{{catalystcenter_password}}"
catalystcenter_verify: "{{catalystcenter_verify}}"
catalystcenter_port: "{{catalystcenter_port}}"
catalystcenter_version: "{{catalystcenter_version}}"
catalystcenter_debug: "{{catalystcenter_debug}}"
aaaOverride: true
acctServers:
- string
aclName: string
authServer: string
authServers:
- string
authType: string
basicServiceSetClientIdleTimeout: 0
basicServiceSetMaxIdleEnable: true
cckmTsfTolerance: 0
clientExclusionEnable: true
clientExclusionTimeout: 0
clientRateLimit: 0
coverageHoleDetectionEnable: true
directedMulticastServiceEnable: true
egressQos: string
externalAuthIpAddress: string
fastTransition: string
fastTransitionOverTheDistributedSystemEnable: true
ghz24Policy: string
ghz6PolicyClientSteering: true
id: string
ingressQos: string
inheritedSiteName: string
inheritedSiteUUID: string
ipv6AclName: string
isApBeaconProtectionEnabled: true
isAuthKey8021x: true
isAuthKey8021xPlusFT: true
isAuthKey8021x_SHA256: true
isAuthKeyEasyPSK: true
isAuthKeyOWE: true
isAuthKeyPSK: true
isAuthKeyPSKPlusFT: true
isAuthKeyPSKSHA256: true
isAuthKeySae: true
isAuthKeySaeExt: true
isAuthKeySaeExtPlusFT: true
isAuthKeySaePlusFT: true
isAuthKeySuiteB1921x: true
isAuthKeySuiteB1x: true
isBroadcastSSID: true
isCckmEnabled: true
isCustomNasIdOptions: true
isEnabled: true
isFastLaneEnabled: true
isHex: true
isLoadBalancingEnabledForAcctGroup: true
isLoadBalancingEnabledForAuthGroup: true
isMacFilteringEnabled: true
isPosturingEnabled: true
isRadiusProfilingEnabled: true
isRandomMacFilterEnabled: true
l3AuthType: string
managementFrameProtectionClientprotection: string
multiPSKSettings:
- passphrase: string
passphraseType: string
priority: 0
nasOptions:
- string
neighborListEnable: true
openSsid: string
passphrase: string
policyProfileName: string
profileName: string
protectedManagementFrame: string
rsnCipherSuiteCcmp128: true
rsnCipherSuiteCcmp256: true
rsnCipherSuiteGcmp128: true
rsnCipherSuiteGcmp256: true
sessionTimeOut: 0
sessionTimeOutEnable: true
siteId: string
sleepingClientEnable: true
sleepingClientTimeout: 0
ssid: string
ssidRadioType: string
urlAclName: string
webPassthrough: true
wlanBandSelectEnable: true
wlanType: string
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
A dictionary or list with the response returned by the Cisco Catalyst Center Python SDK Returned: always Sample: :ansible-rv-sample-value:`{"response": {"taskId": "string", "url": "string"}, "version": "string"}` |