使用Ansible ping模块测试Fortigate主机时出现‘Unknown action 0’错误求助
Ansible ping模块在Fortigate/Cisco设备上执行失败问题
问题描述
我是Ansible新手,目标是管理Fortigate/Cisco设备。已搭建Ubuntu 22.04虚拟机并安装所有Ansible运行所需组件,创建的hosts文件如下:
[firewalls] 10.23.60.120 10.23.60.122
能正常ping通各防火墙并通过SSH连接,但执行ansible -i hosts firewalls -m ping命令时出现错误,错误输出如下:
[WARNING]: Platform unknown on host 10.23.60.120 is using the discovered Python interpreter at /usr/bin/python, but future installation of another Python interpreter could change the meaning of that path. See https://docs.ansible.com/ansible-core/2.13/reference_appendices/interpreter_discovery.html for more information. 10.23.60.120 | FAILED! => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "module_stderr": "Shared connection to 10.23.60.120 closed.\r\n", "module_stdout": "TR1-SDWAN-LAB-01 # 8415: Unknown action 0\r\nCommand fail. Return code -1\r\n\r\n TR1-SDWAN-LAB-01 # ", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 0 }
问题原因
Ansible默认的ping模块基于Python运行,但Fortigate/Cisco这类网络设备的操作系统(如FortiOS)通常没有安装Python环境,也无法兼容标准Python模块,直接调用会触发执行失败。
解决方法
1. 使用网络设备专用ping模块
针对不同厂商设备,使用对应的Ansible专用集合模块:
- 安装Fortigate集合:
ansible-galaxy collection install fortinet.fortios
- 安装Cisco IOS集合:
ansible-galaxy collection install cisco.ios
编写playbook执行ping测试(以Fortigate为例):
- name: Test Fortigate reachability hosts: firewalls gather_facts: no collections: - fortinet.fortios tasks: - name: Execute ping from Fortigate fortios_system_ping: vdom: "root" system_ping: destination: "10.23.60.1" # 替换为你的测试目标IP count: 3 register: ping_result - name: Show ping result debug: var: ping_result
2. 用raw模块执行原生CLI ping命令
直接调用设备CLI的ping命令,无需依赖Python:
ansible -i hosts firewalls -m raw -a "ping 10.23.60.1 -c 3"
3. 禁用Python解释器自动发现
在hosts文件中指定非Python解释器,消除警告并适配设备环境:
[firewalls] 10.23.60.120 ansible_python_interpreter=/bin/sh 10.23.60.122 ansible_python_interpreter=/bin/sh
内容的提问来源于stack exchange,提问作者knicholson
相关产品推荐
相关产品推荐

