cisco.catalystcenter.switches_configs_intended_security_update module -- Resource module for Switches Configs Intended Security Update

Note

This module is part of the cisco.catalystcenter collection (version 2.11.0).

To install it, use: ansible-galaxy collection install cisco.catalystcenter. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: cisco.catalystcenter.switches_configs_intended_security_update.

New in cisco.catalystcenter 2.11.0

Synopsis

  • Manage operation update of the resource Switches Configs Intended Security Update. - > This API updates the configurations for an intended feature on a switch. Updates to other intended features can be done over several iterations. Once all the updates to intended features are complete, they can be deployed to a device using the API /api/v1/switches/{id}/configs/intended/deploy. When the intended features are deployed, they are applied on top of the existing configurations on the device. Any existing configurations on the device which are not included in the intended features, are retained on the device.

Note

This module has a corresponding action plugin.

Requirements

The below requirements are needed on the host that executes this module.

  • catalystcentersdk >= 3.2.3.0.0

  • python >= 3.12

Parameters

Parameter

Comments

arpInspectionConfig

dictionary

This feature for configuring ARP Inspection protocol on the device, which monitors and validates ARP packets to prevent ARP spoofing and ensure network security.

items

list / elements=dictionary

List of arp inspection config feature entries.

configType

string

Type of network functionality under a feature. Config type ARP_INSPECTION_VLAN_CONFIG is for configuring ARP Inspection settings for specific VLANs.

vlanId

integer

ARP Inspection VLAN.

catalystcenter_debug

aliases: dnac_debug

boolean

Flag for Cisco Catalyst Center SDK to enable debugging.

Choices:

catalystcenter_host

aliases: dnac_host

string / required

The Cisco Catalyst Center hostname.

catalystcenter_password

aliases: dnac_password

string

The Cisco Catalyst Center password to authenticate.

catalystcenter_port

aliases: dnac_port, catalystcenter_api_port

integer

The Cisco Catalyst Center port.

Default: :ansible-option-default:`443`

catalystcenter_username

aliases: dnac_username, user

string

The Cisco Catalyst Center username to authenticate.

Default: :ansible-option-default:`"admin"`

catalystcenter_verify

aliases: dnac_verify

boolean

Flag to enable or disable SSL certificate verification.

Choices:

catalystcenter_version

aliases: dnac_version

string

Informs the SDK which version of Cisco Catalyst Center to use.

Default: :ansible-option-default:`"3.1.6.0"`

ctsConfig

dictionary

This feature is for configuring CTS.

items

list / elements=dictionary

List of cts config feature entries.

authorizationList

string

Authorization list for Cisco TrustSec policies. This list defines which policies are applied for TrustSec authorization decisions on the device. Unconfigure Value - use "" to unconfigure.

configType

string

Type of network functionality under a feature. Config type CTS_CONFIG is for configuring centralized traffic shaping and generation parameters.

ctsSgt

integer

Security Group Tag (SGT) value for TrustSec. Used to classify endpoints for policy enforcement. Unconfigure Value - use 0 to unconfigure.

defaultSxpPassword

string

Default password for SXP connections. Used for authentication when no peer-specific password is set. Unconfigure Value - use "" to unconfigure.

enforcementVlans

string

List of VLANs for Cisco TrustSec enforcement. Specifies which VLANs are subject to TrustSec security policies for segmentation and access control. Unconfigure Value - use "" to unconfigure.

ipSgtMappings

dictionary

Define mappings between IP addresses and SGTs.

configType

string

Security Group Tag (SGT) mapping configuration for Cisco TrustSec (CTS) to manage security group tag mappings.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

Type of network functionality under a feature. Config type SGT_MAP_CONFIG is for configuring the security group tag mapping within the network.

hostOrSubnetIpAddress

string

IPv4/IPv6 Host Address.

sgt

integer

Security Group Tag (SGT) value for VRF mapping. Assigns a security group to endpoints within a VRF. Unconfigure Value - use 0 to unconfigure.

ipVrfSgtMappings

dictionary

Per-VRF IP-to-SGT mapping configuration for Cisco TrustSec.

configType

string

Security Group Tag (SGT) mapping list configuration for Cisco TrustSec (CTS) to manage security group tag mappings in lists.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

Config type SGT_MAP_LIST_GEN is for configuring Security Group Tag (SGT) Mapping lists which are used to define and apply security policies within network devices.

ipAddress

string

IPv4/IPv6 Host Address.

sgt

integer

Security Group Tag (SGT) value for mapping. Assigns a security group to the specified IP address for TrustSec access control. Unconfigure Value - use 0 to unconfigure.

vrfName

string

Select VPN Routing/Forwarding instance for the binding.

isRoleBasedEnforcementEnabled

boolean

Enables enforcement-only mode for Cisco TrustSec role-based policies. When enabled, the device enforces policies but does not perform authorization checks. Unconfigure Value - use false to revert to default settings.

Choices:

isSxpEnabled

boolean

Enable CTS SXP support. Unconfigure Value - use false to revert to default settings.

Choices:

roleBasedPermissions

dictionary

Configure IP or SGT ranges for role-based enforcement.

configType

string

Role-based permissions configuration for Cisco TrustSec (CTS) to manage security group tag ranges.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

The generation and management of continuous time series ranges within network features.

destinationSgtRanges

dictionary

Map source and destination ranges for CTS role-based enforcement.

configType

string

Role-based range configuration for Cisco TrustSec (CTS) to manage security group tag ranges.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

Configuring access control policies based on role-based IP range mappings within the network.

destinationSgt

integer

Destination SGT range for Cisco TrustSec permissions. Sets the range of SGTs that are allowed as destinations for specific TrustSec policies.

ipv4RoleBasedAclName

string

ACL name for permissions between SGT ranges. Specifies the access control list used to permit or deny traffic between defined SGT ranges. Derived From - The available IPv4 role-based ACL names include IPv4 Role-Based Access List configurations from the current profile and the device. Unconfigure Value - use "" to unconfigure.

ipv6RoleBasedAclName

string

IPv6 ACL name for permissions between SGT ranges. Defines the IPv6 access control list for traffic between specified SGT ranges. Derived From - The available IPv6 role-based ACL names include IPv6 Role-Based Access List configurations from the current profile and the device. Unconfigure Value - use "" to unconfigure.

sourceSgtRange

integer

Source SGT range for Cisco TrustSec permissions. Defines the range of Security Group Tags (SGTs) that are allowed as sources for specific policies.

sxpIpV4Peers

dictionary

Configure SXP IPv4 settings without a VRF.

configType

string

SXP IPv4 Peer configuration.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

ConfigType CTS_SXP_IPV4_NO_VRF_GEN is for configuring SXP connections for IPv4 without VRF support.

ipV4Address

string

IPv4 address of the SXP peer. Specifies the remote peer for SXP connections.

localDeviceMode

string

Additional options for SXP peer connection. Allows customization of SXP peer behavior. Unconfigure Value - use SPEAKER to revert to default settings.

maximumHoldTime

integer

Maximum time in seconds before SXP peer connection times out. Controls how long the peer connection can remain idle. Unconfigure Value - use 0 to revert to default settings.

minimumHoldTime

integer

Hold time in seconds for SXP peer connection. Determines how long the connection remains active without updates. Unconfigure Value - use 0 to revert to default settings.

mode

string

Mode for SXP peer connection (speaker, listener, both, none). Defines the role of the peer in SXP communication. Unconfigure Value - use "" to unconfigure.

passwordType

string

Password for SXP peer connection. Used to authenticate SXP peers. Unconfigure Value - use "" to unconfigure.

sourceIpv4Address

string

Source interface for SXP peer connection. Specifies which interface initiates the SXP connection. Unconfigure Value - use "" to unconfigure.

deviceTrackingConfig

dictionary

This feature is for configuring Device Tracking Settings.

items

list / elements=dictionary

List of device tracking config feature entries.

configType

string

Type of network functionality under a feature. Config type DEVICE_TRACKING is for configuring the tracking and management of device connectivity and location data within a network.

deviceTrackingPolicy

dictionary

Configure policies for Device Tracking.

configType

string

Device tracking policy configuration type.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

addressCountLimit

integer

Maximum number of addresses allowed per device on an interface. This restricts the number of IP addresses a single device can use on a port. Unconfigure Value - use 0 to unconfigure. Supported IOS-XE versions - This property is viewable only (read-only) on Cisco switches running IOS version earlier than 17.18.1. Since IOS version 17.18.1 or later, configuration for this property is supported.

configType

string

Type of network functionality under a feature. Config type INET_ADDRESS is for configuring IP addresses related to device tracking within the defined network environment.

deviceRole

string

Configuration for device roles in device tracking policies. This allows you to define and assign roles to tracked devices for policy enforcement. Supported IOS-XE versions - This property is viewable only (read-only) on Cisco switches running IOS version earlier than 17.15.1. Since IOS version 17.15.1 or later, configuration for this property is supported. Unconfigure Value - use NODE to revert to default settings.

isDestinationGleanLogOnly

boolean

Enables logging only for destination glean events without taking action. Use this to monitor glean events for analysis without enforcing policies. Unconfigure Value - use false to unconfigure.

Choices:

isPrefixGleanEnabled

boolean

Enables gleaning of device prefixes for tracking. This helps in identifying devices by their network prefixes for more granular tracking. Unconfigure Value - use false to unconfigure.

Choices:

isProtocolArpEnabled

boolean

Enables device tracking for ARP protocol. This allows the system to track devices using ARP messages for IPv4 address resolution. Unconfigure Value - use true to revert to default settings.

Choices:

isProtocolDhcp4Enabled

boolean

Enables device tracking for DHCPv4 protocol. This allows tracking of devices that obtain IPv4 addresses via DHCP. Unconfigure Value - use true to revert to default settings.

Choices:

isProtocolDhcp6Enabled

boolean

Enables device tracking for DHCPv6 protocol. This allows tracking of devices that obtain IPv6 addresses via DHCPv6. Unconfigure Value - use true to revert to default settings.

Choices:

isProtocolNdpEnabled

boolean

Enables device tracking for IPv6 Neighbor Discovery Protocol (NDP). This helps track IPv6 devices using NDP messages. Unconfigure Value - use true to revert to default settings.

Choices:

isSecurityLevelGleanEnabled

boolean

Security level for gleaned device tracking entries. Set the security level for entries learned via gleaning to control access and monitoring. Unconfigure Value - use false to revert to default settings.

Choices:

isTrackingEnabled

boolean

Enables or disables device tracking on the interface. When enabled, the interface will track connected devices for security and management. Unconfigure Value - use false to revert to default settings.

Choices:

isTrustedPortEnabled

boolean

Marks the port as trusted for device tracking. Trusted ports are exempt from certain security checks and restrictions. Unconfigure Value - use false to revert to default settings.

Choices:

policyName

string

Policy name or identifier for device tracking. Use this to reference and apply specific device tracking policies to interfaces.

fallbackSourceIpv4Address

string

IPv4 address used as fallback for auto source in device tracking. This address is used if automatic learning fails. Unconfigure Value - use "" to unconfigure.

fallbackSourceIpv4Mask

string

Subnet mask for fallback IPv4 auto source. Defines the network mask for the fallback address. Unconfigure Value - use "" to unconfigure.

isAutoSourceEnabled

boolean

Enables automatic source address learning for device tracking. This allows the system to automatically learn source addresses for tracked devices. Unconfigure Value - use false to unconfigure.

Choices:

isFallbackSourceOverrideEnabled

boolean

Overrides default fallback behavior for auto source. Use this to customize how fallback addresses are handled. Unconfigure Value - use false to unconfigure.

Choices:

isLoggingTheftEnabled

boolean

Enables logging of device theft events detected by device tracking. This helps in security monitoring by recording suspected theft incidents. Unconfigure Value - use false to unconfigure.

Choices:

isTrackingEnabled

boolean

Enables or disables device tracking globally. When enabled, device tracking features are active across the system. Unconfigure Value - use false to unconfigure.

Choices:

maxBindingEntries

integer

Maximum number of device tracking entries allowed per interface. This limits how many devices can be tracked on a single interface to prevent resource exhaustion. Unconfigure Value - use 0 to unconfigure.

deviceTrackingVlanConfig

dictionary

This feature is for configuring Device Tracking Vlan Settings.

items

list / elements=dictionary

List of device tracking vlan config feature entries.

configType

string

Type of network functionality under a feature. Config type DEVICE_TRACKING_VLAN is for configuring VLAN-based device tracking to monitor and manage devices connected to a network.

deviceTrackingPolicy

string

Configure policies for Device Tracking. Derived From - The available policy names include Device Tracking Policy configurations from the current profile and the device. Unconfigure Value - use "" to unconfigure.

isDeviceTrackingEnabled

boolean

Enable device tracking for the VLAN. Unconfigure Value - use false to unconfigure.

Choices:

vlanId

string

VLAN ID for configuration entry. Enter the VLAN identifier to apply specific configuration settings to that VLAN.

dhcpSnoopingConfig

dictionary

This feature is for configuring DHCP Snooping. DHCP Snooping is a security feature that acts as a firewall between untrusted hosts and trusted DHCP servers. It helps to prevent malicious or malformed DHCP traffic and ensures that only valid DHCP servers can assign IP addresses.

items

list / elements=dictionary

List of dhcp snooping config feature entries.

configType

string

Type of network functionality under a feature. Config type DHCP_SNOOPING_CONFIG is for configuring DHCP Snooping settings.

databaseTimeout

integer

Timeout value in seconds for DHCP snooping database entries. Set how long DHCP snooping records are kept before being removed. Unconfigure Value - use 300 to revert to default settings.

databaseUrl

string

URL for DHCP snooping database storage. Specify the location where DHCP snooping data is stored for auditing and monitoring. Unconfigure Value - use "" to unconfigure.

dhcpSnoopingVlans

dictionary

Configure VLANs for DHCP snooping.

configType

string

Configure DHCP Snooping settings for specific VLANs.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

isDhcpSnoopingEnabled

boolean

DHCP Snooping. Unconfigure Value - use false to unconfigure.

Choices:

isGleanEnabled

boolean

Enables gleaning of DHCP snooping information. When enabled, additional DHCP data is collected for enhanced security and troubleshooting. Unconfigure Value - use false to revert to default settings.

Choices:

isSnoopingInfoOptionEnabled

boolean

Option for DHCP snooping information. Specify which DHCP options should be monitored and recorded by snooping. Unconfigure Value - use true to revert to default settings.

Choices:

isSnoopingOptionAllowUntrustedEnabled

boolean

Allows untrusted DHCP snooping information options. Enable this to accept DHCP options from untrusted sources for flexibility in network design. Unconfigure Value - use false to unconfigure.

Choices:

writeDelay

integer

Write delay in seconds for DHCP snooping database updates. Set how frequently changes are written to the snooping database. Unconfigure Value - use 300 to revert to default settings.

dot1xConfig

dictionary

This feature is for configuring 802.1x. IEEE 802.1x is a standard which facilitates access control between a client and a server. Before services can be provided to a client by a Local Access Network (LAN) or switch, the client connected to the switch port has to be authenticated by the authentication server which runs Remote Authentication Dial-In User Service (RADIUS). 802.1x authentication restricts unauthorized clients from connecting to a LAN through publicly-accessible ports.

items

list / elements=dictionary

List of dot1x config feature entries.

configType

string

Setting global parameters for IEEE 802 authentication across the network infrastructure.

dot1xCredentials

dictionary

Configure Dot1x Credentials.

configType

string

Dot1xCredentials.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

Configuring credentials for 802.1X authentication, including username, password, and encryption type.

password

string

Secret password used for 802.1X authentication credentials. This password is used for secure network access authentication. Unconfigure Value - use "" to unconfigure.

passwordType

string

Type of password for 802.1X credentials (clear or encrypted). Choose between clear text or encrypted password storage for security. Unconfigure Value - use "" to unconfigure.

profileName

string

Profile name for 802.1X authentication credentials. Use this to organize and manage different authentication profiles.

username

string

Username for 802.1X authentication credentials. This username is used for network access authentication. Unconfigure Value - use "" to unconfigure.

isDot1xEnabled

boolean

Enables system-wide 802.1X authentication control. This activates 802.1X authentication across all interfaces on the device. Unconfigure Value - use false to revert to default settings.

Choices:

isLoggingVerboseEnabled

boolean

Enables verbose logging for 802.1X authentication events. When enabled, detailed logs are generated for troubleshooting and auditing. Unconfigure Value - use false to revert to default settings.

Choices:

feature

string

Feature path parameter. Name of the feature to configure.

id

string

Id path parameter. Network device id of the switch. The Network device id can be identified from the GET network device API /dna/intent/api/v1/network-device response.

ipV4ExtendedAccessListConfig

dictionary

This feature is for configuring IP Access List Extended settings. It allows defining extended access control lists for more granular traffic control.

items

list / elements=dictionary

List of ip v4 extended access list config feature entries.

accessListSequenceRules

dictionary

Sequence rule list for the IPv4 extended access-list.

configType

string

Type of network functionality under a feature. Config type IPV4_ROLE_BASED_ACCESS_LIST_RULES is for configuring IP ACL List Sequence Rule settings.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

action

string

Action for the extended access-list rule (permit or deny). This determines whether matching traffic is allowed or blocked by the access-list.

configType

string

Type of network functionality under a feature. Config type IPV4_EXTENDED_ACCESS_LIST_RULE is for configuring IP Standard Access List Sequence Rule settings.

destinationEndRange

string

End range for destination port in ACL rules, enhancing traffic control and security.

destinationIpV4Address

string

Destination host IP address for the extended access-list rule. This allows you to specify a single host as the destination for filtering.

destinationIpV4Subnet

string

Destination IPv4 address for the extended access-list rule. This specifies the target address for traffic filtering.

destinationStartRange

string

Start range for destination port in ACL rules, enhancing traffic control and security.

destinationType

string

Defines the type of destination port for ACL rules, enhancing traffic control and security.

destinationValue

string

Destination value for the ACL rule, such as port numbers or protocol types.

destinationWildcard

string

Subnet mask for the destination IPv4 address in the extended access-list rule. This defines the network portion of the destination address for matching.

isDestinationAnyEnabled

boolean

Matches any destination IP address in the extended access-list rule. This allows the rule to apply to all possible destination addresses.

Choices:

isLoggingEnabled

boolean

Enables logging for the extended access-list rule. When enabled, matching traffic will be logged for monitoring and troubleshooting.

Choices:

isSourceAnyEnabled

boolean

Matches any IP address in the extended access-list rule. Use this to create rules that apply to all IP addresses, regardless of source or destination.

Choices:

matchDscp

string

Differentiated Services Code Point (DSCP) value for QoS matching in the extended access-list rule. Use this to filter or prioritize traffic based on QoS markings.

protocol

string

Protocol matched by the extended access-list rule (e.g. Tcp, udp, icmp). This allows filtering based on network protocol type.

sequence

integer

Sequence number for the extended access-list rule. This determines the order in which rules are evaluated and applied.

sourceEndRange

string

End range for source port in ACL rules, enhancing traffic control and security.

sourceIpV4Address

string

Host IP address for the extended access-list rule. This is used to match traffic to or from a specific host.

sourceIpV4Subnet

string

IPv4 address for the extended access-list rule. Use this to match traffic based on a specific IPv4 address.

sourceStartRange

string

Start range for source port in ACL rules, enhancing traffic control and security.

sourceType

string

Defines the type of source port for ACL rules, enhancing traffic control and security.

sourceValue

string

Source value for the ACL rule, such as port numbers or protocol types.

sourceWildcard

string

Subnet mask for the IPv4 address in the extended access-list rule. This helps define which addresses are matched by the rule.

aclName

string

Name of the extended access-list. Assigning a name helps with identification, management, and referencing the access-list in configurations.

configType

string

Type of network functionality under a feature. Config type IPV4_EXTENDED_ACCESS_LIST_CONFIG is for configuring IP Access List Extended settings.

ipV4RoleBasedAccessListConfig

dictionary

This feature is for configuring IP ACL Role Based settings. It allows defining access control lists based on roles to enhance network security.

items

list / elements=dictionary

List of ip v4 role based access list config feature entries.

accessListSequenceRules

dictionary

Sequence rule list for the IPv4 role-based access-list.

configType

string

Type of network functionality under a feature. Config type IPV4_ROLE_BASED_ACCESS_LIST_RULES is for configuring IP ACL List Sequence Rule settings.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

action

string

Action for the role-based access-list rule (permit or deny). This determines whether matching traffic is allowed or blocked by the role-based access-list.

configType

string

Type of network functionality under a feature. Config type IPV4_ROLE_BASED_ACCESS_LIST_RULE is for configuring IP ACL List Sequence Rule settings.

isLoggingEnabled

boolean

Enables logging for the role-based access-list rule. When enabled, matching traffic will be logged for monitoring and auditing.

Choices:

protocol

string

Protocol matched by the role-based access-list rule (e.g. Tcp, udp, icmp). This allows filtering based on protocol type for role-based access control.

sequence

integer

Sequence number for the role-based access-list rule, used to determine rule order. This value controls the evaluation order of rules within a role-based ACL, affecting which rule is matched first.

aclName

string

Name of the role-based access-list, used for identification and management. Assign a unique name to easily reference and manage the ACL in configurations and policies.

configType

string

Type of network functionality under a feature. Config type IPV4_ROLE_BASED_ACCESS_LIST_CONFIG is for configuring IP ACL Role Based settings.

ipV4StandardAccessListConfig

dictionary

This feature is for configuring IP Access List Standard settings. It allows defining standard access control lists for basic traffic control.

items

list / elements=dictionary

List of ip v4 standard access list config feature entries.

accessListSequenceRules

dictionary

Sequence rule list for the IPv4 standard access-list.

configType

string

Type of network functionality under a feature. Config type IPV4_ROLE_BASED_ACCESS_LIST_RULES is for configuring IP ACL List Sequence Rule settings.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

configType

string

Configuration type for the access list sequence rule.

isDenyAnyEnabled

boolean

Denies any IP address in the standard access-list rule. Use this to block all traffic regardless of source address, providing a catch-all deny rule.

Choices:

isDenyLogEnabled

boolean

Enables logging for denied packets in the standard access-list rule. When enabled, all denied traffic will be recorded for monitoring and troubleshooting.

Choices:

isPermitAnyEnabled

boolean

Permits any IP address in the standard access-list rule. Use this to allow all traffic regardless of source address, providing a catch-all permit rule.

Choices:

isPermitLogEnabled

boolean

Enables logging for permitted packets in the standard access-list rule. When enabled, all allowed traffic will be recorded for monitoring and auditing.

Choices:

sequence

integer

Sequence number for the standard access-list rule, used to determine rule order. This value controls the evaluation order of rules within a standard ACL, affecting which rule is matched first.

sourceHostIpV4Address

string

Host IPv4 address to permit in the standard access-list rule. Use this to allow traffic from a specific source IP address.

sourceIpV4Address

string

IPv4 address prefix to deny in the standard access-list rule. Specify a network or subnet to block traffic from a range of addresses.

sourceWildcard

string

Subnet mask for the denied IPv4 address in the standard access-list rule. Use this to define the network portion of addresses to be denied.

subnetHostIpV4Address

string

Host IPv4 address to deny in the standard access-list rule. Use this to block traffic from a specific source IP address.

subnetIpV4Address

string

IPv4 address prefix to permit in the standard access-list rule. Specify a network or subnet to allow traffic from a range of addresses.

subnetWildcard

string

Subnet mask for the permitted IPv4 address in the standard access-list rule. Use this to define the network portion of addresses to be permitted.

aclName

string

Name of the standard access-list, used for identification and management. Assign a unique name to easily reference and manage the ACL in configurations and policies.

configType

string

Type of network functionality under a feature. Config type IPV4_STANDARD_ACCESS_LIST_CONFIG is for configuring IP Access List Standard settings.

ipV6AccessListConfig

dictionary

This feature is for configuring IP Named ACL settings. It allows defining named access control lists for easier management and configuration.

items

list / elements=dictionary

List of ip v6 access list config feature entries.

accessListSequenceRules

dictionary

Sequence rule list for the IPv6 access-list.

configType

string

IPv6 Access List Sequence Rule configuration type.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

aclName

string

Name of the IPv6 access-list. Assign a unique name to identify and manage the access-list in IPv6 security and traffic policies.

configType

string

Configuration type for the named ACL.

ipV6RoleBasedAccessListConfig

dictionary

This feature is for configuring IPv6 Acc List Role Seq Rule Gen settings. It allows defining role-based access control lists for easier management and configuration.

items

list / elements=dictionary

List of ip v6 role based access list config feature entries.

accessListSequenceRules

dictionary

Sequence rule list for the IPv6 role-based access-list.

configType

string

IPv6 Role-based Access List Sequence Rule configuration type.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

action

string

Action for the role-based IPv6 access-list rule (permit or deny). This setting controls whether matching IPv6 traffic is allowed or blocked based on user roles. Or deny.

configType

string

Type of network functionality under a feature. Config type IPV6_ROLE_BASED_ACCESS_LIST_RULE is for configuring the sequence of access control rules in an IPv6 role-based access list.

isLogEnabled

boolean

Enables logging for the role-based IPv6 access-list rule. When enabled, matching traffic is recorded for monitoring, auditing, and troubleshooting.

Choices:

protocolType

string

Protocol type for the IPv6 role-based access list rule, such as TCP, UDP, or ICMP.

protocolValue

string

Protocol value for the IPv6 role-based access list rule, such as TCP port numbers or ICMP types.

sequence

integer

Sequence number for the role-based IPv6 access-list rule. This value determines the order of rule evaluation, impacting which rule is applied first for role-based IPv6 filtering.

aclName

string

Name of the role-based IPv6 access-list. Assign a unique name to reference and manage role-based IPv6 access policies. It from others for simplified management and configuration.

configType

string

Type of network functionality under a feature. Config type IPV6_ROLE_BASED_ACCESS_LIST_CONFIG is for configuring sequential rule generation for IPv6 access list role assignments.

macExtendedAccessListConfig

dictionary

This feature is for configuring MAC Acc List Extended Gen settings. It allows defining extended MAC access control lists for easier management and configuration.

items

list / elements=dictionary

List of mac extended access list config feature entries.

accessListExtendedEntries

dictionary

Extended entry list for the MAC access-list.

configType

string

Mac Access List Extended configuration type.

items

list / elements=dictionary

Switches Configs Intended Security Update's items.

action

string

Action for the extended MAC access-list entry (permit or deny). This determines whether matching MAC traffic is allowed or blocked by the access-list.

configType

string

Type of network functionality under a feature. Config type MAC_ACCESS_LIST_EXTENDED_ENTRY is for configuring detailed access control rules that specify which packets are permitted or denied based on criteria such as source and destination IP addresses, protocol types, and port numbers.

values

string

Values for the extended MAC access-list entry. Specify MAC addresses or other criteria to match traffic for filtering or monitoring.

aclName

string

Identifier for the extended MAC access-list. Assign a unique ID to reference and manage the MAC access-list for security policies. It from others for simplified management and configuration.

configType

string

Type of network functionality under a feature. Config type MAC_ACCESS_LIST_EXTENDED_CONFIG is for configuring extended MAC address accessibility options for enhanced network control.

validate_response_schema

boolean

Flag for Cisco Catalyst Center SDK to enable the validation of request bodies against a JSON schema.

Choices:

Notes

Note

  • SDK Method used are wired.Wired.update_intended_security_configurations,

  • Paths used are put /dna/campus/api/v1/switches/{id}/configs/intended/security/{feature},

  • Does not support check_mode

  • The plugin runs on the control node and does not use any ansible connection plugins,

  • but instead uses the embedded connection manager from Cisco CATALYST SDK

  • Requires Python >= 3.10, matching the controller Python versions supported by the collection's minimum ansible-core version (see the collection README for the current ansible-core / Python compatibility range)

See Also

See also

Cisco Catalyst Center documentation for Wired UpdateIntendedSecurityConfigurations

Complete reference of the UpdateIntendedSecurityConfigurations API.

Examples

---
- name: Update by id
  cisco.catalystcenter.switches_configs_intended_security_update:
    catalystcenter_host: "{{catalystcenter_host}}"
    catalystcenter_username: "{{catalystcenter_username}}"
    catalystcenter_password: "{{catalystcenter_password}}"
    catalystcenter_verify: "{{catalystcenter_verify}}"
    catalystcenter_port: "{{catalystcenter_port}}"
    catalystcenter_version: "{{catalystcenter_version}}"
    catalystcenter_debug: "{{catalystcenter_debug}}"
    arpInspectionConfig:
      items:
        - configType: string
          vlanId: 0
    ctsConfig:
      items:
        - authorizationList: string
          configType: string
          ctsSgt: 0
          defaultSxpPassword: string
          enforcementVlans: string
          ipSgtMappings:
            configType: string
            items:
              - configType: string
                hostOrSubnetIpAddress: string
                sgt: 0
          ipVrfSgtMappings:
            configType: string
            items:
              - configType: string
                ipAddress: string
                sgt: 0
                vrfName: string
          isRoleBasedEnforcementEnabled: true
          isSxpEnabled: true
          roleBasedPermissions:
            configType: string
            items:
              - configType: string
                destinationSgtRanges:
                  configType: string
                  items:
                    - configType: string
                      destinationSgt: 0
                      ipv4RoleBasedAclName: string
                      ipv6RoleBasedAclName: string
                sourceSgtRange: 0
          sxpIpV4Peers:
            configType: string
            items:
              - configType: string
                ipV4Address: string
                localDeviceMode: string
                maximumHoldTime: 0
                minimumHoldTime: 0
                mode: string
                passwordType: string
                sourceIpv4Address: string
    deviceTrackingConfig:
      items:
        - configType: string
          deviceTrackingPolicy:
            configType: string
            items:
              - addressCountLimit: 0
                configType: string
                deviceRole: string
                isDestinationGleanLogOnly: true
                isPrefixGleanEnabled: true
                isProtocolArpEnabled: true
                isProtocolDhcp4Enabled: true
                isProtocolDhcp6Enabled: true
                isProtocolNdpEnabled: true
                isSecurityLevelGleanEnabled: true
                isTrackingEnabled: true
                isTrustedPortEnabled: true
                policyName: string
          fallbackSourceIpv4Address: string
          fallbackSourceIpv4Mask: string
          isAutoSourceEnabled: true
          isFallbackSourceOverrideEnabled: true
          isLoggingTheftEnabled: true
          isTrackingEnabled: true
          maxBindingEntries: 0
    deviceTrackingVlanConfig:
      items:
        - configType: string
          deviceTrackingPolicy: string
          isDeviceTrackingEnabled: true
          vlanId: string
    dhcpSnoopingConfig:
      items:
        - configType: string
          databaseTimeout: 0
          databaseUrl: string
          dhcpSnoopingVlans:
            configType: string
            items:
              - configType: string
                vlanId: 0
          isDhcpSnoopingEnabled: true
          isGleanEnabled: true
          isSnoopingInfoOptionEnabled: true
          isSnoopingOptionAllowUntrustedEnabled: true
          writeDelay: 0
    dot1xConfig:
      items:
        - configType: string
          dot1xCredentials:
            configType: string
            items:
              - configType: string
                password: string
                passwordType: string
                profileName: string
                username: string
          isDot1xEnabled: true
          isLoggingVerboseEnabled: true
    feature: string
    id: string
    ipV4ExtendedAccessListConfig:
      items:
        - accessListSequenceRules:
            configType: string
            items:
              - action: string
                configType: string
                destinationEndRange: string
                destinationIpV4Address: string
                destinationIpV4Subnet: string
                destinationStartRange: string
                destinationType: string
                destinationValue: string
                destinationWildcard: string
                isDestinationAnyEnabled: true
                isLoggingEnabled: true
                isSourceAnyEnabled: true
                matchDscp: string
                protocol: string
                sequence: 0
                sourceEndRange: string
                sourceIpV4Address: string
                sourceIpV4Subnet: string
                sourceStartRange: string
                sourceType: string
                sourceValue: string
                sourceWildcard: string
          aclName: string
          configType: string
    ipV4RoleBasedAccessListConfig:
      items:
        - accessListSequenceRules:
            configType: string
            items:
              - action: string
                configType: string
                isLoggingEnabled: true
                protocol: string
                sequence: 0
          aclName: string
          configType: string
    ipV4StandardAccessListConfig:
      items:
        - accessListSequenceRules:
            configType: string
            items:
              - configType: string
                isDenyAnyEnabled: true
                isDenyLogEnabled: true
                isPermitAnyEnabled: true
                isPermitLogEnabled: true
                sequence: 0
                sourceHostIpV4Address: string
                sourceIpV4Address: string
                sourceWildcard: string
                subnetHostIpV4Address: string
                subnetIpV4Address: string
                subnetWildcard: string
          aclName: string
          configType: string
    ipV6AccessListConfig:
      items:
        - accessListSequenceRules:
            configType: string
            items:
              - action: string
                configType: string
                destinationEndRange: string
                destinationIpV6Address: string
                destinationNetworkAddress: string
                destinationNetworkWildcard: string
                destinationPrefix: string
                destinationStartRange: string
                destinationType: string
                destinationValue: string
                isDestinationAnyEnabled: true
                isEstablishedEnabled: true
                isLoggingEnabled: true
                isSourceAnyEnabled: true
                matchDscp: string
                protocol: string
                sequence: 0
                sourceEndRange: string
                sourceIpV6Address: string
                sourceNetworkAddress: string
                sourceNetworkWildcard: string
                sourcePrefix: string
                sourceStartRange: string
                sourceType: string
                sourceValue: string
          aclName: string
          configType: string
    ipV6RoleBasedAccessListConfig:
      items:
        - accessListSequenceRules:
            configType: string
            items:
              - action: string
                configType: string
                isLogEnabled: true
                protocolType: string
                protocolValue: string
                sequence: 0
          aclName: string
          configType: string
    macExtendedAccessListConfig:
      items:
        - accessListExtendedEntries:
            configType: string
            items:
              - action: string
                configType: string
                values: string
          aclName: string
          configType: string

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

catalystcenter_response

dictionary

A dictionary or list with the response returned by the Cisco Catalyst Center Python SDK

Returned: always

Sample: :ansible-rv-sample-value:`{"response": {"taskId": "string", "url": "string"}, "version": "string"}`

Authors

  • Bryan Vargas (@bvargasre)