This URL retrieves the inspection options policy.
Resource URL
GET /protectionoptionspolicy/<policy_id>
Request Parameters
URL Parameter
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Policy id | Number |
| Policy name | String |
| Domain id | Number |
| Visible to child | Boolean |
| Description | String |
| Last updated by | String |
| Last updated date | String |
| All options tabs | Object |
Details of protectionOptions:
Field Name | Description | Data Type |
|---|---|---|
| Inspection options | Object |
| Advanced botnet detection options | Object |
| GTI endpoint reputation analysis options | Object |
| Web server heuristic analysis options | Object |
| Web server DOS options | Object |
Details of inspectionOptions:
Field Name | Description | Data Type |
|---|---|---|
| HTTP response traffic scanning | String |
| HTTP response decompression | String |
| Chunked HTTP response decoding | String |
| HTML encoded HTTP response decoding | String |
| Base64 SMTP decoding | String |
| Description | String |
| Quoted printable SMTP decoding | String |
| HTTP2 traffic scanning | String |
| HTTP2 server push scanning | String |
| MSRPC SMB fragment reassembly | String |
| Microsoft Office Deep File Inspection | String |
| XFF header parsing | String |
| Layer 7 data collection | String |
| Passive device profiling | String |
| Attack blocking simulation | String |
Possible values for above attributes should be:
INBOUND_ONLY
OUTBOUND_ONLY
DISABLED
INBOUND_AND_OUTBOUND
Details of advancedBotnetDetectionOptions:
Field Name | Description | Data Type |
|---|---|---|
| Advanced botnet detection | String |
| Sensitivity | String |
| Fast flux detection | String |
| Domain generation algorithm detection | String |
| Domain name allow list processing | String |
| Export traffic to NTBA | Boolean |
| DNS sink holing | String |
Possible values for above attributes should be:
INBOUND_ONLY
OUTBOUND_ONLY
DISABLED
INBOUND_AND_OUTBOUND
Possible values for sensitivity should be:
LOW
MEDIUM
HIGH
Details of gtiEndpointReputationAnalysysOptions:
Field Name | Description | Data Type |
|---|---|---|
| GTI endpoint reputation analysis
| String |
| Use to influence SmartBlocking | Boolean |
| Exclude internal endpoint | Boolean |
| CIDRs excluded | Stringlist |
| Protocols excluded | Stringlist |
| URL reputation analysis | String |
| URL reputation min risk | String |
Details of webserverHuresticAnalysysOptions:
Field Name | Description | Data Type |
|---|---|---|
| Heuristic analysis. Direction value as specified above | String |
| Options: ALL or SPECIFIC | String |
| Block text list | Stringlist |
| Website path to protect list | Stringlist |
Details of webserverDOSOptions:
Field Name | Description | Data Type |
|---|---|---|
| DoS prevention: Direction mode | String |
| Max connection allowed to WS | Number |
| Slow connection attack prevention | Boolean |
| Max HTTP request per second to any path | Number |
| Website path to protect options: ALL or SPECIFIC | String |
| Browser detection method | String |
| Website path to protect list | Objectlist |
Example
Request
GET https://<NSM_IP>/sdkapi/protectionoptionspolicy/2
Response
{
"policyId": 2,
"policyName": "httpresponse",
"domainId": 0,
"visibleToChild": true,
"description": "Enable xff",
"isEditable": true,
"lastUpdatedBy": "admin",
"lastUpdated": "2014-Aug-11 16:19",
"protectionOptions":
{
"inspectionOptions":
{
"httpResponseTrafficScanning": "INBOUND_AND_OUTBOUND",
"httpResponseDecompression": "INBOUND_AND_OUTBOUND",
"chunkedHTTPResponseDecoding": "INBOUND_AND_OUTBOUND",
"htmlEncodedHTTPResponseDecoding": "INBOUND_AND_OUTBOUND",
"base64SMTPDecoding": "DISABLED",
"quotedPrintableSMTPDecoding": "DISABLED",
"http2TrafficScanning": "INBOUND_AND_OUTBOUND",
"http2ServerPushScanning": "INBOUND_AND_OUTBOUND",
"msRPCSMBFragmentReassembly": "DISABLED",
"msOfficeDeepFileInspection": "INBOUND_AND_OUTBOUND",
"xffHeaderParsing": "INBOUND_AND_OUTBOUND",
"layer7DataCollection": "INBOUND_AND_OUTBOUND",
"passiveDeviceProfiling": "INBOUND_AND_OUTBOUND",
"attackBlockingSimulation": true
},
"advancedBotnetDetectionOptions":
{
"advancedBotnetDetection": "INBOUND_AND_OUTBOUND",
"sensitivity": "LOW",
"exportTrafficToNTBA": false,
"fastFluxDetection": "DISABLED",
"domainGenerationAlgorithmDetection": "DISABLED",
"dnsSinkholing": false,
"domainNameAllowlistProcessing": true,
"cidrsExcluded": [],
},
"gtiEndpointReputationAnalysysOptions":
{
"gtiEndpointReputationAnalysys": "DISABLED",
"useToInfluenceSmartBlocking": false,
"excludeInternalEndpoint": false
"cidrsExcluded": [],
"protocalsExcluded": [],
"urlReputationAnalysis": null,
"urlReputationMinimumRisk": null
},
"webserverHuresticAnalysysOptions":
{
"huresticAnalysys": "INBOUND_ONLY",
"websitePathToProtect": "ALL",
"blockedTextList": [],
"websitePathToProtectList": [],
},
"webserverDOSOptions":
{
"dosPrevention": "INBOUND_ONLY",
"maxConnectionAllowedToWS": 750000,
"slowConnectionAttackPrevention": false,
"maxHTTPRequestPERSecondTOAnyPath": 10000,
"websitePathToProtect": "ALL",
"clientBrowserDetection": false,
"browserDetectionMethod": null,
"websitePathToProtectList": [],
}
}
}
Error Information
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 4301 | Invalid domain id |