The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Firewall Policy

Prev Next

This URL updates the firewall policy details.

Resource URL

PUT /firewallpolicy/<policy_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
policy_id Firewall policy id Number Yes

Payload Request Parameters:

Field Name Description Data Type Mandatory
FirewallPolicyId Unique firewall policy id Number No
Name Policy name String Yes
DomainId Id of domain to which this firewall policy belongs to Number Yes
VisibleToChild Policy visible to child domain Boolean Yes
Description Firewall policy description String No
LastModifiedTime Last modified time of the firewall policy String Yes
IsEditable Policy is editable or not Boolean Yes
PolicyType Policy type, can be "ADVANCED" / "CLASSIC" String Yes
PolicyVersion Policy version Number Yes
LastModifiedUser Last user that modified the policy String Yes
MemberDetails Member firewall rules in the policy Object Yes

Details of MemberDetails:

Field Name Description Data Type Mandatory
MemberRuleList List of firewall rules in the policy Array Yes

Details of fields in MemberRuleList

Field Name Description Data Type Mandatory
Description Rule description String Yes
Enabled Is rule enabled or not Boolean Yes
Response Action to be performed if the traffic matches this rule. Can be "SCAN" / "DROP" / "DENY" / "IGNORE" / "STATELESS_IGNORE" / "STATELESS_DROP" / "REQUIRE_AUTHENTICATION" String Yes
isLogging Is logging enabled for this rule Boolean Yes
Direction Rule direction, can be "INBOUND" / "OUTBOUND" / "EITHER" String Yes
SourceAddressObjectList Source address rule object list Array Yes
SourceUserObjectList Source user rule object list Array Yes
DestinationAddressObjectList Destination address rule object list Array Yes
ServiceObjectList Service rule object list Array Yes
ApplicationObjectList Application rule object list Array Yes
TimeObjectList Time rule object list Array Yes

Details of SourceAddressObjectList and DestinationAddressObjectList:

Field Name Description Data Type Mandatory
RuleObjectId Unique rule object id String Yes
Name Rule object name String Yes
RuleObjectType Source/destination mode. Can be "COUNTRY" / "HOST_DNS_NAME" / "HOST_IPV_4" / "HOST_IPV_6" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" / "NETWORK_GROUP" String Yes

Details of SourceUserObjectList:

Field Name Description Data Type Mandatory
RuleObjectId Unique rule object id String Yes
Name Rule object name String Yes
RuleObjectType Source user. Can be "USER" / "USER_GROUP" String Yes

Details of ServiceObjectList and ApplicationObjectList:

Field Name Description Data Type Mandatory
RuleObjectId Unique service rule object id String Yes
Name Rule object name String Yes
RuleObjectType Service/application mode. Can be "APPLICATION" / "APPLICATION_GROUP" / "APPLICATION_ON_CUSTOM_PORT" / "SERVICE" / "SERVICE_GROUP" String Yes
ApplicationType Application type. Can be "DEFAULT" / "CUSTOM" String Yes

Details of TimeObjectList:

Field Name Description Data Type Mandatory
RuleObjectId Unique service rule object id String Yes
Name Rule object name String Yes
RuleObjectType Time mode. Can be "FINITE_TIME_PERIOD" / "RECURRING_TIME_PERIOD" / "RECURRING_TIME_PERIOD_GROUP" String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
status Update status Number

Example

Request

PUT https://%3CNSM_IP%3E/sdkapi/firewallpolicy/120

Payload:

{
	"FirewallPolicyId" : 120,
	"Name" : "TestFirewallPolicy",
	"DomainId" : 0,
	"VisibleToChild" : true,
	"Description" : "test the firewallpolicy",
	"LastModifiedTime" : "2012-12-12 12:32:44",
	"IsEditable" : true,
	"PolicyType" : "ADVANCED",
	"PolicyVersion" : 1,
	"LastModifiedUser" : "admin",
	"MemberDetails" : {
		"MemberRuleList" : [{
				"Description" : "Test Member Rule",
				"Enabled" : true,
				"Response" : "IGNORE",
				"IsLogging" : false,
				"Direction" : "OUTBOUND",
				"SourceAddressObjectList" : [{
						"RuleObjectId" : "AF",
						"Name" : "Afghanistan",
						"RuleObjectType" : "COUNTRY"
					}
				],
				"DestinationAddressObjectList" : [{
						"RuleObjectId" : "101",
						"Name" : "hostDNSRule",
						"RuleObjectType" : "HOST_DNS_NAME"
					}, {
						"RuleObjectId" : "102",
						"Name" : "hostIpv4",
						"RuleObjectType" : "HOST_IPV_4"
					}, {
						"RuleObjectId" : "103",
						"Name" : "ipv4Addressrange",
					"RuleObjectType" : "IPV_4_ADDRESS_RANGE"
					}, {
						"RuleObjectId" : "104",
						"Name" : "networkgroup",
					"RuleObjectType" : "NETWORK_GROUP"
					}
				],
				"SourceUserObjectList" : [{
						"RuleObjectId" : "-1",
						"Name" : "ANY",
						"RuleObjectType" : "USER"
					}
				],
				"ServiceObjectList" : [],
				"ApplicationObjectList" : [{
						"RuleObjectId" : "1308991488",
						"Name" : "100bao",
						"RuleObjectType" : "APPLICATION",
						"ApplicationType" : "DEFAULT"
					}, {
						"RuleObjectId" : "106",
						"Name" : "applicaionOncutomPort",
			"RuleObjectType" : "APPLICATION_ON_CUSTOM_PORT",
						"ApplicationType" : "CUSTOM"
					}, {
						"RuleObjectId" : "105",
						"Name" : "applicationgroup",
					"RuleObjectType" : "APPLICATION_GROUP",
						"ApplicationType" : "CUSTOM"
					}
				],
				"TimeObjectList" : [{
						"RuleObjectId" : "107",
						"Name" : "finiteTimePeriod",
					"RuleObjectType" : "FINITE_TIMING_PERIOD"
					}, {
						"RuleObjectId" : "108",
						"Name" : "recuringTimePeriod",
				"RuleObjectType" : "RECURRING_TIME_PERIOD"
					}, {
						"RuleObjectId" : "109",
						"Name" : "recurringTimeperiodGroup",
			"RuleObjectType" : "RECURRING_TIME_PERIOD_GROUP"
					}
				]
			}
		]
	}
} 

Response

{
"status":1
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 404 1105 Invalid domain
3 400 1702 Invalid rule object type
4 400 1801 Invalid firewall policy Id/ firewall policy not visible to this domain
5 400 1804 Maximum of 10 rule objects are allowed in each object list of an advanced firewall/QoS policy
6 400 1805 Multiple rule objects in a single source/destination object list is not supported for a classic firewall policy
7 400 1806 Only host IPV4/network IPV4 type rule objects are supported for classic firewall policy
8 400 1807 Only service type rule object is supported for classic firewall policy
9 400 1808 Time object list is not applicable for classic firewall policy
10 400 1809 Application object list is not applicable for classic firewall policy
11 400 1810 Multiple rule objects in a single Service object list is not supported for a classic firewall policy
12 400 1811 Policy type cannot be modified from advanced to classic
13 400 1812 Deny response is applicable for TCP traffic only
14 400 1813 Source/destination object list is not provided
15 400 1814 Service/application object list is not provided
16 400 1815 Time object list is not provided
17 400 1816 Firewall policy name is required
18 400 1817 For stateless action, application object list is not applicable
19 400 1818 Unsupported firewall policy type
20 406 1819 Stateless response with any/TCP/IP protocol no.6/default services are not allowed
21 400 1820 Is logging should not enabled for stateless action
22 400 1821 Either application or service object list can be defined in a member rule for an advanced firewall policy
23 400 1822 Composite rule object(Multiple items in a rule object) is allowed for advanced firewall policy only
24 400 1824 Source user object list is not applicable for classic firewall policy
25 400 1825 Source address object list is not applicable for classic firewall policy
26 400 1826 Destination address object list is not applicable for classic firewall policy
27 400 1827 Firewall policy with the same name was defined
28 400 1828 Invalid firewall policy
29 400 1829 Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore
30 400 1830 Firewall policy name should not be greater than 40 chars
31 400 1831 Firewall policy provided is not upto date
32 400 1832 Source address and destination address object list cannot combine IPV6 rule objects with host IPV4, network IPV4, IPV4 address range, country and host DNS name rule objects
33 400 1833 Require authentication is valid only when source user object list is set to any
34 400 1834 Require authentication is valid only when HTTP (default service) is selected
35 400 1835 Firewall policy description should not be greater than 255 chars
36 400 1836 Member rule description should not be greater than 64 chars
37 400 1837 Source user object list is not provided
38 400 1838 Time object list can contain one finite time period
39 400 1839 Stateless response with source user or source user group rule objects are not allowed