- Home
- Documentation
- VPN
- Resources
- xcsh_ike_phase2_profile (Resource)
xcsh_ike_phase2_profile (Resource)
Manages a IKE Phase2 Profile resource in F5 Distributed Cloud for ike phase2 profile specification. configuration.
~> Note: For more information, see the F5 Distributed Cloud API documentation.
Example Usage
Section titled “Example Usage”# IKEPhase2Profile Resource Example# Manages a IKE Phase2 Profile resource in F5 Distributed Cloud for ike phase2 profile specification.
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Basic IKEPhase2Profile configurationresource "xcsh_ike_phase2_profile" "example" { name = "example-ike-phase2-profile" namespace = "staging"
authentication_algos = ["example-value"] encryption_algos = ["example-value"]}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the IKE Phase2 Profile. Must be unique within the namespace
• namespace - Required String
Namespace where the IKE Phase2 Profile is created
• annotations - Optional Map
Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata
• description - Optional String
Human readable description for the object
• disable - Optional Bool
A value of true administratively disables the object
• labels - Optional Map
Labels is a user defined key value map that can be attached to resources for organization and filtering
Spec Argument Reference
Section titled “Spec Argument Reference”• authentication_algos - Required List Defaults to AUTH_ALG_DEFAULT
Possible values are AUTH_ALG_DEFAULT, SHA256_HMAC, SHA384_HMAC, SHA512_HMAC, AUTH_ALG_NONE
[Enum: AUTH_ALG_DEFAULT|SHA256_HMAC|SHA384_HMAC|SHA512_HMAC|AUTH_ALG_NONE] Choose one or more Authentication Algorithm. Use None option when using the
AES-gcm or AES-ccm encryption algorithms
-> One of the following:
• dh_group_set - Optional Block
Choose the acceptable Diffie Hellman(DH) Group or Groups that you are willing to accept as part of this profile
See Dh Group Set below for details.
• disable_pfs - Optional Object
Configuration parameter for disable pfs
• encryption_algos - Required List Defaults to ENC_ALG_DEFAULT
Possible values are ENC_ALG_DEFAULT, AES128_CBC, AES192_CBC, AES256_CBC, TRIPLE_DES_CBC, AES128_GCM, AES192_GCM, AES256_GCM
[Enum: ENC_ALG_DEFAULT|AES128_CBC|AES192_CBC|AES256_CBC|TRIPLE_DES_CBC|AES128_GCM|AES192_GCM|AES256_GCM] Choose one or more
encryption algorithms
-> One of the following:
• ike_keylifetime_hours - Optional Block
Configuration parameter for IKE keylifetime hours
See IKE Keylifetime Hours below for details.
• ike_keylifetime_minutes - Optional Block
Configuration parameter for IKE keylifetime minutes
See IKE Keylifetime Minutes below for details.
• timeouts - Optional Block
See Timeouts below for details.
• use_default_keylifetime - Optional Object
Configuration parameter for use default keylifetime
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• id - Optional String
Unique identifier for the resource
Dh Group Set
Section titled “Dh Group Set”A dh_group_set block supports the following:
• dh_groups - Optional List Defaults to DH_GROUP_DEFAULT
Possible values are DH_GROUP_DEFAULT, DH_GROUP_14, DH_GROUP_15, DH_GROUP_16, DH_GROUP_17, DH_GROUP_18, DH_GROUP_19, DH_GROUP_20, DH_GROUP_21, DH_GROUP_26
[Enum:
DH_GROUP_DEFAULT|DH_GROUP_14|DH_GROUP_15|DH_GROUP_16|DH_GROUP_17|DH_GROUP_18|DH_GROUP_19|DH_GROUP_20|DH_GROUP_21|DH_GROUP_26] Choose the acceptable Diffie Hellman(DH) Group or Groups that you are willing to accept as part of this profile
Disable Pfs
Section titled “Disable Pfs”A disable_pfs block supports the following:
IKE Keylifetime Hours
Section titled “IKE Keylifetime Hours”An ike_keylifetime_hours block supports the following:
• duration - Optional Number
Duration. Configuration parameter for duration
IKE Keylifetime Minutes
Section titled “IKE Keylifetime Minutes”An ike_keylifetime_minutes block supports the following:
• duration - Optional Number
Duration. Configuration parameter for duration
Timeouts
Section titled “Timeouts”A timeouts block supports the following:
• create - Optional String (Defaults to 10 minutes)
Used when creating the resource
• delete - Optional String (Defaults to 10 minutes)
Used when deleting the resource
• read - Optional String (Defaults to 5 minutes)
Used when retrieving the resource
• update - Optional String (Defaults to 10 minutes)
Used when updating the resource
Use Default Keylifetime
Section titled “Use Default Keylifetime”An use_default_keylifetime block supports the following:
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |
Import
Section titled “Import”Import is supported using the following syntax:
# Import using namespace/name formatterraform import xcsh_ike_phase2_profile.example system/example