meraki_mx_l3_firewall – Manage MX appliance layer 3 firewalls in the Meraki cloud¶
New in version 2.7.
Synopsis¶
- Allows for creation, management, and visibility into layer 3 firewalls implemented on Meraki MX firewalls. 
Parameters¶
Notes¶
Note
- Module assumes a complete list of firewall rules are passed as a parameter. 
- If there is interest in this module allowing manipulation of a single firewall rule, please submit an issue against this module. 
- More information about the Meraki API can be found at https://dashboard.meraki.com/api_docs. 
- Some of the options are likely only used for developers within Meraki. 
- As of Ansible 2.9, Meraki modules output keys as snake case. To use camel case, set the - ANSIBLE_MERAKI_FORMATenvironment variable to- camelcase.
- Ansible’s Meraki modules will stop supporting camel case output in Ansible 2.13. Please update your playbooks. 
Examples¶
- name: Query firewall rules
  meraki_mx_l3_firewall:
    auth_key: abc123
    org_name: YourOrg
    net_name: YourNet
    state: query
  delegate_to: localhost
- name: Set two firewall rules
  meraki_mx_l3_firewall:
    auth_key: abc123
    org_name: YourOrg
    net_name: YourNet
    state: present
    rules:
      - comment: Block traffic to server
        src_cidr: 192.0.1.0/24
        src_port: any
        dest_cidr: 192.0.2.2/32
        dest_port: any
        protocol: any
        policy: deny
      - comment: Allow traffic to group of servers
        src_cidr: 192.0.1.0/24
        src_port: any
        dest_cidr: 192.0.2.0/24
        dest_port: any
        protocol: any
        policy: permit
  delegate_to: localhost
- name: Set one firewall rule and enable logging of the default rule
  meraki_mx_l3_firewall:
    auth_key: abc123
    org_name: YourOrg
    net_name: YourNet
    state: present
    rules:
      - comment: Block traffic to server
        src_cidr: 192.0.1.0/24
        src_port: any
        dest_cidr: 192.0.2.2/32
        dest_port: any
        protocol: any
        policy: deny
    syslog_default_rule: yes
  delegate_to: localhost
Return Values¶
Common return values are documented here, the following are the fields unique to this module:
Status¶
- This module is not guaranteed to have a backwards compatible interface. [preview] 
- This module is maintained by the Ansible Community. [community] 
Authors¶
- Kevin Breit (@kbreit) 
Hint
If you notice any issues in this documentation, you can edit this document to improve it.
