FortiManager

FortiManager is a single console central management system that manages Fortinet devices.

Network Security · FortiManager

Details

IDFortiManager
ProviderFortinet
CategoryNetwork Security
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

FortiManager is a single console central management system that manages Fortinet Devices.
This integration was integrated and tested with version 6.2.2 of FortiManager

Required Permissions

Following are the required permissions for the integration commands:

Setting Minimal Requirement
device-manager Read-Only
global-policy-packages Read-Write
adom-policy-packages Read-Write
deploy-management Read-Write

The eligible predefined administrator profiles are: Super User, Standard User, and Package User.
For more information about administrator permissions see the FortiManager documentation.

Configure FortiManager in Cortex

Parameter Description Required
url Server URL True
credentials Username True
adom The instance ADOM True
insecure Trust any certificate (not secure) False
proxy Use system proxy settings False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

fortimanager-devices-list


List all devices in the ADOM instance.

Base Command

fortimanager-devices-list

Input

Argument Name Description Required
adom The FortiManager Administrative Domain (ADOM) from which to fetch the devices. Leave empty to use the instance ADOM. Optional
device The name of a specific device to get. If not specified, will get all devices. Optional
offset From which index to start the list. Default is 0. Optional
limit Until which index to get the list. Default is 50. Optional

Context Output

Path Type Description
FortiManager.Device.adm_pass String The ADOM password.
FortiManager.Device.adm_usr String The ADOM user.
FortiManager.Device.app_ver String The app version of the device.
FortiManager.Device.av_ver String The antivirus version of the device.
FortiManager.Device.beta Number The beta version of the device.
FortiManager.Device.branch_pt Number The branch point of the device.
FortiManager.Device.build Number The build of the device.
FortiManager.Device.checksum String The checksum of the device.
FortiManager.Device.conf_status String The configuration status of the device.
FortiManager.Device.conn_mode String The connection mode of the device.
FortiManager.Device.conn_status String The connection status of the device.
FortiManager.Device.db_status String The database status of the device.
FortiManager.Device.desc String The description of the device.
FortiManager.Device.dev_status String The status of the device.
FortiManager.Device.fap_cnt Number The FortiManager access point count.
FortiManager.Device.faz.full_act Number Full act.
FortiManager.Device.faz.perm Number Perm.
FortiManager.Device.faz.quota Number Quota.
FortiManager.Device.faz.used Number Used.
FortiManager.Device.fex_cnt Number Fex count.
FortiManager.Device.flags String Flags.
FortiManager.Device.foslic_cpu Number Foslic CPU.
FortiManager.Device.foslic_dr_site String Foslic dr site.
FortiManager.Device.foslic_inst_time Number Foslic inst time.
FortiManager.Device.foslic_last_sync Number Foslic last sync.
FortiManager.Device.foslic_ram Number Foslic RAM.
FortiManager.Device.foslic_type String Foslic type.
FortiManager.Device.foslic_utm String Foslic UTM.
FortiManager.Device.fsw_cnt Number FSW count.
FortiManager.Device.ha_group_id Number HA group ID.
FortiManager.Device.ha_group_name String HA group name.
FortiManager.Device.ha_mode String HA mode.
FortiManager.Device.hdisk_size Number Hard disk size.
FortiManager.Device.hostname String Hostname.
FortiManager.Device.hw_rev_major Number Hardware major revision number.
FortiManager.Device.hw_rev_minor Number Hardware minor revision number.
FortiManager.Device.ip String Device IP.
FortiManager.Device.ips_ext Number External IP.
FortiManager.Device.ips_ver String IP version.
FortiManager.Device.last_checked Number Last checked.
FortiManager.Device.last_resync Number Last resync.
FortiManager.Device.latitude String Latitude.
FortiManager.Device.lic_flags Number License flags.
FortiManager.Device.lic_region String License region.
FortiManager.Device.location_from String Location from.
FortiManager.Device.logdisk_size Number Log disk size.
FortiManager.Device.longitude String Longitude.
FortiManager.Device.maxvdom Number Maximum VDOM.
FortiManager.Device.meta_fields String Meta fields.
FortiManager.Device.mgmt_id Number Management ID.
FortiManager.Device.mgmt_if String Management IF.
FortiManager.Device.mgmt_mode String Management mode.
FortiManager.Device.mgt_vdom String Management VDOM.
FortiManager.Device.module_sn String Module serial number.
FortiManager.Device.mr Number Mr.
FortiManager.Device.name String Device name.
FortiManager.Device.os_type String Device operating system type.
FortiManager.Device.os_ver String Device operating system version.
FortiManager.Device.patch Number Patch.
FortiManager.Device.platform_str String Platform string.
FortiManager.Device.prefer_img_ver String Prefer image version.
FortiManager.Device.prio Number Prio.
FortiManager.Device.psk String PSK.
FortiManager.Device.role String Device role.
FortiManager.Device.sn String Serial number.
FortiManager.Device.vdom.comments String VDOM comments.
FortiManager.Device.vdom.name String VDOM name.
FortiManager.Device.vdom.opmode String VDOM opmode.
FortiManager.Device.vdom.rtm_prof_id Number VDOM rtm prof ID.
FortiManager.Device.vdom.status String VDOM status.
FortiManager.Device.vdom.vpn_id Number VDOM VPN ID.
FortiManager.Device.version Number Device version.
FortiManager.Device.vm_cpu Number VM CPU.
FortiManager.Device.vm_cpu_limit Number VM CPU limit.
FortiManager.Device.vm_lic_expire Number VM license expiration.
FortiManager.Device.vm_mem Number VM memory.
FortiManager.Device.vm_mem_limit Number VM memory limit.
FortiManager.Device.vm_status Number VM status.

Command Example

!fortimanager-devices-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "Device": [
            {
                "adm_pass": [
                    "ENC",
                    "MMM"
                ],
                "adm_usr": "",
                "app_ver": "",
                "av_ver": "",
                "beta": -1,
                "branch_pt": 4271,
                "build": 4148,
                "checksum": "",
                "conf_status": 0,
                "conn_mode": 0,
                "conn_status": 0,
                "db_status": 2,
                "desc": "",
                "dev_status": 0,
                "fap_cnt": 0,
                "faz.full_act": 0,
                "faz.perm": 15,
                "faz.quota": 0,
                "faz.used": 0,
                "fex_cnt": 0,
                "flags": 2,
                "foslic_cpu": 0,
                "foslic_dr_site": 0,
                "foslic_inst_time": 0,
                "foslic_last_sync": 0,
                "foslic_ram": 0,
                "foslic_type": 0,
                "foslic_utm": 0,
                "fsw_cnt": 0,
                "ha_group_id": 0,
                "ha_group_name": "",
                "ha_mode": 0,
                "ha_slave": null,
                "hdisk_size": 0,
                "hostname": "",
                "hw_rev_major": 0,
                "hw_rev_minor": 0,
                "ip": "1.2.3.4",
                "ips_ext": 0,
                "ips_ver": "",
                "last_checked": 0,
                "last_resync": 0,
                "latitude": "0.0",
                "lic_flags": 0,
                "lic_region": "",
                "location_from": null,
                "logdisk_size": 0,
                "longitude": "0.0",
                "maxvdom": 500,
                "mgmt.__data[0]": 0,
                "mgmt.__data[1]": 0,
                "mgmt.__data[2]": 0,
                "mgmt.__data[3]": 0,
                "mgmt.__data[4]": 0,
                "mgmt.__data[5]": 0,
                "mgmt.__data[6]": 0,
                "mgmt.__data[7]": 0,
                "mgmt_id": 2104064363,
                "mgmt_if": "",
                "mgmt_mode": 2,
                "mgt_vdom": "",
                "module_sn": null,
                "mr": 6,
                "name": "device_name",
                "node_flags": 0,
                "oid": 156,
                "opts": 0,
                "os_type": 0,
                "os_ver": 5,
                "patch": 6,
                "platform_str": "Fortigate-6000F",
                "prefer_img_ver": null,
                "psk": "",
                "sn": "device_name",
                "source": 2,
                "tab_status": "",
                "tunnel_cookie": "",
                "tunnel_ip": "",
                "vdom": [
                    {
                        "comments": null,
                        "devid": "device_name",
                        "ext_flags": 1,
                        "flags": 0,
                        "name": "root",
                        "node_flags": 0,
                        "oid": 3,
                        "opmode": 1,
                        "rtm_prof_id": 0,
                        "status": null,
                        "tab_status": null,
                        "vpn_id": 0
                    },
                    {
                        "comments": null,
                        "devid": "device_name",
                        "ext_flags": 0,
                        "flags": 0,
                        "name": "mgmt-vdom",
                        "node_flags": 0,
                        "oid": 101,
                        "opmode": 1,
                        "rtm_prof_id": 0,
                        "status": null,
                        "tab_status": null,
                        "vpn_id": 0
                    }
                ],
                "version": 500,
                "vm_cpu": 0,
                "vm_cpu_limit": 0,
                "vm_lic_expire": 0,
                "vm_mem": 0,
                "vm_mem_limit": 0,
                "vm_status": 0
            }
        ]
    }
}

Human Readable Output

ADOM adom/root Devices

Name Ip Hostname Os Type Adm Usr Vdom Ha Mode
device_name 1.2.3.4   0   root, mgmt-vdom 0
Another_device 2.3.4.5 Another_device 4 admin root 0

fortimanager-device-groups-list


List ADOM device groups.

Base Command

fortimanager-device-groups-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the device groups. Leave empty to use the instance ADOM. Optional
group The name of a device group to fetch. If not specified, will get all device groups. Optional
offset From which index to start the list. Default is 0. Optional
limit Until which index to get the list. Default is 50. Optional

Context Output

Path Type Description
FortiManager.DeviceGroup.desc String Description.
FortiManager.DeviceGroup.meta_fields String Device group meta fields.
FortiManager.DeviceGroup.name String Device group name.
FortiManager.DeviceGroup.os_type String Device group operating system type.
FortiManager.DeviceGroup.type String Device group type.

Command Example

!fortimanager-device-groups-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "DeviceGroup": [
            {
                "desc": "",
                "name": "All_FortiAnalyzer",
                "oid": 253,
                "os_type": 4,
                "type": 1
            },
            {
                "desc": "",
                "name": "All_FortiGate",
                "oid": 101,
                "os_type": 0,
                "type": 1
            }
        ]
    }
}

Human Readable Output

ADOM adom/root Device Groups

Name Type Os Type
All_FortiAnalyzer 1 4
All_FortiGate 1 0

fortimanager-address-list


List ADOM firewall IPv4 addresses.

Base Command

fortimanager-address-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the addresses. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
address The name of a specific address to fetch. If not specified, will get all addresses. Optional

Context Output

Path Type Description
FortiManager.Address._image-base64 String Base64 of the address image.
FortiManager.Address.allow-routing String Enable/disable use of this address in the static route configuration.
FortiManager.Address.associated-interface String Network interface associated with address.
FortiManager.Address.cache-ttl Number Defines the minimal TTL of individual IP addresses in FQDN cache measured in seconds.
FortiManager.Address.color Number The color of the icon in the GUI.
FortiManager.Address.comment String The comments attached to the address.
FortiManager.Address.country String The IP addresses associated with a specific country.
FortiManager.Address.dynamic_mapping String The address dynamic mapping information.
FortiManager.Address.end-ip String The final IP address (inclusive) in the range for the address.
FortiManager.Address.epg-name String The endpoint group name.
FortiManager.Address.filter String The match criteria filter.
FortiManager.Address.fqdn String The fully qualified domain name (fqdn) address.
FortiManager.Address.list.ip String The IP list associated with the address.
FortiManager.Address.name String The address name.
FortiManager.Address.obj-id String The object ID for NSX.
FortiManager.Address.organization String The organization domain name (Syntax: organization/domain).
FortiManager.Address.policy-group String The policy group name.
FortiManager.Address.sdn String The software defined networking (SDN).
FortiManager.Address.sdn-tag String The software defined networking (SDN) tag.
FortiManager.Address.start-ip String The first IP address (inclusive) in the range for the address.
FortiManager.Address.subnet String The IP address and subnet mask of address.
FortiManager.Address.subnet-name String The subnet name.
FortiManager.Address.tagging.category String The tag category.
FortiManager.Address.tagging.name String The tagging entry name.
FortiManager.Address.tagging.tags String The tags.
FortiManager.Address.tenant String The tenant.
FortiManager.Address.type String The type of address.
FortiManager.Address.uuid String Universally Unique Identifier (UUID). This is automatically assigned but can be manually reset.
FortiManager.Address.visibility String Enable/disable address visibility in the GUI.
FortiManager.Address.wildcard String The IP address and wildcard netmask.
FortiManager.Address.wildcard-fqdn String The fully qualified domain name (fqdn) with wildcard characters.

Command Example

!fortimanager-address-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "Address": [
            {
                "associated-interface": [
                    "any"
                ],
                "clearpass-spt": 0,
                "color": 0,
                "dynamic_mapping": null,
                "end-ip": "1.2.3.4",
                "end-mac": "00:00:00:00:00:00",
                "list": null,
                "name": "FAC-SAML",
                "sdn-addr-type": 0,
                "start-ip": "2.3.4.5",
                "start-mac": "00:00:00:00:00:00",
                "tagging": null,
                "type": 1,
                "uuid": "Some-ID",
                "visibility": 1
            },
            {
                "allow-routing": 0,
                "associated-interface": [
                    "any"
                ],
                "clearpass-spt": 0,
                "color": 0,
                "dynamic_mapping": null,
                "end-mac": "00:00:00:00:00:00",
                "list": null,
                "name": "FIREWALL_AUTH_PORTAL_ADDRESS",
                "sdn-addr-type": 0,
                "start-mac": "00:00:00:00:00:00",
                "subnet": [
                    "0.0.0.0",
                    "0.0.0.0"
                ],
                "tagging": null,
                "type": 0,
                "uuid": "Some-ID",
                "visibility": 0
            }
        ]
    }
}

Human Readable Output

Firewall IPv4 Addresses

Name Type Subnet Start-ip End-ip
FAC-SAML 1   1.2.3.4 2.3.4.5
FIREWALL_AUTH_PORTAL_ADDRESS 0 0.0.0.0,
0.0.0.0
   

fortimanager-address-create


Add a new IPv4 address.

Base Command

fortimanager-address-create

Input

Argument Name Description Required
adom The ADOM on which to create the address. Leave empty to use the instance ADOM. Optional
name The address name. Required
type The type of address. Possible values are: “ipmask”, “iprange”, “fqdn”, “wildcard”, “geography”, “wildcard-fqdn”, and “dynamic”. Required
policy_group Policy group name. Optional
comment A comment to add to the address. Optional
associated_interface The network interface associated with the address. Optional
fqdn The fully qualified domain name (fqdn) address. Required for fqdn address type. Optional
start_ip First IP address (inclusive) in the range for the address. Required for iprange address type. Optional
end_ip Final IP address (inclusive) in the range for the address. Required for iprange address type. Optional
subnet IP address and subnet mask of address. Required for ipmask address type. Optional
subnet_name The subnet name Optional
sdn The address SDN. Required for dynamic address type. Possible values are: “aci”, “aws”, “nsx”, “nuage”, and “azure”. Optional
wildcard IP address and wildcard netmask. Required for wildcard address type. Optional
wildcard_fqdn The fully qualified domain name (fqdn) with wildcard characters. Required for wildcard-fqdn address type. Optional
country The two letter abbreviation representing a country associated with an IP address (for example: “us”). Required for geography address type. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-create name=new_address type=iprange start_ip=1.2.3.4 end_ip=2.3.4.5

Human Readable Output

Created new Address new_address

fortimanager-address-update


Add a new IPv4 address.

Base Command

fortimanager-address-update

Input

Argument Name Description Required
adom The ADOM on which to update the address. Leave empty to use the instance ADOM. Optional
name The address name. Required
type Type of address. Possible values are: “ipmask”, “iprange”, “fqdn”, “wildcard”, “geography”, “wildcard-fqdn”, and “dynamic”. Optional
policy_group Policy group name. Optional
comment A comment to add to the address. Optional
associated_interface Network interface associated with address. Optional
fqdn The fully qualified domain name (fqdn) address. Required for fqdn address type. Optional
start_ip First IP address (inclusive) in the range for the address. Required for iprange address type. Optional
end_ip Final IP address (inclusive) in the range for the address. Required for iprange address type. Optional
subnet IP address and subnet mask of address. Required for ipmask address type. Optional
subnet_name The subnet name Optional
sdn The address SDN. Required for dynamic address type. Possible values are: “aci”, “aws”, “nsx”, “nuage”, and “azure”. Optional
wildcard IP address and wildcard netmask. Required for wildcard address type. Optional
wildcard_fqdn The fully qualified domain name (fqdn) with wildcard characters. Required for wildcard-fqdn address type. Optional
country The two letter abbreviation representing a country associated with an IP address (for example: “us”). Required for geography address type. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-update name=new_address end_ip=3.3.3.3

Human Readable Output

Updated Address new_address

fortimanager-address-delete


Delete an address.

Base Command

fortimanager-address-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the address. Leave empty to use the default integration ADOM. Optional
address The address to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-delete address=new_address

Human Readable Output

Deleted Address new_address

fortimanager-address-group-list


List ADOM IPv4 address groups.

Base Command

fortimanager-address-group-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the address groups. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
address_group Name for a specific address group to fetch. If not specified, will get all address groups. Optional

Context Output

Path Type Description
FortiManager.AddressGroup._image-base64 String Base64 of the address group image.
FortiManager.AddressGroup.allow-routing String Enable/disable use of this group in the static route configuration.
FortiManager.AddressGroup.color Number The color of the icon in the GUI.
FortiManager.AddressGroup.comment String The comment about the address group.
FortiManager.AddressGroup.dynamic_mapping._image-base64 String The address group dynamic mapping base64 image.
FortiManager.AddressGroup.dynamic_mapping._scope.name String The address group dynamic mapping scope name.
FortiManager.AddressGroup.dynamic_mapping._scope.vdom String The address group dynamic mapping scope VDOM.
FortiManager.AddressGroup.dynamic_mapping.allow-routing String Enable/disable use of this dynamic mapping in the static route configuration.
FortiManager.AddressGroup.dynamic_mapping.color Number The color of the icon in the GUI.
FortiManager.AddressGroup.dynamic_mapping.comment String The comment about the address group dynamic mapping.
FortiManager.AddressGroup.dynamic_mapping.exclude String Whether to enable or disable the exclusion of the dynamic mapping.
FortiManager.AddressGroup.dynamic_mapping.exclude-member String The exclude member.
FortiManager.AddressGroup.dynamic_mapping.global-object Number The global object.
FortiManager.AddressGroup.dynamic_mapping.member String The address group dynamic mapping member.
FortiManager.AddressGroup.dynamic_mapping.tags String The address group dynamic mapping tags.
FortiManager.AddressGroup.dynamic_mapping.type String The address group dynamic mapping type.
FortiManager.AddressGroup.dynamic_mapping.uuid String The address group dynamic mapping UUID.
FortiManager.AddressGroup.dynamic_mapping.visibility String The address group dynamic mapping visibility.
FortiManager.AddressGroup.member String The address objects contained within the group.
FortiManager.AddressGroup.name String The address group name.
FortiManager.AddressGroup.tagging.category String The tag category.
FortiManager.AddressGroup.tagging.name String The tagging entry name.
FortiManager.AddressGroup.tagging.tags String The tags.
FortiManager.AddressGroup.uuid String Universally Unique Identifier (UUID). This is automatically assigned but can be manually reset.
FortiManager.AddressGroup.visibility String Enable/disable address visibility in the GUI.

Command Example

!fortimanager-address-group-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "AddressGroup": [
            {
                "allow-routing": 0,
                "color": 0,
                "dynamic_mapping": null,
                "exclude": 0,
                "exclude-member": [],
                "member": [
                    "address1",
                    "address2",
                ],
                "name": "my_address_group",
                "tagging": null,
                "uuid": "Some-ID",
                "visibility": 1
            },
            {
                "allow-routing": 1,
                "color": 0,
                "comment": "VPN: To-600E (Created by VPN wizard)",
                "dynamic_mapping": null,
                "exclude": 0,
                "exclude-member": [],
                "member": [
                    "some_address"
                ],
                "name": "another_address_group",
                "tagging": null,
                "uuid": "Some-ID",
                "visibility": 1
            }
        ]
    }
}

Human Readable Output

Firewall IPv4 Address Groups

Name Member Allow-routing
my_address_group address1,
address2
0
another_address_group some_address 1

fortimanager-address-group-create


Create a new address group.

Base Command

fortimanager-address-group-create

Input

Argument Name Description Required
adom The ADOM on which to create the address group. Leave empty to use the instance ADOM. Optional
name Address group name. Required
member A comma-separated list of the address or address group objects contained within the group. Required
comment A comment about the address group. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-group-create name=new_address_group member=new_address,my_address2

Human Readable Output

Created new Address Group new_address_group

fortimanager-address-group-update


Create a new address group.

Base Command

fortimanager-address-group-update

Input

Argument Name Description Required
adom The ADOM on which to update the address group. Leave empty to use the instance ADOM. Optional
name Address group name. Required
member A comma-separated list of the address or address group objects contained within the group. Optional
comment A comment about the address group. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-group-update name=new_address_group member=new_address

Human Readable Output

Updated Address Group new_address_group

fortimanager-address-group-delete


Delete an address group.

Base Command

fortimanager-address-group-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the address group. Leave empty to use the default integration ADOM. Optional
address_group The address group to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-address-group-delete address_group=new_address_group

Human Readable Output

Deleted Address Group new_address_group

fortimanager-service-categories-list


List the ADOM service categories.

Base Command

fortimanager-service-categories-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the service categories. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
service_category Name of a specific category to fetch. If not specified, will get all service groups. Optional

Context Output

Path Type Description
FortiManager.ServiceCategory.comment String Comment.
FortiManager.ServiceCategory.name String Service category name.

Command Example

!fortimanager-service-categories-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "ServiceCategory": [
            {
                "comment": "Web access.",
                "name": "Web Access",
                "obj seq": 2
            },
            {
                "comment": "File access.",
                "name": "File Access",
                "obj seq": 3
            }
        ]
    }
}

Human Readable Output

Service Categories

Name Comment
Web Access Web access.
File Access File access.

fortimanager-service-group-list


List ADOM service groups.

Base Command

fortimanager-service-group-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the service groups. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
service_group Name of a specific service group to fetch. If not specified, will get all service groups. Optional

Context Output

Path Type Description
FortiManager.ServiceGroup.color Number The color of the icon in the GUI.
FortiManager.ServiceGroup.comment String Comment.
FortiManager.ServiceGroup.member String The service objects contained within the group.
FortiManager.ServiceGroup.name String The address group name.
FortiManager.ServiceGroup.proxy String Enable/disable web proxy service group.

Command Example

!fortimanager-service-group-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "ServiceGroup": [
            {
                "color": 0,
                "member": [
                    "DNS",
                    "HTTP",
                    "HTTPS"
                ],
                "name": "Web Access",
                "proxy": 0
            },
            {
                "color": 0,
                "member": [
                    "DCE-RPC",
                    "DNS",
                    "KERBEROS",
                    "LDAP",
                    "LDAP_UDP",
                    "SAMBA",
                    "SMB"
                ],
                "name": "Windows AD",
                "proxy": 0
            }
        ]
    }
}

Human Readable Output

Service Groups

Name Member Proxy
Web Access DNS,
HTTP,
HTTPS
0
Windows AD DCE-RPC,
DNS,
KERBEROS,
LDAP,
LDAP_UDP,
SAMBA,
SMB
0

fortimanager-service-group-create


Creates a new service group.

Base Command

fortimanager-service-group-create

Input

Argument Name Description Required
adom The ADOM on which to create the service group. Leave empty to use the instance ADOM. Optional
comment A comment. Optional
name The created service group name. Required
proxy Enable/disable a web proxy service group. Optional
member A comma-separated list of service objects to be contained within the group. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-service-group-create member=new_service name=new_service_group

Human Readable Output

Created new Service Group new_service_group

fortimanager-service-group-update


Create a new service group.

Base Command

fortimanager-service-group-update

Input

Argument Name Description Required
adom The ADOM on which to update the service group. Leave empty to use the instance ADOM. Optional
comment A comment. Optional
name The created service group name. Required
proxy Enable/disable a web proxy service group. Optional
member A comma-sperated list of service objects to be contained within the group. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-service-group-update name=new_service_group proxy=disable

Human Readable Output

Updated Service Group new_service_group

fortimanager-service-group-delete


Delete a service group

Base Command

fortimanager-service-group-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the service group. Leave empty to use the default integration ADOM. Optional
service_group The service group to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-service-group-delete service_group=new_service_group

Human Readable Output

Deleted Service Group new_service_group

fortimanager-custom-service-list


List the custom services.

Base Command

fortimanager-custom-service-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the custom service. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
custom_service Name of a specific custom service to fetch. If not specified, will get all custom services. Optional

Context Output

Path Type Description
FortiManager.CustomService.app-category Number Application category ID.
FortiManager.CustomService.app-service-type String Application service type.
FortiManager.CustomService.application Number Application ID.
FortiManager.CustomService.category String Service category.
FortiManager.CustomService.check-reset-range String Configure the type of ICMP error message verification.
FortiManager.CustomService.color Number Color of icon in the GUI.
FortiManager.CustomService.comment String Comment.
FortiManager.CustomService.fqdn String Fully qualified domain (fqdn) name.
FortiManager.CustomService.helper String Helper name.
FortiManager.CustomService.icmpcode Number ICMP code.
FortiManager.CustomService.icmptype Number ICMP type.
FortiManager.CustomService.iprange String Start and end of the IP range associated with service.
FortiManager.CustomService.name String Custom service name.
FortiManager.CustomService.protocol String Protocol type based on IANA numbers.
FortiManager.CustomService.protocol-number Number IP protocol number.
FortiManager.CustomService.proxy String Enable/disable a web proxy service.
FortiManager.CustomService.sctp-portrange String Multiple SCTP port ranges.
FortiManager.CustomService.session-ttl Number Session TTL (300 - 604800. Default is 0.).
FortiManager.CustomService.tcp-halfclose-timer Number Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec. Default is 0.).
FortiManager.CustomService.tcp-halfopen-timer Number Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec. Default is 0.).
FortiManager.CustomService.tcp-portrange String Multiple TCP port ranges.
FortiManager.CustomService.tcp-timewait-timer Number Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec. Default is 0.).
FortiManager.CustomService.udp-idle-timer Number UDP half close timeout (0 - 86400 sec. Default is 0.).
FortiManager.CustomService.udp-portrange String Multiple UDP port ranges.
FortiManager.CustomService.visibility String Enable/disable the visibility of the service in the GUI.

Command Example

!fortimanager-custom-service-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "CustomService": [
            {
                "app-category": [],
                "app-service-type": 0,
                "application": [],
                "category": [
                    "General"
                ],
                "check-reset-range": 3,
                "color": 0,
                "helper": 1,
                "iprange": "0.0.0.0",
                "name": "ALL_TCP",
                "obj seq": 2,
                "protocol": 5,
                "proxy": 0,
                "sctp-portrange": [],
                "session-ttl": 0,
                "tcp-halfclose-timer": 0,
                "tcp-halfopen-timer": 0,
                "tcp-portrange": [
                    "1-65535"
                ],
                "tcp-timewait-timer": 0,
                "udp-idle-timer": 0,
                "udp-portrange": [],
                "visibility": 1
            },
            {
                "app-category": [],
                "app-service-type": 0,
                "application": [],
                "category": [
                    "General"
                ],
                "check-reset-range": 3,
                "color": 0,
                "helper": 1,
                "iprange": "0.0.0.0",
                "name": "ALL_UDP",
                "obj seq": 3,
                "protocol": 5,
                "proxy": 0,
                "sctp-portrange": [],
                "session-ttl": 0,
                "tcp-halfclose-timer": 0,
                "tcp-halfopen-timer": 0,
                "tcp-portrange": [],
                "tcp-timewait-timer": 0,
                "udp-idle-timer": 0,
                "udp-portrange": [
                    "1-65535"
                ],
                "visibility": 1
            }
        ]
    }
}

Human Readable Output

Custom Services

Name Category Protocol Iprange
ALL_TCP General 5 0.0.0.0
ALL_UDP General 5 0.0.0.0

fortimanager-custom-service-create


Create a new custom service.

Base Command

fortimanager-custom-service-create

Input

Argument Name Description Required
adom The ADOM from which to fetch the custom service. Leave empty to use the instance ADOM. Optional
name The name of the new custom service. Required
app_category Application category ID. Optional
app_service_type Application service type. Possible values are: “app-id”, “disable”, and “app-category”. Default is “disable”. Optional
application The application ID. Optional
category The service category. Optional
check_reset_range Configure the type of ICMP error message verification. Possible values are: “disable”, “default”, and “strict”. Optional
comment A comment. Optional
fqdn Fully qualified domain name (fqdn). Optional
helper Helper name. Optional
icmpcode ICMP code. Optional
icmptype ICMP type. Optional
iprange Start and end of the IP range associated with the service. Optional
protocol Protocol type based on IANA numbers. Possible values are: “ICMP”, “IP”, “TCP/UDP/SCTP”, “ICMP6”, “HTTP”, “FTP”, “CONNECT”, “SOCKS”, “ALL”, “SOCKS-TCP”, and “SOCKS-UDP”. Optional
proxy Enable/disable a web proxy service. Optional
sctp_portrange Multiple SCTP port ranges. Optional
session_ttl Session TTL in the range of 300 - 604800. Default is 0. Optional
tcp_halfclose_timer Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec). Default is 0. Optional
tcp_halfopen_timer Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec). Default is 0. Optional
tcp_portrange Multiple TCP port ranges. Optional
tcp_timewait_timer Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec). Default is 0. Optional
udp_idle_timer UDP half close timeout (0 - 86400 sec). Default is 0. Optional
udp_portrange Multiple UDP port ranges. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-custom-service-create name=new_service fqdn=demisto.com

Human Readable Output

Created new Custom Service new_service

fortimanager-custom-service-update


Update a custom service.

Base Command

fortimanager-custom-service-update

Input

Argument Name Description Required
adom The ADOM in which to update the custom service. Leave empty to use the instance ADOM. Optional
name The name of the new custom service. Required
app_category Application category ID. Optional
app_service_type Application service type. Possible values are: “app-id”, “disable”, and “app-category”. Default is “disable”. Optional
application The application ID. Optional
category The service category. Optional
check_reset_range Configure the type of ICMP error message verification. Possible values are: “disable”, “default”, and “strict”. Optional
comment A comment. Optional
fqdn Fully qualified domain name (fqdn). Optional
helper Helper name. Optional
icmpcode ICMP code. Optional
icmptype ICMP type. Optional
iprange Start and end of the IP range associated with service. Optional
protocol Protocol type based on IANA numbers. Possible values are: “ICMP”, “IP”, “TCP/UDP/SCTP”, “ICMP6”, “HTTP”, “FTP”, “CONNECT”, “SOCKS”, “ALL”, “SOCKS-TCP”, and “SOCKS-UDP”. Optional
proxy Enable/disable a web proxy service. Optional
sctp_portrange Multiple SCTP port ranges. Optional
session_ttl Session TTL in the range of 300 - 604800. Default is 0. Optional
tcp_halfclose_timer Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec). Default is 0. Optional
tcp_halfopen_timer Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec). Default is 0. Optional
tcp_portrange Multiple TCP port ranges. Optional
tcp_timewait_timer Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec). Default is 0. Optional
udp_idle_timer UDP half close timeout (0 - 86400 sec). Default is 0. Optional
udp_portrange Multiple UDP port ranges. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-custom-service-update name=new_service proxy=enable

Human Readable Output

Updated Custom Service new_service

fortimanager-custom-service-delete


Delete a custom service.

Base Command

fortimanager-custom-service-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the custom service. Leave empty to use the default integration ADOM. Optional
custom The custome service to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-custom-service-delete custom=new_service

Human Readable Output

Deleted Custom Service new_service

fortimanager-firewall-policy-package-list


List ADOM policy packages.

Base Command

fortimanager-firewall-policy-package-list

Input

Argument Name Description Required
adom The ADOM from which to fetch the firewall policy packages. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional
policy_package Name of a specific policy package to fetch. If not specified, will get all policy packages. Optional

Context Output

Path Type Description
FortiManager.PolicyPackage.name String Policy package name.
FortiManager.PolicyPackage.obj_ver Number Policy package object version.
FortiManager.PolicyPackage.oid Number Policy package OID.
FortiManager.PolicyPackage.package setting.central-nat String Whether to use the central NAT.
FortiManager.PolicyPackage.package setting.consolidated-firewall-mode String Whether to enable consolidate firewall mode.
FortiManager.PolicyPackage.package setting.fwpolicy-implicit-log String Whether to enable firewall policy implicit log.
FortiManager.PolicyPackage.package setting.fwpolicy6-implicit-log String Whether to enable firewall policy 6 implicit log.
FortiManager.PolicyPackage.package setting.inspection-mode String Package inspection mode.
FortiManager.PolicyPackage.package setting.ngfw-mode String Package NGFW mode.
FortiManager.PolicyPackage.package setting.ssl-ssh-profile String Package SSL SSH profile.
FortiManager.PolicyPackage.scope_member.name String Policy package scope member name.
FortiManager.PolicyPackage.scope_member.vdom String Policy package scope member VDOM.
FortiManager.PolicyPackage.subobj Unknown Policy package sub-objects.
FortiManager.PolicyPackage.type String Policy package type.

Command Example

!fortimanager-firewall-policy-package-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "PolicyPackage": [
            {
                "name": "default",
                "obj ver": 1,
                "oid": 1303,
                "package settings": {
                    "central-nat": 0,
                    "consolidated-firewall-mode": 0,
                    "fwpolicy-implicit-log": 0,
                    "fwpolicy6-implicit-log": 0,
                    "ngfw-mode": 0
                },
                "type": "pkg"
            },
            {
                "name": "my_package",
                "obj ver": 8,
                "oid": 1356,
                "package settings": {
                    "fwpolicy-implicit-log": 0,
                    "fwpolicy6-implicit-log": 0,
                    "ngfw-mode": 1,
                    "ssl-ssh-profile": [
                        "NGFW-SSL-Inspection"
                    ]
                },
                "type": "pkg"
            }
        ]
    }
}

Human Readable Output

Policy Packages

Name Type
FG5H0E3917901297_root pkg
Corp_Shared pkg

fortimanager-firewall-policy-package-create


Create a new firewall policy package.

Base Command

fortimanager-firewall-policy-package-create

Input

Argument Name Description Required
adom The ADOM on which to create the service group. Leave empty to use the instance ADOM. Optional
name The name of the new policy package. Required
type The type of package. Possible values are: “pkg” and “folder”. Required
central_nat Whether to use central NAT. Default is “disable”. Optional
consolidated_firewall_mode Whether to enable consolidate firewall mode. Default is “disable”. Optional
fwpolicy_implicit_log Whether to enable firewall policy implicit log. Default is “disable”. Optional
fwpolicy6_implicit_log Whether to enable firewall policy 6 implicit log. Default is “disable”. Optional
inspection_mode Package inspection mode. Possible values are: “proxy” and “flow”. Default is “proxy”. Optional
ngfw_mode Package NGFW mode. Possible values are: “profile-based” and “policy-based”. Default is “profile-based”. Optional
ssl_ssh_profile Package SSL SSH profile. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-package-create name=new_package type=pkg

Human Readable Output

Created new Policy Package new_package

fortimanager-firewall-policy-package-update


Create a new firewall policy package.

Base Command

fortimanager-firewall-policy-package-update

Input

Argument Name Description Required
adom The ADOM on which to update the service group. Leave empty to use the instance ADOM. Optional
name The name of the Policy Package to update. Required
type The type og package. Possible values are: “pkg” and “folder”. Optional
central_nat Whether to use central NAT. Optional
consolidated_firewall_mode Whether to enable consolidate firewall mode. Optional
fwpolicy_implicit_log Whether to enable firewall policy implicit log. Optional
fwpolicy6_implicit_log Whether to enable firewall policy 6 implicit log. Optional
inspection_mode Package inspection mode. Possible values are: “proxy” and “flow”. Optional
ngfw_mode Package NGFW mode. Possible values are: “profile-based” and “policy-based”. Optional
ssl_ssh_profile Package SSL SSH profile. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-package-update name=new_package central_nat=enable

Human Readable Output

Update Policy Package new_package

fortimanager-firewall-policy-package-delete


Delete a firewall policy package.

Base Command

fortimanager-firewall-policy-package-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the policy package. Leave empty to use the default integration ADOM. Optional
pkg_path The policy package path to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-package-delete pkg_path=new_package

Human Readable Output

Deleted Policy Package new_package

fortimanager-firewall-policy-list


List specific firewall policies from a policy package.

Base Command

fortimanager-firewall-policy-list

Input

Argument Name Description Required
package The package from which to fetch the policies. Required
adom The ADOM from which to fetch the policies. Leave empty to use the instance ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Optional
policy_id An ID for the specific policy to fetch. If not specified, will get all policies. Optional

Context Output

Path Type Description
FortiManager.PolicyPackage.Policy.action String Policy action (allow/deny/ipsec).
FortiManager.PolicyPackage.Policy.app-category String Application category ID list.
FortiManager.PolicyPackage.Policy.app-group String Application group names.
FortiManager.PolicyPackage.Policy.application Number Application ID list.
FortiManager.PolicyPackage.Policy.application-list String Name of an existing application list.
FortiManager.PolicyPackage.Policy.auth-cert String HTTPS server certificate for policy authentication.
FortiManager.PolicyPackage.Policy.auth-path String Enable/disable authentication-based routing.
FortiManager.PolicyPackage.Policy.auth-redirect-addr String HTTP-to-HTTPS redirect address for firewall authentication.
FortiManager.PolicyPackage.Policy.auto-asic-offload String Enable/disable offloading security profile processing to CP processors.
FortiManager.PolicyPackage.Policy.av-profile String Name of an existing antivirus profile.
FortiManager.PolicyPackage.Policy.block-notification String Enable/disable block notification.
FortiManager.PolicyPackage.Policy.captive-portal-exempt String Enable to exempt some users from the captive portal.
FortiManager.PolicyPackage.Policy.capture-packet String Enable/disable capture packets.
FortiManager.PolicyPackage.Policy.comments String Comments.
FortiManager.PolicyPackage.Policy.custom-log-fields String Custom fields to append to log messages for this policy.
FortiManager.PolicyPackage.Policy.delay-tcp-npu-session String Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
FortiManager.PolicyPackage.Policy.devices String Names of devices or device groups that can be matched by the policy.
FortiManager.PolicyPackage.Policy.diffserv-forward String Enable to change packet DiffServ values to the specified diffservcode-forward value.
FortiManager.PolicyPackage.Policy.diffserv-reverse String Enable to change packet reverse (reply) DiffServ values to the specified diffservcode-rev value.
FortiManager.PolicyPackage.Policy.diffservcode-forward String Change packet DiffServ to this value.
FortiManager.PolicyPackage.Policy.diffservcode-rev String Change packet reverse (reply) DiffServ to this value.
FortiManager.PolicyPackage.Policy.disclaimer String Enable/disable user authentication disclaimer.
FortiManager.PolicyPackage.Policy.dlp-sensor String Name of an existing DLP sensor.
FortiManager.PolicyPackage.Policy.dnsfilter-profile String Name of an existing DNS filter profile.
FortiManager.PolicyPackage.Policy.dscp-match String Enable DSCP check.
FortiManager.PolicyPackage.Policy.dscp-negate String Enable negated DSCP match.
FortiManager.PolicyPackage.Policy.dscp-value String DSCP value.
FortiManager.PolicyPackage.Policy.dsri String Enable DSRI to ignore HTTP server responses.
FortiManager.PolicyPackage.Policy.dstaddr String Destination address and address group names.
FortiManager.PolicyPackage.Policy.dstaddr-negate String When enabled, dstaddr specifies what the destination address must NOT be.
FortiManager.PolicyPackage.Policy.dstintf String Outgoing (egress) interface.
FortiManager.PolicyPackage.Policy.firewall-session-dirty String How to handle sessions if the configuration of this firewall policy changes.
FortiManager.PolicyPackage.Policy.fixedport String Enable to prevent source NAT from changing a session source port.
FortiManager.PolicyPackage.Policy.fsso String Enable/disable Fortinet single sign-on.
FortiManager.PolicyPackage.Policy.fsso-agent-for-ntlm String FSSO agent to use for NTLM authentication.
FortiManager.PolicyPackage.Policy.global-label String Label for the policy that appears when the GUI is in Global View mode.
FortiManager.PolicyPackage.Policy.groups String Names of user groups that can authenticate with this policy.
FortiManager.PolicyPackage.Policy.gtp-profile String GTP profile.
FortiManager.PolicyPackage.Policy.icap-profile String Name of an existing ICAP profile.
FortiManager.PolicyPackage.Policy.identity-based-route String Name of identity-based routing rule.
FortiManager.PolicyPackage.Policy.inbound String Policy-based IPsec VPN. Only traffic from the remote network can initiate a VPN.
FortiManager.PolicyPackage.Policy.internet-service String Enable/disable use of internet services for this policy. If enabled, destination address and service are not used.
FortiManager.PolicyPackage.Policy.internet-service-custom String Custom internet service name.
FortiManager.PolicyPackage.Policy.internet-service-id String Internet service ID.
FortiManager.PolicyPackage.Policy.internet-service-negate String When enabled, internet service specifies what the service must NOT be.
FortiManager.PolicyPackage.Policy.internet-service-src String Enable/disable use of internet services in source for this policy. If enabled, source address is not used.
FortiManager.PolicyPackage.Policy.internet-service-src-custom String Custom internet service source name.
FortiManager.PolicyPackage.Policy.internet-service-src-id String Internet service source ID.
FortiManager.PolicyPackage.Policy.internet-service-src-negate String When enabled, internet-service-src specifies what the service must NOT be.
FortiManager.PolicyPackage.Policy.ippool String Enable to use IP pools for source NAT.
FortiManager.PolicyPackage.Policy.ips-sensor String Name of an existing IPS sensor.
FortiManager.PolicyPackage.Policy.label String Label for the policy that appears when the GUI is in Section View mode.
FortiManager.PolicyPackage.Policy.learning-mode String Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
FortiManager.PolicyPackage.Policy.logtraffic String Enable or disable logging. Log all sessions or security profile sessions.
FortiManager.PolicyPackage.Policy.logtraffic-start String Record logs when a session starts and ends.
FortiManager.PolicyPackage.Policy.match-vip String Enable to match packets that have had their destination addresses changed by a VIP.
FortiManager.PolicyPackage.Policy.mms-profile String Name of an existing MMS profile.
FortiManager.PolicyPackage.Policy.name String Policy name.
FortiManager.PolicyPackage.Policy.nat String Enable/disable a source NAT.
FortiManager.PolicyPackage.Policy.natinbound String Policy-based IPsec VPN: apply destination NAT to inbound traffic.
FortiManager.PolicyPackage.Policy.natip String Policy-based IPsec VPN: source NAT IP address for outgoing traffic.
FortiManager.PolicyPackage.Policy.natoutbound String Policy-based IPsec VPN: apply source NAT to outbound traffic.
FortiManager.PolicyPackage.Policy.np-acceleration String Enable/disable UTM Network Processor acceleration.
FortiManager.PolicyPackage.Policy.ntlm String Enable/disable NTLM authentication.
FortiManager.PolicyPackage.Policy.ntlm-enabled-browsers String HTTP-User-Agent value of supported browsers.
FortiManager.PolicyPackage.Policy.ntlm-guest String Enable/disable NTLM guest user access.
FortiManager.PolicyPackage.Policy.outbound String Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.
FortiManager.PolicyPackage.Policy.per-ip-shaper String Per-IP traffic shaper.
FortiManager.PolicyPackage.Policy.permit-any-host String Accept UDP packets from any host.
FortiManager.PolicyPackage.Policy.permit-stun-host String Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
FortiManager.PolicyPackage.Policy.policyid Number Policy ID.
FortiManager.PolicyPackage.Policy.poolname String IP pool names.
FortiManager.PolicyPackage.Policy.profile-group String Name of profile group.
FortiManager.PolicyPackage.Policy.profile-protocol-options String Name of an existing protocol options profile.
FortiManager.PolicyPackage.Policy.profile-type String Determine whether the firewall policy allows security profile groups or single profiles only.
FortiManager.PolicyPackage.Policy.radius-mac-auth-bypass String Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
FortiManager.PolicyPackage.Policy.redirect-url String The URL users are directed to after seeing and accepting the disclaimer or authenticating.
FortiManager.PolicyPackage.Policy.replacemsg-override-group String Override the default replacement message group for this policy.
FortiManager.PolicyPackage.Policy.rsso String Enable/disable RADIUS single sign-on (RSSO).
FortiManager.PolicyPackage.Policy.rtp-addr String Address names if this is an RTP NAT policy.
FortiManager.PolicyPackage.Policy.rtp-nat String Enable Real Time Protocol (RTP) NAT.
FortiManager.PolicyPackage.Policy.scan-botnet-connections String Block or monitor connections to Botnet servers or disable Botnet scanning.
FortiManager.PolicyPackage.Policy.schedule String Schedule name.
FortiManager.PolicyPackage.Policy.schedule-timeout String Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
FortiManager.PolicyPackage.Policy.send-deny-packet String Enable to send a reply when a session is denied or blocked by a firewall policy.
FortiManager.PolicyPackage.Policy.service String Service and service group names.
FortiManager.PolicyPackage.Policy.service-negate String When enabled, service specifies what the service must NOT be.
FortiManager.PolicyPackage.Policy.session-ttl Number TTL in seconds for sessions accepted by this policy. (0 means use the system default session TTL.)
FortiManager.PolicyPackage.Policy.spamfilter-profile String Name of an existing spam filter profile.
FortiManager.PolicyPackage.Policy.srcaddr String Source address and address group names.
FortiManager.PolicyPackage.Policy.srcaddr-negate String When enabled, srcaddr specifies what the source address must NOT be.
FortiManager.PolicyPackage.Policy.srcintf String Incoming (ingress) interface.
FortiManager.PolicyPackage.Policy.ssh-filter-profile String Name of an existing SSH filter profile.
FortiManager.PolicyPackage.Policy.ssl-mirror String Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
FortiManager.PolicyPackage.Policy.ssl-mirror-intf String SSL mirror interface name.
FortiManager.PolicyPackage.Policy.ssl-ssh-profile String Name of an existing SSL SSH profile.
FortiManager.PolicyPackage.Policy.status String Enable or disable this policy.
FortiManager.PolicyPackage.Policy.tcp-mss-receiver Number Receiver TCP maximum segment size (MSS).
FortiManager.PolicyPackage.Policy.tcp-mss-sender Number Sender TCP maximum segment size (MSS).
FortiManager.PolicyPackage.Policy.tcp-session-without-syn String Enable/disable creation of TCP session without SYN flag.
FortiManager.PolicyPackage.Policy.timeout-send-rst String Enable/disable sending RST packets when TCP sessions expire.
FortiManager.PolicyPackage.Policy.traffic-shaper String Traffic shaper.
FortiManager.PolicyPackage.Policy.traffic-shaper-reverse String Reverse traffic shaper.
FortiManager.PolicyPackage.Policy.url-category String URL category ID list.
FortiManager.PolicyPackage.Policy.users String Names of individual users that can authenticate with this policy.
FortiManager.PolicyPackage.Policy.utm-status String Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
FortiManager.PolicyPackage.Policy.uuid String Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
FortiManager.PolicyPackage.Policy.vlan-cos-fwd Number VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.
FortiManager.PolicyPackage.Policy.vlan-cos-rev Number VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.
FortiManager.PolicyPackage.Policy.vlan-filter String Set VLAN filters.
FortiManager.PolicyPackage.Policy.voip-profile String Name of an existing VoIP profile.
FortiManager.PolicyPackage.Policy.vpn_dst_node.host String VPN destination node host.
FortiManager.PolicyPackage.Policy.vpn_dst_node.seq Number VPN destination node sequence.
FortiManager.PolicyPackage.Policy.vpn_dst_node.subnet String VPN destination node subnet.
FortiManager.PolicyPackage.Policy.vpn_src_node.host String VPN source node host.
FortiManager.PolicyPackage.Policy.vpn_src_node.seq Number VPN source node sequence.
FortiManager.PolicyPackage.Policy.vpn_src_node.subnet String VPN source node subnet.
FortiManager.PolicyPackage.Policy.vpntunnel String Policy-based IPsec VPN: name of the IPsec VPN Phase 1.
FortiManager.PolicyPackage.Policy.waf-profile String Name of an existing Web application firewall profile.
FortiManager.PolicyPackage.Policy.wanopt String Enable/disable WAN optimization.
FortiManager.PolicyPackage.Policy.wanopt-detection String WAN optimization auto-detection mode.
FortiManager.PolicyPackage.Policy.wanopt-passive-opt String WAN optimization passive mode options. This option decides what IP address will be used to connect server.
FortiManager.PolicyPackage.Policy.wanopt-peer String WAN optimization peer.
FortiManager.PolicyPackage.Policy.wanopt-profile String WAN optimization profile.
FortiManager.PolicyPackage.Policy.wccp String Enable/disable forwarding traffic matching this policy to a configured WCCP server.
FortiManager.PolicyPackage.Policy.webcache String Enable/disable a web cache.
FortiManager.PolicyPackage.Policy.webcache-https String Enable/disable a web cache for HTTPS.
FortiManager.PolicyPackage.Policy.webfilter-profile String Name of an existing Web filter profile.
FortiManager.PolicyPackage.Policy.wsso String Enable/disable WiFi single sign-on (WSSO).

Command Example

!fortimanager-firewall-policy-list package=new_package

Context Example

{
    "FortiManager": {
        "PolicyPackage": {
            "Policy": {
                "_byte": 0,
                "_first_hit": 0,
                "_first_session": 0,
                "_global-vpn": [],
                "_global-vpn-tgt": 0,
                "_hitcount": 0,
                "_last_hit": 0,
                "_last_session": 0,
                "_pkts": 0,
                "_policy_block": 0,
                "_sesscount": 0,
                "action": 1,
                "anti-replay": 1,
                "app-group": [],
                "auto-asic-offload": 1,
                "block-notification": 0,
                "captive-portal-exempt": 0,
                "capture-packet": 0,
                "custom-log-fields": [],
                "delay-tcp-npu-session": 0,
                "diffserv-forward": 0,
                "diffserv-reverse": 0,
                "disclaimer": 0,
                "dsri": 0,
                "dstaddr": [
                    "all"
                ],
                "dstaddr-negate": 0,
                "dstintf": [
                    "any"
                ],
                "email-collect": 0,
                "fsso": 1,
                "fsso-agent-for-ntlm": [],
                "fsso-groups": [],
                "geoip-anycast": 0,
                "groups": [],
                "inspection-mode": 1,
                "internet-service": 0,
                "internet-service-src": 0,
                "logtraffic": 3,
                "logtraffic-start": 0,
                "match-vip": 0,
                "match-vip-only": 0,
                "name": "new_policy",
                "nat": 0,
                "natip": [
                    "0.0.0.0",
                    "0.0.0.0"
                ],
                "np-acceleration": 1,
                "obj seq": 1,
                "per-ip-shaper": [],
                "permit-any-host": 0,
                "policyid": 9,
                "profile-protocol-options": [
                    "default"
                ],
                "profile-type": 0,
                "radius-mac-auth-bypass": 0,
                "replacemsg-override-group": [],
                "reputation-direction": 2,
                "reputation-minimum": 0,
                "rtp-nat": 0,
                "schedule": [
                    "always"
                ],
                "schedule-timeout": 0,
                "service": [
                    "ALL"
                ],
                "service-negate": 0,
                "session-ttl": 0,
                "srcaddr": [
                    "all"
                ],
                "srcaddr-negate": 0,
                "srcintf": [
                    "any"
                ],
                "ssl-mirror": 0,
                "ssl-mirror-intf": [],
                "ssl-ssh-profile": [
                    "no-inspection"
                ],
                "status": 1,
                "tcp-mss-receiver": 0,
                "tcp-mss-sender": 0,
                "tcp-session-without-syn": 2,
                "timeout-send-rst": 0,
                "tos": "0x00",
                "tos-mask": "0x00",
                "tos-negate": 0,
                "traffic-shaper": [],
                "traffic-shaper-reverse": [],
                "users": [],
                "utm-status": 0,
                "uuid": "some-id",
                "vlan-cos-fwd": 255,
                "vlan-cos-rev": 255,
                "vpn_dst_node": null,
                "vpn_src_node": null,
                "wccp": 0,
                "webcache-https": 0,
                "webproxy-forward-server": [],
                "webproxy-profile": []
            }
        }
    }
}

Human Readable Output

ADOM root Policy Package new_package Policies

Policyid Name Srcintf Dstintf Srcaddr Dstaddr Schedule Service Action
9 new_policy any any all all always ALL 1

fortimanager-firewall-policy-create


Create a firewall policy.

Base Command

fortimanager-firewall-policy-create

Input

Argument Name Description Required
adom The ADOM on which to create the service group. Leave empty to use the instance ADOM. Optional
package The package from which to create the policy. Required
action The policy action. Possible values are: “deny”, “accept”, “ipsec”, and “ssl-vpn”. Required
comments A comment. Optional
dstaddr Destination address name. Note: dstaddr6 or dstaddr must be set. Optional
dstaddr6 IPv6 destination address (web proxy only). Note: dstaddr6 or dstaddr must be set. Optional
dstaddr_negate Enable/disable a negated destination address match. Optional
dstintf Destination interface name. Optional
srcaddr Source address name. Note: srcaddr or srcaddr6 must be set. Optional
srcaddr6 IPv6 source address (web proxy only). Note: srcaddr or srcaddr6 must be set. Optional
srcaddr_negate Enable/disable a negated source address match. Optional
srcintf Source interface name. Optional
additional_params A comma-separated list of additional params and their values. For example: Field1=Value1,Field2=Value2. Optional
name The name of the policy to create. Required
logtraffic Enable or disable logging. Log all sessions or security profile sessions. Possible values are: “enable”, “disable”, “all”, and “utm”. Required
schedule Schedule name. Default is “always”. Required
service Service and service group names. Default is “ALL”. Required
status Enable or disable this policy. Required
policyid The ID of the policy to create. Leave empty to use system default. Optional

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-create action=accept logtraffic=utm name=new_policy package=new_package dstaddr=all srcaddr=all policyid=9

Human Readable Output

Created policy with ID 9

fortimanager-firewall-policy-update


Update a firewall policy.

Base Command

fortimanager-firewall-policy-update

Input

Argument Name Description Required
adom The ADOM on which to update the service group. Leave empty to use the instance ADOM. Optional
package The package from which to update the policy. Required
action The policy action. Possible values are: “deny”, “accept”, “ipsec”, and “ssl-vpn”. Optional
comments A comment. Optional
dstaddr Destination address name. Note: dstaddr6 or dstaddr must be set. Optional
dstaddr6 IPv6 destination address (web proxy only). Note: dstaddr6 or dstaddr must be set. Optional
dstaddr_negate Enable/disable a negated destination address match. Optional
dstintf Destination interface name. Optional
srcaddr Source address name. Note: srcaddr or srcaddr6 must be set. Optional
srcaddr6 IPv6 source address (web proxy only). Note: srcaddr or srcaddr6 must be set. Optional
srcaddr_negate Enable/disable a negated source address match. Optional
srcintf Source interface name. Optional
additional_params A comma-separated list of additional params and their values. exmaple: Field1=Value1,Field2=Value2. Optional
name The name of the policy to update. Optional
logtraffic Enable or disable logging. Log all sessions or security profile sessions. Possible values are: “enable”, “disable”, “all”, and “utm”. Optional
schedule Schedule name. Optional
service Service and service group names. Optional
status Enable or disable this policy. Optional
policyid The ID of the policy to update. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-update package=new_package policyid=9 status=disable

Human Readable Output

Updated policy with ID 9

fortimanager-firewall-policy-delete


Delete a firewall policy.

Base Command

fortimanager-firewall-policy-delete

Input

Argument Name Description Required
adom The ADOM from which to delete the policy. Leave empty to use the default integration ADOM. Optional
package The policy package from which we want to delete the policy. Required
policy The policy we want to delete. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-delete package=new_package policy=9

Human Readable Output

Deleted Policy 9

fortimanager-firewall-policy-move


Move a policy in the package.

Base Command

fortimanager-firewall-policy-move

Input

Argument Name Description Required
adom The ADOM from which to move the policy. Leave empty to use the default integration ADOM. Optional
package The policy package from which we want to move the policy. Required
policy The ID of the policy we want to move. Required
target The ID of the target policy by which we want to move the policy. Required
option Whether to move the policy before or after the target policy. Possible values are: “before” and “after”. Default is “before”. Required

Context Output

There is no context output for this command.

Command Example

!fortimanager-firewall-policy-move option=after package=some_package policy=1 target=2

Human Readable Output

Moved policy with ID 1 after 2 in Policy Package: some_package

fortimanager-dynamic-interface-list


List dynamic interfaces

Base Command

fortimanager-dynamic-interface-list

Input

Argument Name Description Required
adom The ADOM from which to list dynamic interfaces. Leave empty to use the default integration ADOM. Optional
offset From which index to start the list. Default is 0. Optional
limit To which index to get the list. Default is 50. Optional

Context Output

Path Type Description
FortiManager.DynamicInterface.color Number Color of the icon in the GUI.
FortiManager.DynamicInterface.default-mapping String Default mapping of the Interface.
FortiManager.DynamicInterface.defmap-intf String Default mapping interface.
FortiManager.DynamicInterface.defmap-intrazone-deny String Default mapping intrazone deny.
FortiManager.DynamicInterface.defmap-zonemember String Default mapping zone members
FortiManager.DynamicInterface.description String Dynamic interface description.
FortiManager.DynamicInterface.dynamic_mapping._scope.name String Dynamic mapping scope name.
FortiManager.DynamicInterface.dynamic_mapping._scope.vdom String Dynamic mapping scope VDOM.
FortiManager.DynamicInterface.dynamic_mapping.egress-shaping-profile String Dynamic mapping egress shaping profile.
FortiManager.DynamicInterface.dynamic_mapping.intrazone-deny String Dynamic mapping intrazone deny.
FortiManager.DynamicInterface.dynamic_mapping.local-intf String Dynamic mapping local interface.
FortiManager.DynamicInterface.egress-shaping-profile String Egress shaping profile.
FortiManager.DynamicInterface.name String Dynamic interface name.
FortiManager.DynamicInterface.platform_mapping.egress-shaping-profile String Platform mapping egress shaping profile.
FortiManager.DynamicInterface.platform_mapping.intf-zone String Platform mapping interface zone.
FortiManager.DynamicInterface.platform_mapping.intrazone-deny String Platform mapping intrazone deny.
FortiManager.DynamicInterface.platform_mapping.name String Platform mapping name.
FortiManager.DynamicInterface.single-intf String Dynamic interface single interface.

Command Example

!fortimanager-dynamic-interface-list offset=1 limit=2

Context Example

{
    "FortiManager": {
        "DynamicInterface": [
            {
                "color": 0,
                "default-mapping": 0,
                "defmap-intrazone-deny": 0,
                "defmap-zonemember": [],
                "dynamic_mapping": [
                    {
                        "_scope": [
                            {
                                "name": "device_name",
                                "vdom": "root"
                            }
                        ],
                        "egress-shaping-profile": [],
                        "ingress-shaping-profile": [],
                        "intrazone-deny": 0,
                        "local-intf": [
                            "bgp loopback"
                        ]
                    }
                ],
                "egress-shaping-profile": [],
                "ingress-shaping-profile": [],
                "name": "bgp loopback",
                "single-intf": 1
            },
            {
                "color": 0,
                "default-mapping": 0,
                "defmap-intrazone-deny": 0,
                "defmap-zonemember": [],
                "dynamic_mapping": [
                    {
                        "_scope": [
                            {
                                "name": "device_name",
                                "vdom": "root"
                            }
                        ],
                        "egress-shaping-profile": [],
                        "ingress-shaping-profile": [],
                        "intrazone-deny": 0,
                        "local-intf": [
                            "branch"
                        ]
                    }
                ],
                "egress-shaping-profile": [],
                "ingress-shaping-profile": [],
                "name": "branch",
                "single-intf": 1
            }
        ]
    }
}

Human Readable Output

ADOM root Dynamic Interfaces

Name
bgp loopback
branch

fortimanager-firewall-policy-package-install


Schedule a policy package installation.

Base Command

fortimanager-firewall-policy-package-install

Input

Argument Name Description Required
adom_rev_comment The comment for the new ADOM revision. Optional
adom_rev_name The name for the new ADOM revision. Optional
adom The ADOM in which to install the policy package. Leave empty to use the default integration ADOM. Optional
dev_rev_comment The comment for the device configuration revision that will be generated during install. Optional
package The policy package to install. Required
name The device or device group name on which to install the package. Required
vdom vdom on which to install the package. Optional

Context Output

Path Type Description
FortiManager.Installation.id Number The installation task ID.

Command Example

!fortimanager-policy-package-install package=package_to_install name=device_name vdom=root adom_rev_name=testing_installation

Human Readable Output

Installed a policy package my_package in ADOM: root
On Device my_device and VDOM vdom_name.
Task ID: 175

Context Example

{
    "FortiManager": {
        "Installation": {
            "id": 175
        }   
    }
}

fortimanager-firewall-policy-package-install-status


Get installation status.

Base Command

fortimanager-firewall-policy-package-install-status

Input

Argument Name Description Required
task_id The installation task ID. Required

Context Output

Path Type Description
FortiManager.Installation.adom Number The ADOM on which the installation occurred.
FortiManager.Installation.end_tm Number The installation task end time.
FortiManager.Installation.flags Number The installation_task_flags.
FortiManager.Installation.id Number The installation task ID.
FortiManager.Installation.line.detail String The installation status details.
FortiManager.Installation.line.end_tm Number The installation task end time.
FortiManager.Installation.line.err Number The installation error.
FortiManager.Installation.line.history String Installation task historical details.
FortiManager.Installation.line.ip String The installation IP.
FortiManager.Installation.line.name String The installation name.
FortiManager.Installation.line.oid Number The installation task oid.
FortiManager.Installation.line.percent Number The installation task completion percent.
FortiManager.Installation.line.start_tm Number The installation task start time.
FortiManager.Installation.line.state String The installation task state.
FortiManager.Installation.line.vdom String The VDOM on which the installation occurred.
FortiManager.Installation.num_done Number The number of done tasks.
FortiManager.Installation.num_err Number The number of errors found.
FortiManager.Installation.num_lines Number The number of installation data lines.
FortiManager.Installation.num_warn Number The number of warnings found.
FortiManager.Installation.percent Number The installation task completion percent.
FortiManager.Installation.pid Number The installation task PID.
FortiManager.Installation.src String The installation task source
FortiManager.Installation.start_tm Number The installation task start time.
FortiManager.Installation.state String The installation task state.
FortiManager.Installation.title String The installation task title.
FortiManager.Installation.tot_percent Number The installation task completion percent.
FortiManager.Installation.user String The installation task user.

Command Example

!fortimanager-policy-package-install-status task_id=175

Configuration parameters

  • url — Server URL (required)
  • credentials — Username (required)
  • adom — The instance ADOM (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (31)

  • fortimanager-address-create

    Add a new IPv4 address.

  • fortimanager-address-delete

    Delete an address.

  • fortimanager-address-group-create

    Create a new address group.

  • fortimanager-address-group-delete

    Delete an address group.

  • fortimanager-address-group-list

    List ADOM IPv4 address groups.

  • fortimanager-address-group-update

    Create a new address group.

  • fortimanager-address-list

    List ADOM firewall IPv4 addresses.

  • fortimanager-address-update

    Add a new IPv4 address.

  • fortimanager-custom-service-create

    Create a new custom service.

  • fortimanager-custom-service-delete

    Delete a custom service.

  • fortimanager-custom-service-list

    List the custom services.

  • fortimanager-custom-service-update

    Update a custom service.

  • fortimanager-device-groups-list

    List ADOM device groups.

  • fortimanager-devices-list

    List all devices in the ADOM instance.

  • fortimanager-dynamic-interface-list

    List dynamic interfaces.

  • fortimanager-firewall-policy-create

    Create a firewall policy.

  • fortimanager-firewall-policy-delete

    Delete a firewall policy.

  • fortimanager-firewall-policy-list

    List specific firewall policies from a policy package.

  • fortimanager-firewall-policy-move

    Move a policy in the package.

  • fortimanager-firewall-policy-package-create

    Create a new firewall policy package.

  • fortimanager-firewall-policy-package-delete

    Delete a firewall policy package.

  • fortimanager-firewall-policy-package-install

    Schedule a policy package installation.

  • fortimanager-firewall-policy-package-install-status

    Get installation status.

  • fortimanager-firewall-policy-package-list

    List ADOM policy packages.

  • fortimanager-firewall-policy-package-update

    Create a new firewall policy package.

  • fortimanager-firewall-policy-update

    Update a firewall policy.

  • fortimanager-service-categories-list

    List the ADOM service categories.

  • fortimanager-service-group-create

    Creates a new service group.

  • fortimanager-service-group-delete

    Delete a service group.

  • fortimanager-service-group-list

    List ADOM service groups.

  • fortimanager-service-group-update

    Create a new service group.

category: Network Security
provider: Fortinet
commonfields:
  id: FortiManager
  version: -1
configuration:
- display: Server URL
  name: url
  required: true
  type: 0
- display: Username
  name: credentials
  required: true
  type: 9
- defaultvalue: global
  display: The instance ADOM
  name: adom
  required: true
  type: 0
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
description: FortiManager is a single console central management system that manages Fortinet devices.
display: FortiManager
name: FortiManager
script:
  commands:
  - arguments:
    - description: The FortiManager Administrative Domain (ADOM) from which to fetch the devices. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of a specific device to get. If not specified, will get all devices.
      name: device
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: Until which index to get the list. Default is 50.
      name: limit
    description: List all devices in the ADOM instance.
    name: fortimanager-devices-list
    outputs:
    - contextPath: FortiManager.Device.adm_pass
      description: The ADOM password.
      type: String
    - contextPath: FortiManager.Device.adm_usr
      description: The ADOM user.
      type: String
    - contextPath: FortiManager.Device.app_ver
      description: The app version of the device.
      type: String
    - contextPath: FortiManager.Device.av_ver
      description: The antivirus version of the device.
      type: String
    - contextPath: FortiManager.Device.beta
      description: The beta version of the device.
      type: Number
    - contextPath: FortiManager.Device.branch_pt
      description: The branch point of the device.
      type: Number
    - contextPath: FortiManager.Device.build
      description: The build of the device.
      type: Number
    - contextPath: FortiManager.Device.checksum
      description: The checksum of the device.
      type: String
    - contextPath: FortiManager.Device.conf_status
      description: The configuration status of the device.
      type: String
    - contextPath: FortiManager.Device.conn_mode
      description: The connection mode of the device.
      type: String
    - contextPath: FortiManager.Device.conn_status
      description: The connection status of the device.
      type: String
    - contextPath: FortiManager.Device.db_status
      description: The database status of the device.
      type: String
    - contextPath: FortiManager.Device.desc
      description: The description of the device.
      type: String
    - contextPath: FortiManager.Device.dev_status
      description: The status of the device.
      type: String
    - contextPath: FortiManager.Device.fap_cnt
      description: The FortiManager access point count.
      type: Number
    - contextPath: FortiManager.Device.faz.full_act
      description: Full act.
      type: Number
    - contextPath: FortiManager.Device.faz.perm
      description: Perm.
      type: Number
    - contextPath: FortiManager.Device.faz.quota
      description: Quota.
      type: Number
    - contextPath: FortiManager.Device.faz.used
      description: Used.
      type: Number
    - contextPath: FortiManager.Device.fex_cnt
      description: Fex count.
      type: Number
    - contextPath: FortiManager.Device.flags
      description: Flags.
      type: String
    - contextPath: FortiManager.Device.foslic_cpu
      description: Foslic CPU.
      type: Number
    - contextPath: FortiManager.Device.foslic_dr_site
      description: Foslic dr site.
      type: String
    - contextPath: FortiManager.Device.foslic_inst_time
      description: Foslic inst time.
      type: Number
    - contextPath: FortiManager.Device.foslic_last_sync
      description: Foslic last sync.
      type: Number
    - contextPath: FortiManager.Device.foslic_ram
      description: Foslic RAM.
      type: Number
    - contextPath: FortiManager.Device.foslic_type
      description: Foslic type.
      type: String
    - contextPath: FortiManager.Device.foslic_utm
      description: Foslic UTM.
      type: String
    - contextPath: FortiManager.Device.fsw_cnt
      description: FSW count.
      type: Number
    - contextPath: FortiManager.Device.ha_group_id
      description: HA group ID.
      type: Number
    - contextPath: FortiManager.Device.ha_group_name
      description: HA group name.
      type: String
    - contextPath: FortiManager.Device.ha_mode
      description: HA mode.
      type: String
    - contextPath: FortiManager.Device.hdisk_size
      description: Hard disk size.
      type: Number
    - contextPath: FortiManager.Device.hostname
      description: Hostname.
      type: String
    - contextPath: FortiManager.Device.hw_rev_major
      description: Hardware major revision number.
      type: Number
    - contextPath: FortiManager.Device.hw_rev_minor
      description: Hardware minor revision number.
      type: Number
    - contextPath: FortiManager.Device.ip
      description: Device IP.
      type: String
    - contextPath: FortiManager.Device.ips_ext
      description: External IP.
      type: Number
    - contextPath: FortiManager.Device.ips_ver
      description: IP version.
      type: String
    - contextPath: FortiManager.Device.last_checked
      description: Last checked.
      type: Number
    - contextPath: FortiManager.Device.last_resync
      description: Last resync.
      type: Number
    - contextPath: FortiManager.Device.latitude
      description: Latitude.
      type: String
    - contextPath: FortiManager.Device.lic_flags
      description: License flags.
      type: Number
    - contextPath: FortiManager.Device.lic_region
      description: License region.
      type: String
    - contextPath: FortiManager.Device.location_from
      description: Location from.
      type: String
    - contextPath: FortiManager.Device.logdisk_size
      description: Log disk size.
      type: Number
    - contextPath: FortiManager.Device.longitude
      description: Longitude.
      type: String
    - contextPath: FortiManager.Device.maxvdom
      description: Maximum VDOM.
      type: Number
    - contextPath: FortiManager.Device.meta_fields
      description: Meta fields.
      type: String
    - contextPath: FortiManager.Device.mgmt_id
      description: Management ID.
      type: Number
    - contextPath: FortiManager.Device.mgmt_if
      description: Management IF.
      type: String
    - contextPath: FortiManager.Device.mgmt_mode
      description: Management mode.
      type: String
    - contextPath: FortiManager.Device.mgt_vdom
      description: Management VDOM.
      type: String
    - contextPath: FortiManager.Device.module_sn
      description: Module serial number.
      type: String
    - contextPath: FortiManager.Device.mr
      description: Mr.
      type: Number
    - contextPath: FortiManager.Device.name
      description: Device name.
      type: String
    - contextPath: FortiManager.Device.os_type
      description: Device operating system type.
      type: String
    - contextPath: FortiManager.Device.os_ver
      description: Device operating system version.
      type: String
    - contextPath: FortiManager.Device.patch
      description: Patch.
      type: Number
    - contextPath: FortiManager.Device.platform_str
      description: Platform string.
      type: String
    - contextPath: FortiManager.Device.prefer_img_ver
      description: Prefer image version.
      type: String
    - contextPath: FortiManager.Device.prio
      description: Prio.
      type: Number
    - contextPath: FortiManager.Device.psk
      description: PSK.
      type: String
    - contextPath: FortiManager.Device.role
      description: Device role.
      type: String
    - contextPath: FortiManager.Device.sn
      description: Serial number.
      type: String
    - contextPath: FortiManager.Device.vdom.comments
      description: VDOM comments.
      type: String
    - contextPath: FortiManager.Device.vdom.name
      description: VDOM name.
      type: String
    - contextPath: FortiManager.Device.vdom.opmode
      description: VDOM opmode.
      type: String
    - contextPath: FortiManager.Device.vdom.rtm_prof_id
      description: VDOM rtm prof ID.
      type: Number
    - contextPath: FortiManager.Device.vdom.status
      description: VDOM status.
      type: String
    - contextPath: FortiManager.Device.vdom.vpn_id
      description: VDOM VPN ID.
      type: Number
    - contextPath: FortiManager.Device.version
      description: Device version.
      type: Number
    - contextPath: FortiManager.Device.vm_cpu
      description: VM CPU.
      type: Number
    - contextPath: FortiManager.Device.vm_cpu_limit
      description: VM CPU limit.
      type: Number
    - contextPath: FortiManager.Device.vm_lic_expire
      description: VM license expiration.
      type: Number
    - contextPath: FortiManager.Device.vm_mem
      description: VM memory.
      type: Number
    - contextPath: FortiManager.Device.vm_mem_limit
      description: VM memory limit.
      type: Number
    - contextPath: FortiManager.Device.vm_status
      description: VM status.
      type: Number
  - arguments:
    - description: The ADOM from which to fetch the device groups. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of a device group to fetch.  If not specified, will get all device groups.
      name: group
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: Until which index to get the list. Default is 50.
      name: limit
    description: List ADOM device groups.
    name: fortimanager-device-groups-list
    outputs:
    - contextPath: FortiManager.DeviceGroup.desc
      description: Description.
      type: String
    - contextPath: FortiManager.DeviceGroup.meta_fields
      description: Device group meta fields.
      type: String
    - contextPath: FortiManager.DeviceGroup.name
      description: Device group name.
      type: String
    - contextPath: FortiManager.DeviceGroup.os_type
      description: Device group operating system type.
      type: String
    - contextPath: FortiManager.DeviceGroup.type
      description: Device group type.
      type: String
  - arguments:
    - description: The ADOM from which to fetch the addresses. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: The name of a specific address to fetch.  If not specified, will get all addresses.
      name: address
    description: List ADOM firewall IPv4 addresses.
    name: fortimanager-address-list
    outputs:
    - contextPath: FortiManager.Address._image-base64
      description: Base64 of the address image.
      type: String
    - contextPath: FortiManager.Address.allow-routing
      description: Enable/disable use of this address in the static route configuration.
      type: String
    - contextPath: FortiManager.Address.associated-interface
      description: Network interface associated with address.
      type: String
    - contextPath: FortiManager.Address.cache-ttl
      description: Defines the minimal TTL of individual IP addresses in FQDN cache measured in seconds.
      type: Number
    - contextPath: FortiManager.Address.color
      description: The color of the icon in the GUI.
      type: Number
    - contextPath: FortiManager.Address.comment
      description: The comments attached to the address.
      type: String
    - contextPath: FortiManager.Address.country
      description: The IP addresses associated with a specific country.
      type: String
    - contextPath: FortiManager.Address.dynamic_mapping
      description: The address dynamic mapping information.
      type: String
    - contextPath: FortiManager.Address.end-ip
      description: The final IP address (inclusive) in the range for the address.
      type: String
    - contextPath: FortiManager.Address.epg-name
      description: The endpoint group name.
      type: String
    - contextPath: FortiManager.Address.filter
      description: The match criteria filter.
      type: String
    - contextPath: FortiManager.Address.fqdn
      description: The fully qualified domain name (fqdn) address.
      type: String
    - contextPath: FortiManager.Address.list.ip
      description: The IP list associated with the address.
      type: String
    - contextPath: FortiManager.Address.name
      description: The address name.
      type: String
    - contextPath: FortiManager.Address.obj-id
      description: The object ID for NSX.
      type: String
    - contextPath: FortiManager.Address.organization
      description: 'The organization domain name (Syntax: organization/domain).'
      type: String
    - contextPath: FortiManager.Address.policy-group
      description: The policy group name.
      type: String
    - contextPath: FortiManager.Address.sdn
      description: The software defined networking (SDN).
      type: String
    - contextPath: FortiManager.Address.sdn-tag
      description: The software defined networking (SDN) tag.
      type: String
    - contextPath: FortiManager.Address.start-ip
      description: The first IP address (inclusive) in the range for the address.
      type: String
    - contextPath: FortiManager.Address.subnet
      description: The IP address and subnet mask of address.
      type: String
    - contextPath: FortiManager.Address.subnet-name
      description: The subnet name.
      type: String
    - contextPath: FortiManager.Address.tagging.category
      description: The tag category.
      type: String
    - contextPath: FortiManager.Address.tagging.name
      description: The tagging entry name.
      type: String
    - contextPath: FortiManager.Address.tagging.tags
      description: The tags.
      type: String
    - contextPath: FortiManager.Address.tenant
      description: The tenant.
      type: String
    - contextPath: FortiManager.Address.type
      description: The type of address.
      type: String
    - contextPath: FortiManager.Address.uuid
      description: Universally Unique Identifier (UUID). This is automatically assigned but can be manually reset.
      type: String
    - contextPath: FortiManager.Address.visibility
      description: Enable/disable address visibility in the GUI.
      type: String
    - contextPath: FortiManager.Address.wildcard
      description: The IP address and wildcard netmask.
      type: String
    - contextPath: FortiManager.Address.wildcard-fqdn
      description: The fully qualified domain name (fqdn) with wildcard characters.
      type: String
  - arguments:
    - description: The ADOM on which to create the address. Leave empty to use the instance ADOM.
      name: adom
    - description: The address name.
      name: name
      required: true
    - auto: PREDEFINED
      description: 'The type of address. Possible values are: "ipmask", "iprange", "fqdn", "wildcard", "geography", "wildcard-fqdn", and "dynamic".'
      name: type
      predefined:
      - ipmask
      - iprange
      - fqdn
      - wildcard
      - geography
      - wildcard-fqdn
      - dynamic
      required: true
    - description: Policy group name.
      name: policy_group
    - description: A comment to add to the address.
      name: comment
    - description: The network interface associated with the address.
      name: associated_interface
    - description: The fully qualified domain name (fqdn) address. Required for fqdn address type.
      name: fqdn
    - description: First IP address (inclusive) in the range for the address. Required for iprange address type.
      name: start_ip
    - description: Final IP address (inclusive) in the range for the address. Required for iprange address type.
      name: end_ip
    - description: IP address and subnet mask of address. Required for ipmask address type.
      name: subnet
    - description: The subnet name.
      name: subnet_name
    - auto: PREDEFINED
      description: 'The address SDN. Required for dynamic address type. Possible values are: "aci", "aws", "nsx", "nuage", and "azure".'
      name: sdn
      predefined:
      - aci
      - aws
      - nsx
      - nuage
      - azure
    - description: IP address and wildcard netmask. Required for wildcard address type.
      name: wildcard
    - description: The fully qualified domain name (fqdn) with wildcard characters. Required for wildcard-fqdn address type.
      name: wildcard_fqdn
    - description: 'The two letter abbreviation representing a country associated with an IP address (for example: "us"). Required for geography address type. '
      name: country
    description: Add a new IPv4 address.
    name: fortimanager-address-create
  - arguments:
    - description: The ADOM on which to update the address. Leave empty to use the instance ADOM.
      name: adom
    - description: The address name.
      name: name
      required: true
    - auto: PREDEFINED
      description: 'Type of address. Possible values are: "ipmask", "iprange", "fqdn", "wildcard", "geography", "wildcard-fqdn", and "dynamic".'
      name: type
      predefined:
      - ipmask
      - iprange
      - fqdn
      - wildcard
      - geography
      - wildcard-fqdn
      - dynamic
    - description: Policy group name.
      name: policy_group
    - description: A comment to add to the address.
      name: comment
    - description: Network interface associated with address.
      name: associated_interface
    - description: The fully qualified domain name (fqdn) address. Required for fqdn address type.
      name: fqdn
    - description: First IP address (inclusive) in the range for the address. Required for iprange address type.
      name: start_ip
    - description: Final IP address (inclusive) in the range for the address. Required for iprange address type.
      name: end_ip
    - description: IP address and subnet mask of address. Required for ipmask address type.
      name: subnet
    - description: The subnet name.
      name: subnet_name
    - auto: PREDEFINED
      description: 'The address SDN. Required for dynamic address type. Possible values are: "aci", "aws", "nsx", "nuage", and "azure".'
      name: sdn
      predefined:
      - aci
      - aws
      - nsx
      - nuage
      - azure
    - description: IP address and wildcard netmask. Required for wildcard address type.
      name: wildcard
    - description: The fully qualified domain name (fqdn) with wildcard characters. Required for wildcard-fqdn address type.
      name: wildcard_fqdn
    - description: 'The two letter abbreviation representing a country associated with an IP address (for example: "us"). Required for geography address type. '
      name: country
    description: Add a new IPv4 address.
    name: fortimanager-address-update
  - arguments:
    - description: The ADOM from which to delete the address. Leave empty to use the default integration ADOM.
      name: adom
    - description: The address to delete.
      name: address
      required: true
    description: Delete an address.
    name: fortimanager-address-delete
  - arguments:
    - description: The ADOM from which to fetch the address groups. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: Name for a specific address group to fetch. If not specified, will get all address groups.
      name: address_group
    description: List ADOM IPv4 address groups.
    name: fortimanager-address-group-list
    outputs:
    - contextPath: FortiManager.AddressGroup._image-base64
      description: Base64 of the address group image.
      type: String
    - contextPath: FortiManager.AddressGroup.allow-routing
      description: Enable/disable use of this group in the static route configuration.
      type: String
    - contextPath: FortiManager.AddressGroup.color
      description: The color of the icon in the GUI.
      type: Number
    - contextPath: FortiManager.AddressGroup.comment
      description: The comment about the address group.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping._image-base64
      description: The address group dynamic mapping base64 image.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping._scope.name
      description: The address group dynamic mapping scope name.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping._scope.vdom
      description: The address group dynamic mapping scope VDOM.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.allow-routing
      description: Enable/disable use of this dynamic mapping in the static route configuration.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.color
      description: The color of the icon in the GUI.
      type: Number
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.comment
      description: The comment about the address group dynamic mapping.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.exclude
      description: Whether to enable or disable the exclusion of the dynamic mapping.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.exclude-member
      description: The exclude member.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.global-object
      description: The global object.
      type: Number
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.member
      description: The address group dynamic mapping member.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.tags
      description: The address group dynamic mapping tags.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.type
      description: The address group dynamic mapping type.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.uuid
      description: The address group dynamic mapping UUID.
      type: String
    - contextPath: FortiManager.AddressGroup.dynamic_mapping.visibility
      description: The address group dynamic mapping visibility.
      type: String
    - contextPath: FortiManager.AddressGroup.member
      description: The address objects contained within the group.
      type: String
    - contextPath: FortiManager.AddressGroup.name
      description: The address group name.
      type: String
    - contextPath: FortiManager.AddressGroup.tagging.category
      description: The tag category.
      type: String
    - contextPath: FortiManager.AddressGroup.tagging.name
      description: The tagging entry name.
      type: String
    - contextPath: FortiManager.AddressGroup.tagging.tags
      description: The tags.
      type: String
    - contextPath: FortiManager.AddressGroup.uuid
      description: Universally Unique Identifier (UUID). This is automatically assigned but can be manually reset.
      type: String
    - contextPath: FortiManager.AddressGroup.visibility
      description: Enable/disable address visibility in the GUI.
      type: String
  - arguments:
    - description: The ADOM on which to create the address group. Leave empty to use the instance ADOM.
      name: adom
    - description: Address group name.
      name: name
      required: true
    - description: A comma-separated list of the address or address group objects contained within the group.
      name: member
      required: true
    - description: A comment about the address group.
      name: comment
    description: Create a new address group.
    name: fortimanager-address-group-create
  - arguments:
    - description: The ADOM on which to update the address group. Leave empty to use the instance ADOM.
      name: adom
    - description: Address group name.
      name: name
      required: true
    - description: A comma-separated list of the address or address group objects contained within the group.
      name: member
    - description: A comment about the address group.
      name: comment
    description: Create a new address group.
    name: fortimanager-address-group-update
  - arguments:
    - description: The ADOM from which to delete the address group. Leave empty to use the default integration ADOM.
      name: adom
    - description: The address group to delete.
      name: address_group
      required: true
    description: Delete an address group.
    name: fortimanager-address-group-delete
  - arguments:
    - description: The ADOM from which to fetch the service categories. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: Name of a specific category to fetch. If not specified, will get all service groups.
      name: service_category
    description: List the ADOM service categories.
    name: fortimanager-service-categories-list
    outputs:
    - contextPath: FortiManager.ServiceCategory.comment
      description: Comment.
      type: String
    - contextPath: FortiManager.ServiceCategory.name
      description: Service category name.
      type: String
  - arguments:
    - description: The ADOM from which to fetch the service groups. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: Name of a specific service group to fetch. If not specified, will get all service groups.
      name: service_group
    description: List ADOM service groups.
    name: fortimanager-service-group-list
    outputs:
    - contextPath: FortiManager.ServiceGroup.color
      description: The color of the icon in the GUI.
      type: Number
    - contextPath: FortiManager.ServiceGroup.comment
      description: Comment.
      type: String
    - contextPath: FortiManager.ServiceGroup.member
      description: The service objects contained within the group.
      type: String
    - contextPath: FortiManager.ServiceGroup.name
      description: The address group name.
      type: String
    - contextPath: FortiManager.ServiceGroup.proxy
      description: Enable/disable web proxy service group.
      type: String
  - arguments:
    - description: The ADOM on which to create the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: A comment.
      name: comment
    - description: The created service group name.
      name: name
      required: true
    - auto: PREDEFINED
      description: Enable/disable a web proxy service group.
      name: proxy
      predefined:
      - enable
      - disable
    - description: A comma-separated list of service objects to be contained within the group.
      name: member
      required: true
    description: Creates a new service group.
    name: fortimanager-service-group-create
  - arguments:
    - description: The ADOM on which to update the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: A comment.
      name: comment
    - description: The created service group name.
      name: name
      required: true
    - auto: PREDEFINED
      description: Enable/disable a web proxy service group.
      name: proxy
      predefined:
      - enable
      - disable
    - description: A comma-sperated list of service objects to be contained within the group.
      name: member
    description: Create a new service group.
    name: fortimanager-service-group-update
  - arguments:
    - description: The ADOM from which to delete the service group. Leave empty to use the default integration ADOM.
      name: adom
    - description: The service group to delete.
      name: service_group
      required: true
    description: Delete a service group.
    name: fortimanager-service-group-delete
  - arguments:
    - description: The ADOM from which to fetch the custom service. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: Name of a specific custom service to fetch.  If not specified, will get all custom services.
      name: custom_service
    description: List the custom services.
    name: fortimanager-custom-service-list
    outputs:
    - contextPath: FortiManager.CustomService.app-category
      description: Application category ID.
      type: Number
    - contextPath: FortiManager.CustomService.app-service-type
      description: Application service type.
      type: String
    - contextPath: FortiManager.CustomService.application
      description: Application ID.
      type: Number
    - contextPath: FortiManager.CustomService.category
      description: Service category.
      type: String
    - contextPath: FortiManager.CustomService.check-reset-range
      description: Configure the type of ICMP error message verification.
      type: String
    - contextPath: FortiManager.CustomService.color
      description: Color of icon in the GUI.
      type: Number
    - contextPath: FortiManager.CustomService.comment
      description: Comment.
      type: String
    - contextPath: FortiManager.CustomService.fqdn
      description: Fully qualified domain (fqdn) name.
      type: String
    - contextPath: FortiManager.CustomService.helper
      description: Helper name.
      type: String
    - contextPath: FortiManager.CustomService.icmpcode
      description: ICMP code.
      type: Number
    - contextPath: FortiManager.CustomService.icmptype
      description: ICMP type.
      type: Number
    - contextPath: FortiManager.CustomService.iprange
      description: Start and end of the IP range associated with service.
      type: String
    - contextPath: FortiManager.CustomService.name
      description: Custom service name.
      type: String
    - contextPath: FortiManager.CustomService.protocol
      description: Protocol type based on IANA numbers.
      type: String
    - contextPath: FortiManager.CustomService.protocol-number
      description: IP protocol number.
      type: Number
    - contextPath: FortiManager.CustomService.proxy
      description: Enable/disable a web proxy service.
      type: String
    - contextPath: FortiManager.CustomService.sctp-portrange
      description: Multiple SCTP port ranges.
      type: String
    - contextPath: FortiManager.CustomService.session-ttl
      description: Session TTL (300 - 604800. Default is 0.).
      type: Number
    - contextPath: FortiManager.CustomService.tcp-halfclose-timer
      description: Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec. Default is 0.).
      type: Number
    - contextPath: FortiManager.CustomService.tcp-halfopen-timer
      description: Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec. Default is 0.).
      type: Number
    - contextPath: FortiManager.CustomService.tcp-portrange
      description: Multiple TCP port ranges.
      type: String
    - contextPath: FortiManager.CustomService.tcp-timewait-timer
      description: Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec. Default is 0.).
      type: Number
    - contextPath: FortiManager.CustomService.udp-idle-timer
      description: UDP half close timeout (0 - 86400 sec. Default is 0.).
      type: Number
    - contextPath: FortiManager.CustomService.udp-portrange
      description: Multiple UDP port ranges.
      type: String
    - contextPath: FortiManager.CustomService.visibility
      description: Enable/disable the visibility of the service in the GUI.
      type: String
  - arguments:
    - description: The ADOM from which to fetch the custom service. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of the new custom service.
      name: name
      required: true
    - description: Application category ID.
      name: app_category
    - auto: PREDEFINED
      defaultValue: disable
      description: 'Application service type. Possible values are: "app-id", "disable", and "app-category". Default is "disable".'
      name: app_service_type
      predefined:
      - app-id
      - disable
      - app-category
    - description: The application ID.
      name: application
    - description: The service category.
      name: category
    - auto: PREDEFINED
      description: 'Configure the type of ICMP error message verification. Possible values are: "disable", "default", and "strict".'
      name: check_reset_range
      predefined:
      - disable
      - default
      - strict
    - description: A comment.
      name: comment
    - description: Fully qualified domain name (fqdn).
      name: fqdn
    - auto: PREDEFINED
      description: Helper name.
      name: helper
      predefined:
      - disable
      - auto
      - ftp
      - tftp
      - ras
      - h323
      - tns
      - mms
      - sip
      - pptp
      - rtsp
      - dns-udp
      - dns-tcp
      - pmap
      - rsh
      - dcerpc
      - mgcp
      - gtp-c
      - gtp-u
      - gtp-b
    - description: ICMP code.
      name: icmpcode
    - description: ICMP type.
      name: icmptype
    - description: Start and end of the IP range associated with the service.
      name: iprange
    - auto: PREDEFINED
      description: 'Protocol type based on IANA numbers. Possible values are: "ICMP", "IP", "TCP/UDP/SCTP", "ICMP6", "HTTP", "FTP", "CONNECT", "SOCKS", "ALL", "SOCKS-TCP", and "SOCKS-UDP".'
      name: protocol
      predefined:
      - ICMP
      - IP
      - TCP/UDP/SCTP
      - ICMP6
      - HTTP
      - FTP
      - CONNECT
      - SOCKS
      - ALL
      - SOCKS-TCP
      - SOCKS-UDP
    - auto: PREDEFINED
      description: Enable/disable a web proxy service.
      name: proxy
      predefined:
      - enable
      - disable
    - description: Multiple SCTP port ranges.
      name: sctp_portrange
    - defaultValue: '0'
      description: Session TTL in the range of 300 - 604800. Default is 0.
      name: session_ttl
    - defaultValue: '0'
      description: Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec). Default is 0.
      name: tcp_halfclose_timer
    - defaultValue: '0'
      description: Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec). Default is 0.
      name: tcp_halfopen_timer
    - description: Multiple TCP port ranges.
      name: tcp_portrange
    - defaultValue: '0'
      description: Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec). Default is 0.
      name: tcp_timewait_timer
    - defaultValue: '0'
      description: UDP half close timeout (0 - 86400 sec). Default is 0.
      name: udp_idle_timer
    - description: Multiple UDP port ranges.
      name: udp_portrange
    description: Create a new custom service.
    name: fortimanager-custom-service-create
  - arguments:
    - description: The ADOM in which to update the custom service. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of the new custom service.
      name: name
      required: true
    - description: Application category ID.
      name: app_category
    - auto: PREDEFINED
      defaultValue: disable
      description: 'Application service type. Possible values are: "app-id", "disable", and "app-category". Default is "disable".'
      name: app_service_type
      predefined:
      - app-id
      - disable
      - app-category
    - description: The application ID.
      name: application
    - description: The service category.
      name: category
    - auto: PREDEFINED
      description: 'Configure the type of ICMP error message verification. Possible values are: "disable", "default", and "strict".'
      name: check_reset_range
      predefined:
      - disable
      - default
      - strict
    - description: A comment.
      name: comment
    - description: Fully qualified domain name (fqdn).
      name: fqdn
    - auto: PREDEFINED
      description: Helper name.
      name: helper
      predefined:
      - disable
      - auto
      - ftp
      - tftp
      - ras
      - h323
      - tns
      - mms
      - sip
      - pptp
      - rtsp
      - dns-udp
      - dns-tcp
      - pmap
      - rsh
      - dcerpc
      - mgcp
      - gtp-c
      - gtp-u
      - gtp-b
    - description: ICMP code.
      name: icmpcode
    - description: ICMP type.
      name: icmptype
    - description: Start and end of the IP range associated with service.
      name: iprange
    - auto: PREDEFINED
      description: 'Protocol type based on IANA numbers. Possible values are: "ICMP", "IP", "TCP/UDP/SCTP", "ICMP6", "HTTP", "FTP", "CONNECT", "SOCKS", "ALL", "SOCKS-TCP", and "SOCKS-UDP".'
      name: protocol
      predefined:
      - ICMP
      - IP
      - TCP/UDP/SCTP
      - ICMP6
      - HTTP
      - FTP
      - CONNECT
      - SOCKS
      - ALL
      - SOCKS-TCP
      - SOCKS-UDP
    - auto: PREDEFINED
      description: Enable/disable a web proxy service.
      name: proxy
      predefined:
      - enable
      - disable
    - description: Multiple SCTP port ranges.
      name: sctp_portrange
    - defaultValue: '0'
      description: Session TTL in the range of 300 - 604800. Default is 0.
      name: session_ttl
    - defaultValue: '0'
      description: Wait time to close a TCP session waiting for an unanswered FIN packet (1 - 86400 sec). Default is 0.
      name: tcp_halfclose_timer
    - defaultValue: '0'
      description: Wait time to close a TCP session waiting for an unanswered open session packet (1 - 86400 sec). Default is 0.
      name: tcp_halfopen_timer
    - description: Multiple TCP port ranges.
      name: tcp_portrange
    - defaultValue: '0'
      description: Set the length of the TCP TIME-WAIT state in seconds (1 - 300 sec). Default is 0.
      name: tcp_timewait_timer
    - defaultValue: '0'
      description: UDP half close timeout (0 - 86400 sec). Default is 0.
      name: udp_idle_timer
    - description: Multiple UDP port ranges.
      name: udp_portrange
    description: Update a custom service.
    name: fortimanager-custom-service-update
  - arguments:
    - description: The ADOM from which to delete the custom service. Leave empty to use the default integration ADOM.
      name: adom
    - description: The custome service to delete.
      name: custom
      required: true
    description: Delete a custom service.
    name: fortimanager-custom-service-delete
  - arguments:
    - description: The ADOM from which to fetch the firewall policy packages. Leave empty to use the instance ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    - description: Name of a specific policy package to fetch. If not specified, will get all policy packages.
      name: policy_package
    description: List ADOM policy packages.
    name: fortimanager-firewall-policy-package-list
    outputs:
    - contextPath: FortiManager.PolicyPackage.name
      description: Policy package name.
      type: String
    - contextPath: FortiManager.PolicyPackage.obj_ver
      description: Policy package object version.
      type: Number
    - contextPath: FortiManager.PolicyPackage.oid
      description: Policy package OID.
      type: Number
    - contextPath: FortiManager.PolicyPackage.package setting.central-nat
      description: Whether to use the central NAT.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.consolidated-firewall-mode
      description: Whether to enable consolidate firewall mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.fwpolicy-implicit-log
      description: Whether to enable firewall policy implicit log.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.fwpolicy6-implicit-log
      description: Whether to enable firewall policy 6 implicit log.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.inspection-mode
      description: Package inspection mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.ngfw-mode
      description: Package NGFW mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.package setting.ssl-ssh-profile
      description: Package SSL SSH profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.scope_member.name
      description: Policy package scope member name.
      type: String
    - contextPath: FortiManager.PolicyPackage.scope_member.vdom
      description: Policy package scope member VDOM.
      type: String
    - contextPath: FortiManager.PolicyPackage.subobj
      description: Policy package sub-objects.
      type: Unknown
    - contextPath: FortiManager.PolicyPackage.type
      description: Policy package type.
      type: String
  - arguments:
    - description: The ADOM on which to create the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of the new policy package.
      name: name
      required: true
    - auto: PREDEFINED
      description: 'The type of package. Possible values are: "pkg" and "folder".'
      name: type
      predefined:
      - pkg
      - folder
      required: true
    - auto: PREDEFINED
      defaultValue: disable
      description: Whether to use central NAT. Default is "disable".
      name: central_nat
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      defaultValue: disable
      description: Whether to enable consolidate firewall mode. Default is "disable".
      name: consolidated_firewall_mode
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      defaultValue: disable
      description: Whether to enable firewall policy implicit log. Default is "disable".
      name: fwpolicy_implicit_log
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      defaultValue: disable
      description: Whether to enable firewall policy 6 implicit log. Default is "disable".
      name: fwpolicy6_implicit_log
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      defaultValue: proxy
      description: 'Package inspection mode. Possible values are: "proxy" and "flow". Default is "proxy".'
      name: inspection_mode
      predefined:
      - proxy
      - flow
    - auto: PREDEFINED
      defaultValue: profile-based
      description: 'Package NGFW mode. Possible values are: "profile-based" and "policy-based". Default is "profile-based".'
      name: ngfw_mode
      predefined:
      - profile-based
      - policy-based
    - description: Package SSL SSH profile.
      name: ssl_ssh_profile
      predefined:
      - ''
    description: Create a new firewall policy package.
    name: fortimanager-firewall-policy-package-create
  - arguments:
    - description: The ADOM on which to update the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: The name of the Policy Package to update.
      name: name
      required: true
    - auto: PREDEFINED
      description: 'The type og package. Possible values are: "pkg" and "folder".'
      name: type
      predefined:
      - pkg
      - folder
    - auto: PREDEFINED
      description: Whether to use central NAT.
      name: central_nat
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      description: Whether to enable consolidate firewall mode.
      name: consolidated_firewall_mode
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      description: Whether to enable firewall policy implicit log.
      name: fwpolicy_implicit_log
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      description: Whether to enable firewall policy 6 implicit log.
      name: fwpolicy6_implicit_log
      predefined:
      - enable
      - disable
    - auto: PREDEFINED
      description: 'Package inspection mode. Possible values are: "proxy" and "flow".'
      name: inspection_mode
      predefined:
      - proxy
      - flow
    - auto: PREDEFINED
      description: 'Package NGFW mode. Possible values are: "profile-based" and "policy-based".'
      name: ngfw_mode
      predefined:
      - profile-based
      - policy-based
    - description: Package SSL SSH profile.
      name: ssl_ssh_profile
      predefined:
      - ''
    description: Create a new firewall policy package.
    name: fortimanager-firewall-policy-package-update
  - arguments:
    - description: The ADOM from which to delete the policy package. Leave empty to use the default integration ADOM.
      name: adom
    - description: The policy package path to delete.
      name: pkg_path
      required: true
    description: Delete a firewall policy package.
    name: fortimanager-firewall-policy-package-delete
  - arguments:
    - description: The package from which to fetch the policies.
      name: package
      required: true
    - description: The ADOM from which to fetch the policies. Leave empty to use the instance ADOM.
      name: adom
    - auto: PREDEFINED
      defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
      predefined:
      - '50'
    - description: To which index to get the list.
      name: limit
    - description: An ID for the specific policy to fetch. If not specified, will get all policies.
      name: policy_id
    description: List specific firewall policies from a policy package.
    name: fortimanager-firewall-policy-list
    outputs:
    - contextPath: FortiManager.PolicyPackage.Policy.action
      description: Policy action (allow/deny/ipsec).
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.app-category
      description: Application category ID list.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.app-group
      description: Application group names.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.application
      description: Application ID list.
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.application-list
      description: Name of an existing application list.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.auth-cert
      description: HTTPS server certificate for policy authentication.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.auth-path
      description: Enable/disable authentication-based routing.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.auth-redirect-addr
      description: HTTP-to-HTTPS redirect address for firewall authentication.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.auto-asic-offload
      description: Enable/disable offloading security profile processing to CP processors.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.av-profile
      description: Name of an existing antivirus profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.block-notification
      description: Enable/disable block notification.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.captive-portal-exempt
      description: Enable to exempt some users from the captive portal.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.capture-packet
      description: Enable/disable capture packets.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.comments
      description: Comments.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.custom-log-fields
      description: Custom fields to append to log messages for this policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.delay-tcp-npu-session
      description: Enable TCP NPU session delay to guarantee packet order of 3-way handshake.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.devices
      description: Names of devices or device groups that can be matched by the policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.diffserv-forward
      description: Enable to change packet DiffServ values to the specified diffservcode-forward value.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.diffserv-reverse
      description: Enable to change packet reverse (reply) DiffServ values to the specified diffservcode-rev value.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.diffservcode-forward
      description: Change packet DiffServ to this value.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.diffservcode-rev
      description: Change packet reverse (reply) DiffServ to this value.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.disclaimer
      description: Enable/disable user authentication disclaimer.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dlp-sensor
      description: Name of an existing DLP sensor.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dnsfilter-profile
      description: Name of an existing DNS filter profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dscp-match
      description: Enable DSCP check.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dscp-negate
      description: Enable negated DSCP match.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dscp-value
      description: DSCP value.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dsri
      description: Enable DSRI to ignore HTTP server responses.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dstaddr
      description: Destination address and address group names.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dstaddr-negate
      description: When enabled, dstaddr specifies what the destination address must NOT be.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.dstintf
      description: Outgoing (egress) interface.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.firewall-session-dirty
      description: How to handle sessions if the configuration of this firewall policy changes.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.fixedport
      description: Enable to prevent source NAT from changing a session source port.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.fsso
      description: Enable/disable Fortinet single sign-on.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.fsso-agent-for-ntlm
      description: FSSO agent to use for NTLM authentication.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.global-label
      description: Label for the policy that appears when the GUI is in Global View mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.groups
      description: Names of user groups that can authenticate with this policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.gtp-profile
      description: GTP profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.icap-profile
      description: Name of an existing ICAP profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.identity-based-route
      description: Name of identity-based routing rule.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.inbound
      description: Policy-based IPsec VPN. Only traffic from the remote network can initiate a VPN.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service
      description: Enable/disable use of internet services for this policy. If enabled, destination address and service are not used.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-custom
      description: Custom internet service name.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-id
      description: Internet service ID.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-negate
      description: When enabled, internet service specifies what the service must NOT be.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-src
      description: Enable/disable use of internet services in source for this policy. If enabled, source address is not used.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-src-custom
      description: Custom internet service source name.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-src-id
      description: Internet service source ID.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.internet-service-src-negate
      description: When enabled, internet-service-src specifies what the service must NOT be.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ippool
      description: Enable to use IP pools for source NAT.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ips-sensor
      description: Name of an existing IPS sensor.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.label
      description: Label for the policy that appears when the GUI is in Section View mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.learning-mode
      description: Enable to allow everything, but log all of the meaningful data for security information gathering. A learning report will be generated.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.logtraffic
      description: Enable or disable logging. Log all sessions or security profile sessions.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.logtraffic-start
      description: Record logs when a session starts and ends.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.match-vip
      description: Enable to match packets that have had their destination addresses changed by a VIP.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.mms-profile
      description: Name of an existing MMS profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.name
      description: Policy name.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.nat
      description: Enable/disable a source NAT.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.natinbound
      description: 'Policy-based IPsec VPN: apply destination NAT to inbound traffic.'
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.natip
      description: 'Policy-based IPsec VPN: source NAT IP address for outgoing traffic.'
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.natoutbound
      description: 'Policy-based IPsec VPN: apply source NAT to outbound traffic.'
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.np-acceleration
      description: Enable/disable UTM Network Processor acceleration.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ntlm
      description: Enable/disable NTLM authentication.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ntlm-enabled-browsers
      description: HTTP-User-Agent value of supported browsers.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ntlm-guest
      description: Enable/disable NTLM guest user access.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.outbound
      description: 'Policy-based IPsec VPN: only traffic from the internal network can initiate a VPN.'
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.per-ip-shaper
      description: Per-IP traffic shaper.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.permit-any-host
      description: Accept UDP packets from any host.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.permit-stun-host
      description: Accept UDP packets from any Session Traversal Utilities for NAT (STUN) host.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.policyid
      description: Policy ID.
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.poolname
      description: IP pool names.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.profile-group
      description: Name of profile group.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.profile-protocol-options
      description: Name of an existing protocol options profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.profile-type
      description: Determine whether the firewall policy allows security profile groups or single profiles only.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.radius-mac-auth-bypass
      description: Enable MAC authentication bypass. The bypassed MAC address must be received from RADIUS server.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.redirect-url
      description: The URL users are directed to after seeing and accepting the disclaimer or authenticating.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.replacemsg-override-group
      description: Override the default replacement message group for this policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.rsso
      description: Enable/disable RADIUS single sign-on (RSSO).
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.rtp-addr
      description: Address names if this is an RTP NAT policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.rtp-nat
      description: Enable Real Time Protocol (RTP) NAT.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.scan-botnet-connections
      description: Block or monitor connections to Botnet servers or disable Botnet scanning.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.schedule
      description: Schedule name.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.schedule-timeout
      description: Enable to force current sessions to end when the schedule object times out. Disable allows them to end from inactivity.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.send-deny-packet
      description: Enable to send a reply when a session is denied or blocked by a firewall policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.service
      description: Service and service group names.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.service-negate
      description: When enabled, service specifies what the service must NOT be.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.session-ttl
      description: TTL in seconds for sessions accepted by this policy. (0 means use the system default session TTL.)
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.spamfilter-profile
      description: Name of an existing spam filter profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.srcaddr
      description: Source address and address group names.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.srcaddr-negate
      description: When enabled, srcaddr specifies what the source address must NOT be.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.srcintf
      description: Incoming (ingress) interface.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ssh-filter-profile
      description: Name of an existing SSH filter profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ssl-mirror
      description: Enable to copy decrypted SSL traffic to a FortiGate interface (called SSL mirroring).
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ssl-mirror-intf
      description: SSL mirror interface name.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.ssl-ssh-profile
      description: Name of an existing SSL SSH profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.status
      description: Enable or disable this policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.tcp-mss-receiver
      description: Receiver TCP maximum segment size (MSS).
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.tcp-mss-sender
      description: Sender TCP maximum segment size (MSS).
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.tcp-session-without-syn
      description: Enable/disable creation of TCP session without SYN flag.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.timeout-send-rst
      description: Enable/disable sending RST packets when TCP sessions expire.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.traffic-shaper
      description: Traffic shaper.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.traffic-shaper-reverse
      description: Reverse traffic shaper.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.url-category
      description: URL category ID list.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.users
      description: Names of individual users that can authenticate with this policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.utm-status
      description: Enable to add one or more security profiles (AV, IPS, etc.) to the firewall policy.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.uuid
      description: Universally Unique Identifier (UUID; automatically assigned but can be manually reset).
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vlan-cos-fwd
      description: 'VLAN forward direction user priority: 255 passthrough, 0 lowest, 7 highest.'
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.vlan-cos-rev
      description: 'VLAN reverse direction user priority: 255 passthrough, 0 lowest, 7 highest.'
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.vlan-filter
      description: Set VLAN filters.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.voip-profile
      description: Name of an existing VoIP profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_dst_node.host
      description: VPN destination node host.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_dst_node.seq
      description: VPN destination node sequence.
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_dst_node.subnet
      description: VPN destination node subnet.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_src_node.host
      description: VPN source node host.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_src_node.seq
      description: VPN source node sequence.
      type: Number
    - contextPath: FortiManager.PolicyPackage.Policy.vpn_src_node.subnet
      description: VPN source node subnet.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.vpntunnel
      description: 'Policy-based IPsec VPN: name of the IPsec VPN Phase 1.'
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.waf-profile
      description: Name of an existing Web application firewall profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wanopt
      description: Enable/disable WAN optimization.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wanopt-detection
      description: WAN optimization auto-detection mode.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wanopt-passive-opt
      description: WAN optimization passive mode options. This option decides what IP address will be used to connect server.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wanopt-peer
      description: WAN optimization peer.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wanopt-profile
      description: WAN optimization profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wccp
      description: Enable/disable forwarding traffic matching this policy to a configured WCCP server.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.webcache
      description: Enable/disable a web cache.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.webcache-https
      description: Enable/disable a web cache for HTTPS.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.webfilter-profile
      description: Name of an existing Web filter profile.
      type: String
    - contextPath: FortiManager.PolicyPackage.Policy.wsso
      description: Enable/disable WiFi single sign-on (WSSO).
      type: String
  - arguments:
    - description: The ADOM on which to create the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: The package from which to create the policy.
      name: package
      required: true
    - auto: PREDEFINED
      description: 'The policy action. Possible values are: "deny", "accept", "ipsec", and "ssl-vpn".'
      name: action
      predefined:
      - deny
      - accept
      - ipsec
      - ssl-vpn
      required: true
    - description: A comment.
      name: comments
    - description: 'Destination address name. Note: dstaddr6 or dstaddr must be set.'
      name: dstaddr
    - description: 'IPv6 destination address (web proxy only). Note: dstaddr6 or dstaddr must be set.'
      name: dstaddr6
    - auto: PREDEFINED
      description: Enable/disable a negated destination address match.
      name: dstaddr_negate
      predefined:
      - disable
      - enable
    - defaultValue: any
      description: Destination interface name.
      name: dstintf
    - description: 'Source address name. Note: srcaddr or srcaddr6 must be set.'
      name: srcaddr
    - description: 'IPv6 source address (web proxy only). Note: srcaddr or srcaddr6 must be set.'
      name: srcaddr6
    - auto: PREDEFINED
      description: Enable/disable a negated source address match.
      name: srcaddr_negate
      predefined:
      - disable
      - enable
    - defaultValue: any
      description: Source interface name.
      name: srcintf
    - description: 'A comma-separated list of additional params and their values. For example: Field1=Value1,Field2=Value2.'
      name: additional_params
    - description: The name of the policy to create.
      name: name
      required: true
    - auto: PREDEFINED
      defaultValue: utm
      description: 'Enable or disable logging. Log all sessions or security profile sessions. Possible values are: "enable", "disable", "all", and "utm".'
      name: logtraffic
      predefined:
      - enable
      - disable
      - all
      - utm
      required: true
    - defaultValue: always
      description: Schedule name. Default is "always".
      name: schedule
      required: true
    - defaultValue: ALL
      description: Service and service group names. Default is "ALL".
      name: service
      required: true
    - auto: PREDEFINED
      defaultValue: enable
      description: Enable or disable this policy.
      name: status
      predefined:
      - enable
      - disable
      required: true
    - description: The ID of the policy to create. Leave empty to use system default.
      name: policyid
    description: Create a firewall policy.
    name: fortimanager-firewall-policy-create
  - arguments:
    - description: The ADOM on which to update the service group. Leave empty to use the instance ADOM.
      name: adom
    - description: The package from which to update the policy.
      name: package
      required: true
    - auto: PREDEFINED
      description: 'The policy action. Possible values are: "deny", "accept", "ipsec", and "ssl-vpn".'
      name: action
      predefined:
      - deny
      - accept
      - ipsec
      - ssl-vpn
    - description: A comment.
      name: comments
    - description: 'Destination address name. Note: dstaddr6 or dstaddr must be set.'
      name: dstaddr
    - description: 'IPv6 destination address (web proxy only). Note: dstaddr6 or dstaddr must be set.'
      name: dstaddr6
    - auto: PREDEFINED
      description: Enable/disable a negated destination address match.
      name: dstaddr_negate
      predefined:
      - disable
      - enable
    - description: Destination interface name.
      name: dstintf
    - description: 'Source address name. Note: srcaddr or srcaddr6 must be set.'
      name: srcaddr
    - description: 'IPv6 source address (web proxy only). Note: srcaddr or srcaddr6 must be set.'
      name: srcaddr6
    - auto: PREDEFINED
      description: Enable/disable a negated source address match.
      name: srcaddr_negate
      predefined:
      - disable
      - enable
    - description: Source interface name.
      name: srcintf
    - description: 'A comma-separated list of additional params and their values. exmaple: Field1=Value1,Field2=Value2.'
      name: additional_params
    - description: The name of the policy to update.
      name: name
    - auto: PREDEFINED
      description: 'Enable or disable logging. Log all sessions or security profile sessions. Possible values are: "enable", "disable", "all", and "utm".'
      name: logtraffic
      predefined:
      - enable
      - disable
      - all
      - utm
    - description: Schedule name.
      name: schedule
    - description: Service and service group names.
      name: service
    - auto: PREDEFINED
      description: Enable or disable this policy.
      name: status
      predefined:
      - enable
      - disable
    - description: The ID of the policy to update.
      name: policyid
      required: true
    description: Update a firewall policy.
    name: fortimanager-firewall-policy-update
  - arguments:
    - description: The ADOM from which to delete the policy. Leave empty to use the default integration ADOM.
      name: adom
    - description: The policy package from which we want to delete the policy.
      name: package
      required: true
    - description: The policy we want to delete.
      name: policy
      required: true
    description: Delete a firewall policy.
    name: fortimanager-firewall-policy-delete
  - arguments:
    - description: The ADOM from which to move the policy. Leave empty to use the default integration ADOM.
      name: adom
    - description: The policy package from which we want to move the policy.
      name: package
      required: true
    - description: The ID of the policy we want to move.
      name: policy
      required: true
    - description: The ID of the target policy by which we want to move the policy.
      name: target
      required: true
    - auto: PREDEFINED
      defaultValue: before
      description: 'Whether to move the policy before or after the target policy. Possible values are: "before" and "after". Default is "before".'
      name: option
      predefined:
      - before
      - after
      required: true
    description: Move a policy in the package.
    name: fortimanager-firewall-policy-move
  - arguments:
    - description: The ADOM from which to list dynamic interfaces. Leave empty to use the default integration ADOM.
      name: adom
    - defaultValue: '0'
      description: From which index to start the list. Default is 0.
      name: offset
    - defaultValue: '50'
      description: To which index to get the list. Default is 50.
      name: limit
    description: List dynamic interfaces.
    name: fortimanager-dynamic-interface-list
    outputs:
    - contextPath: FortiManager.DynamicInterface.color
      description: Color of the icon in the GUI.
      type: Number
    - contextPath: FortiManager.DynamicInterface.default-mapping
      description: Default mapping of the Interface.
      type: String
    - contextPath: FortiManager.DynamicInterface.defmap-intf
      description: Default mapping interface.
      type: String
    - contextPath: FortiManager.DynamicInterface.defmap-intrazone-deny
      description: Default mapping intrazone deny.
      type: String
    - contextPath: FortiManager.DynamicInterface.defmap-zonemember
      description: Default mapping zone members.
      type: String
    - contextPath: FortiManager.DynamicInterface.description
      description: Dynamic interface description.
      type: String
    - contextPath: FortiManager.DynamicInterface.dynamic_mapping._scope.name
      description: Dynamic mapping scope name.
      type: String
    - contextPath: FortiManager.DynamicInterface.dynamic_mapping._scope.vdom
      description: Dynamic mapping scope VDOM.
      type: String
    - contextPath: FortiManager.DynamicInterface.dynamic_mapping.egress-shaping-profile
      description: Dynamic mapping egress shaping profile.
      type: String
    - contextPath: FortiManager.DynamicInterface.dynamic_mapping.intrazone-deny
      description: Dynamic mapping intrazone deny.
      type: String
    - contextPath: FortiManager.DynamicInterface.dynamic_mapping.local-intf
      description: Dynamic mapping local interface.
      type: String
    - contextPath: FortiManager.DynamicInterface.egress-shaping-profile
      description: Egress shaping profile.
      type: String
    - contextPath: FortiManager.DynamicInterface.name
      description: Dynamic interface name.
      type: String
    - contextPath: FortiManager.DynamicInterface.platform_mapping.egress-shaping-profile
      description: Platform mapping egress shaping profile.
      type: String
    - contextPath: FortiManager.DynamicInterface.platform_mapping.intf-zone
      description: Platform mapping interface zone.
      type: String
    - contextPath: FortiManager.DynamicInterface.platform_mapping.intrazone-deny
      description: Platform mapping intrazone deny.
      type: String
    - contextPath: FortiManager.DynamicInterface.platform_mapping.name
      description: Platform mapping name.
      type: String
    - contextPath: FortiManager.DynamicInterface.single-intf
      description: Dynamic interface single interface.
      type: String
  - arguments:
    - description: The comment for the new ADOM revision.
      name: adom_rev_comment
    - description: The name for the new ADOM revision.
      name: adom_rev_name
    - description: The ADOM in which to install the policy package. Leave empty to use the default integration ADOM.
      name: adom
    - description: The comment for the device configuration revision that will be generated during install.
      name: dev_rev_comment
    - description: The policy package to install.
      name: package
      required: true
    - description: The device or device group name on which to install the package.
      name: name
      required: true
    - description: vdom on which to install the package.
      name: vdom
    description: Schedule a policy package installation.
    name: fortimanager-firewall-policy-package-install
    outputs:
    - contextPath: FortiManager.Installation.id
      description: The installation task ID.
      type: Number
  - arguments:
    - description: The installation task ID.
      name: task_id
      required: true
    description: Get installation status.
    name: fortimanager-firewall-policy-package-install-status
    outputs:
    - contextPath: FortiManager.Installation.adom
      description: The ADOM on which the installation occurred.
      type: Number
    - contextPath: FortiManager.Installation.end_tm
      description: The installation task end time.
      type: Number
    - contextPath: FortiManager.Installation.flags
      description: The installation_task_flags.
      type: Number
    - contextPath: FortiManager.Installation.id
      description: The installation task ID.
      type: Number
    - contextPath: FortiManager.Installation.line.detail
      description: The installation status details.
      type: String
    - contextPath: FortiManager.Installation.line.end_tm
      description: The installation task end time.
      type: Number
    - contextPath: FortiManager.Installation.line.err
      description: The installation error.
      type: Number
    - contextPath: FortiManager.Installation.line.history
      description: Installation task historical details.
      type: String
    - contextPath: FortiManager.Installation.line.ip
      description: The installation IP.
      type: String
    - contextPath: FortiManager.Installation.line.name
      description: The installation name.
      type: String
    - contextPath: FortiManager.Installation.line.oid
      description: The installation task oid.
      type: Number
    - contextPath: FortiManager.Installation.line.percent
      description: The installation task completion percent.
      type: Number
    - contextPath: FortiManager.Installation.line.start_tm
      description: The installation task start time.
      type: Number
    - contextPath: FortiManager.Installation.line.state
      description: The installation task state.
      type: String
    - contextPath: FortiManager.Installation.line.vdom
      description: The VDOM on which the installation occurred.
      type: String
    - contextPath: FortiManager.Installation.num_done
      description: The number of done tasks.
      type: Number
    - contextPath: FortiManager.Installation.num_err
      description: The number of errors found.
      type: Number
    - contextPath: FortiManager.Installation.num_lines
      description: The number of installation data lines.
      type: Number
    - contextPath: FortiManager.Installation.num_warn
      description: The number of warnings found.
      type: Number
    - contextPath: FortiManager.Installation.percent
      description: The installation task completion percent.
      type: Number
    - contextPath: FortiManager.Installation.pid
      description: The installation task PID.
      type: Number
    - contextPath: FortiManager.Installation.src
      description: The installation task source.
      type: String
    - contextPath: FortiManager.Installation.start_tm
      description: The installation task start time.
      type: Number
    - contextPath: FortiManager.Installation.state
      description: The installation task state.
      type: String
    - contextPath: FortiManager.Installation.title
      description: The installation task title.
      type: String
    - contextPath: FortiManager.Installation.tot_percent
      description: The installation task completion percent.
      type: Number
    - contextPath: FortiManager.Installation.user
      description: The installation task user.
      type: String
  dockerimage: demisto/python3:3.12.13.10116658
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- No tests
fromversion: 5.0.0