This URL adds a new firewall policy and access rules.
Resource URL
POST /firewallpolicy
Request Parameters
Payload Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| FirewallPolicyId | Unique firewall policy id, not required for POST | Number | No |
| Name | Policy name | String | Yes |
| DomainId | Id of domain to which this firewall policy belongs to | Number | Yes |
| VisibleToChild | Policy visible to child domain | Boolean | Yes |
| Description | Firewall policy description | String | No |
| LastModifiedTime | Last modified time of the firewall policy, not required for POST | String | No |
| IsEditable | Policy is editable or not | Boolean | Yes |
| PolicyType | Policy type, can be "ADVANCED" / "CLASSIC" | String | Yes |
| PolicyVersion | Policy version, not required for POST | Number | No |
| LastModifiedUser | Latest user that modified the policy, not required for POST | String | No |
| MemberDetails | Firewall rules in the policy | Object | Yes |
Details of MemberDetails:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| MemberRuleList | List of firewall rules in the policy | Array | Yes |
Details of fields in MemberRuleList
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Description | Rule description | String | Yes |
| Enabled | Is rule enabled or not | Boolean | Yes |
| Response | Action to be performed if the traffic matches this rule. Can be " SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION" | String | Yes |
| isLogging | Is logging enabled for this rule | Boolean | Yes |
| Direction | Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER" | String | Yes |
| SourceAddressObjectList | Source address rule object list | Array | Yes |
| SourceUserObjectList | Source user rule object list | Array | Yes |
| DestinationAddressObjectList | Destination address rule object list | Array | Yes |
| ServiceObjectList | Service rule object list | Array | Yes |
| ApplicationObjectList | Application rule object list | Array | Yes |
| TimeObjectList | Time rule object list | Array | Yes |
Details of SourceAddressObjectList and DestinationAddressObjectList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| RuleObjectId | Unique rule object id | String | Yes |
| Name | Rule object name | String | Yes |
| RuleObjectType | Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP" | String | Yes |
Details of SourceUserObjectList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| RuleObjectId | Unique rule object id | String | Yes |
| Name | Rule object name | String | Yes |
| RuleObjectType | Source user. Can be "USER" / "USER_GROUP" | String | Yes |
Details of ServiceObjectList and ApplicationObjectList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| RuleObjectId | Unique service rule object id | String | Yes |
| Name | Rule object name | String | Yes |
| RuleObjectType | Servic/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP" | String | Yes |
| ApplicationType | Application type. Can be "DEFAULT" / "CUSTOM" | String | Yes |
Details of TimeObjectList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| RuleObjectId | Unique service rule object id | String | Yes |
| Name | Rule object name | String | Yes |
| RuleObjectType | Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP" | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Unique ID of the created subinterface | Integer |
Example
Request
POST https://%3CNSM_IP%3E/sdkapi/firewallpolicy
{
"Name" : "TestFirewallPolicy",
"DomainId" : 0,
"VisibleToChild" : true,
"Description" : "test the firewallpolicy",
"LastModifiedTime" : "2012-12-12 12:30:47",
"IsEditable" : true,
"PolicyType" : "ADVANCED",
"PolicyVersion" : 1,
"LastModifiedUser" : "admin",
"MemberDetails" : {
"MemberRuleList" : [{
"Description" : "Test Member Rule",
"Enabled" : true,
"Response" : "SCAN",
"IsLogging" : false,
"Direction" : "INBOUND",
"SourceAddressObjectList" : [{
"RuleObjectId" : "AF",
"Name" : "Afghanistan",
"RuleObjectType" : "COUNTRY"
}
],
"DestinationAddressObjectList" : [{
"RuleObjectId" : "101",
"Name" : "hostDNSRule",
"RuleObjectType" : "HOST_DNS_NAME"
}, {
"RuleObjectId" : "102",
"Name" : "hostIpv4",
"RuleObjectType" : "HOST_IPV_4"
}, {
"RuleObjectId" : "103",
"Name" : "ipv4Addressrange",
"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
}, {
"RuleObjectId" : "104",
"Name" : "networkgroup",
"RuleObjectType" : "NETWORK_GROUP"
}
],
"SourceUserObjectList" : [{
"RuleObjectId" : "-1",
"Name" : "Any",
"RuleObjectType" : "USER"
}
],
"ServiceObjectList" : [],
"ApplicationObjectList" : [{
"RuleObjectId" : "1308991488",
"Name" : "100bao",
"RuleObjectType" : "APPLICATION",
"ApplicationType" : "DEFAULT"
}, {
"RuleObjectId" : "106",
"Name" : "applicaionOncutomPort",
"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
"ApplicationType" : "CUSTOM"
}, {
"RuleObjectId" : "105",
"Name" : "applicationgroup",
"RuleObjectType" : "APPLICATION_GROUP",
"ApplicationType" : "CUSTOM"
}
],
"TimeObjectList" : [{
"RuleObjectId" : "107",
"Name" : "finiteTimePeriod",
"RuleObjectType" : "FINITE_TIMING_PERIOD"
}, {
"RuleObjectId" : "108",
"Name" : "recuringTimePeriod",
"RuleObjectType" : "RECURRING_TIME_PERIOD"
}, {
"RuleObjectId" : "109",
"Name" : "recurringTimeperiodGroup",
"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
}
]
}
]
}
}
Response
{
"createdResourceId":120
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | Internal error |
| 2 | 404 | 1105 | Invalid domain |
| 3 | 400 | 1702 | Invalid rule object type |
| 4 | 400 | 1804 | Maximum of 10 rule objects are allowed in each object list of an advanced firewall/QoS policy |
| 5 | 400 | 1805 | Multiple rule objects in a single source/destination object list is not supported for a classic firewall policy |
| 6 | 400 | 1806 | Only host IPV4/network IPV4 type rule objects are supported for classic firewall policy |
| 7 | 400 | 1807 | Only service type rule object is supported for classic firewall policy |
| 8 | 400 | 1808 | Time object list is not applicable for classic firewall policy |
| 9 | 400 | 1809 | Application object list is not applicable for classic firewall policy |
| 10 | 400 | 1810 | Multiple rule objects in a single service object list is not supported for a classic firewall policy |
| 11 | 400 | 1811 | Policy type cannot be modified from advanced to classic |
| 12 | 400 | 1812 | Deny response is applicable for TCP traffic only |
| 13 | 400 | 1813 | Source/destination object list is not provided |
| 14 | 400 | 1814 | Service/application object list is not provided |
| 15 | 400 | 1815 | Time object list is not provided |
| 16 | 400 | 1816 | Firewall policy name is required |
| 17 | 400 | 1817 | For stateless action, application object list is not applicable |
| 18 | 400 | 1818 | Unsupported firewall policy type |
| 19 | 406 | 1819 | Stateless response with any/TCP/IP protocol no.6/default services are not allowed |
| 20 | 400 | 1820 | Is logging should not be enabled for stateless action |
| 21 | 400 | 1821 | Either application or service object list can be defined in a member rule for an advanced firewall policy |
| 22 | 400 | 1822 | Composite rule object(Multiple items in a rule object) is allowed for advanced firewall policy only |
| 23 | 400 | 1824 | Source user object list is not applicable for classic firewall policy |
| 24 | 400 | 1825 | Source address object list is not applicable for classic firewall policy |
| 25 | 400 | 1826 | Destination address object list is not applicable for classic firewall policy |
| 26 | 400 | 1827 | Firewall policy with the same name was defined |
| 27 | 400 | 1829 | Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore |
| 28 | 400 | 1830 | Firewall policy name should not be greater than 40 chars |
| 29 | 400 | 1831 | Firewall policy provided is not upto date |
| 30 | 400 | 1832 | Source address and destination address object list cannot combine IPV6 rule objects with host IPV4, network IPV4, IPV4 address range, country and host DNS name rule objects |
| 31 | 400 | 1833 | Require authentication is valid only when source user object list is set to any |
| 32 | 400 | 1834 | Require authentication is valid only when HTTP (default service) is selected |
| 33 | 400 | 1835 | Firewall policy description should not be greater than 255 chars |
| 34 | 400 | 1836 | Member rule description should not be greater than 64 chars |
| 35 | 400 | 1837 | Source user object list is not provided |
| 36 | 400 | 1838 | Time object list can contain one finite time period |
| 37 | 400 | 1839 | Stateless response with source user or source user group rule objects are not allowed |