Re: Automate “Mcafee web gateway” actions with Ansible
we don't have an ansible module, but a REST API that can be used and additional functionality to include external data source. Depending on the use case on or the other might fit:
1.) The REST API is documented in the product guide. It will give full access to all lists, rule sets, rules, settings and other options. It requires some efforts on the client side, e.g. you need a source to read the block listed entries from and put that into the policy.
2.) Subscribed lists will allow you to put an MWG style list or some simple plain text list to a web server. MWG can fetch this list every few minutes and update the local lists based on this results. If you have sort of a "global block list" which should be filled by some other department or a ticket system, this might be an easy solution. There is not much efforts required, only some code that reads the source and spits out a list in the proper format (hosted on a web server).
3.) External list will allow you to query a REST endpoint, LDAP server or Postgres Database real time from the rule engine. E.g. is user "andre" comes in you can setup MWG to make a query such as http://myinternalserver.local/blacklist.php?username=asabban. The "blacklist.php" (which is a service that already has to exist...) can return a list of blocked web sites and in the policy you can check what is in the list and apply an action based on this.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.