This URL creates/updates a light weight policy for a specific interface or sub interface.
Resource URL
POST /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensor_id | Sensor Id | Number | Yes |
| interface_id or subinterface_id | Unique interface/sub interface id | Number | Yes |
Payload Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| PolicyDescriptor | Baseline IPS policy details | Object | Yes |
Details of PolicyDescriptor:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| PolicyName | Baseline IPS policy name | String | Yes |
| Description | Policy description | String | Yes |
| IsVisibleToChildren | Is policy visible to child domain | Boolean | Yes |
| InboundRuleSet | Inbound policy rule set | String | Yes |
| OutboundRuleSet | Outbound policy rule set | String | Yes |
| AttackCategory | Attack category | Object | Yes |
| OutboundAttackCategory | Outbound attack category | Object | Yes |
| DosPolicy | DoS policy | Object | Yes |
| ReconPolicy | Recon policy | Object | Yes |
| DosResponseSensitivityLevel | DoS response sensitivity level | Number | Yes |
| IsEditable | Is policy editable | Boolean | Yes |
| Timestamp | Time stamp at which the policy was added | String | Yes |
| VersionNum | Policy version number | Number | Yes |
| IsLightWeightPolicy | Is light weight policy configured | Boolean | Yes |
Details of object in AttackCategory:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ExpolitAttackList | List of exploit attacks | Array | Yes |
Details of object in ExpolitAttackList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attackName | Attack name | String | Yes |
| nspId | NSP ID of the attack | String | Yes |
| severity | Attack severity, number between 0 & 9 | Number | Yes |
| isSeverityCustomized | Is attack severity customized | Boolean | Yes |
| isEnabled | Is attack enabled | Boolean | Yes |
| isAlertCustomized | Is alert customized | Boolean | Yes |
| isRecommendedForSmartBlocking | Is attack recommended for smart blocking | Boolean | Yes |
| AttackResponse | Attack response | Object | Yes |
| notification | Notifications configured | Object | Yes |
| protocolList | List of protocols | Array | Yes |
| applicationsImpactedList | List of applications impacted | Array | Yes |
| attackVector | List of attack vectors | Array | Yes |
| benignTriggerProbability | Attack benign trigger probability | String | Yes |
| target | Attack target, can be "Server" or "Client" | String | Yes |
| blockingType | Blocking type, can be "Attack Packet" | String | Yes |
| subCategory | Attack sub category | String | Yes |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String | Yes |
| isAttackCustomized | Is attack customized | Boolean | Yes |
Details of object in AttackResponse:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| TCPReset | TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” | String | Yes |
| isTCPResetCustomized | Is TCP reset customized | Boolean | Yes |
| isICMPSend | Send ICMP host unreachable to Source | Boolean | Yes |
| isICMPSendCustomized | Send ICMP host unreachable to Source customized | Boolean | Yes |
| mcafeeNACNotification | NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” | String | Yes |
| isMcafeeNACNotificationEnabled | Is NAC notification enabled | Boolean | Yes |
| isQuarantineCustomized | Is quarantine customized | Boolean | Yes |
| isRemediateEnabled | Is remediate enabled | Boolean | Yes |
| blockingOption | Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” | String | Yes |
| isBlockingOptionCustomized | Is blocking option customized | Boolean | Yes |
| isCapturedPrior | Should application data be captured prior to attack | Boolean | Yes |
| isCapturedPriorCustomized | Should application data be captured prior to attack customized | Boolean | Yes |
| action | Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” | String | Yes |
| isLogCustomized | Is logging customized | Boolean | Yes |
| flow | Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” | String | Yes |
| isFlowCustomized | Customize flow type | Boolean | Yes |
| isNbytesCustomized | Is logging N bytes in each packet customized | Boolean | Yes |
| numberOfBytesInEachPacket | Number of bytes to be logged in each packet | Object | Yes |
| loggingDuration | Packet logging duration | Object | Yes |
| TimeStamp | Time stamp | String | Yes |
Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| LogEntirePacket | Log entire packet | Object | Yes |
| CaptureNBytes | Capture N bytes | Object | Yes |
Details of object in CaptureNBytes:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| NumberOfBytes | Number of bytes to log | Number | Yes |
Details of object in loggingDuration (Can be either of the below mentioned):
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| AttackPacketOnly | Log attack packet only | Object | Yes |
| CaptureNPackets | Capture N packets | Object | Yes |
| CaptureTimeDuration | Capture for a time duration | Object | Yes |
| RestOfFlow | Capture rest of flow | Object | Yes |
Details of object in CaptureNPackets:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| npackets | Log n packets | Number | Yes |
Details of object in CaptureTimeDuration:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| time | Capture time | String | Yes |
| timeUnit | Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" | String | Yes |
Details of object in notification:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| isEmail | Is notification configured through email | Boolean | Yes |
| isPager | Is notification configured through pager | Boolean | Yes |
| isScript | Is notification configured through script | Boolean | Yes |
| isAutoAck | Is notification configured through auto ack | Boolean | Yes |
| isSnmp | Is notification configured through SNMP | Boolean | Yes |
| isSyslog | Is notification configured through Syslog | Boolean | Yes |
| isEmailCustomized | Is notification through Email customized | Boolean | Yes |
| isPagerCustomized | Is notification through Pager customized | Boolean | Yes |
| isScriptCustomized | Is notification through Script customized | Boolean | Yes |
| isAutoAckCustomized | Is notification through Auto Ack customized | Boolean | Yes |
| isSnmpCustomized | Is notification through SNMP customized | Boolean | Yes |
| isSyslogCustomized | Is notification through Syslog customized | Boolean | Yes |
Details of object in DosPolicy:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| LearningAttack | List of learning attacks | Array | Yes |
| ThresholdAttack | List of threshold attacks | Array | Yes |
| TimeStamp | Time stamp | String | Yes |
Details of object in LearningAttack:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attackName | Attack name | String | Yes |
| nspId | NSP id of the attack | String | Yes |
| isSeverityCustomized | Is attack severity customized | Boolean | Yes |
| severity | Attack severity, number between 0 & 9 | Number | Yes |
| isBlockingSettingCustomized | Is blocking customized | Boolean | Yes |
| isDropPacket | Drop DoS attack packets of this attack type when detected | Boolean | Yes |
| isAlertCustomized | Is alert customized | Boolean | Yes |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String | Yes |
| timeStamp | Time stamp | String | Yes |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String | Yes |
| notification | Notification to be sent | Object | Yes |
| isAttackCustomized | Is DoS learning attack customized | Boolean | Yes |
Details of object in ThresholdAttack:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attackName | Attack name | String | Yes |
| nspId | NSP id of the attack | String | Yes |
| isSeverityCustomized | Is attack severity customized | Boolean | Yes |
| severity | Attack severity, number between 0 & 9 | Number | Yes |
| isThresholdValueCustomized | Is threshold value customized | Boolean | Yes |
| isThresholdDurationCustomized | is threshold duration customized | Boolean | Yes |
| ThresholdValue | Threshold values | Number | Yes |
| ThresholdDuration | Threshold interval (Seconds) | Number | Yes |
| isAlertCustomized | Is alert customized | Boolean | Yes |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String | Yes |
| TimeStamp | Time stamp | String | Yes |
| Notification | Notification to be sent via | Object | Yes |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String | Yes |
| isAttackCustomized | Is DoS threshold attack customized | Boolean | Yes |
Details of object in ReconPolicy:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ReconAttackList | List of recon attacks | Array | Yes |
| TimeStamp | Time stamp | String | Yes |
| attackName | Attack name | String | yes |
| nspId | NSP id of the attack | String | Yes |
| isSeverityCustomized | Is attack severity customized | Boolean | Yes |
| severity | Severity, number between 0 & 9 | Number | Yes |
| isThresholdValueCustomized | Is threshold value customized | Boolean | Yes |
| Is Threshold valuecustomized | is threshold duration customized | Boolean | Yes |
| ThresholdValue | Threshold values | Number | Yes |
| ThresholdDuration | Threshold interval (seconds) | Number | Yes |
| mcAfeeNACNotification | Configured NAC notification that can be
"DISABLED" / "ALL_HOSTS" / "MCAFEE_NAC_UNMANAGED_HOSTS" |
String | Yes |
| isMcAfeeNACNotificationEnable | Is NAC notification enabled | Boolean | Yes |
| isQuarantineCustomized | Is quarantine customized | Boolean | Yes |
| isRemediateEnabled | is remediate enabled | Boolean | Yes |
| isAlertSuppressionTimerCustom | Is alert suppression customized | Boolean | Yes |
| alertSuppressionTimer | Alert suppression timer | Number | Yes |
| IsAlertCustomized | Is alert customized | Boolean | Yes |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String | Yes |
| timestamp | Time stamp | String | Yes |
| direction | Attack direction that can be "INBOUND" /
"OUTBOUND" / "BOTH" |
String | Yes |
| notification | Notification to be sent via | Object | Yes |
| isAttackCustomized | Is recon attack customized | Boolean | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Unique id of the light weight policy | Number |
Example
Request
POST https://%3CNSM_IP%3E/sdkapi/sensor/1001/interface/105/localipspolicy
Payload:
{
"PolicyDescriptor":
{
"IsVisibleToChildren": true,
"InboundRuleSet": "testRuleSet",
"OutboundRuleSet": "Null",
"AttackCategory":
{
"ExpolitAttackList":
[
{
"attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
"nspId": "0x42700e00",
"severity": 6,
"isSeverityCustomized": true,
"isEnabled": true,
"isAlertCustomized": false,
"isRecommendedForSmartBlocking": false,
"AttackResponse":
{
"TCPReset": "DISABLED",
"isTcpResetCustomized": false,
"isICMPSend": false,
"isICMPSendCustomized": false,
"mcAfeeNACNotification": "DISABLED",
"isMcAfeeNACNotificationEnabled": false,
"isQuarantineCustomized": false,
"isRemediateEnabled": false,
"blockingOption": "DISABLE",
"isBlockingOptionCustomized": false,
"isCapturedPrior": true,
"isCapturedPriorCustomized": false,
"action": "SEND_ALERT_ONLY",
"isLogCustomized": false,
"isFlowCustomized": false,
"isNbytesCustomized": false,
"numberOfBytesInEachPacket":
{
"LogEntirePacket":
{
}
}
},
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"protocolList":
[
"ident"
],
"benignTriggerProbability": "3 (Medium)",
"blockingType": "attack-packet",
"subCategory": "buffer-overflow",
"direction": "INBOUND",
"isAttackCustomized": true
}
]
},
"OutboundAttackCategory":
{
},
"DosPolicy":
{
"LearningAttack":
[
{
"attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
"nspId": "0x40018000",
"isSeverityCustomized": false,
"severity": 7,
"isBlockingSettingCustomized": false,
"isDropPacket": false,
"IsAlertCustomized": false,
"isSendAlertToManager": true,
"direction": "OUTBOUND",
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"isAttackCustomized": false
}
],
"ThresholdAttack":
[
{
"attackName": "Too Many Outbound IP Fragments",
"nspId": "0x40018800",
"isSeverityCustomized": false,
"severity": 6,
"isThresholdValueCustomized": false,
"isThresholdDurationCustomized": false,
"ThresholdValue": 1000,
"ThresholdDuration": 5,
"isAlertCustomized": false,
"isSendAlertToManager": false,
"Notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"direction": "OUTBOUND",
"isAttackCustomized": false
}
],
"TimeStamp": "2012-08-31 15:20:54.000"
},
'ReconPolicy': {
'TimeStamp': None,
'ReconAttackList': [{
'IsAlertCustomized': False,
'isSeverityCustomized': False,
'direction': None,
'severity': 5,
'isThresholdDurationCustomized': False,
'isSendAlertToManager': False,
'isQuarantineCustomized': False,
'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
'ThresholdDuration': 0,
'alertSuppressionTimer': 0,
'isAlertSuppressionTimerCustomized': False,
'isAttackCustomized': False,
'isMcAfeeNACNotificationEnabled': False,
'isThresholdValueCustomized': False,
'nspId': '0x43f00900',
'mcAfeeNACNotification': 'DISABLED',
'isRemediateEnabled': False,
'timeStamp': None,
'ThresholdValue': 0,
'notification': {
'isSnmp': False,
'isAutoAckCustomized': False,
'isPagerCustomized': False,
'isSyslogCustomized': False,
'isEmail': False,
'isSyslog': False,
'isScriptCustomized': False,
'isSnmpCustomized': False,
'isScript': False,
'isPager': False,
'isEmailCustomized': False,
'isAutoAck': False
}
}]
},
"DosResponseSensitivityLevel": 0,
"IsEditable": false,
"Timestamp": "2012-08-31 15:20:55.000",
"VersionNum": 1,
"IsLightWeightPolicy": true
}
}
Response
{
"createdResourceId":105
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1106 | Invalid Sensor |
| 2 | 404 | 1107 | Invalid interface or sub-interface id |
| 3 | 400 | 1301 | The number of attacks does not match the number in the baseline policy |
| 4 | 400 | 1302 | Number of bytes has to be between 1 to 255 |
| 5 | 400 | 1303 | Please provide the number of bytes to be logged |
| 6 | 400 | 1304 | Please provide duration of logging for flow |
| 7 | 400 | 1305 | Number of bytes has to be between 2 to 255 |
| 8 | 400 | 1306 | Time has to be between 1 to 63 |
| 9 | 400 | 1307 | Please provide a time |
| 10 | 400 | 1308 | Please provide a time interval |
| 11 | 400 | 1309 | Please provide the flow |
| 12 | 400 | 1310 | Invalid severity - please provide a value between 0 and 10 |
| 13 | 400 | 1311 | Invalid threshold value - please enter a value between 1 and 2147483647 |
| 14 | 400 | 1312 | Invalid threshold duration - please enter a value between 1 and 2147483647 |