This URL gets the firewall policy details.
Resource URL
GET /firewallpolicy/<policy_id>
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policy_id | Policy id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| FirewallPolicyId | Unique firewall policy id | Number |
| Name | Policy name | String |
| DomainId | Id of domain to which this firewall policy belongs to | Number |
| VisibleToChild | Policy visible to child domain | Boolean |
| Description | Firewall policy description | String |
| LastModifiedTime | Last modified time of the firewall policy | String |
| IsEditable | Policy is editable or not | Boolean |
| PolicyType | Policy type, can be "ADVANCED" / "CLASSIC" | String |
| PolicyVersion | Policy version | Number |
| LastModifiedUser | Last user that modified the policy | String |
| MemberDetails | Member firewall rules in the policy | String |
Details of MemberDetails:
| Field Name | Description | Data Type |
|---|---|---|
| MemberRuleList | List of firewall rules in the policy | Array |
Details of fields in MemberRuleList:
| Field Name | Description | Data Type |
|---|---|---|
| Description | Rule description | String |
| Enabled | Is rule enabled or not | Boolean |
| Response | Action to be performed if the traffic matches this rule. Can be "SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION" | String |
| IsLogging | Is logging enabled for this rule | Boolean |
| Direction | Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER" | String |
| SourceAddressObjectList | Source address rule object list | Array |
| SourceUserObjectList | Source user rule object list | Array |
| DestinationAddressObjectList | Destination address rule object list | Array |
| ServiceObjectList | Service rule object list | Array |
| ApplicationObjectList | Application rule object list | Array |
| TimeObjectList | Time rule object list | Array |
Details of SourceAddressObjectList and DestinationAddressObjectList:
| Field Name | Description | Data Type |
|---|---|---|
| RuleObjectId | Unique rule object id | String |
| Name | Rule object name | String |
| RuleObjectType | Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP" | String |
Details of SourceUserObjectList:
| Field Name | Description | Data Type |
|---|---|---|
| RuleObjectId | Unique rule object id | String |
| Name | Rule object name | String |
| RuleObjectType | Source user. Can be "USER" / "USER_GROUP" | String |
Details of ServiceObjectList and ApplicationObjectList:
| Field Name | Description | Data Type |
|---|---|---|
| RuleObjectId | Unique service rule object id | String |
| Name | Rule object name | String |
| RuleObjectType | Service/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP" | String |
| ApplicationType | Application type. Can be "DEFAULT" / "CUSTOM" | String |
Details of TimeObjectList:
| Field Name | Description | Data Type |
|---|---|---|
| RuleObjectId | Unique service rule object id | String |
| Name | Rule object name | String |
| RuleObjectType | Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP" | String |
Example
Request
GET https://%3CNSM_IP%3E/sdkapi/firewallpolicy/120
Response
{
"FirewallPolicyId" : 120,
"Name" : "TestFirewallPolicy",
"DomainId" : 0,
"VisibleToChild" : true,
"Description" : "test the firewallpolicy",
"LastModifiedTime" : "2012-12-12 12:43:54",
"IsEditable" : true,
"PolicyType" : "ADVANCED",
"PolicyVersion" : 1,
"LastModifiedUser" : "admin",
"MemberDetails" : {
"MemberRuleList" : [{
"Description" : "Test Member Rule",
"Enabled" : true,
"Response" : "IGNORE",
"IsLogging" : false,
"Direction" : "OUTBOUND",
"SourceAddressObjectList" : [{
"RuleObjectId" : "AF",
"Name" : "Afghanistan",
"RuleObjectType" : "COUNTRY"
}
],
"DestinationAddressObjectList" : [{
"RuleObjectId" : "101",
"Name" : "hostDNSRule",
"RuleObjectType" : "HOST_DNS_NAME"
}, {
"RuleObjectId" : "102",
"Name" : "hostIpv4",
"RuleObjectType" : "HOST_IPV_4"
}, {
"RuleObjectId" : "103",
"Name" : "ipv4Addressrange",
"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
}, {
"RuleObjectId" : "104",
"Name" : "networkgroup",
"RuleObjectType" : "NETWORK_GROUP"
}
],
"SourceUserObjectList" : [{
"RuleObjectId" : "-1",
"Name" : "ANY",
"RuleObjectType" : "USER"
}
],
"ServiceObjectList" : [],
"ApplicationObjectList" : [{
"RuleObjectId" : "1308991488",
"Name" : "100bao",
"RuleObjectType" : "APPLICATION",
"ApplicationType" : "DEFAULT"
}, {
"RuleObjectId" : "106",
"Name" : "applicaionOncutomPort",
"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
"ApplicationType" : "CUSTOM"
}, {
"RuleObjectId" : "105",
"Name" : "applicationgroup",
"RuleObjectType" : "APPLICATION_GROUP",
"ApplicationType" : "CUSTOM"
}
],
"TimeObjectList" : [{
"RuleObjectId" : "107",
"Name" : "finiteTimePeriod",
"RuleObjectType" : "FINITE_TIMING_PERIOD"
}, {
"RuleObjectId" : "108",
"Name" : "recuringTimePeriod",
"RuleObjectType" : "RECURRING_TIME_PERIOD"
}, {
"RuleObjectId" : "109",
"Name" : "recurringTimeperiodGroup",
"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
}
]
}
]
}
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | Internal error |
| 2 | 404 | 1801 | Invalid firewall policy id/ firewall policy not visible to this domain |