Fortios v0.0.6 published on Tuesday, Jul 9, 2024 by pulumiverse
fortios.firewall.getPolicy
Explore with Pulumi AI
Use this data source to get information on an fortios firewall policy
Using getPolicy
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getPolicy(args: GetPolicyArgs, opts?: InvokeOptions): Promise<GetPolicyResult>
function getPolicyOutput(args: GetPolicyOutputArgs, opts?: InvokeOptions): Output<GetPolicyResult>def get_policy(policyid: Optional[int] = None,
               vdomparam: Optional[str] = None,
               opts: Optional[InvokeOptions] = None) -> GetPolicyResult
def get_policy_output(policyid: Optional[pulumi.Input[int]] = None,
               vdomparam: Optional[pulumi.Input[str]] = None,
               opts: Optional[InvokeOptions] = None) -> Output[GetPolicyResult]func LookupPolicy(ctx *Context, args *LookupPolicyArgs, opts ...InvokeOption) (*LookupPolicyResult, error)
func LookupPolicyOutput(ctx *Context, args *LookupPolicyOutputArgs, opts ...InvokeOption) LookupPolicyResultOutput> Note: This function is named LookupPolicy in the Go SDK.
public static class GetPolicy 
{
    public static Task<GetPolicyResult> InvokeAsync(GetPolicyArgs args, InvokeOptions? opts = null)
    public static Output<GetPolicyResult> Invoke(GetPolicyInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetPolicyResult> getPolicy(GetPolicyArgs args, InvokeOptions options)
public static Output<GetPolicyResult> getPolicy(GetPolicyArgs args, InvokeOptions options)
fn::invoke:
  function: fortios:firewall/getPolicy:getPolicy
  arguments:
    # arguments dictionaryThe following arguments are supported:
- Policyid int
- Specify the policyid of the desired firewall policy.
- Vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- Policyid int
- Specify the policyid of the desired firewall policy.
- Vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- policyid Integer
- Specify the policyid of the desired firewall policy.
- vdomparam String
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- policyid number
- Specify the policyid of the desired firewall policy.
- vdomparam string
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- policyid int
- Specify the policyid of the desired firewall policy.
- vdomparam str
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
- policyid Number
- Specify the policyid of the desired firewall policy.
- vdomparam String
- Specifies the vdom to which the data source will be applied when the FortiGate unit is running in VDOM mode. Only one vdom can be specified. If you want to inherit the vdom configuration of the provider, please do not set this parameter.
getPolicy Result
The following output properties are available:
- Action string
- Policy action (allow/deny/ipsec).
- AntiReplay string
- Enable/disable anti-replay check.
- AppCategories List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy App Category> 
- Application category ID list. The structure of app_categoryblock is documented below.
- AppGroups List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy App Group> 
- Application group names. The structure of app_groupblock is documented below.
- ApplicationList string
- Name of an existing Application list.
- Applications
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Application> 
- Application ID list. The structure of applicationblock is documented below.
- AuthCert string
- HTTPS server certificate for policy authentication.
- AuthPath string
- Enable/disable authentication-based routing.
- AuthRedirect stringAddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- AutoAsic stringOffload 
- Enable/disable policy traffic ASIC offloading.
- AvProfile string
- Name of an existing Antivirus profile.
- BlockNotification string
- Enable/disable block notification.
- CaptivePortal stringExempt 
- Enable to exempt some users from the captive portal.
- CapturePacket string
- Enable/disable capture packets.
- CasbProfile string
- Name of an existing CASB profile.
- CifsProfile string
- Name of an existing CIFS profile.
- Comments string
- Comment.
- CustomLog List<Pulumiverse.Fields Fortios. Firewall. Outputs. Get Policy Custom Log Field> 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- DecryptedTraffic stringMirror 
- Decrypted traffic mirror.
- DelayTcp stringNpu Session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- Devices
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Device> 
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- DiameterFilter stringProfile 
- Name of an existing Diameter filter profile.
- DiffservCopy string
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- DiffservForward string
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- DiffservReverse string
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- DiffservcodeForward string
- Change packet's DiffServ to this value.
- DiffservcodeRev string
- Change packet's reverse (reply) DiffServ to this value.
- Disclaimer string
- Enable/disable user authentication disclaimer.
- DlpProfile string
- Name of an existing DLP profile.
- DlpSensor string
- Name of an existing DLP sensor.
- DnsfilterProfile string
- Name of an existing DNS filter profile.
- Dsri string
- Enable DSRI to ignore HTTP server responses.
- Dstaddr6Negate string
- When enabled dstaddr6 specifies what the destination address must NOT be.
- Dstaddr6s
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Dstaddr6> 
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- DstaddrNegate string
- When enabled dstaddr specifies what the destination address must NOT be.
- Dstaddrs
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Dstaddr> 
- Destination address and address group names. The structure of dstaddrblock is documented below.
- Dstintfs
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Dstintf> 
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- DynamicShaping string
- Enable/disable dynamic RADIUS defined traffic shaping.
- EmailCollect string
- Enable/disable email collection.
- EmailfilterProfile string
- Name of an existing email filter profile.
- Fec string
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- FileFilter stringProfile 
- Name of an existing file-filter profile.
- FirewallSession stringDirty 
- How to handle sessions if the configuration of this firewall policy changes.
- Fixedport string
- Enable to prevent source NAT from changing a session's source port.
- Fsso string
- Enable/disable Fortinet Single Sign-On.
- FssoAgent stringFor Ntlm 
- FSSO agent to use for NTLM authentication.
- FssoGroups List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Fsso Group> 
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- GeoipAnycast string
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- GeoipMatch string
- Match geography address based either on its physical location or registered location.
- GlobalLabel string
- Label for the policy that appears when the GUI is in Global View mode.
- Groups
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Group> 
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- HttpPolicy stringRedirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- IcapProfile string
- Name of an existing ICAP profile.
- Id string
- The provider-assigned unique ID for this managed resource.
- IdentityBased stringRoute 
- Name of identity-based routing rule.
- Inbound string
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- InspectionMode string
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- InternetService string
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- InternetService6 string
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- InternetService6Custom List<Pulumiverse.Groups Fortios. Firewall. Outputs. Get Policy Internet Service6Custom Group> 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- InternetService6Customs List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Internet Service6Custom> 
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- InternetService6Groups List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Internet Service6Group> 
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- InternetService6Names List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Internet Service6Name> 
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- InternetService6Negate string
- When enabled internet-service6 specifies what the service must NOT be.
- InternetService6Src string
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- InternetService6Src List<Pulumiverse.Custom Groups Fortios. Firewall. Outputs. Get Policy Internet Service6Src Custom Group> 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- InternetService6Src List<Pulumiverse.Customs Fortios. Firewall. Outputs. Get Policy Internet Service6Src Custom> 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- InternetService6Src List<Pulumiverse.Groups Fortios. Firewall. Outputs. Get Policy Internet Service6Src Group> 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- InternetService6Src List<Pulumiverse.Names Fortios. Firewall. Outputs. Get Policy Internet Service6Src Name> 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- InternetService6Src stringNegate 
- When enabled internet-service6-src specifies what the service must NOT be.
- InternetService List<Pulumiverse.Custom Groups Fortios. Firewall. Outputs. Get Policy Internet Service Custom Group> 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- InternetService List<Pulumiverse.Customs Fortios. Firewall. Outputs. Get Policy Internet Service Custom> 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- InternetService List<Pulumiverse.Groups Fortios. Firewall. Outputs. Get Policy Internet Service Group> 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- InternetService List<Pulumiverse.Ids Fortios. Firewall. Outputs. Get Policy Internet Service Id> 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- InternetService List<Pulumiverse.Names Fortios. Firewall. Outputs. Get Policy Internet Service Name> 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- InternetService stringNegate 
- When enabled internet-service specifies what the service must NOT be.
- InternetService stringSrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- InternetService List<Pulumiverse.Src Custom Groups Fortios. Firewall. Outputs. Get Policy Internet Service Src Custom Group> 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- InternetService List<Pulumiverse.Src Customs Fortios. Firewall. Outputs. Get Policy Internet Service Src Custom> 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- InternetService List<Pulumiverse.Src Groups Fortios. Firewall. Outputs. Get Policy Internet Service Src Group> 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- InternetService List<Pulumiverse.Src Ids Fortios. Firewall. Outputs. Get Policy Internet Service Src Id> 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- InternetService List<Pulumiverse.Src Names Fortios. Firewall. Outputs. Get Policy Internet Service Src Name> 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- InternetService stringSrc Negate 
- When enabled internet-service-src specifies what the service must NOT be.
- Ippool string
- Enable to use IP Pools for source NAT.
- IpsSensor string
- Name of an existing IPS sensor.
- IpsVoip stringFilter 
- Name of an existing VoIP (ips) profile.
- Label string
- Label for the policy that appears when the GUI is in Section View mode.
- LearningMode string
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- Logtraffic string
- Enable or disable logging. Log all sessions or security profile sessions.
- LogtrafficStart string
- Record logs when a session starts.
- MatchVip string
- Enable to match packets that have had their destination addresses changed by a VIP.
- MatchVip stringOnly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- Name string
- Mirror Interface name.
- Nat string
- Enable/disable source NAT.
- Nat46 string
- Enable/disable NAT46.
- Nat64 string
- Enable/disable NAT64.
- Natinbound string
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- Natip string
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- Natoutbound string
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- NetworkService List<Pulumiverse.Dynamics Fortios. Firewall. Outputs. Get Policy Network Service Dynamic> 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- NetworkService List<Pulumiverse.Src Dynamics Fortios. Firewall. Outputs. Get Policy Network Service Src Dynamic> 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- NpAcceleration string
- Enable/disable UTM Network Processor acceleration.
- Ntlm string
- Enable/disable NTLM authentication.
- NtlmEnabled List<Pulumiverse.Browsers Fortios. Firewall. Outputs. Get Policy Ntlm Enabled Browser> 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- NtlmGuest string
- Enable/disable NTLM guest user access.
- Outbound string
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- PassiveWan stringHealth Measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- PcpInbound string
- Enable/disable PCP inbound DNAT.
- PcpOutbound string
- Enable/disable PCP outbound SNAT.
- PcpPoolnames List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Pcp Poolname> 
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- PerIp stringShaper 
- Per-IP traffic shaper.
- PermitAny stringHost 
- Accept UDP packets from any host.
- PermitStun stringHost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- PolicyExpiry string
- Enable/disable policy expiry.
- PolicyExpiry stringDate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- PolicyExpiry stringDate Utc 
- Policy expiry date and time, in epoch format.
- Policyid int
- Policy ID.
- Poolname6s
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Poolname6> 
- IPv6 pool names. The structure of poolname6block is documented below.
- Poolnames
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Poolname> 
- IP Pool names. The structure of poolnameblock is documented below.
- PortPreserve string
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- ProfileGroup string
- Name of profile group.
- ProfileProtocol stringOptions 
- Name of an existing Protocol options profile.
- ProfileType string
- Determine whether the firewall policy allows security profile groups or single profiles only.
- RadiusMac stringAuth Bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- RedirectUrl string
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- ReplacemsgOverride stringGroup 
- Override the default replacement message group for this policy.
- ReputationDirection string
- Direction of the initial traffic for reputation to take effect.
- ReputationDirection6 string
- Direction of the initial traffic for IPv6 reputation to take effect.
- ReputationMinimum int
- Minimum Reputation to take action.
- ReputationMinimum6 int
- IPv6 Minimum Reputation to take action.
- Rsso string
- Enable/disable RADIUS single sign-on (RSSO).
- RtpAddrs List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Rtp Addr> 
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- RtpNat string
- Enable Real Time Protocol (RTP) NAT.
- ScanBotnet stringConnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- Schedule string
- Schedule name.
- ScheduleTimeout string
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- SctpFilter stringProfile 
- Name of an existing SCTP filter profile.
- SendDeny stringPacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- ServiceNegate string
- When enabled service specifies what the service must NOT be.
- Services
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Service> 
- Service and service group names. The structure of serviceblock is documented below.
- SessionTtl int
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- SgtCheck string
- Enable/disable security group tags (SGT) check.
- Sgts
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Sgt> 
- Security group tags. The structure of sgtblock is documented below.
- SpamfilterProfile string
- Name of an existing Spam filter profile.
- SrcVendor List<Pulumiverse.Macs Fortios. Firewall. Outputs. Get Policy Src Vendor Mac> 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- Srcaddr6Negate string
- When enabled srcaddr6 specifies what the source address must NOT be.
- Srcaddr6s
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Srcaddr6> 
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- SrcaddrNegate string
- When enabled srcaddr specifies what the source address must NOT be.
- Srcaddrs
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Srcaddr> 
- Source address and address group names. The structure of srcaddrblock is documented below.
- Srcintfs
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Srcintf> 
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- SshFilter stringProfile 
- Name of an existing SSH filter profile.
- SshPolicy stringRedirect 
- Redirect SSH traffic to matching transparent proxy policy.
- SslMirror string
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- SslMirror List<Pulumiverse.Intfs Fortios. Firewall. Outputs. Get Policy Ssl Mirror Intf> 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- SslSsh stringProfile 
- Name of an existing SSL SSH profile.
- Status string
- Enable or disable this policy.
- TcpMss intReceiver 
- Receiver TCP maximum segment size (MSS).
- TcpMss intSender 
- Sender TCP maximum segment size (MSS).
- TcpSession stringWithout Syn 
- Enable/disable creation of TCP session without SYN flag.
- TimeoutSend stringRst 
- Enable/disable sending RST packets when TCP sessions expire.
- Tos string
- ToS (Type of Service) value used for comparison.
- TosMask string
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- TosNegate string
- Enable negated TOS match.
- TrafficShaper string
- Traffic shaper.
- TrafficShaper stringReverse 
- Reverse traffic shaper.
- UrlCategories List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Url Category> 
- URL category ID list. The structure of url_categoryblock is documented below.
- Users
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy User> 
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- UtmStatus string
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- Uuid string
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- VideofilterProfile string
- Name of an existing VideoFilter profile.
- VirtualPatch stringProfile 
- Name of an existing virtual-patch profile.
- VlanCos intFwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- VlanCos intRev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- VlanFilter string
- Set VLAN filters.
- VoipProfile string
- Name of an existing VoIP profile.
- Vpntunnel string
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- WafProfile string
- Name of an existing Web application firewall profile.
- Wanopt string
- Enable/disable WAN optimization.
- WanoptDetection string
- WAN optimization auto-detection mode.
- WanoptPassive stringOpt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- WanoptPeer string
- WAN optimization peer.
- WanoptProfile string
- WAN optimization profile.
- Wccp string
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- Webcache string
- Enable/disable web cache.
- WebcacheHttps string
- Enable/disable web cache for HTTPS.
- WebfilterProfile string
- Name of an existing Web filter profile.
- WebproxyForward stringServer 
- Web proxy forward server name.
- WebproxyProfile string
- Webproxy profile name.
- Wsso string
- Enable/disable WiFi Single Sign On (WSSO).
- ZtnaDevice stringOwnership 
- Enable/disable zero trust device ownership.
- 
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Ztna Ems Tag Secondary> 
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- 
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Ztna Ems Tag> 
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- 
List<Pulumiverse.Fortios. Firewall. Outputs. Get Policy Ztna Geo Tag> 
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ZtnaPolicy stringRedirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ZtnaStatus string
- Enable/disable zero trust access.
- string
- ZTNA tag matching logic.
- Vdomparam string
- Action string
- Policy action (allow/deny/ipsec).
- AntiReplay string
- Enable/disable anti-replay check.
- AppCategories []GetPolicy App Category 
- Application category ID list. The structure of app_categoryblock is documented below.
- AppGroups []GetPolicy App Group 
- Application group names. The structure of app_groupblock is documented below.
- ApplicationList string
- Name of an existing Application list.
- Applications
[]GetPolicy Application 
- Application ID list. The structure of applicationblock is documented below.
- AuthCert string
- HTTPS server certificate for policy authentication.
- AuthPath string
- Enable/disable authentication-based routing.
- AuthRedirect stringAddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- AutoAsic stringOffload 
- Enable/disable policy traffic ASIC offloading.
- AvProfile string
- Name of an existing Antivirus profile.
- BlockNotification string
- Enable/disable block notification.
- CaptivePortal stringExempt 
- Enable to exempt some users from the captive portal.
- CapturePacket string
- Enable/disable capture packets.
- CasbProfile string
- Name of an existing CASB profile.
- CifsProfile string
- Name of an existing CIFS profile.
- Comments string
- Comment.
- CustomLog []GetFields Policy Custom Log Field 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- DecryptedTraffic stringMirror 
- Decrypted traffic mirror.
- DelayTcp stringNpu Session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- Devices
[]GetPolicy Device 
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- DiameterFilter stringProfile 
- Name of an existing Diameter filter profile.
- DiffservCopy string
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- DiffservForward string
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- DiffservReverse string
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- DiffservcodeForward string
- Change packet's DiffServ to this value.
- DiffservcodeRev string
- Change packet's reverse (reply) DiffServ to this value.
- Disclaimer string
- Enable/disable user authentication disclaimer.
- DlpProfile string
- Name of an existing DLP profile.
- DlpSensor string
- Name of an existing DLP sensor.
- DnsfilterProfile string
- Name of an existing DNS filter profile.
- Dsri string
- Enable DSRI to ignore HTTP server responses.
- Dstaddr6Negate string
- When enabled dstaddr6 specifies what the destination address must NOT be.
- Dstaddr6s
[]GetPolicy Dstaddr6 
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- DstaddrNegate string
- When enabled dstaddr specifies what the destination address must NOT be.
- Dstaddrs
[]GetPolicy Dstaddr 
- Destination address and address group names. The structure of dstaddrblock is documented below.
- Dstintfs
[]GetPolicy Dstintf 
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- DynamicShaping string
- Enable/disable dynamic RADIUS defined traffic shaping.
- EmailCollect string
- Enable/disable email collection.
- EmailfilterProfile string
- Name of an existing email filter profile.
- Fec string
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- FileFilter stringProfile 
- Name of an existing file-filter profile.
- FirewallSession stringDirty 
- How to handle sessions if the configuration of this firewall policy changes.
- Fixedport string
- Enable to prevent source NAT from changing a session's source port.
- Fsso string
- Enable/disable Fortinet Single Sign-On.
- FssoAgent stringFor Ntlm 
- FSSO agent to use for NTLM authentication.
- FssoGroups []GetPolicy Fsso Group 
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- GeoipAnycast string
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- GeoipMatch string
- Match geography address based either on its physical location or registered location.
- GlobalLabel string
- Label for the policy that appears when the GUI is in Global View mode.
- Groups
[]GetPolicy Group 
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- HttpPolicy stringRedirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- IcapProfile string
- Name of an existing ICAP profile.
- Id string
- The provider-assigned unique ID for this managed resource.
- IdentityBased stringRoute 
- Name of identity-based routing rule.
- Inbound string
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- InspectionMode string
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- InternetService string
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- InternetService6 string
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- InternetService6Custom []GetGroups Policy Internet Service6Custom Group 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- InternetService6Customs []GetPolicy Internet Service6Custom 
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- InternetService6Groups []GetPolicy Internet Service6Group 
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- InternetService6Names []GetPolicy Internet Service6Name 
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- InternetService6Negate string
- When enabled internet-service6 specifies what the service must NOT be.
- InternetService6Src string
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- InternetService6Src []GetCustom Groups Policy Internet Service6Src Custom Group 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- InternetService6Src []GetCustoms Policy Internet Service6Src Custom 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- InternetService6Src []GetGroups Policy Internet Service6Src Group 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- InternetService6Src []GetNames Policy Internet Service6Src Name 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- InternetService6Src stringNegate 
- When enabled internet-service6-src specifies what the service must NOT be.
- InternetService []GetCustom Groups Policy Internet Service Custom Group 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- InternetService []GetCustoms Policy Internet Service Custom 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- InternetService []GetGroups Policy Internet Service Group 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- InternetService []GetIds Policy Internet Service Id 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- InternetService []GetNames Policy Internet Service Name 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- InternetService stringNegate 
- When enabled internet-service specifies what the service must NOT be.
- InternetService stringSrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- InternetService []GetSrc Custom Groups Policy Internet Service Src Custom Group 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- InternetService []GetSrc Customs Policy Internet Service Src Custom 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- InternetService []GetSrc Groups Policy Internet Service Src Group 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- InternetService []GetSrc Ids Policy Internet Service Src Id 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- InternetService []GetSrc Names Policy Internet Service Src Name 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- InternetService stringSrc Negate 
- When enabled internet-service-src specifies what the service must NOT be.
- Ippool string
- Enable to use IP Pools for source NAT.
- IpsSensor string
- Name of an existing IPS sensor.
- IpsVoip stringFilter 
- Name of an existing VoIP (ips) profile.
- Label string
- Label for the policy that appears when the GUI is in Section View mode.
- LearningMode string
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- Logtraffic string
- Enable or disable logging. Log all sessions or security profile sessions.
- LogtrafficStart string
- Record logs when a session starts.
- MatchVip string
- Enable to match packets that have had their destination addresses changed by a VIP.
- MatchVip stringOnly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- Name string
- Mirror Interface name.
- Nat string
- Enable/disable source NAT.
- Nat46 string
- Enable/disable NAT46.
- Nat64 string
- Enable/disable NAT64.
- Natinbound string
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- Natip string
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- Natoutbound string
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- NetworkService []GetDynamics Policy Network Service Dynamic 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- NetworkService []GetSrc Dynamics Policy Network Service Src Dynamic 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- NpAcceleration string
- Enable/disable UTM Network Processor acceleration.
- Ntlm string
- Enable/disable NTLM authentication.
- NtlmEnabled []GetBrowsers Policy Ntlm Enabled Browser 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- NtlmGuest string
- Enable/disable NTLM guest user access.
- Outbound string
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- PassiveWan stringHealth Measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- PcpInbound string
- Enable/disable PCP inbound DNAT.
- PcpOutbound string
- Enable/disable PCP outbound SNAT.
- PcpPoolnames []GetPolicy Pcp Poolname 
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- PerIp stringShaper 
- Per-IP traffic shaper.
- PermitAny stringHost 
- Accept UDP packets from any host.
- PermitStun stringHost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- PolicyExpiry string
- Enable/disable policy expiry.
- PolicyExpiry stringDate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- PolicyExpiry stringDate Utc 
- Policy expiry date and time, in epoch format.
- Policyid int
- Policy ID.
- Poolname6s
[]GetPolicy Poolname6 
- IPv6 pool names. The structure of poolname6block is documented below.
- Poolnames
[]GetPolicy Poolname 
- IP Pool names. The structure of poolnameblock is documented below.
- PortPreserve string
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- ProfileGroup string
- Name of profile group.
- ProfileProtocol stringOptions 
- Name of an existing Protocol options profile.
- ProfileType string
- Determine whether the firewall policy allows security profile groups or single profiles only.
- RadiusMac stringAuth Bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- RedirectUrl string
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- ReplacemsgOverride stringGroup 
- Override the default replacement message group for this policy.
- ReputationDirection string
- Direction of the initial traffic for reputation to take effect.
- ReputationDirection6 string
- Direction of the initial traffic for IPv6 reputation to take effect.
- ReputationMinimum int
- Minimum Reputation to take action.
- ReputationMinimum6 int
- IPv6 Minimum Reputation to take action.
- Rsso string
- Enable/disable RADIUS single sign-on (RSSO).
- RtpAddrs []GetPolicy Rtp Addr 
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- RtpNat string
- Enable Real Time Protocol (RTP) NAT.
- ScanBotnet stringConnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- Schedule string
- Schedule name.
- ScheduleTimeout string
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- SctpFilter stringProfile 
- Name of an existing SCTP filter profile.
- SendDeny stringPacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- ServiceNegate string
- When enabled service specifies what the service must NOT be.
- Services
[]GetPolicy Service 
- Service and service group names. The structure of serviceblock is documented below.
- SessionTtl int
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- SgtCheck string
- Enable/disable security group tags (SGT) check.
- Sgts
[]GetPolicy Sgt 
- Security group tags. The structure of sgtblock is documented below.
- SpamfilterProfile string
- Name of an existing Spam filter profile.
- SrcVendor []GetMacs Policy Src Vendor Mac 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- Srcaddr6Negate string
- When enabled srcaddr6 specifies what the source address must NOT be.
- Srcaddr6s
[]GetPolicy Srcaddr6 
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- SrcaddrNegate string
- When enabled srcaddr specifies what the source address must NOT be.
- Srcaddrs
[]GetPolicy Srcaddr 
- Source address and address group names. The structure of srcaddrblock is documented below.
- Srcintfs
[]GetPolicy Srcintf 
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- SshFilter stringProfile 
- Name of an existing SSH filter profile.
- SshPolicy stringRedirect 
- Redirect SSH traffic to matching transparent proxy policy.
- SslMirror string
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- SslMirror []GetIntfs Policy Ssl Mirror Intf 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- SslSsh stringProfile 
- Name of an existing SSL SSH profile.
- Status string
- Enable or disable this policy.
- TcpMss intReceiver 
- Receiver TCP maximum segment size (MSS).
- TcpMss intSender 
- Sender TCP maximum segment size (MSS).
- TcpSession stringWithout Syn 
- Enable/disable creation of TCP session without SYN flag.
- TimeoutSend stringRst 
- Enable/disable sending RST packets when TCP sessions expire.
- Tos string
- ToS (Type of Service) value used for comparison.
- TosMask string
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- TosNegate string
- Enable negated TOS match.
- TrafficShaper string
- Traffic shaper.
- TrafficShaper stringReverse 
- Reverse traffic shaper.
- UrlCategories []GetPolicy Url Category 
- URL category ID list. The structure of url_categoryblock is documented below.
- Users
[]GetPolicy User 
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- UtmStatus string
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- Uuid string
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- VideofilterProfile string
- Name of an existing VideoFilter profile.
- VirtualPatch stringProfile 
- Name of an existing virtual-patch profile.
- VlanCos intFwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- VlanCos intRev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- VlanFilter string
- Set VLAN filters.
- VoipProfile string
- Name of an existing VoIP profile.
- Vpntunnel string
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- WafProfile string
- Name of an existing Web application firewall profile.
- Wanopt string
- Enable/disable WAN optimization.
- WanoptDetection string
- WAN optimization auto-detection mode.
- WanoptPassive stringOpt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- WanoptPeer string
- WAN optimization peer.
- WanoptProfile string
- WAN optimization profile.
- Wccp string
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- Webcache string
- Enable/disable web cache.
- WebcacheHttps string
- Enable/disable web cache for HTTPS.
- WebfilterProfile string
- Name of an existing Web filter profile.
- WebproxyForward stringServer 
- Web proxy forward server name.
- WebproxyProfile string
- Webproxy profile name.
- Wsso string
- Enable/disable WiFi Single Sign On (WSSO).
- ZtnaDevice stringOwnership 
- Enable/disable zero trust device ownership.
- 
[]GetPolicy Ztna Ems Tag Secondary 
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- 
[]GetPolicy Ztna Ems Tag 
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- 
[]GetPolicy Ztna Geo Tag 
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ZtnaPolicy stringRedirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ZtnaStatus string
- Enable/disable zero trust access.
- string
- ZTNA tag matching logic.
- Vdomparam string
- action String
- Policy action (allow/deny/ipsec).
- antiReplay String
- Enable/disable anti-replay check.
- appCategories List<GetPolicy App Category> 
- Application category ID list. The structure of app_categoryblock is documented below.
- appGroups List<GetPolicy App Group> 
- Application group names. The structure of app_groupblock is documented below.
- applicationList String
- Name of an existing Application list.
- applications
List<GetPolicy Application> 
- Application ID list. The structure of applicationblock is documented below.
- authCert String
- HTTPS server certificate for policy authentication.
- authPath String
- Enable/disable authentication-based routing.
- authRedirect StringAddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- autoAsic StringOffload 
- Enable/disable policy traffic ASIC offloading.
- avProfile String
- Name of an existing Antivirus profile.
- blockNotification String
- Enable/disable block notification.
- captivePortal StringExempt 
- Enable to exempt some users from the captive portal.
- capturePacket String
- Enable/disable capture packets.
- casbProfile String
- Name of an existing CASB profile.
- cifsProfile String
- Name of an existing CIFS profile.
- comments String
- Comment.
- customLog List<GetFields Policy Custom Log Field> 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- decryptedTraffic StringMirror 
- Decrypted traffic mirror.
- delayTcp StringNpu Session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- devices
List<GetPolicy Device> 
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- diameterFilter StringProfile 
- Name of an existing Diameter filter profile.
- diffservCopy String
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- diffservForward String
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- diffservReverse String
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- diffservcodeForward String
- Change packet's DiffServ to this value.
- diffservcodeRev String
- Change packet's reverse (reply) DiffServ to this value.
- disclaimer String
- Enable/disable user authentication disclaimer.
- dlpProfile String
- Name of an existing DLP profile.
- dlpSensor String
- Name of an existing DLP sensor.
- dnsfilterProfile String
- Name of an existing DNS filter profile.
- dsri String
- Enable DSRI to ignore HTTP server responses.
- dstaddr6Negate String
- When enabled dstaddr6 specifies what the destination address must NOT be.
- dstaddr6s
List<GetPolicy Dstaddr6> 
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- dstaddrNegate String
- When enabled dstaddr specifies what the destination address must NOT be.
- dstaddrs
List<GetPolicy Dstaddr> 
- Destination address and address group names. The structure of dstaddrblock is documented below.
- dstintfs
List<GetPolicy Dstintf> 
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- dynamicShaping String
- Enable/disable dynamic RADIUS defined traffic shaping.
- emailCollect String
- Enable/disable email collection.
- emailfilterProfile String
- Name of an existing email filter profile.
- fec String
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- fileFilter StringProfile 
- Name of an existing file-filter profile.
- firewallSession StringDirty 
- How to handle sessions if the configuration of this firewall policy changes.
- fixedport String
- Enable to prevent source NAT from changing a session's source port.
- fsso String
- Enable/disable Fortinet Single Sign-On.
- fssoAgent StringFor Ntlm 
- FSSO agent to use for NTLM authentication.
- fssoGroups List<GetPolicy Fsso Group> 
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- geoipAnycast String
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- geoipMatch String
- Match geography address based either on its physical location or registered location.
- globalLabel String
- Label for the policy that appears when the GUI is in Global View mode.
- groups
List<GetPolicy Group> 
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- httpPolicy StringRedirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- icapProfile String
- Name of an existing ICAP profile.
- id String
- The provider-assigned unique ID for this managed resource.
- identityBased StringRoute 
- Name of identity-based routing rule.
- inbound String
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- inspectionMode String
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- internetService String
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6 String
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6Custom List<GetGroups Policy Internet Service6Custom Group> 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- internetService6Customs List<GetPolicy Internet Service6Custom> 
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- internetService6Groups List<GetPolicy Internet Service6Group> 
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- internetService6Names List<GetPolicy Internet Service6Name> 
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- internetService6Negate String
- When enabled internet-service6 specifies what the service must NOT be.
- internetService6Src String
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- internetService6Src List<GetCustom Groups Policy Internet Service6Src Custom Group> 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- internetService6Src List<GetCustoms Policy Internet Service6Src Custom> 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- internetService6Src List<GetGroups Policy Internet Service6Src Group> 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- internetService6Src List<GetNames Policy Internet Service6Src Name> 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- internetService6Src StringNegate 
- When enabled internet-service6-src specifies what the service must NOT be.
- internetService List<GetCustom Groups Policy Internet Service Custom Group> 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- internetService List<GetCustoms Policy Internet Service Custom> 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- internetService List<GetGroups Policy Internet Service Group> 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- internetService List<GetIds Policy Internet Service Id> 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- internetService List<GetNames Policy Internet Service Name> 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- internetService StringNegate 
- When enabled internet-service specifies what the service must NOT be.
- internetService StringSrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- internetService List<GetSrc Custom Groups Policy Internet Service Src Custom Group> 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- internetService List<GetSrc Customs Policy Internet Service Src Custom> 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- internetService List<GetSrc Groups Policy Internet Service Src Group> 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- internetService List<GetSrc Ids Policy Internet Service Src Id> 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- internetService List<GetSrc Names Policy Internet Service Src Name> 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- internetService StringSrc Negate 
- When enabled internet-service-src specifies what the service must NOT be.
- ippool String
- Enable to use IP Pools for source NAT.
- ipsSensor String
- Name of an existing IPS sensor.
- ipsVoip StringFilter 
- Name of an existing VoIP (ips) profile.
- label String
- Label for the policy that appears when the GUI is in Section View mode.
- learningMode String
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- logtraffic String
- Enable or disable logging. Log all sessions or security profile sessions.
- logtrafficStart String
- Record logs when a session starts.
- matchVip String
- Enable to match packets that have had their destination addresses changed by a VIP.
- matchVip StringOnly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- name String
- Mirror Interface name.
- nat String
- Enable/disable source NAT.
- nat46 String
- Enable/disable NAT46.
- nat64 String
- Enable/disable NAT64.
- natinbound String
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- natip String
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- natoutbound String
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- networkService List<GetDynamics Policy Network Service Dynamic> 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- networkService List<GetSrc Dynamics Policy Network Service Src Dynamic> 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- npAcceleration String
- Enable/disable UTM Network Processor acceleration.
- ntlm String
- Enable/disable NTLM authentication.
- ntlmEnabled List<GetBrowsers Policy Ntlm Enabled Browser> 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- ntlmGuest String
- Enable/disable NTLM guest user access.
- outbound String
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- passiveWan StringHealth Measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- pcpInbound String
- Enable/disable PCP inbound DNAT.
- pcpOutbound String
- Enable/disable PCP outbound SNAT.
- pcpPoolnames List<GetPolicy Pcp Poolname> 
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- perIp StringShaper 
- Per-IP traffic shaper.
- permitAny StringHost 
- Accept UDP packets from any host.
- permitStun StringHost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- policyExpiry String
- Enable/disable policy expiry.
- policyExpiry StringDate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- policyExpiry StringDate Utc 
- Policy expiry date and time, in epoch format.
- policyid Integer
- Policy ID.
- poolname6s
List<GetPolicy Poolname6> 
- IPv6 pool names. The structure of poolname6block is documented below.
- poolnames
List<GetPolicy Poolname> 
- IP Pool names. The structure of poolnameblock is documented below.
- portPreserve String
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- profileGroup String
- Name of profile group.
- profileProtocol StringOptions 
- Name of an existing Protocol options profile.
- profileType String
- Determine whether the firewall policy allows security profile groups or single profiles only.
- radiusMac StringAuth Bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- redirectUrl String
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- replacemsgOverride StringGroup 
- Override the default replacement message group for this policy.
- reputationDirection String
- Direction of the initial traffic for reputation to take effect.
- reputationDirection6 String
- Direction of the initial traffic for IPv6 reputation to take effect.
- reputationMinimum Integer
- Minimum Reputation to take action.
- reputationMinimum6 Integer
- IPv6 Minimum Reputation to take action.
- rsso String
- Enable/disable RADIUS single sign-on (RSSO).
- rtpAddrs List<GetPolicy Rtp Addr> 
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- rtpNat String
- Enable Real Time Protocol (RTP) NAT.
- scanBotnet StringConnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- schedule String
- Schedule name.
- scheduleTimeout String
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- sctpFilter StringProfile 
- Name of an existing SCTP filter profile.
- sendDeny StringPacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- serviceNegate String
- When enabled service specifies what the service must NOT be.
- services
List<GetPolicy Service> 
- Service and service group names. The structure of serviceblock is documented below.
- sessionTtl Integer
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- sgtCheck String
- Enable/disable security group tags (SGT) check.
- sgts
List<GetPolicy Sgt> 
- Security group tags. The structure of sgtblock is documented below.
- spamfilterProfile String
- Name of an existing Spam filter profile.
- srcVendor List<GetMacs Policy Src Vendor Mac> 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- srcaddr6Negate String
- When enabled srcaddr6 specifies what the source address must NOT be.
- srcaddr6s
List<GetPolicy Srcaddr6> 
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- srcaddrNegate String
- When enabled srcaddr specifies what the source address must NOT be.
- srcaddrs
List<GetPolicy Srcaddr> 
- Source address and address group names. The structure of srcaddrblock is documented below.
- srcintfs
List<GetPolicy Srcintf> 
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- sshFilter StringProfile 
- Name of an existing SSH filter profile.
- sshPolicy StringRedirect 
- Redirect SSH traffic to matching transparent proxy policy.
- sslMirror String
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- sslMirror List<GetIntfs Policy Ssl Mirror Intf> 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- sslSsh StringProfile 
- Name of an existing SSL SSH profile.
- status String
- Enable or disable this policy.
- tcpMss IntegerReceiver 
- Receiver TCP maximum segment size (MSS).
- tcpMss IntegerSender 
- Sender TCP maximum segment size (MSS).
- tcpSession StringWithout Syn 
- Enable/disable creation of TCP session without SYN flag.
- timeoutSend StringRst 
- Enable/disable sending RST packets when TCP sessions expire.
- tos String
- ToS (Type of Service) value used for comparison.
- tosMask String
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- tosNegate String
- Enable negated TOS match.
- trafficShaper String
- Traffic shaper.
- trafficShaper StringReverse 
- Reverse traffic shaper.
- urlCategories List<GetPolicy Url Category> 
- URL category ID list. The structure of url_categoryblock is documented below.
- users
List<GetPolicy User> 
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- utmStatus String
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- uuid String
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- videofilterProfile String
- Name of an existing VideoFilter profile.
- virtualPatch StringProfile 
- Name of an existing virtual-patch profile.
- vlanCos IntegerFwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanCos IntegerRev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanFilter String
- Set VLAN filters.
- voipProfile String
- Name of an existing VoIP profile.
- vpntunnel String
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- wafProfile String
- Name of an existing Web application firewall profile.
- wanopt String
- Enable/disable WAN optimization.
- wanoptDetection String
- WAN optimization auto-detection mode.
- wanoptPassive StringOpt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- wanoptPeer String
- WAN optimization peer.
- wanoptProfile String
- WAN optimization profile.
- wccp String
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- webcache String
- Enable/disable web cache.
- webcacheHttps String
- Enable/disable web cache for HTTPS.
- webfilterProfile String
- Name of an existing Web filter profile.
- webproxyForward StringServer 
- Web proxy forward server name.
- webproxyProfile String
- Webproxy profile name.
- wsso String
- Enable/disable WiFi Single Sign On (WSSO).
- ztnaDevice StringOwnership 
- Enable/disable zero trust device ownership.
- 
List<GetPolicy Ztna Ems Tag Secondary> 
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- 
List<GetPolicy Ztna Ems Tag> 
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- 
List<GetPolicy Ztna Geo Tag> 
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ztnaPolicy StringRedirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ztnaStatus String
- Enable/disable zero trust access.
- String
- ZTNA tag matching logic.
- vdomparam String
- action string
- Policy action (allow/deny/ipsec).
- antiReplay string
- Enable/disable anti-replay check.
- appCategories GetPolicy App Category[] 
- Application category ID list. The structure of app_categoryblock is documented below.
- appGroups GetPolicy App Group[] 
- Application group names. The structure of app_groupblock is documented below.
- applicationList string
- Name of an existing Application list.
- applications
GetPolicy Application[] 
- Application ID list. The structure of applicationblock is documented below.
- authCert string
- HTTPS server certificate for policy authentication.
- authPath string
- Enable/disable authentication-based routing.
- authRedirect stringAddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- autoAsic stringOffload 
- Enable/disable policy traffic ASIC offloading.
- avProfile string
- Name of an existing Antivirus profile.
- blockNotification string
- Enable/disable block notification.
- captivePortal stringExempt 
- Enable to exempt some users from the captive portal.
- capturePacket string
- Enable/disable capture packets.
- casbProfile string
- Name of an existing CASB profile.
- cifsProfile string
- Name of an existing CIFS profile.
- comments string
- Comment.
- customLog GetFields Policy Custom Log Field[] 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- decryptedTraffic stringMirror 
- Decrypted traffic mirror.
- delayTcp stringNpu Session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- devices
GetPolicy Device[] 
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- diameterFilter stringProfile 
- Name of an existing Diameter filter profile.
- diffservCopy string
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- diffservForward string
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- diffservReverse string
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- diffservcodeForward string
- Change packet's DiffServ to this value.
- diffservcodeRev string
- Change packet's reverse (reply) DiffServ to this value.
- disclaimer string
- Enable/disable user authentication disclaimer.
- dlpProfile string
- Name of an existing DLP profile.
- dlpSensor string
- Name of an existing DLP sensor.
- dnsfilterProfile string
- Name of an existing DNS filter profile.
- dsri string
- Enable DSRI to ignore HTTP server responses.
- dstaddr6Negate string
- When enabled dstaddr6 specifies what the destination address must NOT be.
- dstaddr6s
GetPolicy Dstaddr6[] 
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- dstaddrNegate string
- When enabled dstaddr specifies what the destination address must NOT be.
- dstaddrs
GetPolicy Dstaddr[] 
- Destination address and address group names. The structure of dstaddrblock is documented below.
- dstintfs
GetPolicy Dstintf[] 
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- dynamicShaping string
- Enable/disable dynamic RADIUS defined traffic shaping.
- emailCollect string
- Enable/disable email collection.
- emailfilterProfile string
- Name of an existing email filter profile.
- fec string
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- fileFilter stringProfile 
- Name of an existing file-filter profile.
- firewallSession stringDirty 
- How to handle sessions if the configuration of this firewall policy changes.
- fixedport string
- Enable to prevent source NAT from changing a session's source port.
- fsso string
- Enable/disable Fortinet Single Sign-On.
- fssoAgent stringFor Ntlm 
- FSSO agent to use for NTLM authentication.
- fssoGroups GetPolicy Fsso Group[] 
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- geoipAnycast string
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- geoipMatch string
- Match geography address based either on its physical location or registered location.
- globalLabel string
- Label for the policy that appears when the GUI is in Global View mode.
- groups
GetPolicy Group[] 
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- httpPolicy stringRedirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- icapProfile string
- Name of an existing ICAP profile.
- id string
- The provider-assigned unique ID for this managed resource.
- identityBased stringRoute 
- Name of identity-based routing rule.
- inbound string
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- inspectionMode string
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- internetService string
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6 string
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6Custom GetGroups Policy Internet Service6Custom Group[] 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- internetService6Customs GetPolicy Internet Service6Custom[] 
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- internetService6Groups GetPolicy Internet Service6Group[] 
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- internetService6Names GetPolicy Internet Service6Name[] 
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- internetService6Negate string
- When enabled internet-service6 specifies what the service must NOT be.
- internetService6Src string
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- internetService6Src GetCustom Groups Policy Internet Service6Src Custom Group[] 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- internetService6Src GetCustoms Policy Internet Service6Src Custom[] 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- internetService6Src GetGroups Policy Internet Service6Src Group[] 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- internetService6Src GetNames Policy Internet Service6Src Name[] 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- internetService6Src stringNegate 
- When enabled internet-service6-src specifies what the service must NOT be.
- internetService GetCustom Groups Policy Internet Service Custom Group[] 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- internetService GetCustoms Policy Internet Service Custom[] 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- internetService GetGroups Policy Internet Service Group[] 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- internetService GetIds Policy Internet Service Id[] 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- internetService GetNames Policy Internet Service Name[] 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- internetService stringNegate 
- When enabled internet-service specifies what the service must NOT be.
- internetService stringSrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- internetService GetSrc Custom Groups Policy Internet Service Src Custom Group[] 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- internetService GetSrc Customs Policy Internet Service Src Custom[] 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- internetService GetSrc Groups Policy Internet Service Src Group[] 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- internetService GetSrc Ids Policy Internet Service Src Id[] 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- internetService GetSrc Names Policy Internet Service Src Name[] 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- internetService stringSrc Negate 
- When enabled internet-service-src specifies what the service must NOT be.
- ippool string
- Enable to use IP Pools for source NAT.
- ipsSensor string
- Name of an existing IPS sensor.
- ipsVoip stringFilter 
- Name of an existing VoIP (ips) profile.
- label string
- Label for the policy that appears when the GUI is in Section View mode.
- learningMode string
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- logtraffic string
- Enable or disable logging. Log all sessions or security profile sessions.
- logtrafficStart string
- Record logs when a session starts.
- matchVip string
- Enable to match packets that have had their destination addresses changed by a VIP.
- matchVip stringOnly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- name string
- Mirror Interface name.
- nat string
- Enable/disable source NAT.
- nat46 string
- Enable/disable NAT46.
- nat64 string
- Enable/disable NAT64.
- natinbound string
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- natip string
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- natoutbound string
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- networkService GetDynamics Policy Network Service Dynamic[] 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- networkService GetSrc Dynamics Policy Network Service Src Dynamic[] 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- npAcceleration string
- Enable/disable UTM Network Processor acceleration.
- ntlm string
- Enable/disable NTLM authentication.
- ntlmEnabled GetBrowsers Policy Ntlm Enabled Browser[] 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- ntlmGuest string
- Enable/disable NTLM guest user access.
- outbound string
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- passiveWan stringHealth Measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- pcpInbound string
- Enable/disable PCP inbound DNAT.
- pcpOutbound string
- Enable/disable PCP outbound SNAT.
- pcpPoolnames GetPolicy Pcp Poolname[] 
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- perIp stringShaper 
- Per-IP traffic shaper.
- permitAny stringHost 
- Accept UDP packets from any host.
- permitStun stringHost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- policyExpiry string
- Enable/disable policy expiry.
- policyExpiry stringDate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- policyExpiry stringDate Utc 
- Policy expiry date and time, in epoch format.
- policyid number
- Policy ID.
- poolname6s
GetPolicy Poolname6[] 
- IPv6 pool names. The structure of poolname6block is documented below.
- poolnames
GetPolicy Poolname[] 
- IP Pool names. The structure of poolnameblock is documented below.
- portPreserve string
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- profileGroup string
- Name of profile group.
- profileProtocol stringOptions 
- Name of an existing Protocol options profile.
- profileType string
- Determine whether the firewall policy allows security profile groups or single profiles only.
- radiusMac stringAuth Bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- redirectUrl string
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- replacemsgOverride stringGroup 
- Override the default replacement message group for this policy.
- reputationDirection string
- Direction of the initial traffic for reputation to take effect.
- reputationDirection6 string
- Direction of the initial traffic for IPv6 reputation to take effect.
- reputationMinimum number
- Minimum Reputation to take action.
- reputationMinimum6 number
- IPv6 Minimum Reputation to take action.
- rsso string
- Enable/disable RADIUS single sign-on (RSSO).
- rtpAddrs GetPolicy Rtp Addr[] 
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- rtpNat string
- Enable Real Time Protocol (RTP) NAT.
- scanBotnet stringConnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- schedule string
- Schedule name.
- scheduleTimeout string
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- sctpFilter stringProfile 
- Name of an existing SCTP filter profile.
- sendDeny stringPacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- serviceNegate string
- When enabled service specifies what the service must NOT be.
- services
GetPolicy Service[] 
- Service and service group names. The structure of serviceblock is documented below.
- sessionTtl number
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- sgtCheck string
- Enable/disable security group tags (SGT) check.
- sgts
GetPolicy Sgt[] 
- Security group tags. The structure of sgtblock is documented below.
- spamfilterProfile string
- Name of an existing Spam filter profile.
- srcVendor GetMacs Policy Src Vendor Mac[] 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- srcaddr6Negate string
- When enabled srcaddr6 specifies what the source address must NOT be.
- srcaddr6s
GetPolicy Srcaddr6[] 
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- srcaddrNegate string
- When enabled srcaddr specifies what the source address must NOT be.
- srcaddrs
GetPolicy Srcaddr[] 
- Source address and address group names. The structure of srcaddrblock is documented below.
- srcintfs
GetPolicy Srcintf[] 
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- sshFilter stringProfile 
- Name of an existing SSH filter profile.
- sshPolicy stringRedirect 
- Redirect SSH traffic to matching transparent proxy policy.
- sslMirror string
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- sslMirror GetIntfs Policy Ssl Mirror Intf[] 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- sslSsh stringProfile 
- Name of an existing SSL SSH profile.
- status string
- Enable or disable this policy.
- tcpMss numberReceiver 
- Receiver TCP maximum segment size (MSS).
- tcpMss numberSender 
- Sender TCP maximum segment size (MSS).
- tcpSession stringWithout Syn 
- Enable/disable creation of TCP session without SYN flag.
- timeoutSend stringRst 
- Enable/disable sending RST packets when TCP sessions expire.
- tos string
- ToS (Type of Service) value used for comparison.
- tosMask string
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- tosNegate string
- Enable negated TOS match.
- trafficShaper string
- Traffic shaper.
- trafficShaper stringReverse 
- Reverse traffic shaper.
- urlCategories GetPolicy Url Category[] 
- URL category ID list. The structure of url_categoryblock is documented below.
- users
GetPolicy User[] 
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- utmStatus string
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- uuid string
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- videofilterProfile string
- Name of an existing VideoFilter profile.
- virtualPatch stringProfile 
- Name of an existing virtual-patch profile.
- vlanCos numberFwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanCos numberRev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanFilter string
- Set VLAN filters.
- voipProfile string
- Name of an existing VoIP profile.
- vpntunnel string
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- wafProfile string
- Name of an existing Web application firewall profile.
- wanopt string
- Enable/disable WAN optimization.
- wanoptDetection string
- WAN optimization auto-detection mode.
- wanoptPassive stringOpt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- wanoptPeer string
- WAN optimization peer.
- wanoptProfile string
- WAN optimization profile.
- wccp string
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- webcache string
- Enable/disable web cache.
- webcacheHttps string
- Enable/disable web cache for HTTPS.
- webfilterProfile string
- Name of an existing Web filter profile.
- webproxyForward stringServer 
- Web proxy forward server name.
- webproxyProfile string
- Webproxy profile name.
- wsso string
- Enable/disable WiFi Single Sign On (WSSO).
- ztnaDevice stringOwnership 
- Enable/disable zero trust device ownership.
- 
GetPolicy Ztna Ems Tag Secondary[] 
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- 
GetPolicy Ztna Ems Tag[] 
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- 
GetPolicy Ztna Geo Tag[] 
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ztnaPolicy stringRedirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ztnaStatus string
- Enable/disable zero trust access.
- string
- ZTNA tag matching logic.
- vdomparam string
- action str
- Policy action (allow/deny/ipsec).
- anti_replay str
- Enable/disable anti-replay check.
- app_categories Sequence[GetPolicy App Category] 
- Application category ID list. The structure of app_categoryblock is documented below.
- app_groups Sequence[GetPolicy App Group] 
- Application group names. The structure of app_groupblock is documented below.
- application_list str
- Name of an existing Application list.
- applications
Sequence[GetPolicy Application] 
- Application ID list. The structure of applicationblock is documented below.
- auth_cert str
- HTTPS server certificate for policy authentication.
- auth_path str
- Enable/disable authentication-based routing.
- auth_redirect_ straddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- auto_asic_ stroffload 
- Enable/disable policy traffic ASIC offloading.
- av_profile str
- Name of an existing Antivirus profile.
- block_notification str
- Enable/disable block notification.
- captive_portal_ strexempt 
- Enable to exempt some users from the captive portal.
- capture_packet str
- Enable/disable capture packets.
- casb_profile str
- Name of an existing CASB profile.
- cifs_profile str
- Name of an existing CIFS profile.
- comments str
- Comment.
- custom_log_ Sequence[Getfields Policy Custom Log Field] 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- decrypted_traffic_ strmirror 
- Decrypted traffic mirror.
- delay_tcp_ strnpu_ session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- devices
Sequence[GetPolicy Device] 
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- diameter_filter_ strprofile 
- Name of an existing Diameter filter profile.
- diffserv_copy str
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- diffserv_forward str
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- diffserv_reverse str
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- diffservcode_forward str
- Change packet's DiffServ to this value.
- diffservcode_rev str
- Change packet's reverse (reply) DiffServ to this value.
- disclaimer str
- Enable/disable user authentication disclaimer.
- dlp_profile str
- Name of an existing DLP profile.
- dlp_sensor str
- Name of an existing DLP sensor.
- dnsfilter_profile str
- Name of an existing DNS filter profile.
- dsri str
- Enable DSRI to ignore HTTP server responses.
- dstaddr6_negate str
- When enabled dstaddr6 specifies what the destination address must NOT be.
- dstaddr6s
Sequence[GetPolicy Dstaddr6] 
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- dstaddr_negate str
- When enabled dstaddr specifies what the destination address must NOT be.
- dstaddrs
Sequence[GetPolicy Dstaddr] 
- Destination address and address group names. The structure of dstaddrblock is documented below.
- dstintfs
Sequence[GetPolicy Dstintf] 
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- dynamic_shaping str
- Enable/disable dynamic RADIUS defined traffic shaping.
- email_collect str
- Enable/disable email collection.
- emailfilter_profile str
- Name of an existing email filter profile.
- fec str
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- file_filter_ strprofile 
- Name of an existing file-filter profile.
- firewall_session_ strdirty 
- How to handle sessions if the configuration of this firewall policy changes.
- fixedport str
- Enable to prevent source NAT from changing a session's source port.
- fsso str
- Enable/disable Fortinet Single Sign-On.
- fsso_agent_ strfor_ ntlm 
- FSSO agent to use for NTLM authentication.
- fsso_groups Sequence[GetPolicy Fsso Group] 
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- geoip_anycast str
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- geoip_match str
- Match geography address based either on its physical location or registered location.
- global_label str
- Label for the policy that appears when the GUI is in Global View mode.
- groups
Sequence[GetPolicy Group] 
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- http_policy_ strredirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- icap_profile str
- Name of an existing ICAP profile.
- id str
- The provider-assigned unique ID for this managed resource.
- identity_based_ strroute 
- Name of identity-based routing rule.
- inbound str
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- inspection_mode str
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- internet_service str
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- internet_service6 str
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- internet_service6_ Sequence[Getcustom_ groups Policy Internet Service6Custom Group] 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- internet_service6_ Sequence[Getcustoms Policy Internet Service6Custom] 
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- internet_service6_ Sequence[Getgroups Policy Internet Service6Group] 
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- internet_service6_ Sequence[Getnames Policy Internet Service6Name] 
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- internet_service6_ strnegate 
- When enabled internet-service6 specifies what the service must NOT be.
- internet_service6_ strsrc 
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- internet_service6_ Sequence[Getsrc_ custom_ groups Policy Internet Service6Src Custom Group] 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- internet_service6_ Sequence[Getsrc_ customs Policy Internet Service6Src Custom] 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- internet_service6_ Sequence[Getsrc_ groups Policy Internet Service6Src Group] 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- internet_service6_ Sequence[Getsrc_ names Policy Internet Service6Src Name] 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- internet_service6_ strsrc_ negate 
- When enabled internet-service6-src specifies what the service must NOT be.
- internet_service_ Sequence[Getcustom_ groups Policy Internet Service Custom Group] 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- internet_service_ Sequence[Getcustoms Policy Internet Service Custom] 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- internet_service_ Sequence[Getgroups Policy Internet Service Group] 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- internet_service_ Sequence[Getids Policy Internet Service Id] 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- internet_service_ Sequence[Getnames Policy Internet Service Name] 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- internet_service_ strnegate 
- When enabled internet-service specifies what the service must NOT be.
- internet_service_ strsrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- internet_service_ Sequence[Getsrc_ custom_ groups Policy Internet Service Src Custom Group] 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- internet_service_ Sequence[Getsrc_ customs Policy Internet Service Src Custom] 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- internet_service_ Sequence[Getsrc_ groups Policy Internet Service Src Group] 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- internet_service_ Sequence[Getsrc_ ids Policy Internet Service Src Id] 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- internet_service_ Sequence[Getsrc_ names Policy Internet Service Src Name] 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- internet_service_ strsrc_ negate 
- When enabled internet-service-src specifies what the service must NOT be.
- ippool str
- Enable to use IP Pools for source NAT.
- ips_sensor str
- Name of an existing IPS sensor.
- ips_voip_ strfilter 
- Name of an existing VoIP (ips) profile.
- label str
- Label for the policy that appears when the GUI is in Section View mode.
- learning_mode str
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- logtraffic str
- Enable or disable logging. Log all sessions or security profile sessions.
- logtraffic_start str
- Record logs when a session starts.
- match_vip str
- Enable to match packets that have had their destination addresses changed by a VIP.
- match_vip_ stronly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- name str
- Mirror Interface name.
- nat str
- Enable/disable source NAT.
- nat46 str
- Enable/disable NAT46.
- nat64 str
- Enable/disable NAT64.
- natinbound str
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- natip str
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- natoutbound str
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- network_service_ Sequence[Getdynamics Policy Network Service Dynamic] 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- network_service_ Sequence[Getsrc_ dynamics Policy Network Service Src Dynamic] 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- np_acceleration str
- Enable/disable UTM Network Processor acceleration.
- ntlm str
- Enable/disable NTLM authentication.
- ntlm_enabled_ Sequence[Getbrowsers Policy Ntlm Enabled Browser] 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- ntlm_guest str
- Enable/disable NTLM guest user access.
- outbound str
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- passive_wan_ strhealth_ measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- pcp_inbound str
- Enable/disable PCP inbound DNAT.
- pcp_outbound str
- Enable/disable PCP outbound SNAT.
- pcp_poolnames Sequence[GetPolicy Pcp Poolname] 
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- per_ip_ strshaper 
- Per-IP traffic shaper.
- permit_any_ strhost 
- Accept UDP packets from any host.
- permit_stun_ strhost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- policy_expiry str
- Enable/disable policy expiry.
- policy_expiry_ strdate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- policy_expiry_ strdate_ utc 
- Policy expiry date and time, in epoch format.
- policyid int
- Policy ID.
- poolname6s
Sequence[GetPolicy Poolname6] 
- IPv6 pool names. The structure of poolname6block is documented below.
- poolnames
Sequence[GetPolicy Poolname] 
- IP Pool names. The structure of poolnameblock is documented below.
- port_preserve str
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- profile_group str
- Name of profile group.
- profile_protocol_ stroptions 
- Name of an existing Protocol options profile.
- profile_type str
- Determine whether the firewall policy allows security profile groups or single profiles only.
- radius_mac_ strauth_ bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- redirect_url str
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- replacemsg_override_ strgroup 
- Override the default replacement message group for this policy.
- reputation_direction str
- Direction of the initial traffic for reputation to take effect.
- reputation_direction6 str
- Direction of the initial traffic for IPv6 reputation to take effect.
- reputation_minimum int
- Minimum Reputation to take action.
- reputation_minimum6 int
- IPv6 Minimum Reputation to take action.
- rsso str
- Enable/disable RADIUS single sign-on (RSSO).
- rtp_addrs Sequence[GetPolicy Rtp Addr] 
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- rtp_nat str
- Enable Real Time Protocol (RTP) NAT.
- scan_botnet_ strconnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- schedule str
- Schedule name.
- schedule_timeout str
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- sctp_filter_ strprofile 
- Name of an existing SCTP filter profile.
- send_deny_ strpacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- service_negate str
- When enabled service specifies what the service must NOT be.
- services
Sequence[GetPolicy Service] 
- Service and service group names. The structure of serviceblock is documented below.
- session_ttl int
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- sgt_check str
- Enable/disable security group tags (SGT) check.
- sgts
Sequence[GetPolicy Sgt] 
- Security group tags. The structure of sgtblock is documented below.
- spamfilter_profile str
- Name of an existing Spam filter profile.
- src_vendor_ Sequence[Getmacs Policy Src Vendor Mac] 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- srcaddr6_negate str
- When enabled srcaddr6 specifies what the source address must NOT be.
- srcaddr6s
Sequence[GetPolicy Srcaddr6] 
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- srcaddr_negate str
- When enabled srcaddr specifies what the source address must NOT be.
- srcaddrs
Sequence[GetPolicy Srcaddr] 
- Source address and address group names. The structure of srcaddrblock is documented below.
- srcintfs
Sequence[GetPolicy Srcintf] 
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- ssh_filter_ strprofile 
- Name of an existing SSH filter profile.
- ssh_policy_ strredirect 
- Redirect SSH traffic to matching transparent proxy policy.
- ssl_mirror str
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- ssl_mirror_ Sequence[Getintfs Policy Ssl Mirror Intf] 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- ssl_ssh_ strprofile 
- Name of an existing SSL SSH profile.
- status str
- Enable or disable this policy.
- tcp_mss_ intreceiver 
- Receiver TCP maximum segment size (MSS).
- tcp_mss_ intsender 
- Sender TCP maximum segment size (MSS).
- tcp_session_ strwithout_ syn 
- Enable/disable creation of TCP session without SYN flag.
- timeout_send_ strrst 
- Enable/disable sending RST packets when TCP sessions expire.
- tos str
- ToS (Type of Service) value used for comparison.
- tos_mask str
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- tos_negate str
- Enable negated TOS match.
- traffic_shaper str
- Traffic shaper.
- traffic_shaper_ strreverse 
- Reverse traffic shaper.
- url_categories Sequence[GetPolicy Url Category] 
- URL category ID list. The structure of url_categoryblock is documented below.
- users
Sequence[GetPolicy User] 
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- utm_status str
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- uuid str
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- videofilter_profile str
- Name of an existing VideoFilter profile.
- virtual_patch_ strprofile 
- Name of an existing virtual-patch profile.
- vlan_cos_ intfwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlan_cos_ intrev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlan_filter str
- Set VLAN filters.
- voip_profile str
- Name of an existing VoIP profile.
- vpntunnel str
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- waf_profile str
- Name of an existing Web application firewall profile.
- wanopt str
- Enable/disable WAN optimization.
- wanopt_detection str
- WAN optimization auto-detection mode.
- wanopt_passive_ stropt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- wanopt_peer str
- WAN optimization peer.
- wanopt_profile str
- WAN optimization profile.
- wccp str
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- webcache str
- Enable/disable web cache.
- webcache_https str
- Enable/disable web cache for HTTPS.
- webfilter_profile str
- Name of an existing Web filter profile.
- webproxy_forward_ strserver 
- Web proxy forward server name.
- webproxy_profile str
- Webproxy profile name.
- wsso str
- Enable/disable WiFi Single Sign On (WSSO).
- ztna_device_ strownership 
- Enable/disable zero trust device ownership.
- ztna_ems_ Sequence[Gettag_ secondaries Policy Ztna Ems Tag Secondary] 
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- 
Sequence[GetPolicy Ztna Ems Tag] 
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- 
Sequence[GetPolicy Ztna Geo Tag] 
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ztna_policy_ strredirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ztna_status str
- Enable/disable zero trust access.
- str
- ZTNA tag matching logic.
- vdomparam str
- action String
- Policy action (allow/deny/ipsec).
- antiReplay String
- Enable/disable anti-replay check.
- appCategories List<Property Map>
- Application category ID list. The structure of app_categoryblock is documented below.
- appGroups List<Property Map>
- Application group names. The structure of app_groupblock is documented below.
- applicationList String
- Name of an existing Application list.
- applications List<Property Map>
- Application ID list. The structure of applicationblock is documented below.
- authCert String
- HTTPS server certificate for policy authentication.
- authPath String
- Enable/disable authentication-based routing.
- authRedirect StringAddr 
- HTTP-to-HTTPS redirect address for firewall authentication.
- autoAsic StringOffload 
- Enable/disable policy traffic ASIC offloading.
- avProfile String
- Name of an existing Antivirus profile.
- blockNotification String
- Enable/disable block notification.
- captivePortal StringExempt 
- Enable to exempt some users from the captive portal.
- capturePacket String
- Enable/disable capture packets.
- casbProfile String
- Name of an existing CASB profile.
- cifsProfile String
- Name of an existing CIFS profile.
- comments String
- Comment.
- customLog List<Property Map>Fields 
- Custom fields to append to log messages for this policy. The structure of custom_log_fieldsblock is documented below.
- decryptedTraffic StringMirror 
- Decrypted traffic mirror.
- delayTcp StringNpu Session 
- Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
- devices List<Property Map>
- Names of devices or device groups that can be matched by the policy. The structure of devicesblock is documented below.
- diameterFilter StringProfile 
- Name of an existing Diameter filter profile.
- diffservCopy String
- Enable to copy packet's DiffServ values from session's original direction to its reply direction.
- diffservForward String
- Enable to change packet's DiffServ values to the specified diffservcode-forward value.
- diffservReverse String
- Enable to change packet's reverse (reply) DiffServ values to the specified diffservcode-rev value.
- diffservcodeForward String
- Change packet's DiffServ to this value.
- diffservcodeRev String
- Change packet's reverse (reply) DiffServ to this value.
- disclaimer String
- Enable/disable user authentication disclaimer.
- dlpProfile String
- Name of an existing DLP profile.
- dlpSensor String
- Name of an existing DLP sensor.
- dnsfilterProfile String
- Name of an existing DNS filter profile.
- dsri String
- Enable DSRI to ignore HTTP server responses.
- dstaddr6Negate String
- When enabled dstaddr6 specifies what the destination address must NOT be.
- dstaddr6s List<Property Map>
- Destination IPv6 address name and address group names. The structure of dstaddr6block is documented below.
- dstaddrNegate String
- When enabled dstaddr specifies what the destination address must NOT be.
- dstaddrs List<Property Map>
- Destination address and address group names. The structure of dstaddrblock is documented below.
- dstintfs List<Property Map>
- Outgoing (egress) interface. The structure of dstintfblock is documented below.
- dynamicShaping String
- Enable/disable dynamic RADIUS defined traffic shaping.
- emailCollect String
- Enable/disable email collection.
- emailfilterProfile String
- Name of an existing email filter profile.
- fec String
- Enable/disable Forward Error Correction on traffic matching this policy on a FEC device.
- fileFilter StringProfile 
- Name of an existing file-filter profile.
- firewallSession StringDirty 
- How to handle sessions if the configuration of this firewall policy changes.
- fixedport String
- Enable to prevent source NAT from changing a session's source port.
- fsso String
- Enable/disable Fortinet Single Sign-On.
- fssoAgent StringFor Ntlm 
- FSSO agent to use for NTLM authentication.
- fssoGroups List<Property Map>
- Names of FSSO groups. The structure of fsso_groupsblock is documented below.
- geoipAnycast String
- Enable/disable recognition of anycast IP addresses using the geography IP database.
- geoipMatch String
- Match geography address based either on its physical location or registered location.
- globalLabel String
- Label for the policy that appears when the GUI is in Global View mode.
- groups List<Property Map>
- Names of user groups that can authenticate with this policy. The structure of groupsblock is documented below.
- httpPolicy StringRedirect 
- Redirect HTTP(S) traffic to matching transparent web proxy policy.
- icapProfile String
- Name of an existing ICAP profile.
- id String
- The provider-assigned unique ID for this managed resource.
- identityBased StringRoute 
- Name of identity-based routing rule.
- inbound String
- Policy-based IPsec VPN: only traffic from the remote network can initiate a VPN.
- inspectionMode String
- Policy inspection mode (Flow/proxy). Default is Flow mode.
- internetService String
- Enable/disable use of Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6 String
- Enable/disable use of IPv6 Internet Services for this policy. If enabled, destination address and service are not used.
- internetService6Custom List<Property Map>Groups 
- Custom Internet Service6 group name. The structure of internet_service6_custom_groupblock is documented below.
- internetService6Customs List<Property Map>
- Custom IPv6 Internet Service name. The structure of internet_service6_customblock is documented below.
- internetService6Groups List<Property Map>
- Internet Service group name. The structure of internet_service6_groupblock is documented below.
- internetService6Names List<Property Map>
- IPv6 Internet Service name. The structure of internet_service6_nameblock is documented below.
- internetService6Negate String
- When enabled internet-service6 specifies what the service must NOT be.
- internetService6Src String
- Enable/disable use of IPv6 Internet Services in source for this policy. If enabled, source address is not used.
- internetService6Src List<Property Map>Custom Groups 
- Custom Internet Service6 source group name. The structure of internet_service6_src_custom_groupblock is documented below.
- internetService6Src List<Property Map>Customs 
- Custom IPv6 Internet Service source name. The structure of internet_service6_src_customblock is documented below.
- internetService6Src List<Property Map>Groups 
- Internet Service6 source group name. The structure of internet_service6_src_groupblock is documented below.
- internetService6Src List<Property Map>Names 
- IPv6 Internet Service source name. The structure of internet_service6_src_nameblock is documented below.
- internetService6Src StringNegate 
- When enabled internet-service6-src specifies what the service must NOT be.
- internetService List<Property Map>Custom Groups 
- Custom Internet Service group name. The structure of internet_service_custom_groupblock is documented below.
- internetService List<Property Map>Customs 
- Custom Internet Service name. The structure of internet_service_customblock is documented below.
- internetService List<Property Map>Groups 
- Internet Service group name. The structure of internet_service_groupblock is documented below.
- internetService List<Property Map>Ids 
- Internet Service ID. The structure of internet_service_idblock is documented below.
- internetService List<Property Map>Names 
- Internet Service name. The structure of internet_service_nameblock is documented below.
- internetService StringNegate 
- When enabled internet-service specifies what the service must NOT be.
- internetService StringSrc 
- Enable/disable use of Internet Services in source for this policy. If enabled, source address is not used.
- internetService List<Property Map>Src Custom Groups 
- Custom Internet Service source group name. The structure of internet_service_src_custom_groupblock is documented below.
- internetService List<Property Map>Src Customs 
- Custom Internet Service source name. The structure of internet_service_src_customblock is documented below.
- internetService List<Property Map>Src Groups 
- Internet Service source group name. The structure of internet_service_src_groupblock is documented below.
- internetService List<Property Map>Src Ids 
- Internet Service source ID. The structure of internet_service_src_idblock is documented below.
- internetService List<Property Map>Src Names 
- Internet Service source name. The structure of internet_service_src_nameblock is documented below.
- internetService StringSrc Negate 
- When enabled internet-service-src specifies what the service must NOT be.
- ippool String
- Enable to use IP Pools for source NAT.
- ipsSensor String
- Name of an existing IPS sensor.
- ipsVoip StringFilter 
- Name of an existing VoIP (ips) profile.
- label String
- Label for the policy that appears when the GUI is in Section View mode.
- learningMode String
- Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
- logtraffic String
- Enable or disable logging. Log all sessions or security profile sessions.
- logtrafficStart String
- Record logs when a session starts.
- matchVip String
- Enable to match packets that have had their destination addresses changed by a VIP.
- matchVip StringOnly 
- Enable/disable matching of only those packets that have had their destination addresses changed by a VIP.
- name String
- Mirror Interface name.
- nat String
- Enable/disable source NAT.
- nat46 String
- Enable/disable NAT46.
- nat64 String
- Enable/disable NAT64.
- natinbound String
- Policy-based IPsec VPN: apply destination NAT to inbound traffic.
- natip String
- Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
- natoutbound String
- Policy-based IPsec VPN: apply source NAT to outbound traffic.
- networkService List<Property Map>Dynamics 
- Dynamic Network Service name. The structure of network_service_dynamicblock is documented below.
- networkService List<Property Map>Src Dynamics 
- Dynamic Network Service source name. The structure of network_service_src_dynamicblock is documented below.
- npAcceleration String
- Enable/disable UTM Network Processor acceleration.
- ntlm String
- Enable/disable NTLM authentication.
- ntlmEnabled List<Property Map>Browsers 
- HTTP-User-Agent value of supported browsers. The structure of ntlm_enabled_browsersblock is documented below.
- ntlmGuest String
- Enable/disable NTLM guest user access.
- outbound String
- Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
- passiveWan StringHealth Measurement 
- Enable/disable passive WAN health measurement. When enabled, auto-asic-offload is disabled.
- pcpInbound String
- Enable/disable PCP inbound DNAT.
- pcpOutbound String
- Enable/disable PCP outbound SNAT.
- pcpPoolnames List<Property Map>
- PCP pool names. The structure of pcp_poolnameblock is documented below.
- perIp StringShaper 
- Per-IP traffic shaper.
- permitAny StringHost 
- Accept UDP packets from any host.
- permitStun StringHost 
- Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
- policyExpiry String
- Enable/disable policy expiry.
- policyExpiry StringDate 
- Policy expiry date (YYYY-MM-DD HH:MM:SS).
- policyExpiry StringDate Utc 
- Policy expiry date and time, in epoch format.
- policyid Number
- Policy ID.
- poolname6s List<Property Map>
- IPv6 pool names. The structure of poolname6block is documented below.
- poolnames List<Property Map>
- IP Pool names. The structure of poolnameblock is documented below.
- portPreserve String
- Enable/disable preservation of the original source port from source NAT if it has not been used.
- profileGroup String
- Name of profile group.
- profileProtocol StringOptions 
- Name of an existing Protocol options profile.
- profileType String
- Determine whether the firewall policy allows security profile groups or single profiles only.
- radiusMac StringAuth Bypass 
- Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
- redirectUrl String
- URL users are directed to after seeing and accepting the disclaimer or authenticating.
- replacemsgOverride StringGroup 
- Override the default replacement message group for this policy.
- reputationDirection String
- Direction of the initial traffic for reputation to take effect.
- reputationDirection6 String
- Direction of the initial traffic for IPv6 reputation to take effect.
- reputationMinimum Number
- Minimum Reputation to take action.
- reputationMinimum6 Number
- IPv6 Minimum Reputation to take action.
- rsso String
- Enable/disable RADIUS single sign-on (RSSO).
- rtpAddrs List<Property Map>
- Address names if this is an RTP NAT policy. The structure of rtp_addrblock is documented below.
- rtpNat String
- Enable Real Time Protocol (RTP) NAT.
- scanBotnet StringConnections 
- Block or monitor connections to Botnet servers or disable Botnet scanning.
- schedule String
- Schedule name.
- scheduleTimeout String
- Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
- sctpFilter StringProfile 
- Name of an existing SCTP filter profile.
- sendDeny StringPacket 
- Enable to send a reply when a session is denied or blocked by a firewall policy.
- serviceNegate String
- When enabled service specifies what the service must NOT be.
- services List<Property Map>
- Service and service group names. The structure of serviceblock is documented below.
- sessionTtl Number
- TTL in seconds for sessions accepted by this policy (0 means use the system default session TTL).
- sgtCheck String
- Enable/disable security group tags (SGT) check.
- sgts List<Property Map>
- Security group tags. The structure of sgtblock is documented below.
- spamfilterProfile String
- Name of an existing Spam filter profile.
- srcVendor List<Property Map>Macs 
- Vendor MAC source ID. The structure of src_vendor_macblock is documented below.
- srcaddr6Negate String
- When enabled srcaddr6 specifies what the source address must NOT be.
- srcaddr6s List<Property Map>
- Source IPv6 address name and address group names. The structure of srcaddr6block is documented below.
- srcaddrNegate String
- When enabled srcaddr specifies what the source address must NOT be.
- srcaddrs List<Property Map>
- Source address and address group names. The structure of srcaddrblock is documented below.
- srcintfs List<Property Map>
- Incoming (ingress) interface. The structure of srcintfblock is documented below.
- sshFilter StringProfile 
- Name of an existing SSH filter profile.
- sshPolicy StringRedirect 
- Redirect SSH traffic to matching transparent proxy policy.
- sslMirror String
- Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
- sslMirror List<Property Map>Intfs 
- SSL mirror interface name. The structure of ssl_mirror_intfblock is documented below.
- sslSsh StringProfile 
- Name of an existing SSL SSH profile.
- status String
- Enable or disable this policy.
- tcpMss NumberReceiver 
- Receiver TCP maximum segment size (MSS).
- tcpMss NumberSender 
- Sender TCP maximum segment size (MSS).
- tcpSession StringWithout Syn 
- Enable/disable creation of TCP session without SYN flag.
- timeoutSend StringRst 
- Enable/disable sending RST packets when TCP sessions expire.
- tos String
- ToS (Type of Service) value used for comparison.
- tosMask String
- Non-zero bit positions are used for comparison while zero bit positions are ignored.
- tosNegate String
- Enable negated TOS match.
- trafficShaper String
- Traffic shaper.
- trafficShaper StringReverse 
- Reverse traffic shaper.
- urlCategories List<Property Map>
- URL category ID list. The structure of url_categoryblock is documented below.
- users List<Property Map>
- Names of individual users that can authenticate with this policy. The structure of usersblock is documented below.
- utmStatus String
- Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
- uuid String
- Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
- videofilterProfile String
- Name of an existing VideoFilter profile.
- virtualPatch StringProfile 
- Name of an existing virtual-patch profile.
- vlanCos NumberFwd 
- VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanCos NumberRev 
- VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
- vlanFilter String
- Set VLAN filters.
- voipProfile String
- Name of an existing VoIP profile.
- vpntunnel String
- Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
- wafProfile String
- Name of an existing Web application firewall profile.
- wanopt String
- Enable/disable WAN optimization.
- wanoptDetection String
- WAN optimization auto-detection mode.
- wanoptPassive StringOpt 
- WAN optimization passive mode options. This option decides what IP address will be used to connect server.
- wanoptPeer String
- WAN optimization peer.
- wanoptProfile String
- WAN optimization profile.
- wccp String
- Enable/disable forwarding traffic matching this policy to a configured WCCP server.
- webcache String
- Enable/disable web cache.
- webcacheHttps String
- Enable/disable web cache for HTTPS.
- webfilterProfile String
- Name of an existing Web filter profile.
- webproxyForward StringServer 
- Web proxy forward server name.
- webproxyProfile String
- Webproxy profile name.
- wsso String
- Enable/disable WiFi Single Sign On (WSSO).
- ztnaDevice StringOwnership 
- Enable/disable zero trust device ownership.
- List<Property Map>
- Source ztna-ems-tag-secondary names. The structure of ztna_ems_tag_secondaryblock is documented below.
- List<Property Map>
- Source ztna-ems-tag names. The structure of ztna_ems_tagblock is documented below.
- List<Property Map>
- Source ztna-geo-tag names. The structure of ztna_geo_tagblock is documented below.
- ztnaPolicy StringRedirect 
- Redirect ZTNA traffic to matching Access-Proxy proxy-policy.
- ztnaStatus String
- Enable/disable zero trust access.
- String
- ZTNA tag matching logic.
- vdomparam String
Supporting Types
GetPolicyAppCategory   
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicyAppGroup   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyApplication  
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicyCustomLogField    
- FieldId string
- Custom log field.
- FieldId string
- Custom log field.
- fieldId String
- Custom log field.
- fieldId string
- Custom log field.
- field_id str
- Custom log field.
- fieldId String
- Custom log field.
GetPolicyDevice  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyDstaddr  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyDstaddr6  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyDstintf  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyFssoGroup   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyGroup  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6Custom   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6CustomGroup    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6Group   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6Name   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6SrcCustom    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6SrcCustomGroup     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6SrcGroup    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetService6SrcName    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceCustom    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceCustomGroup     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceGroup    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceId    
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicyInternetServiceName    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceSrcCustom     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceSrcCustomGroup      
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceSrcGroup     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyInternetServiceSrcId     
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicyInternetServiceSrcName     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyNetworkServiceDynamic    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyNetworkServiceSrcDynamic     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyNtlmEnabledBrowser    
- UserAgent stringString 
- User agent string.
- UserAgent stringString 
- User agent string.
- userAgent StringString 
- User agent string.
- userAgent stringString 
- User agent string.
- user_agent_ strstring 
- User agent string.
- userAgent StringString 
- User agent string.
GetPolicyPcpPoolname   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyPoolname  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyPoolname6  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyRtpAddr   
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyService  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicySgt  
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicySrcVendorMac    
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicySrcaddr  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicySrcaddr6  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicySrcintf  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicySslMirrorIntf    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyUrlCategory   
- Id int
- Security group tag.
- Id int
- Security group tag.
- id Integer
- Security group tag.
- id number
- Security group tag.
- id int
- Security group tag.
- id Number
- Security group tag.
GetPolicyUser  
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyZtnaEmsTag    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyZtnaEmsTagSecondary     
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
GetPolicyZtnaGeoTag    
- Name string
- Mirror Interface name.
- Name string
- Mirror Interface name.
- name String
- Mirror Interface name.
- name string
- Mirror Interface name.
- name str
- Mirror Interface name.
- name String
- Mirror Interface name.
Package Details
- Repository
- fortios pulumiverse/pulumi-fortios
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the fortiosTerraform Provider.
