This URL gets the firewall policy details.
Resource URL
GET /firewallpolicy/<policy_id>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Unique firewall policy id | Number |
| Policy name | String |
| Id of domain to which this firewall policy belongs to | Number |
| Policy visible to child domain | Boolean |
| Firewall policy description | String |
| Last modified time of the firewall policy | String |
| Policy is editable or not | Boolean |
| Policy type, can be "ADVANCED" / "CLASSIC" | String |
| Policy version | Number |
| Last user that modified the policy | String |
| Member firewall rules in the policy | String |
Details of MemberDetails:
Field Name | Description | Data Type |
|---|---|---|
| List of firewall rules in the policy | Array |
Details of fields in MemberRuleList:
Field Name | Description | Data Type |
|---|---|---|
| Rule description | String |
| Is rule enabled or not | Boolean |
| Action to be performed if the traffic matches this rule. Can be "SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION" | String |
| Is logging enabled for this rule | Boolean |
| Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER" | String |
| Source address rule object list | Array |
| Source user rule object list | Array |
| Destination address rule object list | Array |
| Service rule object list | Array |
| Application rule object list | Array |
| Time rule object list | Array |
Details of SourceAddressObjectList and DestinationAddressObjectList:
Field Name | Description | Data Type |
|---|---|---|
| Unique rule object id | String |
| Rule object name | String |
| Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP" | String |
Details of SourceUserObjectList:
Field Name | Description | Data Type |
|---|---|---|
| Unique rule object id | String |
| Rule object name | String |
| Source user. Can be "USER" / "USER_GROUP" | String |
Details of ServiceObjectList and ApplicationObjectList:
Field Name | Description | Data Type |
|---|---|---|
| Unique service rule object id | String |
| Rule object name | String |
| Service/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP" | String |
| Application type. Can be "DEFAULT" / "CUSTOM" | String |
Details of TimeObjectList:
Field Name | Description | Data Type |
|---|---|---|
| Unique service rule object id | String |
| Rule object name | String |
| Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP" | String |
Example
Request
GET https://<NSM_IP>/sdkapi/firewallpolicy/120
Response
{
"FirewallPolicyId" : 120,
"Name" : "TestFirewallPolicy",
"DomainId" : 0,
"VisibleToChild" : true,
"Description" : "test the firewallpolicy",
"LastModifiedTime" : "2012-12-12 12:43:54",
"IsEditable" : true,
"PolicyType" : "ADVANCED",
"PolicyVersion" : 1,
"LastModifiedUser" : "admin",
"MemberDetails" : {
"MemberRuleList" : [{
"Description" : "Test Member Rule",
"Enabled" : true,
"Response" : "IGNORE",
"IsLogging" : false,
"Direction" : "OUTBOUND",
"SourceAddressObjectList" : [{
"RuleObjectId" : "AF",
"Name" : "Afghanistan",
"RuleObjectType" : "COUNTRY"
}
],
"DestinationAddressObjectList" : [{
"RuleObjectId" : "101",
"Name" : "hostDNSRule",
"RuleObjectType" : "HOST_DNS_NAME"
}, {
"RuleObjectId" : "102",
"Name" : "hostIpv4",
"RuleObjectType" : "HOST_IPV_4"
}, {
"RuleObjectId" : "103",
"Name" : "ipv4Addressrange",
"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
}, {
"RuleObjectId" : "104",
"Name" : "networkgroup",
"RuleObjectType" : "NETWORK_GROUP"
}
],
"SourceUserObjectList" : [{
"RuleObjectId" : "-1",
"Name" : "ANY",
"RuleObjectType" : "USER"
}
],
"ServiceObjectList" : [],
"ApplicationObjectList" : [{
"RuleObjectId" : "1308991488",
"Name" : "100bao",
"RuleObjectType" : "APPLICATION",
"ApplicationType" : "DEFAULT"
}, {
"RuleObjectId" : "106",
"Name" : "applicaionOncutomPort",
"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
"ApplicationType" : "CUSTOM"
}, {
"RuleObjectId" : "105",
"Name" : "applicationgroup",
"RuleObjectType" : "APPLICATION_GROUP",
"ApplicationType" : "CUSTOM"
}
],
"TimeObjectList" : [{
"RuleObjectId" : "107",
"Name" : "finiteTimePeriod",
"RuleObjectType" : "FINITE_TIMING_PERIOD"
}, {
"RuleObjectId" : "108",
"Name" : "recuringTimePeriod",
"RuleObjectType" : "RECURRING_TIME_PERIOD"
}, {
"RuleObjectId" : "109",
"Name" : "recurringTimeperiodGroup",
"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
}
]
}
]
}
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 404 | 1801 | Invalid firewall policy id/ firewall policy not visible to this domain |