Mitigation Group
Bastions Mitigation Profile
Overview
Bastions mitigation profile API for mitigation groups and BGP communities.
Version information
Version : 1.0.0.BETA
License information
Terms of service : https://www.nexusguard.com/
URI scheme
Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS
Paths
Adds a BGP community.
POST /spe/bastions/mitigation_profile/bgp_communities
Description
Creates a BGP community. Maximum 20 per slot_key.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | bgp_community required |
Request payload. | bgp_community |
| Name | Description | Schema |
|---|---|---|
| bgp_community_name required |
bgp community name. Required when slot_key=slotx; omit or empty when slot_key=slot0. | string |
| blackhole_community required |
Blackhole BGP community values. | < string > array |
| mitigation_community optional |
Mitigation community. | < string > array |
| slot_key required |
Slot key, two valid values are supported, it is slotx or slot0. | enum (slotx, slot0) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id optional |
BGP community ID. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets BGP community list.
GET /spe/bastions/mitigation_profile/bgp_communities
Description
Lists BGP communities for the given slot_key. Supports slotx and slot0. slotx represents the slot1–slot8 group (distinct from slot0). For slot0, only one BGP community record exists (auto-initialized on first access); when editing slot0, blackhole_community is required.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | slot_key optional |
Slot key filter. slotx or slot0, default slotx; see API description for slotx vs slot0 behavior. | enum (slotx, slot0) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| bgp_community_list optional |
BGP community profile list. | < bgp_community_list > array |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id optional |
BGP community profile ID. | string |
| bgp_community_name optional |
BGP community profile name. | string |
| blackhole_community optional |
Blackhole BGP community values. | < string > array |
| mitigation_community optional |
Mitigation BGP community values. | < string > array |
| slot optional |
Slot key, slotx or slot0; see API description for slotx vs slot0 behavior. | enum (slotx, slot0) |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Updates a BGP community.
PUT /spe/bastions/mitigation_profile/bgp_communities/{bgp_community_id}
Description
Updates name and community values. Name editable only for slotx. For slot0, only blackhole_community is required; mitigation_community is empty.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | bgp_community_id required |
string | |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | bgp_community required |
Request payload. | bgp_community |
| Name | Description | Schema |
|---|---|---|
| bgp_community_name optional |
BGP community profile name. | string |
| blackhole_community required |
Blackhole BGP community values. | < string > array |
| mitigation_community optional |
Mitigation BGP community values. | < string > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | SuccessResponse |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Deletes a BGP community.
DELETE /spe/bastions/mitigation_profile/bgp_communities/{bgp_community_id}
Description
Deletes BGP community if not referenced by a mitigation group.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | bgp_community_id required |
string | |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | SuccessResponse |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Adds a mitigation group.
POST /spe/bastions/mitigation_profile/mitigation_groups
Description
Creates a mitigation group for slot1-8.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | mitigation_group required |
Mitigation group configuration. Values for netshield_peer, traffic_collector_peer, bgp_community_id, and flowspec fields must be taken from the corresponding fields in GET /spe/bastions/mitigation_profile/mitigation_groups/options (use the same ip_type). At least one of netshield_peer or traffic_collector_peer must contain peer selections; both empty is rejected by the backend. These mitigation groups are referenced when creating or editing a Clean Pipe Network Protection site. | mitigation_group |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id required |
BGP community profile ID. Use bgp_community_id from an item in result.bgp_community in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | string |
| diversion_mode required |
0=Route, 1=FlowSpec, 2=Route and FlowSpec. When set to 1 or 2, flowspec must be provided. Use value from result.flowspec.diversion_mode in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | integer |
| flowspec optional |
FlowSpec diversion configuration. Required when diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec). traffic_collector_peer values must come from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] | flowspec |
| ip_type required |
IP type (ipv4 or ipv6). Must match the ip_type used when calling GET /spe/bastions/mitigation_profile/mitigation_groups/options. | enum (ipv4, ipv6) |
| mitigation_group_desc optional |
Mitigation group description. | string |
| mitigation_group_name required |
Mitigation group name. | string |
| netshield_peer optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Keys and peer_id values must come from result.netshield_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] | < string, < string > array > map |
| pops optional |
Selected IDC/PoP List and not empty when scope is pop. IDC/PoP values must be from result.pops field when calling GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] | < string > array |
| scope optional |
Scope specifies the range of the mitigation group. It accepts two valid values: global and pop, global indicates that the scope covers all POPs, while pop limits the scope to a specified POP.Default value is global. Default : "global" |
enum (global, pop) |
| slot_key required |
Slot key, only one valid value is supported, it is slotx, which means a set of slot1-slot8. | enum (slotx) |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Keys and peer_id values must come from result.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] | < string, < string > array > map |
| Name | Description | Schema |
|---|---|---|
| diversion_target optional |
Diversion target. | diversion_target |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Select peer groups from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | < string, < string > array > map |
| Name | Description | Schema |
|---|---|---|
| redirect_target optional |
FlowSpec redirect target. Required when diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec) | string |
| route_distinguisher optional |
Route distinguisher value. Required when route_distinguisher_enabled is enabled. [Conditionally required] | string |
| route_distinguisher_enabled optional |
0=route distinguisher disabled, 1=enabled. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| mitigation_group_id optional |
Mitigation group ID. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets mitigation group list.
GET /spe/bastions/mitigation_profile/mitigation_groups
Description
Lists mitigation groups for slot1-8. slot_key must be slotx, which means a set of slot1-slot8.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | ip_type required |
IP address family: ipv4 or ipv6. Default ipv4. | enum (ipv4, ipv6) |
| Query | slot_key required |
Slot key. Only one valid value is supported, it is slotx, which means a set of slot1-slot8. | enum (slotx) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| max_quota optional |
Max quota, a configurable value, its default is 20, which sets the maximum number of mitigation groups that can be created.. Minimum value : 0 |
integer |
| mitigation_group_list optional |
Mitigation group list. | < mitigation_group_list > array |
| used_quota optional |
Used quota, indicates the number of mitigation groups currently in use. The minimum value is 0, and the maximum value is determined by Max quota (default is 20). Minimum value : 0 |
integer |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id optional |
BGP community profile ID. | string |
| diversion_mode optional |
Diversion mode (0=Route, 1=FlowSpec, 2=Route and FlowSpec). | integer |
| flowspec optional |
FlowSpec diversion configuration. | flowspec |
| ip_type optional |
IP type (ipv4 or ipv6). | string |
| mitigation_group_desc optional |
Mitigation group description. | string |
| mitigation_group_id optional |
Mitigation group ID. | string |
| mitigation_group_name optional |
Mitigation group name. | string |
| netshield_peer optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. | < string, netshield_peer > map |
| pops optional |
Selected IDC/PoP List when scope is pop. IDC/PoP must contain available BGP peers. | < string > array |
| scope optional |
Scope type (global or pop) | enum (global, pop) |
| slot optional |
Slot key, only slotx. | enum (slotx) |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. | < string, traffic_collector_peer > map |
| Name | Description | Schema |
|---|---|---|
| diversion_target optional |
Diversion target. | diversion_target |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. | < string, traffic_collector_peer > map |
| Name | Description | Schema |
|---|---|---|
| redirect_target optional |
FlowSpec redirect target. | string |
| route_distinguisher optional |
Route distinguisher value. | string |
| route_distinguisher_enabled optional |
0=route distinguisher disabled, 1=enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets mitigation group options.
GET /spe/bastions/mitigation_profile/mitigation_groups/options
Description
Returns peers, BGP communities, and FlowSpec diversion options for creating a group. Peer options are from slot1–slot8 only (slot0 is excluded).
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | ip_type required |
IP address family: ipv4 or ipv6. Default ipv4. | enum (ipv4, ipv6) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| bgp_community optional |
BGP community profile. | < bgp_community > array |
| flowspec optional |
FlowSpec diversion configuration. | flowspec |
| netshield_peer optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes only enabled bgp_netshield peers on slot1–slot8 (slot0 excluded). | < string, netshield_peer > map |
| pops optional |
Available IDC/PoP List containing BGP peers when scope is pop. | < pops > array |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. Includes only enabled bgp_traffic_collector peers added under traffic collectors. Peers under this map are the available options when diversion_mode=0 (Route) or diversion_mode=2 (Route and FlowSpec). | < string, traffic_collector_peer > map |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id optional |
BGP community profile ID. | string |
| bgp_community_name optional |
BGP community profile name. | string |
| blackhole_community optional |
Blackhole BGP community values. | < string > array |
| mitigation_community optional |
Mitigation BGP community values. | < string > array |
| Name | Description | Schema |
|---|---|---|
| diversion_mode optional |
Diversion mode (0=Route, 1=FlowSpec, 2=Route and FlowSpec). | < diversion_mode > array |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. Available peer options for FlowSpec when diversion_mode=1 (FlowSpec) or diversion_mode=2 (Route and FlowSpec). Includes only bgp_traffic_collector peers with flowspec_enabled=1, set via POST /spe/bastions/resource/idc/{pop_id}/peers/{peer_id}/flowspec. | < string, traffic_collector_peer > map |
| Name | Description | Schema |
|---|---|---|
| name optional |
Display diversion mode name. | string |
| value optional |
Filter value. | integer |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
| Name | Description | Schema |
|---|---|---|
| has_flow_peer optional |
0=no flow peer, 1=have flow peer. | integer |
| idc optional |
PoP name. | string |
| name optional |
PoP display name. | string |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets slot0 mitigation group.
GET /spe/bastions/mitigation_profile/mitigation_groups/slot0
Description
Returns or initializes default slot0 mitigation group with BGP community and NetShield peers.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | slot_key optional |
Slot Key. Default slot0. | enum (slot0) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Response payload. | result |
| Name | Description | Schema |
|---|---|---|
| mitigation_group optional |
Slot0 mitigation group configuration. | mitigation_group |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id optional |
BGP community profile ID. | string |
| netshield_peer_ipv4 optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes bgp_netshield IPv4 peers added under all pops. | < string, netshield_peer_ipv4 > map |
| netshield_peer_ipv6 optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes bgp_netshield IPv6 peers added under all pops. | < string, netshield_peer_ipv6 > map |
| slot optional |
Slot key, only slot0. | enum (slot0) |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
| Name | Description | Schema |
|---|---|---|
| name optional |
PoP display name. | string |
| peers optional |
Peers available under this PoP. | < peers > array |
| Name | Description | Schema |
|---|---|---|
| peer_id optional |
Peer ID. | string |
| peer_name optional |
Peer name. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Updates a mitigation group.
PUT /spe/bastions/mitigation_profile/mitigation_groups/{mitigation_group_id}
Description
Updates peers, BGP community, description, and FlowSpec settings.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | mitigation_group_id required |
Mitigation group ID. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | mitigation_group required |
Mitigation group configuration. Values for netshield_peer, traffic_collector_peer, bgp_community_id, and flowspec fields must be taken from the corresponding fields in GET /spe/bastions/mitigation_profile/mitigation_groups/options (use the same ip_type as the mitigation group being updated). At least one of netshield_peer or traffic_collector_peer must contain peer selections; both empty is rejected by the backend. | mitigation_group |
| Name | Description | Schema |
|---|---|---|
| bgp_community_id required |
BGP community profile ID. Use bgp_community_id from an item in result.bgp_community in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | string |
| flowspec optional |
FlowSpec diversion configuration. traffic_collector_peer values must come from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | flowspec |
| mitigation_group_desc optional |
Mitigation group description. | string |
| mitigation_group_name required |
Mitigation group name. | string |
| netshield_peer optional |
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Keys and peer_id values must come from result.netshield_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | < string, < string > array > map |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Keys and peer_id values must come from result.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. | < string, < string > array > map |
| Name | Description | Schema |
|---|---|---|
| diversion_target optional |
Diversion target. | diversion_target |
| traffic_collector_peer optional |
Map keyed by IDC/PoP id (dynamic). Select peer_id values from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. Required when the mitigation group’s diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec). [Conditionally required] | < string, < string > array > map |
| Name | Description | Schema |
|---|---|---|
| redirect_target optional |
FlowSpec redirect target. | string |
| route_distinguisher optional |
Route distinguisher value. | string |
| route_distinguisher_enabled optional |
0=route distinguisher disabled, 1=enabled. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | SuccessResponse |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Deletes a mitigation group.
DELETE /spe/bastions/mitigation_profile/mitigation_groups/{mitigation_group_id}
Description
Deletes mitigation group by ID.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | mitigation_group_id required |
string | |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | SuccessResponse |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Definitions
SuccessResponse
Success response without business payload.
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
Security
ApiKeyAuth
Type : apiKey
Name : access_token
In : QUERY