This URL creates the inspection options policy.
Resource URL
POST /protectionoptionspolicy/
Request Parameters
Payload Parameters:
| Field Name | Description | Data Type |
|---|---|---|
| policyId | Policy id | Number |
| policyName | Policy name | String |
| domainId | Domain id | Number |
| visibleToChild | Visible to child | Boolean |
| description | Description | String |
| protectionOptions | All options tabs | Object |
Details of protectionOptions:
| Field Name | Description | Data Type |
|---|---|---|
| inspectionOptions | Inspection options | Object |
| advancedBotnetDetectionOptions | Advanced botnet detection options | Object |
| gtiEndpointReputationAnalysysOptions | GTI endpoint reputation analysis options | Object |
| webserverHuresticAnalysysOptions | Web server heuristic analysis options | Object |
| webserverDOSOptions | Web server DoS options | Object |
Details of inspectionOptions:
| Field Name | Description | Data Type |
|---|---|---|
| httpResponseTrafficScanning | HTTP response traffic scanning | String |
| httpResponseDecompression | HTTP response decompression | String |
| chunkedHTTPResponseDecoding | Chunked HTTP response decoding | String |
| htmlEncodedHTTPResponseDecoding | HTML encoded HTTP response decoding | String |
| base64SMTPDecoding | Base64 SMTP decoding | String |
| description | Description | String |
| quotedPrintableSMTPDecoding | Quoted printable SMTP decoding | String |
| msRPCSMBFragmentReassembly | MSRPC SMB fragment reassembly | String |
| msOfficeDeepFileInspection | Microsoft Office deep file inspection | String |
| xffHeaderParsing | XFF header parsing | String |
| layer7DataCollection | Layer 7 data collection | String |
| passiveDeviceProfiling | Passive device profiling | String |
| attackBlockingSimulation | Attack blocking simulation | String |
Possible values for above attributes should be:
- INBOUND_ONLY
- OUTBOUND_ONLY
- DISABLED
- INBOUND_AND_OUTBOUND
Details of advancedBotnetDetectionOptions:
| Field Name | Description | Data Type |
|---|---|---|
| advancedBotnetDetection | Advanced botnet detection | String |
| sensitivity | Sensitivity | String |
| fastFluxDetection | Fast flux detection | String |
| domainGenerationAlgorithmDetection | Domain generation algorithm detection | String |
| domainNameAllowlistProcessing | Domain name allow list processing | String |
| exportTrafficToNTBA | Export traffic to NTBA | Boolean |
| dnsSinkHooling | DNS sink holing | String |
Possible values for above attributes should be:
- INBOUND_ONLY
- OUTBOUND_ONLY
- DISABLED
- INBOUND_AND_OUTBOUND
Possible values for sensitivity should be:
- LOW
- MEDIUM
- HIGH
Details of gtiEndpointReputationAnalysysOptions:
| Field Name | Description | Data Type |
|---|---|---|
| gtiEndpointReputationAnalysys | GTI endpoint reputation analysis
|
String |
| useToInfluenceSmartBlocking | Use to influence SmartBlocking | Boolean |
| excludeInternalEndpoint | Exclude internal endpoint | Boolean |
| cidrsExcluded | CIDRs excluded | Stringlist |
| protocalsExcluded | Protocols excluded | Stringlist |
| urlReputationAnalysis | URL reputation analysis
Valid Values:
|
String |
| urlReputationMinimumRisk | URL reputation minium risk:
Valid Values:
|
String |
Details of webserverHuresticAnalysysOptions:
| Field Name | Description | Data Type |
|---|---|---|
| huresticAnalysys | Heuristic analysis. Direction value as specified above | String |
| websitePathToProtect | Options: ALL or SPECIFIC | String |
| blockedTextList | Blocked text list | Stringlist |
| websitePathToProtectList | Website path to protect list | Stringlist |
Details of webserverDOSOptions:
| Field Name | Description | Data Type |
|---|---|---|
| dosPrevention | DOS prevention: Direction mode | String |
| maxConnectionAllowedToWS | Max connection allowed to WS | Number |
| slowConnectionAttackPrevention | Slow connection attack prevention | Boolean |
| maxHTTPRequestPERSecondTOAnyPath | Max HTTP request per second to any path | Number |
| websitePathToProtect | Website path to protect options: ALL or SPECIFIC | String |
| browserDetectionMethod | Browser detection method | String |
| websitePathToProtectList | Website path to protect list | Objectlist |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Policy id | Int |
Example
Request
POST https://<NSM_IP>/sdkapi/protectionoptionspolicy/
{
"policyName": "httpresponse",
"domainId": 0,
"visibleToChild": true,
"description": "Enable xff",
"isEditable": true,
"protectionOptions":
{
"inspectionOptions":
{
"httpResponseTrafficScanning": "INBOUND_AND_OUTBOUND",
"chunkedHTTPResponseDecoding": "DISABLED",
"htmlEncodedHTTPResponseDecoding": "DISABLED",
"base64SMTPDecoding": "DISABLED",
"quotedPrintableSMTPDecoding": "DISABLED",
"msRPCSMBFragmentReassembly": "DISABLED",
“msOfficeDeepFileInspection”: “DISABLED”,
"xffHeaderParsing": "DISABLED",
"layer7DataCollection": "DISABLED",
"passiveDeviceProfiling": "DISABLED",
"attackBlockingSimulation": false
},
"advancedBotnetDetectionOptions":
{
"advancedBotnetDetection": "DISABLED",
"exportTrafficToNTBA": false
},
"gtiEndpointReputationAnalysysOptions":
{
"gtiEndpointReputationAnalysys": "DISABLED",
"useToInfluenceSmartBlocking": false,
"excludeInternalEndpoint": false
“urlReputationAnalysis”: “INBOUND_ONLY”,
“urlReputationMinimumRisk:”MEDIUM”
},
"webserverHuresticAnalysysOptions":
{
"huresticAnalysys": "DISABLED"
},
"webserverDOSOptions":
{
"dosPrevention": "DISABLED",
"maxConnectionAllowedToWS": 0,
"slowConnectionAttackPrevention": false,
"maxHTTPRequestPERSecondTOAnyPath": 0,
"clientBrowserDetection": false
}
}
}
Response
{
"createdResourceId": 101
}
Error Information
Following error code is returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 4301 | Invalid domain id |