netscaler.adc.nspbr6 module – Configuration for PBR6 entry resource.

Note

This module is part of the netscaler.adc collection (version 2.6.2).

It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install netscaler.adc.

To use it in a playbook, specify: netscaler.adc.nspbr6.

New in netscaler.adc 2.0.0

Synopsis

  • Configuration for PBR6 entry resource.

Parameters

Parameter

Comments

action

string

Action to perform on the outgoing IPv6 packets that match the PBR6.

Available settings function as follows:

* ALLOW - The Citrix ADC sends the packet to the designated next-hop router.

* DENY - The Citrix ADC applies the routing table for normal destination-based routing.

Choices:

  • "ALLOW"

  • "DENY"

api_path

string

Base NITRO API path.

Define only in case of an ADM service proxy call

Default: "nitro/v1/config"

destipop

string

Either the equals (=) or does not equal (!=) logical operator.

Choices:

  • "="

  • "!="

  • "EQ"

  • "NEQ"

destipv6

boolean

IP address or range of IP addresses to match against the destination IP address of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen.

Choices:

  • false

  • true

destipv6val

string

IP address or range of IP addresses to match against the destination IP address of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen.

destport

boolean

Port number or range of port numbers to match against the destination port number of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen. For example: 40-90.

Note: The destination port can be specified only for TCP and UDP protocols.

Choices:

  • false

  • true

destportop

string

Either the equals (=) or does not equal (!=) logical operator.

Choices:

  • "="

  • "!="

  • "EQ"

  • "NEQ"

destportval

string

Destination port (range).

detail

boolean

To get a detailed view.

Choices:

  • false

  • true

interface

string

ID of an interface. The Citrix ADC compares the PBR6 only to the outgoing packets on the specified interface. If you do not specify a value, the appliance compares the PBR6 to the outgoing packets on all interfaces.

iptunnel

string

The iptunnel name where packets need to be forwarded upon.

managed_netscaler_instance_id

string

added in netscaler.adc 2.6.0

The ID of the managed NetScaler instance to which NetScaler Console

has to configure as a proxy server.

Define only in case of an ADM service proxy call

managed_netscaler_instance_ip

string

added in netscaler.adc 2.6.0

The IP of the managed NetScaler instance to which NetScaler Console

has to configure as a proxy server.

Define only in case of an ADM service proxy call

managed_netscaler_instance_name

string

added in netscaler.adc 2.6.0

The name of the managed NetScaler instance to which NetScaler Console

has to configure as a proxy server.

Define only in case of an ADM service proxy call

managed_netscaler_instance_password

string

added in netscaler.adc 2.6.0

The password of the managed NetScaler instance.

Define only in case of an ADM service proxy call

In Settings > Administration > System Configurations > Basic Settings,

if you select Prompt Credentials for Instance Login,

ensure to configure username and password of a managed instance.

managed_netscaler_instance_username

string

added in netscaler.adc 2.6.0

The username of the managed NetScaler instance.

Define only in case of an ADM service proxy call

In Settings > Administration > System Configurations > Basic Settings,

if you select Prompt Credentials for Instance Login,

ensure to configure username and password of a managed instance.

monitor

string

The name of the monitor.(Can be only of type ping or ARP )

msr

string

Monitor the route specified by the Next Hop parameter.

Choices:

  • "ENABLED"

  • "DISABLED"

name

string

Name for the PBR6. Must begin with an ASCII alphabetic or underscore \(_\) character, and must contain only ASCII alphanumeric, underscore, hash \(\#\), period \(.\), space, colon \(:\), at \(@\), equals \(=\), and hyphen \(-\) characters. Cannot be changed after the PBR6 is created.

netscaler_console_as_proxy_server

boolean

added in netscaler.adc 2.6.0

The IP address of the NetScaler ADC appliance acting as a proxy server.

Define only in case of an ADM service proxy call

Choices:

  • false ← (default)

  • true

nexthop

boolean

IP address of the next hop router to which to send matching packets if action is set to ALLOW. This next hop should be directly reachable from the appliance.

Choices:

  • false

  • true

nexthopval

string

The Next Hop IPv6 address.

nexthopvlan

float

VLAN number to be used for link local nexthop .

nitro_auth_token

string

The authentication token provided by a login operation.

nitro_pass

string

The password with which to authenticate to the NetScaler ADC node.

nitro_protocol

string

Which protocol to use when accessing the nitro API objects.

Choices:

  • "http"

  • "https" ← (default)

nitro_user

string

The username with which to authenticate to the NetScaler ADC node.

nsip

string / required

The ip address of the NetScaler ADC appliance where the nitro API calls will be made.

The port can be specified with the colon (:). E.g. 192.168.1.1:555.

ownergroup

string

The owner node group in a Cluster for this pbr rule. If owner node group is not specified then the pbr rule is treated as Striped pbr rule.

priority

float

Priority of the PBR6, which determines the order in which it is evaluated relative to the other PBR6s. If you do not specify priorities while creating PBR6s, the PBR6s are evaluated in the order in which they are created.

protocol

string

Protocol, identified by protocol name, to match against the protocol of an outgoing IPv6 packet.

Choices:

  • "ICMPV6"

  • "TCP"

  • "UDP"

  • "ICMP"

  • "IGMP"

  • "EGP"

  • "IGP"

  • "ARGUS"

  • "RDP"

  • "RSVP"

  • "EIGRP"

  • "L2TP"

  • "ISIS"

  • "GGP"

  • "IPoverIP"

  • "ST"

  • "CBT"

  • "BBN-RCC-M"

  • "NVP-II"

  • "PUP"

  • "EMCON"

  • "XNET"

  • "CHAOS"

  • "MUX"

  • "DCN-MEAS"

  • "HMP"

  • "PRM"

  • "XNS-IDP"

  • "TRUNK-1"

  • "TRUNK-2"

  • "LEAF-1"

  • "LEAF-2"

  • "IRTP"

  • "ISO-TP4"

  • "NETBLT"

  • "MFE-NSP"

  • "MERIT-INP"

  • "SEP"

  • "3PC"

  • "IDPR"

  • "XTP"

  • "DDP"

  • "IDPR-CMTP"

  • "TP++"

  • "IL"

  • "IPv6"

  • "SDRP"

  • "IPv6-Route"

  • "IPv6-Frag"

  • "IDRP"

  • "GRE"

  • "MHRP"

  • "BNA"

  • "ESP"

  • "AH"

  • "I-NLSP"

  • "SWIPE"

  • "NARP"

  • "MOBILE"

  • "TLSP"

  • "SKIP"

  • "IPv6-NoNx"

  • "IPv6-Opts"

  • "Any-Host-Internal-Protocol"

  • "CFTP"

  • "Any-Local-Network"

  • "SAT-EXPAK"

  • "KRYPTOLAN"

  • "RVD"

  • "IPPC"

  • "Any-Distributed-File-System"

  • "TFTP"

  • "VISA"

  • "IPCV"

  • "CPNX"

  • "CPHB"

  • "WSN"

  • "PVP"

  • "BR-SAT-MO"

  • "SUN-ND"

  • "WB-MON"

  • "WB-EXPAK"

  • "ISO-IP"

  • "VMTP"

  • "SECURE-VM"

  • "VINES"

  • "TTP"

  • "NSFNET-IG"

  • "DGP"

  • "TCF"

  • "OSPFIGP"

  • "Sprite-RP"

  • "LARP"

  • "MTP"

  • "AX.25"

  • "IPIP"

  • "MICP"

  • "SCC-SP"

  • "ETHERIP"

  • "Any-Private-Encryption-Scheme"

  • "GMTP"

  • "IFMP"

  • "PNNI"

  • "PIM"

  • "ARIS"

  • "SCPS"

  • "QNX"

  • "A/N"

  • "IPComp"

  • "SNP"

  • "Compaq-Pe"

  • "IPX-in-IP"

  • "VRRP"

  • "PGM"

  • "Any-0-Hop-Protocol"

  • "ENCAP"

  • "DDX"

  • "IATP"

  • "STP"

  • "SRP"

  • "UTI"

  • "SMP"

  • "SM"

  • "PTP"

  • "FIRE"

  • "CRTP"

  • "CRUDP"

  • "SSCOPMCE"

  • "IPLT"

  • "SPS"

  • "PIPE"

  • "SCTP"

  • "FC"

  • "RSVP-E2E-IGNORE"

  • "Mobility-Header"

  • "UDPLite"

protocolnumber

float

Protocol, identified by protocol number, to match against the protocol of an outgoing IPv6 packet.

save_config

boolean

If true the module will save the configuration on the NetScaler ADC node if it makes any changes.

The module will not save the configuration on the NetScaler ADC node if it made no changes.

Choices:

  • false ← (default)

  • true

srcipop

string

Either the equals (=) or does not equal (!=) logical operator.

Choices:

  • "="

  • "!="

  • "EQ"

  • "NEQ"

srcipv6

boolean

IP address or range of IP addresses to match against the source IP address of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen.

Choices:

  • false

  • true

srcipv6val

string

IP address or range of IP addresses to match against the source IP address of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen.

srcmac

string

MAC address to match against the source MAC address of an outgoing IPv6 packet.

srcmacmask

string

Used to define range of Source MAC address. It takes string of 0 and 1, 0s are for exact match and 1s for wildcard. For matching first 3 bytes of MAC address, srcMacMask value “000000111111”.

srcport

boolean

Port number or range of port numbers to match against the source port number of an outgoing IPv6 packet. In the command line interface, separate the range with a hyphen. For example: 40-90.

Choices:

  • false

  • true

srcportop

string

Either the equals (=) or does not equal (!=) logical operator.

Choices:

  • "="

  • "!="

  • "EQ"

  • "NEQ"

srcportval

string

Source port (range).

state

string

The state of the resource being configured by the module on the NetScaler ADC node.

When present, the resource will be added/updated configured according to the module’s parameters.

When absent, the resource will be deleted from the NetScaler ADC node.

When enabled, the resource will be enabled on the NetScaler ADC node.

When disabled, the resource will be disabled on the NetScaler ADC node.

When unset, the resource will be unset on the NetScaler ADC node.

Choices:

  • "present" ← (default)

  • "absent"

  • "enabled"

  • "disabled"

  • "unset"

td

float

Integer value that uniquely identifies the traffic domain in which you want to configure the entity. If you do not specify an ID, the entity becomes part of the default traffic domain, which has an ID of 0.

validate_certs

boolean

If false, SSL certificates will not be validated. This should only be used on personally controlled sites using self-signed certificates.

Choices:

  • false

  • true ← (default)

vlan

float

ID of the VLAN. The Citrix ADC compares the PBR6 only to the outgoing packets on the specified VLAN. If you do not specify an interface ID, the appliance compares the PBR6 to the outgoing packets on all VLANs.

vxlan

float

ID of the VXLAN. The Citrix ADC compares the PBR6 only to the outgoing packets on the specified VXLAN. If you do not specify an interface ID, the appliance compares the PBR6 to the outgoing packets on all VXLANs.

vxlanvlanmap

string

The vlan to vxlan mapping to be applied for incoming packets over this pbr tunnel.

Notes

Note

Examples

---
- name: Sample nspbr6 playbook
  hosts: demo_netscalers
  gather_facts: false
  tasks:
    - name: Configure nspbr6
      delegate_to: localhost
      netscaler.adc.nspbr6:
        state: present
        name: test3
        action: DENY
        srcmac: 4a:69:a2:33:00:03
        srcmacmask: '000000001111'

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

changed

boolean

Indicates if any change is made by the module

Returned: always

Sample: true

diff

dictionary

Dictionary of before and after changes

Returned: always

Sample: {"after": {"key2": "pqr"}, "before": {"key1": "xyz"}, "prepared": "changes done"}

diff_list

list / elements=string

List of differences between the actual configured object and the configuration specified in the module

Returned: when changed

Sample: ["Attribute `key1` differs. Desired: (<class 'str'>) XYZ. Existing: (<class 'str'>) PQR"]

failed

boolean

Indicates if the module failed or not

Returned: always

Sample: false

loglines

list / elements=string

list of logged messages by the module

Returned: always

Sample: ["message 1", "message 2"]

Authors

  • Sumanth Lingappa (@sumanth-lingappa)

  • Shiva Shankar Vaddepally (@shivashankar-vaddepally)