summaryrefslogtreecommitdiffstats
path: root/ansible_collections/cisco/ise/playbooks/allowed_protocols.yml
blob: de95f9fcc32a886ba238a8a04ee608fd441e7f82 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
---
- hosts: ise_servers
  gather_facts: false
  tasks:
    # - name: Get allowed protocols, skip first one
    #   cisco.ise.allowed_protocols_info:
    #     ise_hostname: "{{ ise_hostname }}"
    #     ise_username: "{{ ise_username }}"
    #     ise_password: "{{ ise_password }}"
    #     ise_verify: "{{ ise_verify }}"
    #     page: 2
    #     size: 1
    #   register: result

    # - name: Get allowed protocols by name
    #   cisco.ise.allowed_protocols_info:
    #     ise_hostname: "{{ ise_hostname }}"
    #     ise_username: "{{ ise_username }}"
    #     ise_password: "{{ ise_password }}"
    #     ise_verify: "{{ ise_verify }}"
    #     name: "Default Network Access"
    #   register: result

    # - name: Get allowed protocols by id
    #   cisco.ise.allowed_protocols_info:
    #     ise_hostname: "{{ ise_hostname }}"
    #     ise_username: "{{ ise_username }}"
    #     ise_password: "{{ ise_password }}"
    #     ise_verify: "{{ ise_verify }}"
    #     id: "92613980-8c01-11e6-996c-525400b48521"
    #   register: result

    - name: Create or update allowed protocols
      cisco.ise.allowed_protocols:
        ise_hostname: "{{ ise_hostname }}"
        ise_username: "{{ ise_username }}"
        ise_password: "{{ ise_password }}"
        ise_verify: "{{ ise_verify }}"
        state: present
        name: Test Device Admin
        description: Test Allowed Protocol Service Device Admin
        processHostLookup: false
        allowPapAscii: true
        allowChap: true
        allowMsChapV1: true
        allowMsChapV2: false
        allowEapMd5: false
        allowLeap: false
        allowEapTls: false
        allowEapTtls: false
        allowEapFast: false
        allowPeap: false
        allowTeap: false
        allowPreferredEapProtocol: false
        eapTlsLBit: false
        allowWeakCiphersForEap: false
        requireMessageAuth: false
      register: result

    - name: Print Allowed Protocol
      ansible.builtin.debug:
        var: result