zscaler.ziacloud.zia_ips_signature_rules module – Manages ZIA custom IPS Signature Rules

Note

This module is part of the zscaler.ziacloud collection (version 2.2.3).

It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install zscaler.ziacloud. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: zscaler.ziacloud.zia_ips_signature_rules.

New in zscaler.ziacloud 2.1.0

Synopsis

  • Adds, updates, or deletes a custom IPS (Intrusion Prevention System) signature rule.

  • On create, the supplied rule_text is validated against the ZIA dynamic-validation endpoint before submission.

Requirements

The below requirements are needed on the host that executes this module.

Parameters

Parameter

Comments

api_key

string

A string that contains the obfuscated API key.

client_id

string

The client ID for OAuth2 authentication.

client_secret

string

The client secret for OAuth2 authentication.

cloud

string

The Zscaler cloud name provisioned for your organization.

Choices:

  • "beta"

  • "production"

  • "zscaler"

  • "zscalerbeta"

  • "zscalergov"

  • "zscalerone"

  • "zscalerten"

  • "zscalerthree"

  • "zscalertwo"

  • "zscloud"

  • "zspreview"

description

string

Additional notes or information about the IPS Signature Rule.

id

integer

The unique identifier for the IPS Signature Rule.

name

string / required

The name of the IPS Signature Rule.

password

string

A string that contains the password for the API admin.

private_key

string

The private key for JWT-based OAuth2 authentication.

provider

dictionary

A dict containing authentication credentials.

api_key

string

Obfuscated API key.

client_id

string

OAuth2 client ID.

client_secret

string

OAuth2 client secret.

cloud

string

Zscaler cloud name.

Choices:

  • "beta"

  • "production"

  • "zscaler"

  • "zscalerbeta"

  • "zscalergov"

  • "zscalerone"

  • "zscalerten"

  • "zscalerthree"

  • "zscalertwo"

  • "zscloud"

  • "zspreview"

password

string

Password for the API admin.

private_key

string

Private key for OAuth2 JWT.

sandbox_cloud

string

Sandbox Cloud environment.

sandbox_token

string

Sandbox API Key.

use_legacy_client

boolean

Whether to use the legacy Zscaler API client.

Choices:

  • false ← (default)

  • true

username

string

Email ID of the API admin.

vanity_domain

string

Vanity domain for OAuth2.

rule_text

string

The custom signature rule text in Suricata/Snort-style syntax.

On create, this value is validated against the ZIA dynamic-validation endpoint before submission.

sandbox_cloud

string

The Sandbox cloud environment for API access.

sandbox_token

string

A string that contains the Sandbox API Key.

state

string

Specifies the desired state of the resource.

Choices:

  • "present" ← (default)

  • "absent"

use_legacy_client

boolean

Whether to use the legacy Zscaler API client.

Choices:

  • false ← (default)

  • true

username

string

A string that contains the email ID of the API admin.

vanity_domain

string

The vanity domain provisioned by Zscaler for OAuth2 flows.

Notes

Note

  • Check mode is supported.

Examples

- name: Create/Update an IPS Signature Rule
  zscaler.ziacloud.zia_ips_signature_rules:
    provider: '{{ provider }}'
    name: "Custom_IPS_Rule_Example"
    description: "Blocks requests to /admin"
    rule_text: >-
      alert http any any -> any any (msg:"HTTP /admin"; content:"/admin";
      http_uri; nocase; sid:1000010; rev:1;)
    state: present

- name: Delete an IPS Signature Rule by name
  zscaler.ziacloud.zia_ips_signature_rules:
    provider: '{{ provider }}'
    name: "Custom_IPS_Rule_Example"
    state: absent

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

data

dictionary

The IPS Signature Rule resource record after the operation.

Returned: on success

description

string

Additional notes about the IPS Signature Rule.

Returned: success

Sample: "Blocks requests to /admin"

id

integer

The unique identifier for the IPS Signature Rule.

Returned: success

Sample: 1254654

name

string

The name of the IPS Signature Rule.

Returned: success

Sample: "Custom_IPS_Rule_Example"

rule_text

string

The custom signature rule text.

Returned: success

Authors

  • William Guilherme (@willguibr)