netscaler.adc.aaaparameter module – Configuration for AAA parameter resource.
Note
This module is part of the netscaler.adc collection (version 2.6.2).
It is not included in ansible-core
.
To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install netscaler.adc
.
To use it in a playbook, specify: netscaler.adc.aaaparameter
.
New in netscaler.adc 2.0.0
Synopsis
Configuration for AAA parameter resource.
Parameters
Parameter |
Comments |
---|---|
AAAD log level, which specifies the types of AAAD events to log in nsvpn.log. Available values function as follows: * * * * * * * * Choices:
|
|
Source IP address to use for traffic that is sent to the authentication server. |
|
Audit log level, which specifies the types of events to log for cli executed commands. Available values function as follows: * * * * * * * * Choices:
|
|
Base NITRO API path. Define only in case of an ADM service proxy call Default: |
|
Option to enable/disable API cache feature. Choices:
|
|
The default authentication server type. Choices:
|
|
Parameter to enable/disable default CSP header Choices:
|
|
Set by the DHCP client when the IP address was fetched dynamically. Choices:
|
|
Enhanced auth feedback provides more information to the end user about the reason for an authentication failure. The default value is set to Choices:
|
|
Enables/Disables stickiness to authentication servers Choices:
|
|
The default state of VPN Static Page caching. Static Page caching is enabled by default. Choices:
|
|
Parameter to enable/disable EPA v2 functionality Choices:
|
|
Number of minutes an account will be locked if user exceeds maximum permissible attempts |
|
First time user mode determines which configuration options are shown by default when logging in to the GUI. This setting is controlled by the GUI. Choices:
|
|
Parameter to set/reset HttpOnly Flag for NSC_AAAC/NSC_TMAS cookies in nfactor Choices:
|
|
Parameter to encrypt login information for nFactor flow Choices:
|
|
The ID of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The IP of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The name of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The password of the managed NetScaler instance. Define only in case of an ADM service proxy call In Settings > Administration > System Configurations > Basic Settings, if you select Prompt Credentials for Instance Login, ensure to configure username and password of a managed instance. |
|
The username of the managed NetScaler instance. Define only in case of an ADM service proxy call In Settings > Administration > System Configurations > Basic Settings, if you select Prompt Credentials for Instance Login, ensure to configure username and password of a managed instance. |
|
Maximum number of concurrent users allowed to log on to VPN simultaneously. |
|
This will set maximum number of Questions to be asked for KB Validation. Default value is 2, Max Value is 6 |
|
Maximum Number of login Attempts |
|
This will set the maximum deflate size in case of SAML Redirect binding. |
|
The IP address of the NetScaler ADC appliance acting as a proxy server. Define only in case of an ADM service proxy call Choices:
|
|
The authentication token provided by a login operation. |
|
The password with which to authenticate to the NetScaler ADC node. |
|
Which protocol to use when accessing the nitro API objects. Choices:
|
|
The username with which to authenticate to the NetScaler ADC node. |
|
The ip address of the NetScaler ADC appliance where the nitro API calls will be made. The port can be specified with the colon (:). E.g. 192.168.1.1:555. |
|
Persistent storage of unsuccessful user login attempts Choices:
|
|
This will set the threshold time in days for password expiry notification. Default value is 0, which means no notification is sent |
|
SameSite attribute value for Cookies generated in AAATM context. This attribute value will be appended only for the cookies which are specified in the builtin patset ns_cookies_samesite Choices:
|
|
If The module will not save the configuration on the NetScaler ADC node if it made no changes. Choices:
|
|
On enabling this option, the Citrix ADC will send the security insight records to the configured collectors when request comes to Authentication endpoint. * If cs vserver is frontend with Authentication vserver as target for cs action, then record is sent using Authentication vserver name. * If vpn/lb/cs vserver are configured with Authentication ON, then then record is sent using vpn/lb/cs vserver name accordingly. * If authentication vserver is frontend, then record is sent using Authentication vserver name. Choices:
|
|
The state of the resource being configured by the module on the NetScaler ADC node. When When Choices:
|
|
Frequency at which a token must be verified at the Authorization Server (AS) despite being found in cache. |
|
If Choices:
|
|
Entities for which WAF Protection need to be applied. Available settings function as follows: * * * Currently supported only in default partition Choices:
|
Notes
Note
For more information on using Ansible to manage NetScaler ADC Network devices see https://www.ansible.com/integrations/networks/citrixadc.
Examples
---
- name: Sample aaaparameter playbook
hosts: demo_netscalers
gather_facts: false
tasks:
- name: Configure aaaparameter
delegate_to: localhost
netscaler.adc.aaaparameter:
state: present
maxaaausers: '4294967295'
aaasessionloglevel: DEBUG
aaadloglevel: ALERT
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
---|---|
Indicates if any change is made by the module Returned: always Sample: |
|
Dictionary of before and after changes Returned: always Sample: |
|
List of differences between the actual configured object and the configuration specified in the module Returned: when changed Sample: |
|
Indicates if the module failed or not Returned: always Sample: |
|
list of logged messages by the module Returned: always Sample: |