This URL adds a new firewall policy and access rules.
Resource URL
POST /firewallpolicy
Request Parameters
Payload Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique firewall policy id, not required for POST | Number | No |
| Policy name | String | Yes |
| Id of domain to which this firewall policy belongs to | Number | Yes |
| Policy visible to child domain | Boolean | Yes |
| Firewall policy description | String | No |
| Last modified time of the firewall policy, not required for POST | String | No |
| Policy is editable or not | Boolean | Yes |
| Policy type, can be "ADVANCED" / "CLASSIC" | String | Yes |
| Policy version, not required for POST | Number | No |
| Latest user that modified the policy, not required for POST | String | No |
| Firewall rules in the policy | Object | Yes |
Details of MemberDetails:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| List of firewall rules in the policy | Array | Yes |
Details of fields in MemberRuleList
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Rule description | String | Yes |
| Is rule enabled or not | Boolean | Yes |
| Action to be performed if the traffic matches this rule. Can be " SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION" | String | Yes |
| Is logging enabled for this rule | Boolean | Yes |
| Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER" | String | Yes |
| Source address rule object list | Array | Yes |
| Source user rule object list | Array | Yes |
| Destination address rule object list | Array | Yes |
| Service rule object list | Array | Yes |
| Application rule object list | Array | Yes |
| Time rule object list | Array | Yes |
Details of SourceAddressObjectList and DestinationAddressObjectList:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique rule object id | String | Yes |
| Rule object name | String | Yes |
| Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP" | String | Yes |
Details of SourceUserObjectList:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique rule object id | String | Yes |
| Rule object name | String | Yes |
| Source user. Can be "USER" / "USER_GROUP" | String | Yes |
Details of ServiceObjectList and ApplicationObjectList:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique service rule object id | String | Yes |
| Rule object name | String | Yes |
| Servic/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP" | String | Yes |
| Application type. Can be "DEFAULT" / "CUSTOM" | String | Yes |
Details of TimeObjectList:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique service rule object id | String | Yes |
| Rule object name | String | Yes |
| Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP" | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Unique ID of the created subinterface | Integer |
Example
Request
POST https://<NSM_IP>/sdkapi/firewallpolicy
{
"Name" : "TestFirewallPolicy",
"DomainId" : 0,
"VisibleToChild" : true,
"Description" : "test the firewallpolicy",
"LastModifiedTime" : "2012-12-12 12:30:47",
"IsEditable" : true,
"PolicyType" : "ADVANCED",
"PolicyVersion" : 1,
"LastModifiedUser" : "admin",
"MemberDetails" : {
"MemberRuleList" : [{
"Description" : "Test Member Rule",
"Enabled" : true,
"Response" : "SCAN",
"IsLogging" : false,
"Direction" : "INBOUND",
"SourceAddressObjectList" : [{
"RuleObjectId" : "AF",
"Name" : "Afghanistan",
"RuleObjectType" : "COUNTRY"
}
],
"DestinationAddressObjectList" : [{
"RuleObjectId" : "101",
"Name" : "hostDNSRule",
"RuleObjectType" : "HOST_DNS_NAME"
}, {
"RuleObjectId" : "102",
"Name" : "hostIpv4",
"RuleObjectType" : "HOST_IPV_4"
}, {
"RuleObjectId" : "103",
"Name" : "ipv4Addressrange",
"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
}, {
"RuleObjectId" : "104",
"Name" : "networkgroup",
"RuleObjectType" : "NETWORK_GROUP"
}
],
"SourceUserObjectList" : [{
"RuleObjectId" : "-1",
"Name" : "Any",
"RuleObjectType" : "USER"
}
],
"ServiceObjectList" : [],
"ApplicationObjectList" : [{
"RuleObjectId" : "1308991488",
"Name" : "100bao",
"RuleObjectType" : "APPLICATION",
"ApplicationType" : "DEFAULT"
}, {
"RuleObjectId" : "106",
"Name" : "applicaionOncutomPort",
"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
"ApplicationType" : "CUSTOM"
}, {
"RuleObjectId" : "105",
"Name" : "applicationgroup",
"RuleObjectType" : "APPLICATION_GROUP",
"ApplicationType" : "CUSTOM"
}
],
"TimeObjectList" : [{
"RuleObjectId" : "107",
"Name" : "finiteTimePeriod",
"RuleObjectType" : "FINITE_TIMING_PERIOD"
}, {
"RuleObjectId" : "108",
"Name" : "recuringTimePeriod",
"RuleObjectType" : "RECURRING_TIME_PERIOD"
}, {
"RuleObjectId" : "109",
"Name" : "recurringTimeperiodGroup",
"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
}
]
}
]
}
}
Response
{
"createdResourceId":120
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 404 | 1105 | Invalid domain |
3 | 400 | 1702 | Invalid rule object type |
4 | 400 | 1804 | Maximum of 10 rule objects are allowed in each object list of an advanced firewall/QoS policy |
5 | 400 | 1805 | Multiple rule objects in a single source/destination object list is not supported for a classic firewall policy |
6 | 400 | 1806 | Only host IPV4/network IPV4 type rule objects are supported for classic firewall policy |
7 | 400 | 1807 | Only service type rule object is supported for classic firewall policy |
8 | 400 | 1808 | Time object list is not applicable for classic firewall policy |
9 | 400 | 1809 | Application object list is not applicable for classic firewall policy |
10 | 400 | 1810 | Multiple rule objects in a single service object list is not supported for a classic firewall policy |
11 | 400 | 1811 | Policy type cannot be modified from advanced to classic |
12 | 400 | 1812 | Deny response is applicable for TCP traffic only |
13 | 400 | 1813 | Source/destination object list is not provided |
14 | 400 | 1814 | Service/application object list is not provided |
15 | 400 | 1815 | Time object list is not provided |
16 | 400 | 1816 | Firewall policy name is required |
17 | 400 | 1817 | For stateless action, application object list is not applicable |
18 | 400 | 1818 | Unsupported firewall policy type |
19 | 406 | 1819 | Stateless response with any/TCP/IP protocol no.6/default services are not allowed |
20 | 400 | 1820 | Is logging should not be enabled for stateless action |
21 | 400 | 1821 | Either application or service object list can be defined in a member rule for an advanced firewall policy |
22 | 400 | 1822 | Composite rule object(Multiple items in a rule object) is allowed for advanced firewall policy only |
23 | 400 | 1824 | Source user object list is not applicable for classic firewall policy |
24 | 400 | 1825 | Source address object list is not applicable for classic firewall policy |
25 | 400 | 1826 | Destination address object list is not applicable for classic firewall policy |
26 | 400 | 1827 | Firewall policy with the same name was defined |
27 | 400 | 1829 | Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore |
28 | 400 | 1830 | Firewall policy name should not be greater than 40 chars |
29 | 400 | 1831 | Firewall policy provided is not upto date |
30 | 400 | 1832 | Source address and destination address object list cannot combine IPV6 rule objects with host IPV4, network IPV4, IPV4 address range, country and host DNS name rule objects |
31 | 400 | 1833 | Require authentication is valid only when source user object list is set to any |
32 | 400 | 1834 | Require authentication is valid only when HTTP (default service) is selected |
33 | 400 | 1835 | Firewall policy description should not be greater than 255 chars |
34 | 400 | 1836 | Member rule description should not be greater than 64 chars |
35 | 400 | 1837 | Source user object list is not provided |
36 | 400 | 1838 | Time object list can contain one finite time period |
37 | 400 | 1839 | Stateless response with source user or source user group rule objects are not allowed |