This URL is used to update the advanced device configuration at the domain level.
Resource URL
PUT /domain/<domainId>/ advanceddeviceconfiguration
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
Payload Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Inherit settings from the parent domain | Boolean | Yes |
| Enable HTTP2 traffic inspection | Boolean | Yes |
| Attack bytes to capture - Can be 128, 256 | Int | Yes |
| Inspect tunneled traffic | Boolean | Yes |
| Log CLI activity. Values allowed are:
| String | Yes |
| Show CPU usage in CLI | Boolean | Yes |
| Restrict CLI access using SSH | Boolean | Yes |
| Enable SSH logging | Boolean | Yes |
| The permitted IPv4 CIDR list for SSH access to CLI | Object | Yes |
| The permitted IPv6 CIDR list for SSH access to CLI | Object | Yes |
| Chooses either the traditional Trellix IPS snort or the new Suricata snort | Boolean | Yes |
Details of permittedIPv4CIDRBlocks:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ID of the object | Int | No |
| IPv4 CIDR address | String | Yes |
| On delete action, the value should be 'delete' | String | Yes |
Details of permittedIPv6CIDRBlocks:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ID of the object | Int | No |
| IPv6 CIDR address | String | Yes |
| On delete action, the value should be 'delete' | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/domain/0/advanceddeviceconfiguration
Payload
{
"inheritSettings": false,
"enableHTTP2Traffic": true,
"preAttackBytestoCapture": 128,
"inspectTunneledTraffic": false,
"cliActivityLogging": "DISABLED",
"showCPUUsageinCLI": false,
"restrictSSHAccesstoCLI": true,
"enableSSHLogging": false,
"permittedIPv4CIDRBlocks":
[
{
"id": null,
"cidr": "1.1.1.1/32",
"action": null
}
],
"permittedIPv6CIDRBlocks":
[
{
"id": null,
"cidr": "2001:0DB9:0000:0000:0000:0000:0000:0001/128",
"action": null
}
] ,
“useTraditionalSnort”: true
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1105 | Invalid domain |
2 | 400 | 1001 | Pre attack packet capture bytes if provided, can only be 128 and 256 |
3 | 400 | 9101 | Cannot inherit setting for parent domain |
4 | 400 | 1701 | The cidrs provided are not present in the resource :: <list> |
5 | 400 | 1701 | The cidrs provided for addition are already present in the resource :: <list> |
6 | 400 | 1701 | Invalid CIDR notation : <list> |
7 | 400 | 1701 | Duplicate CIDR entry : <list> |
8 | 400 | 1001 | IP list is required |
9 | 500 | 1001 | Internal server errors |