This URL adds a new connection limiting policy.
Resource URL
POST /connectionlimitingpolicy
Request Parameters
Payload Parameters:
| Field Name | Description | Data Type |
|---|---|---|
| properties | Object that contains the basic properties of the policy | Object |
| connectionLimitingRules | List of object that contains rules | Array |
Details of fields in properties:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policyId | Policy Id | Number | No |
| name | Policy name | String | Yes |
| description | Description of the policy | String | No |
| domainId | Domain Id | Number | Yes |
| visibleToChild | Is policy visible to child | Boolean | Yes |
| lastModTimestamp | Last modified time | String | No |
| lastModUser | Last modified user | String | No |
Details of fields in connectionLimitingRules:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| enabled | Is rule enabled | Boolean | Yes |
| description | Description of the rule | String | No |
| direction | Can be one of these: INBOUND/OUTBOUND/EITHER | String | Yes |
| ruleType | Can be one of these: GTI/PROTOCOL | String | Yes |
| thresholdType | Can be one of these: CONNECTION_RATE/ACTIVE_CONNECTIONS | String | Yes |
| thresholdValue | A valid threshold value between 1 and 65535 | Number | Yes |
| externalReputation | Should be provided when ruleType is GTI Can be one of these: HIGH_RISK/MEDIUM_OR_HIGH_RISK/UNVERIFIED_MEDIUM_OR_HIGH_RISK/ANY | String | Yes |
| externalLocation | Should be provided when ruleType is GTI Can be either "Any" or one of the country from the list of country obtained using the URL: https://<NSM_IP>/sdkapi/connectionlimitingpolicy/countrylist | String | Yes |
| serviceType | Should be provided when ruleType is PROTOCOL. Can be one of these: TCP/UDP/PING_ICMP_ECHO_REQ/ALL_TCP_AND_UDP | String | Yes |
| portNumber | Should be provided when serviceType is TCP/UDP. A valid port number between 1 and 65535 | Number | Yes |
| response | Can be one of these: ALERT_ONLY/ALERT_AND_DROP_EXCESS_CONNECTIONS/ALERT_AND_DENY_EXCESS_CONNECTIONS/ALERT_AND_QUARANTINE | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Unique ID of the created policy | Number |
Example
Request
POST https://%3CNSM_IP%3E/sdkapi/connectionlimitingpolicy
Payload
{
"properties":
{
"name": "Test_CLP1",
"description": "CLP of Child Domain",
"domainId": 101,
"visibleToChild": true
},
"connectionLimitingRules":
[
{
"enabled": true,
"description": "",
"direction": "EITHER",
"ruleType": "PROTOCOL",
"thresholdType": "CONNECTION_RATE",
"thresholdValue": 1000,
"externalReputation": null,
"externalLocation": "Any",
"serviceType": "ALL_TCP_AND_UDP",
"portNumber": null,
"response": "ALERT_ONLY"
}
]
}
Response
{
"createdResourceId":104
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 1903 | Threshold type must be CONNECTION_RATE for ruletype GTI |
| 2 | 400 | 1904 | Cannot specify response DENY_EXCESS_CONNECTION for UDP and ICMP protocol |
| 3 | 400 | 1905 | Invalid name provided |
| 4 | 400 | 1906 | Please provide a domain id |
| 5 | 400 | 1907 | Please provide "visibleToChild" field |
| 6 | 400 | 1908 | Please provide "isEnabled" field |
| 7 | 400 | 1909 | Please provide direction |
| 8 | 400 | 1910 | Please provide threshold value |
| 9 | 400 | 1911 | Please provide rule type |
| 10 | 400 | 1912 | Please provide threshold type |
| 11 | 400 | 1913 | Please provide response type |
| 12 | 400 | 1914 | Please provide external reputation |
| 13 | 400 | 1915 | Policy name already in use |
| 14 | 400 | 1916 | Please provide port number in range 1-65535 |
| 15 | 400 | 1917 | Please provide external location |
| 16 | 400 | 1918 | Invalid country name |