The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Firewall Policy

Prev Next

This URL gets the firewall policy details.

Resource URL

GET /firewallpolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

policy_id

Policy id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

FirewallPolicyId

Unique firewall policy id

Number

Name

Policy name

String

DomainId

Id of domain to which this firewall policy belongs to

Number

VisibleToChild

Policy visible to child domain

Boolean

Description

Firewall policy description

String

LastModifiedTime

Last modified time of the firewall policy

String

IsEditable

Policy is editable or not

Boolean

PolicyType

Policy type, can be "ADVANCED" / "CLASSIC"

String

PolicyVersion

Policy version

Number

LastModifiedUser

Last user that modified the policy

String

MemberDetails

Member firewall rules in the policy

String

Details of MemberDetails:

Field Name

Description

Data Type

MemberRuleList

List of firewall rules in the policy

Array

Details of fields in MemberRuleList:

Field Name

Description

Data Type

Description

Rule description

String

Enabled

Is rule enabled or not

Boolean

Response

Action to be performed if the traffic matches this rule. Can be "SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION"

String

IsLogging

Is logging enabled for this rule

Boolean

Direction

Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER"

String

SourceAddressObjectList

Source address rule object list

Array

SourceUserObjectList

Source user rule object list

Array

DestinationAddressObjectList

Destination address rule object list

Array

ServiceObjectList

Service rule object list

Array

ApplicationObjectList

Application rule object list

Array

TimeObjectList

Time rule object list

Array

Details of SourceAddressObjectList and DestinationAddressObjectList:

Field Name

Description

Data Type

RuleObjectId

Unique rule object id

String

Name

Rule object name

String

RuleObjectType

Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP"

String

Details of SourceUserObjectList:

Field Name

Description

Data Type

RuleObjectId

Unique rule object id

String

Name

Rule object name

String

RuleObjectType

Source user. Can be "USER" / "USER_GROUP"

String

Details of ServiceObjectList and ApplicationObjectList:

Field Name

Description

Data Type

RuleObjectId

Unique service rule object id

String

Name

Rule object name

String

RuleObjectType

Service/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP"

String

ApplicationType

Application type. Can be "DEFAULT" / "CUSTOM"

String

Details of TimeObjectList:

Field Name

Description

Data Type

RuleObjectId

Unique service rule object id

String

Name

Rule object name

String

RuleObjectType

Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP"

String

Example

Request

GET https://<NSM_IP>/sdkapi/firewallpolicy/120

Response

{
	"FirewallPolicyId" : 120,
	"Name" : "TestFirewallPolicy",
	"DomainId" : 0,
	"VisibleToChild" : true,
	"Description" : "test the firewallpolicy",
	"LastModifiedTime" : "2012-12-12 12:43:54",
	"IsEditable" : true,
	"PolicyType" : "ADVANCED",
	"PolicyVersion" : 1,
	"LastModifiedUser" : "admin",
	"MemberDetails" : {
		"MemberRuleList" : [{
				"Description" : "Test Member Rule",
				"Enabled" : true,
				"Response" : "IGNORE",
				"IsLogging" : false,
				"Direction" : "OUTBOUND",
				"SourceAddressObjectList" : [{
						"RuleObjectId" : "AF",
						"Name" : "Afghanistan",
						"RuleObjectType" : "COUNTRY"
					}
				],
				"DestinationAddressObjectList" : [{
						"RuleObjectId" : "101",
						"Name" : "hostDNSRule",
						"RuleObjectType" : "HOST_DNS_NAME"
					}, {
						"RuleObjectId" : "102",
						"Name" : "hostIpv4",
						"RuleObjectType" : "HOST_IPV_4"
					}, {
						"RuleObjectId" : "103",
						"Name" : "ipv4Addressrange",
					"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
					}, {
						"RuleObjectId" : "104",
						"Name" : "networkgroup",
					"RuleObjectType" : "NETWORK_GROUP"
					}
				],
				"SourceUserObjectList" : [{
						"RuleObjectId" : "-1",
						"Name" : "ANY",
						"RuleObjectType" : "USER"
					}
				],
				"ServiceObjectList" : [],
				"ApplicationObjectList" : [{
						"RuleObjectId" : "1308991488",
						"Name" : "100bao",
						"RuleObjectType" : "APPLICATION",
						"ApplicationType" : "DEFAULT"
					}, {
						"RuleObjectId" : "106",
						"Name" : "applicaionOncutomPort",
			"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
						"ApplicationType" : "CUSTOM"
					}, {
						"RuleObjectId" : "105",
						"Name" : "applicationgroup",
					"RuleObjectType" : "APPLICATION_GROUP",
						"ApplicationType" : "CUSTOM"
					}
				],
				"TimeObjectList" : [{
						"RuleObjectId" : "107",
						"Name" : "finiteTimePeriod",
					"RuleObjectType" : "FINITE_TIMING_PERIOD"
					}, {
						"RuleObjectId" : "108",
						"Name" : "recuringTimePeriod",
				"RuleObjectType" : "RECURRING_TIME_PERIOD"
					}, {
						"RuleObjectId" : "109",
						"Name" : "recurringTimeperiodGroup",
			"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
					}
				]
			}
		]
	}
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

404

1801

Invalid firewall policy id/ firewall policy not visible to this domain