This URL updates a rule object.
Resource URL
PUT /ruleobject/<ruleobject_id>
Request Parameters
URL Parameters
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleobject_id | Unique ID of rule object | Number | Yes |
Payload Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleobjId | Rule object ID | Number | Yes |
| ruleobjType | Rule object name | String | Yes |
| name | Rule object type | String | Yes |
| description | Description | String | Yes |
| domain | ID of domain in which the rule object is defined | Number | Yes |
| visibleToChild | Is rule object visible to child | Boolean | Yes |
| ApplicationGroup | Application group object, should be defined if ruleobjType is "APPLICATION_GROUP" | Object | No |
| ApplicationOnCustomPort | Application defined on custom port object, should be defined if ruleobjType is "APPLICATION_ON_CUSTOM_PORT" | Object | No |
| FiniteTimePeriod | Finite time period object, should be defined if ruleobjType is "FINITE_TIME_PERIOD" | Object | No |
| HostIPv4 | Host IPv4 address object, should be defined if ruleobjType is "HOST_IPV_4" | Object | No |
| HostIPv6 | Host IPv6 address object, should be defined if ruleobjType is "HOST_IPV_6" | Object | No |
| HostDNSName | Host DNS name object, should be defined if ruleobjType is "HOST_DNS_NAME" | Object | No |
| IPv4AddressRange | IPv4 address range object, should be defined if ruleobjType is "IPV_4_ADDRESS_RANGE" | Object | No |
| IPv6AddressRange | IPv6 address range object, should be defined if ruleobjType is "IPV_6_ADDRESS_RANGE" | Object | No |
| NetworkIPv4 | IPv4 network object, should be defined if ruleobjType is "NETWORK_IPV_4" | Object | No |
| NetworkIPv6 | IPv6 network object, should be defined if ruleobjType is "NETWORK_IPV_6" | Object | No |
| NetworkGroup | Network group object, should be defined if ruleobjType is "NETWORK_GROUP" | Object | No |
| RecurringTimePeriod | Recurring time period object, should be defined if ruleobjType is "RECURRING_TIME_PERIOD" | Object | No |
| RecurringTimePeriodGroup | Recurring time period group object, should be defined if ruleobjType is "RECURRING_TIME_PERIOD_GROUP" | Object | No |
| Service | Service object, should be defined if ruleobjType is "CUSTOM_SERVICE" | Object | No |
| ServiceRange | Service range object, should be defined if ruleobjType is "SERVICE_RANGE" | Object | No |
| ServiceGroup | Service group object, should be defined if ruleobjType is "SERVICE_GROUP" | Object | No |
| NetworkGroupAF | Network group for exception objects should be defined if ruleobjType is "NETWORK_GROUP_AF". This type of rule object is applicable only for alert filter/Ignore rules. | Object | No |
Details of ApplicationGroup:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ApplicationIdentifier | List of applications identifier | Array | Yes |
Details of object in ApplicationIdentifier:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| applicationRuleObjId | Application rule object ID | String | Yes |
| applicationType | Application Type, can be "DEFAULT_APPLICATION" / "APPLICATION_ON_CUSTOM_PORT" | String | Yes |
Details of ApplicationonCustomPort:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| applicationId | Application ID | String | Yes |
| portsList | List of ports | Array | Yes |
Details of object in portsList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IPProtocol | IP protocol, can be "TCP" / "UDP" | String | Yes |
| port | Port | Number | Yes |
Details of FiniteTimePeriod:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| from | From time | String | Yes |
| until | To time | String | Yes |
Details of HostIPv4:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| hostIPv4AddressList | List of IPv4 host address | Object | Yes |
Details of hostIPv4AddressList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| value | IPv4 Address | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can only modify the state and comment fields.
Details of HostIPv6:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| hostIPv6AddressList | List of IPv6 host address | Object | Yes |
Details of hostIPv6AddressList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| value | IPv6 Address | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of HostDNSName
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| hostDNSNameList | List of host DNS names | Object | Yes |
Details of hostDNSNameList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| value | host DNS name | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of IPv4AddressRange:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IPV4RangeList | List of IPv4 address range | Object | Yes |
Details of IPV4RangeList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| FromAddress | Start IP range | String | Yes |
| ToAddress | End IP range | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of IPv6AddressRange:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IPV6RangeList | List of IPv6 address range | Object | Yes |
Details of IPV6RangeList:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| FromAddress | Start IPv6 range | String | Yes |
| ToAddress | End IPv6 range | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of NetworkIPv4:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| networkIPV4List | List of network IPv4 addresses | Object | Yes |
Details of networkIPV4List:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| value | IPv4 network | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of NetworkIPv6:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| networkIPV6List | List of network IPv6 addresses | Object | Yes |
Details of networkIPV6List:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ruleObjID | Rule object ID | Number | Yes |
| state | State of the rule member, should be 1 to Enable and 0 to Disable the rule member. | Number | Yes |
| comment | User comment | String | No |
| userID | User ID | Number | Yes |
| value | IPv6 network | String | Yes |
| changedState | Change the state of a rule member, should be 1 to add, 2 to update and 3 to delete a rule member. | Number | Yes |
Note
You can update only the state and comment fields.
Details of NetworkGroup:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| NetworkGroupIdentifier | List of network objects | Array | Yes |
Details of object in NetworkGroupIdentifier:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| RuleObjId | Network rule object ID | String | Yes |
| type | Network type, can be "COUNTRY" / "HOST_IPV_4" / "HOST_IPV_6" / "HOST_DNS_NAME" / "IPV_4_ADDRESS_RANGE" / "IPV_6_ADDRESS_RANGE" / "NETWORK_IPV_4" / "NETWORK_IPV_6" | String | Yes |
Details of RecurringTimePeriod:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| entireDay | Entire day object | Boolean | Yes |
| duration | Duration object | Object | No |
| day | List of days, can be "MONDAY", "TUESDAY", "WEDNESDAY", "THURSDAY", "FRIDAY", "SATURDAY", "SUNDAY" | String | Yes |
Details of object in duration:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| from | From time | String | Yes |
| until | To time | String | Yes |
Details of RecurringTimePeriodGroup:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| recurringTimePeriodsId | List of recurring time period rule object Id's | Array | Yes |
Details of Service:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| protocol | Protocol, can be "TCP" / "UDP" / "PROTOCOL_NUMBER" | String | Yes |
| portNumber | Port number | String | Yes |
Details of ServiceRange:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| protocol | Protocol, can be "TCP" / "UDP" / "PROTOCOL_NUMBER" | String | Yes |
| From | From port/protocol number | String | Yes |
| To | To port/protocol number | String | Yes |
Details of ServiceGroup:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ServiceIdentifier | List of service objects | Array | Yes |
Details of object in ServiceIdentifier:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ServiceRuleObjId | Service rule object ID | String | Yes |
| ServiceType | Service type, can be "DEFAULT_SERVICE" / "CUSTOM_SERVICE" | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| Status | Status returned by deletion | Number |
Note
Do not assign rule objects with more than 10 rule members to any policy (or) rule object (or) exclusion apart from Firewall policy. Also, do not add assign policies that contain rule objects with more than 10 rule members to any Sensor running on or before version 10.1.5.153.
Example
Request
PUT https://%3CNSM_IP%3E/sdkapi/ruleobject/121
Payload:
{
"RuleObjDef": {
"domain": 0,
"visibleToChild": true,
"description": "try",
"ruleobjId": 234,
"name": "test_SDK3",
"HostIPv4": {
"hostIPv4AddressList": [
{
"ruleObjectID":234,
"state":1,
"comment": "test",
"userID":0,
"value":"172.1.1.3",
"changedState":2
}, {
"ruleObjectID":0,
"state":1,
"comment": "updatecomment",
"userID":0,
"value":"172.0.9.1",
"changedState":2
}, {
"ruleObjectID":234,
"state":1,
"comment": "test",
"userID":0,
"value":"17.90.1.2",
"changedState":3
},{
"ruleObjectID":234,
"state":1,
"comment": "test",
"userID":0,
"value":"10.154.12.45",
"changedState":3
}]
},
"ruleobjType": "HOST_IPV_4"
}
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | A Rule Object with same name already exists |
| 2 | 400 | 1406 | Invalid IP format |
| 3 | 400 | 1418 | Start IP should be less than end IP |
| 4 | 400 | 1701 | Invalid CIDR notation |
| 5 | 400 | 1702 | Rule object type cannot be changed |
| 6 | 400 | 1703 | Please specify at least one day |
| 7 | 400 | 1705 | Port number should be between 1 and 65534 |
| 8 | 400 | 1706 | Rule objects which are not visible to child admin domains cannot be added to a rule object visible to child admin domain |
| 9 | 400 | 1707 | Default rule objects cannot be created/updated/deleted |
| 10 | 400 | 1708 | Start time is greater than end time |
| 11 | 400 | 1709 | Invalid time format |
| 12 | 400 | 1710 | Invalid DNS name |
| 13 | 400 | 1711 | Rule object name is required |
| 14 | 400 | 1712 | From and to both are required |
| 15 | 400 | 1713 | list cannot be empty |
| 16 | 400 | 1714 | Domain Id cannot be changed |
| 17 | 400 | 1716 | Protocol number should be between 0 and 255 |
| 18 | 400 | 1717 | Start port should be less than the end port |
| 19 | 400 | 1718 | Duplicate entry found |
| 20 | 400 | 1719 | List size should be less than or equal to 10 |
| 21 | 400 | 1720 | Invalid rule object id/ rule object not visible to this domain |
| 22 | 400 | 1721 | Network group rule object can contain either IPV4/IPV6 rule objects, but not both simultaneously |