Introduction
F5 BIG-IP Application Security Manager (ASM) protects web applications from attacks. Using Ansible's f5networks.f5_modules collection, you can automate the retrieval of ASM policy information โ useful for auditing, compliance reporting, and configuration management across your F5 infrastructure.
Prerequisites
Install the F5 Collection
ansible-galaxy collection install f5networks.f5_modules
Python Dependencies
pip install f5-sdk f5-icontrol-rest
Connection Setup
F5 modules use the httpapi connection plugin or local connection with provider parameters:
# inventory.ini
[f5]
f5.example.com
[f5:vars]
ansible_connection=httpapi
ansible_httpapi_use_ssl=true
ansible_httpapi_validate_certs=false
ansible_user=admin
ansible_password="{{ vault_f5_password }}"
ansible_network_os=f5networks.f5_modules.bigip
Retrieve ASM Policies
Basic Example
---
- name: Retrieve ASM Policy Facts
hosts: f5
connection: local
collections:
- f5networks.f5_modules
gather_facts: false
vars:
provider:
server: "{{ ansible_host }}"
user: admin
password: "{{ vault_f5_password }}"
validate_certs: false
server_port: 443
tasks:
- name: Get ASM policy information
bigip_device_info:
gather_subset:
- asm-policies
provider: "{{ provider }}"
register: device_facts
- name: Display ASM policy names
ansible.builtin.debug:
var: device_facts | json_query("asm_policies[*].name")
Available Gather Subsets for F5
| Subset | Description |
|---|---|
asm-policies | Application Security Manager policies |
asm-policy-stats | ASM policy statistics |
asm-server-technologies | ASM server technologies |
asm-signature-sets | ASM signature sets |
ltm-pools | Load balancer pools |
ltm-virtual-servers | Virtual servers |
system-info | System information |
devices | Device cluster info |
vlans | VLAN configuration |
self-ips | Self IP addresses |
Filtering and Reporting
Filter Policies by Name
- name: Find specific ASM policy
ansible.builtin.set_fact:
production_policies: >-
{{ device_facts.asm_policies |
selectattr('name', 'match', '.*production.*') |
list }}
- name: Show production policies
ansible.builtin.debug:
var: production_policies
Generate Compliance Report
- name: ASM Policy compliance report
hosts: f5
connection: local
collections:
- f5networks.f5_modules
vars:
provider:
server: "{{ ansible_host }}"
user: admin
password: "{{ vault_f5_password }}"
validate_certs: false
server_port: 443
tasks:
- name: Gather ASM facts
bigip_device_info:
gather_subset:
- asm-policies
provider: "{{ provider }}"
register: device_facts
- name: Generate report
ansible.builtin.template:
src: asm_report.j2
dest: "/tmp/asm_report_{{ ansible_host }}.txt"
delegate_to: localhost
Report template (asm_report.j2):
ASM Policy Report - {{ ansible_host }}
Generated: {{ ansible_date_time.iso8601 }}
========================================
{% for policy in device_facts.asm_policies %}
Policy: {{ policy.name }}
Status: {{ policy.active | ternary('Active', 'Inactive') }}
Type: {{ policy.type | default('N/A') }}
Enforcement: {{ policy.enforcement_mode | default('N/A') }}
{% endfor %}
Total Policies: {{ device_facts.asm_policies | length }}
Export Policies to JSON
- name: Export ASM policies to file
ansible.builtin.copy:
content: "{{ device_facts.asm_policies | to_nice_json }}"
dest: "/tmp/asm_policies_{{ inventory_hostname }}.json"
delegate_to: localhost
Multi-Device Inventory
# Scan all F5 devices for ASM policies
- name: Audit ASM policies across fleet
hosts: f5_devices
connection: local
serial: 5
tasks:
- name: Gather ASM info
bigip_device_info:
gather_subset:
- asm-policies
provider: "{{ provider }}"
register: device_facts
- name: Alert on missing policies
ansible.builtin.debug:
msg: "WARNING: {{ inventory_hostname }} has no ASM policies!"
when: device_facts.asm_policies | length == 0
Common Issues
Authentication Errors
# Ensure provider vars are correct
provider:
server: f5.example.com
user: admin
password: "{{ vault_password }}" # Use Ansible Vault!
validate_certs: false # Set true in production with valid certs
server_port: 443
Timeout on Large Deployments
- name: Gather with extended timeout
bigip_device_info:
gather_subset:
- asm-policies
provider: "{{ provider }}"
timeout: 120
No ASM License
If ASM isn't licensed, the asm-policies subset returns an empty list. Check licensing:
- name: Check F5 system info
bigip_device_info:
gather_subset:
- system-info
provider: "{{ provider }}"
register: sys_info
- name: Show licensed modules
ansible.builtin.debug:
var: sys_info.system_info.product_information
Related Articles
- Ansible Network Automation Guide
- Ansible Best Practices Guide
- Ansible Vault: Encrypt Sensitive Data
- Ansible Debug Module Guide
Conclusion
The bigip_device_info module with the asm-policies gather subset retrieves all ASM policy information from F5 BIG-IP devices. Use json_query filters to extract specific fields, generate compliance reports with Jinja2 templates, and audit your entire F5 fleet with a single playbook. Always store F5 credentials in Ansible Vault and use validate_certs: true in production environments.