Introduction

F5 BIG-IP Application Security Manager (ASM) protects web applications from attacks. Using Ansible's f5networks.f5_modules collection, you can automate the retrieval of ASM policy information โ€” useful for auditing, compliance reporting, and configuration management across your F5 infrastructure.

Prerequisites

Install the F5 Collection

ansible-galaxy collection install f5networks.f5_modules

Python Dependencies

pip install f5-sdk f5-icontrol-rest

Connection Setup

F5 modules use the httpapi connection plugin or local connection with provider parameters:

# inventory.ini
[f5]
f5.example.com

[f5:vars]
ansible_connection=httpapi
ansible_httpapi_use_ssl=true
ansible_httpapi_validate_certs=false
ansible_user=admin
ansible_password="{{ vault_f5_password }}"
ansible_network_os=f5networks.f5_modules.bigip

Retrieve ASM Policies

Basic Example

---
- name: Retrieve ASM Policy Facts
  hosts: f5
  connection: local
  collections:
    - f5networks.f5_modules
  gather_facts: false
  vars:
    provider:
      server: "{{ ansible_host }}"
      user: admin
      password: "{{ vault_f5_password }}"
      validate_certs: false
      server_port: 443

  tasks:
    - name: Get ASM policy information
      bigip_device_info:
        gather_subset:
          - asm-policies
        provider: "{{ provider }}"
      register: device_facts

    - name: Display ASM policy names
      ansible.builtin.debug:
        var: device_facts | json_query("asm_policies[*].name")

Available Gather Subsets for F5

SubsetDescription
asm-policiesApplication Security Manager policies
asm-policy-statsASM policy statistics
asm-server-technologiesASM server technologies
asm-signature-setsASM signature sets
ltm-poolsLoad balancer pools
ltm-virtual-serversVirtual servers
system-infoSystem information
devicesDevice cluster info
vlansVLAN configuration
self-ipsSelf IP addresses

Filtering and Reporting

Filter Policies by Name

- name: Find specific ASM policy
  ansible.builtin.set_fact:
    production_policies: >-
      {{ device_facts.asm_policies |
         selectattr('name', 'match', '.*production.*') |
         list }}

- name: Show production policies
  ansible.builtin.debug:
    var: production_policies

Generate Compliance Report

- name: ASM Policy compliance report
  hosts: f5
  connection: local
  collections:
    - f5networks.f5_modules
  vars:
    provider:
      server: "{{ ansible_host }}"
      user: admin
      password: "{{ vault_f5_password }}"
      validate_certs: false
      server_port: 443

  tasks:
    - name: Gather ASM facts
      bigip_device_info:
        gather_subset:
          - asm-policies
        provider: "{{ provider }}"
      register: device_facts

    - name: Generate report
      ansible.builtin.template:
        src: asm_report.j2
        dest: "/tmp/asm_report_{{ ansible_host }}.txt"
      delegate_to: localhost

Report template (asm_report.j2):

ASM Policy Report - {{ ansible_host }}
Generated: {{ ansible_date_time.iso8601 }}
========================================
{% for policy in device_facts.asm_policies %}
Policy: {{ policy.name }}
  Status: {{ policy.active | ternary('Active', 'Inactive') }}
  Type: {{ policy.type | default('N/A') }}
  Enforcement: {{ policy.enforcement_mode | default('N/A') }}
{% endfor %}
Total Policies: {{ device_facts.asm_policies | length }}

Export Policies to JSON

- name: Export ASM policies to file
  ansible.builtin.copy:
    content: "{{ device_facts.asm_policies | to_nice_json }}"
    dest: "/tmp/asm_policies_{{ inventory_hostname }}.json"
  delegate_to: localhost

Multi-Device Inventory

# Scan all F5 devices for ASM policies
- name: Audit ASM policies across fleet
  hosts: f5_devices
  connection: local
  serial: 5
  tasks:
    - name: Gather ASM info
      bigip_device_info:
        gather_subset:
          - asm-policies
        provider: "{{ provider }}"
      register: device_facts

    - name: Alert on missing policies
      ansible.builtin.debug:
        msg: "WARNING: {{ inventory_hostname }} has no ASM policies!"
      when: device_facts.asm_policies | length == 0

Common Issues

Authentication Errors

# Ensure provider vars are correct
provider:
  server: f5.example.com
  user: admin
  password: "{{ vault_password }}"  # Use Ansible Vault!
  validate_certs: false  # Set true in production with valid certs
  server_port: 443

Timeout on Large Deployments

- name: Gather with extended timeout
  bigip_device_info:
    gather_subset:
      - asm-policies
    provider: "{{ provider }}"
  timeout: 120

No ASM License

If ASM isn't licensed, the asm-policies subset returns an empty list. Check licensing:

- name: Check F5 system info
  bigip_device_info:
    gather_subset:
      - system-info
    provider: "{{ provider }}"
  register: sys_info

- name: Show licensed modules
  ansible.builtin.debug:
    var: sys_info.system_info.product_information

Conclusion

The bigip_device_info module with the asm-policies gather subset retrieves all ASM policy information from F5 BIG-IP devices. Use json_query filters to extract specific fields, generate compliance reports with Jinja2 templates, and audit your entire F5 fleet with a single playbook. Always store F5 credentials in Ansible Vault and use validate_certs: true in production environments.