☰

Resource

Bastions

Overview

Bastions Resource API

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS

Paths

Gets POP (IDC) list.

GET /spe/bastions/resource/idc

Description

Returns the Bastion-enabled POP/IDC list for the current SPE partner. Use pop_id or idc as pop_id path parameter in subsequent resource APIs. The chosen flag indicates the default selected POP in the UI.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
POP/IDC list for Bastion resource management. result

result

Name Description Schema
pop_list
optional
POP/IDC entries for the partner. < pop_list > array

pop_list

Name Description Schema
as_number
optional
BGP AS number for the POP. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
bastion_enabled
optional
0=Bastion disabled on this IDC, 1=enabled. integer
dns_server
optional
DNS server IP. string
gre_pool
optional
GRE IP pools (CIDR strings). < string > array
id
optional
IDC record ID. integer
idc
optional
IDC identifier (same as pop_id). string
latitude
optional
Latitude. string
location
optional
Location region code (e.g. CN, Default). string
location_name
optional
Location display name. string
longitude
optional
Longitude. string
machine_name
optional
Device display name (e.g. MX7000, R650). string
machine_type
optional
Device platform type. enum (mx7000, r650)
mode
optional
IDC deployment mode. enum (standalone, high_availability)
name
optional
POP display name. string
ntp_server
optional
NTP server IP. string
pop_id
optional
POP/IDC identifier used in API paths (e.g. nxg4, nxg_hk). string
slots
optional
Map keyed by slot_key (dynamic, slot1–slot8). Value is the slot hardware profile string. < string, string > map

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates IDC location.

POST /spe/bastions/resource/idc/{pop_id}/location

Description

Updates geographic location metadata.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body location
required
Request payload. location

location

Name Description Schema
latitude
required
Latitude. string
location_code
required
Location code. string
location_name
required
Location name. string
longitude
required
Longitude. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Adds a peer.

POST /spe/bastions/resource/idc/{pop_id}/peers

Description

Creates BGP, flow, or SNMP peer. Flow and SNMP peer types do not support IPv6; use ipv4 only.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body peer
required
Request payload. peer

peer

Name Description Schema
ip_type
required
IP type (ipv4 or ipv6). Required for all peer types. When peer_type is flow or snmp, only ipv4 is allowed; IPv6 is not supported. enum (ipv4, ipv6)
ip_uniq_id
required
Unique ID of the peer IP record. Required for all peer types. Scoped per peer type – use /spe/bastions/resource/idc/{pop_id}/peers/options with matching peer_type. integer
peer_type
required
Peer type (bgp_netshield, bgp_traffic_collector, flow, snmp). Required for all peer types. When bgp_netshield, slot_id, slot_key, and vlan_uniq_id are also required. When bgp_traffic_collector, flow, or snmp, traffic_collector_id is also required. enum (bgp_netshield, bgp_traffic_collector, flow, snmp)
router_id
required
Router ID. Required for all peer types. string
slot_id
optional
Slot record ID. Required when peer_type is bgp_netshield. [Conditionally required] string
slot_key
optional
Slot key (e.g. slot0, slot1, … ,slot8). Required when peer_type is bgp_netshield. [Conditionally required] string
traffic_collector_id
optional
Traffic collector ID. Required when peer_type is bgp_traffic_collector, flow, or snmp. Use result.traffic_collector.traffic_collector_id from GET /spe/bastions/resource/idc/{pop_id}/traffic_collectors/{traffic_collector_id}. [Conditionally required] string
vlan_uniq_id
optional
Inbound VLAN unique ID. Required when peer_type is bgp_netshield. [Conditionally required] integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
peer_id
optional
Peer ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets peer overview.

GET /spe/bastions/resource/idc/{pop_id}/peers

Description

Routers, traffic collector, slots, and peers.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
peers
optional
Peer list grouped by type. Lists active peers only; disabled peers (is_enabled=0) are excluded. < peers > array
router_list
optional
Router list. < router_list > array
slot
optional
Slot reference or slot key. slot
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

peers

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string
peer_type
optional
Peer type (bgp_netshield, bgp_traffic_collector, flow, snmp). enum (bgp_netshield, bgp_traffic_collector, flow, snmp)
router
optional
Router. router
slot
optional
Slot reference or slot key. slot
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

router

Name Description Schema
as_num
optional
BGP AS number. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
router_id
optional
Router ID. string

slot

Name Description Schema
g_num
optional
Slot0 sequence number (1-8). integer
slot_id
optional
Slot record ID. string
slot_key
optional
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
vlan_uniq_id
optional
VLAN unique ID. integer

traffic_collector

Name Description Schema
collector_id
optional
Collector identifier. string
ip_address
optional
IP address. string
traffic_collector_id
optional
Traffic collector ID. string

router_list

Name Description Schema
bgp
optional
BGP configuration. bgp
flow
optional
Flow export configuration. flow
router_id
optional
Router ID. string
router_name
optional
Router name. string
snmp
optional
SNMP query configuration. snmp

bgp

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
netshield
optional
NetShield BGP peer section. netshield
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

netshield

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ips
optional
BGP peer IP list. < peer_ips > array

peer_ips

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

traffic_collector

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ips
optional
BGP peer IP list. < peer_ips > array

peer_ips

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

flow

Name Description Schema
export_ip
optional
Flow export source IP. string
is_enabled
optional
0=disabled, 1=enabled. integer
status
optional
Flow peer status. 0=Unconnected, 1=Connected integer

snmp

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
query_ip
optional
SNMP query target IP. string
status
optional
SNMP peer status. 0=Unconnected, 1=Connected integer

slot

Name Description Schema
slot_id
optional
Slot record ID. string
slots
optional
Sub-slot configuration map. < slots > array

slots

Name Description Schema
in_vlan
optional
Inbound VLAN list. < in_vlan > array
out_vlan
optional
Outbound VLAN list. < object > array
slot_key
optional
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
slot_name
optional
Slot display name. string

in_vlan

Name Description Schema
peer
optional
Associated peer status. peer
vlan_id
optional
VLAN ID. integer
vlan_name
optional
VLAN name. string
vlan_uniq_id
optional
VLAN unique ID. integer

peer

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

traffic_collector

Name Description Schema
as_number
optional
BGP AS number. string
collector_id
optional
Collector identifier. string
collector_ip
optional
Collector IP address. string
hostname
optional
Traffic collector hostname. string
ipv4
optional
IPv4 address. string
ipv6
optional
IPv6 address. string
traffic_collector_id
optional
Traffic collector ID. string
traffic_collector_name
optional
Traffic collector name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets peer options.

GET /spe/bastions/resource/idc/{pop_id}/peers/options

Description

Available routers and IPs for new peer.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
enum (ipv4, ipv6)
Query peer_type
required
Peer type (bgp_netshield, bgp_traffic_collector, flow, snmp). bgp_netshield is a BGP peer created from a router and in_vlan on slot0–slot8. bgp_traffic_collector, flow, and snmp are BGP, Flow, and SNMP peers created from a router and traffic collector respectively. flow and snmp are virtual concepts: they represent router–traffic-collector bindings over the Flow or SNMP protocol. enum (bgp_netshield, bgp_traffic_collector, flow, snmp)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
available_routers
optional
Routers available for peer binding. < available_routers > array

available_routers

Name Description Schema
ip_address
optional
IP address list. < ip_address > array
router_id
optional
Router ID. string
router_name
optional
Router name. string

ip_address

Name Description Schema
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets peer statistics.

GET /spe/bastions/resource/idc/{pop_id}/peers/stat

Description

Counts by peer type.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
flow_peer
optional
Flow peer count or flow peer map. integer
netshield_peer
optional
NetShield peer count or peer map. integer
peer_num
optional
Total peer count. integer
router_num
optional
Total router count. integer
snmp_peer
optional
SNMP peer count. integer
traffic_director_peer
optional
Traffic director peer count. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes a peer.

DELETE /spe/bastions/resource/idc/{pop_id}/peers/{peer_id}

Description

Deletes peer by ID.

Parameters

Type Name Description Schema
Path peer_id
required
Peer ID. string
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles FlowSpec.

POST /spe/bastions/resource/idc/{pop_id}/peers/{peer_id}/flowspec

Description

Enables or disables FlowSpec. Only appliable to peers of type bgp_traffic_collector.

Parameters

Type Name Description Schema
Path peer_id
required
Peer ID. string
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles peer.

POST /spe/bastions/resource/idc/{pop_id}/peers/{peer_id}/switch

Description

Enables or disables peer. Only slot0 peers can be enabled or disabled; Traffic Collector peers and Slot 1–x peers are not supported for this operation.

Parameters

Type Name Description Schema
Path peer_id
required
Peer ID. string
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Adds a router.

POST /spe/bastions/resource/idc/{pop_id}/routers

Description

Creates a bastion router.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body router
required
Router information. router

router

Name Description Schema
desc
optional
Router description. string
location
required
Geographic location of the router. location
model
optional
Router model. string
role
required
Router role. enum (peering_edge, core, route_reflector, others)
router_name
required
Router name. string

location

Name Description Schema
code
required
Country or region code (e.g. AF). string
latitude
required
Latitude. string
longitude
required
Longitude. string
name
required
Country or region name (e.g. Afghanistan). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
router_id
optional
Router ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets router list.

GET /spe/bastions/resource/idc/{pop_id}/routers

Description

Returns routers with SNMP and flow status.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
router_list
optional
Router list. < router_list > array

router_list

Name Description Schema
bgp
optional
BGP configuration. bgp
desc
optional
Description. string
flow
optional
Flow export configuration. flow
location
optional
Geographic location. location
model
optional
Router or device model. string
role
optional
Router role. string
router_id
optional
Router ID. string
router_name
optional
Router name. string
snmp
optional
SNMP query configuration. snmp
type
optional
Resource type (e.g. PARTNER). string

bgp

Name Description Schema
as_num
optional
BGP AS number. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
is_enabled
optional
0=disabled, 1=enabled. integer
netshield
optional
NetShield BGP peer section. netshield
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

netshield

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < peer_ipv4 > array
peer_ipv6
optional
IPv6 BGP peer list. < peer_ipv6 > array

peer_ipv4

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

peer_ipv6

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

traffic_collector

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < peer_ipv4 > array
peer_ipv6
optional
IPv6 BGP peer list. < peer_ipv6 > array

peer_ipv4

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

peer_ipv6

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

flow

Name Description Schema
export_ip
optional
Flow export source IP. string
flow_down_enabled
optional
0=flow-down detection disabled, 1=enabled. integer
flow_down_timeout
optional
Flow-down detection timeout in seconds. integer
force_active_timeout
optional
Force active flow timeout flag. integer
is_enabled
optional
0=disabled, 1=enabled. integer
netflow_time_correction
optional
NetFlow timestamp correction settings. netflow_time_correction
peer
optional
Associated peer status. peer
port
optional
Flow port. 0=unset. Use the matching flow_version.*.port from GET /spe/bastions/resource/idc/{pop_id}/routers/options for the selected version (e.g. 2055, 6343, 4739). integer
resampling
optional
Flow resampling rate. 0=unset; 1–2147483647 when configured.
Minimum value : 0
Maximum value : 2147483647
integer
sampling
optional
Flow sampling rate. 0=unset or auto (when sampling_type is auto); 1–2147483647 when custom.
Minimum value : 0
Maximum value : 2147483647
integer
sampling_type
optional
Sampling type (auto or custom). string
version
optional
Flow version. Empty string when unset. Use a flow_version.*.key value from GET /spe/bastions/resource/idc/{pop_id}/routers/options when configured (e.g. netflow_v5, netflow_v9, sflow_v5, ipfix). enum (, netflow_v5, netflow_v9, sflow_v5, ipfix)

netflow_time_correction

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
offset
optional
Time offset value. integer
type
optional
Resource type (e.g. PARTNER). string

peer

Name Description Schema
ip_uniq_id
optional
Unique ID of the peer IP record. integer
status
optional
Connection status. integer

location

Name Description Schema
code
optional
Country or region code. string
latitude
optional
Latitude. string
longitude
optional
Longitude. string
name
optional
Display name. string

snmp

Name Description Schema
community
optional
SNMP community string. string
is_enabled
optional
0=disabled, 1=enabled. integer
peer
optional
Associated peer status. peer
query_ip
optional
SNMP query target IP. string
version
optional
Protocol version. string

peer

Name Description Schema
ip_uniq_id
optional
Unique ID of the peer IP record. integer
status
optional
Connection status. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets router options.

GET /spe/bastions/resource/idc/{pop_id}/routers/options

Description

Returns fixed candidate values for the add-router form, including router roles, SNMP versions, and flow export versions with default ports.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Fixed candidate values for creating a router. Option keys (peering_edge, v2c, netflow_v5, etc.) are stable; submit the nested key field when calling add router (e.g. role = peering_edge, flow.version = netflow_v5). result

result

Name Description Schema
flow_version
optional
Available flow export protocols and default ports. flow_version
netflow_time_correction_types
optional
Available netflow time correction types. netflow_time_correction_types
role
optional
Available router roles. role
sampling_types
optional
Available sampling types. sampling_types
snmp_version
optional
Available SNMP query versions. snmp_version

flow_version

Name Description Schema
ipfix
optional
IPFIX. ipfix
netflow_v5
optional
NetFlow v5. netflow_v5
netflow_v9
optional
NetFlow v9. netflow_v9
sflow_v5
optional
sFlow v5. sflow_v5

ipfix

Name Description Schema
key
optional
Option key submitted to the API. enum (ipfix)
name
optional
Display name. enum (IPFIX)
port
optional
Protocol port. enum (4739)

netflow_v5

Name Description Schema
key
optional
Option key submitted to the API. enum (netflow_v5)
name
optional
Display name. enum (Netflow V5)
port
optional
Protocol port. enum (2055)

netflow_v9

Name Description Schema
key
optional
Option key submitted to the API. enum (netflow_v9)
name
optional
Display name. enum (Netflow V9)
port
optional
Protocol port. enum (2055)

sflow_v5

Name Description Schema
key
optional
Option key submitted to the API. enum (sflow_v5)
name
optional
Display name. enum (SFlow V5)
port
optional
Protocol port. enum (6343)

netflow_time_correction_types

Name Description Schema
auto
optional
Auto detect offset. auto
custom
optional
assign custom offset. custom

auto

Name Description Schema
key
optional
Option key submitted to the API. enum (auto)
name
optional
Display name. enum (Auto)

custom

Name Description Schema
key
optional
Option key submitted to the API. enum (custom)
name
optional
Display name. enum (Custom)

role

Name Description Schema
core
optional
Core role. core
others
optional
Other router role. others
peering_edge
optional
Peering Edge role. peering_edge
route_reflector
optional
Route Reflector role. route_reflector

core

Name Description Schema
key
optional
Option key submitted to the API. enum (core)
name
optional
Display name. enum (Core)

others

Name Description Schema
key
optional
Option key submitted to the API. enum (others)
name
optional
Display name. enum (Others)

peering_edge

Name Description Schema
key
optional
Option key submitted to the API. enum (peering_edge)
name
optional
Display name. enum (Peering Edge)

route_reflector

Name Description Schema
key
optional
Option key submitted to the API. enum (route_reflector)
name
optional
Display name. enum (Route Reflector)

sampling_types

Name Description Schema
auto
optional
Auto detect sampling rate. auto
custom
optional
assign custom sampling rate. custom

auto

Name Description Schema
key
optional
Option key submitted to the API. enum (auto)
name
optional
Display name. enum (Auto)

custom

Name Description Schema
key
optional
Option key submitted to the API. enum (custom)
name
optional
Display name. enum (Custom)

snmp_version

Name Description Schema
v2c
optional
SNMP v2c. v2c

v2c

Name Description Schema
key
optional
Option key submitted to the API. enum (v2c)
name
optional
Display name. enum (V2C)

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets router for peer.

GET /spe/bastions/resource/idc/{pop_id}/routers/{router_id}

Description

Router details used when configuring peers.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
bgp
optional
BGP configuration. bgp
desc
optional
Description. string
flow
optional
Flow export configuration. flow
location
optional
Geographic location. location
model
optional
Router or device model. string
role
optional
Router role. string
router_id
optional
Router ID. string
router_name
optional
Router name. string
snmp
optional
SNMP query configuration. snmp
type
optional
Resource type (e.g. PARTNER). string

bgp

Name Description Schema
as_num
optional
BGP AS number. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
is_enabled
optional
0=disabled, 1=enabled. integer
netshield
optional
NetShield BGP peer section. netshield
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

netshield

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < peer_ipv4 > array
peer_ipv6
optional
IPv6 BGP peer list. < object > array

peer_ipv4

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
status
optional
Indicates whether this IP is bound to a peer. 0=unbound, 1=bound. When status=1, the IP address and password cannot be changed. integer

traffic_collector

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < object > array
peer_ipv6
optional
IPv6 BGP peer list. < object > array

flow

Name Description Schema
export_ip
optional
Flow export source IP. string
flow_down_enabled
optional
0=flow-down detection disabled, 1=enabled. integer
flow_down_timeout
optional
Flow-down detection timeout in seconds. integer
force_active_timeout
optional
Force active timeout (0=disabled, 1=enabled). integer
is_enabled
optional
0=disabled, 1=enabled. integer
netflow_time_correction
optional
NetFlow timestamp correction settings. netflow_time_correction
peer
optional
Associated peer status. peer
port
optional
Flow port. 0=unset; 2055, 6343, or 4739 when configured. integer
resampling
optional
Flow resampling rate. 0=unset; 1–2147483647 when configured.
Minimum value : 0
Maximum value : 2147483647
integer
sampling
optional
Flow sampling rate. 0=unset or auto (when sampling_type is auto); 1–2147483647 when custom.
Minimum value : 0
Maximum value : 2147483647
integer
sampling_type
optional
Sampling type (auto or custom). string
version
optional
Flow version. Empty string when unset; netflow_v5, netflow_v9, sflow_v5, or ipfix when configured. enum (, netflow_v5, netflow_v9, sflow_v5, ipfix)

netflow_time_correction

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
offset
optional
Time offset value. integer
type
optional
The type accepts two valid values: auto and custom. When set to auto, time is automatically corrected, and no values are required for offset. When set to custom, a custom offset is assigned. string

peer

Name Description Schema
ip_uniq_id
optional
Unique ID of the peer IP record. integer
status
optional
Connection status. integer

location

Name Description Schema
code
optional
Country or region code. string
latitude
optional
Latitude. string
longitude
optional
Longitude. string
name
optional
Display name. string

snmp

Name Description Schema
community
optional
SNMP community string. string
is_enabled
optional
0=disabled, 1=enabled. integer
peer
optional
Associated peer status. peer
query_ip
optional
SNMP query target IP. string
version
optional
Protocol version. string

peer

Name Description Schema
ip_uniq_id
optional
Unique ID of the peer IP record. integer
status
optional
Connection status. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates a router.

PUT /spe/bastions/resource/idc/{pop_id}/routers/{router_id}

Description

Updates router configuration by router_id.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body router
required
Router information. router

router

Name Description Schema
desc
optional
Router description. string
location
required
Geographic location of the router. location
model
optional
Router model. string
role
required
Router role. enum (peering_edge, core, route_reflector, others)
router_name
required
Router name. string

location

Name Description Schema
code
required
Country or region code (e.g. AF). string
latitude
required
Latitude. string
longitude
required
Longitude. string
name
required
Country or region name (e.g. Afghanistan). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes a router.

DELETE /spe/bastions/resource/idc/{pop_id}/routers/{router_id}

Description

Deletes a router by ID.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates router BGP.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/bgp

Description

Updates BGP configuration.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body bgp
required
Request payload. bgp

bgp

Name Description Schema
as_num
required
BGP AS number, integer in the range 1–4294967295 when configured. Cannot be changed if the router already has created peers.
Minimum value : 1
Maximum value : 4294967295
integer
is_enabled
required
0=disabled, 1=enabled. integer
netshield
optional
NetShield BGP peer section. netshield
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

netshield

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < peer_ipv4 > array
peer_ipv6
optional
IPv6 BGP peer list. < peer_ipv6 > array

peer_ipv4

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. When adding a new IP, omit this field or set ip_uniq_id=0. integer
password
optional
BGP password. string

peer_ipv6

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. When adding a new IP, omit this field or set ip_uniq_id=0. integer
password
optional
BGP password. string

traffic_collector

Name Description Schema
ipv6_enabled
optional
0=IPv6 disabled, 1=IPv6 enabled. integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_ipv4
optional
IPv4 BGP peer list. < peer_ipv4 > array
peer_ipv6
optional
IPv6 BGP peer list. < peer_ipv6 > array

peer_ipv4

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. When adding a new IP, omit this field or set ip_uniq_id=0. integer
password
optional
BGP password. string

peer_ipv6

Name Description Schema
address
optional
Peer IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. When adding a new IP, omit this field or set ip_uniq_id=0. integer
password
optional
BGP password. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles router BGP.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/bgp/switch

Description

Toggles router BGP.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates router flow.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/flow

Description

Updates flow export configuration.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body flow
required
Request payload. flow

flow

Name Description Schema
flow
required
Flow export configuration. flow

flow

Name Description Schema
export_ip
required
Flow export source IPv4 address only. string
flow_down_enabled
required
0=flow-down detection disabled, 1=enabled. integer
flow_down_timeout
optional
Flow-down detection timeout in seconds. Must be an integer in the range 1–4294967295.
Minimum value : 1
Maximum value : 4294967295
integer
force_active_timeout
optional
Force active timeout (0=disabled, 1=enabled). integer
is_enabled
required
0=disabled, 1=enabled. integer
netflow_time_correction
optional
Netflow time correction. netflow_time_correction
port
required
Flow port. Use the matching flow_version.*.port from GET /spe/bastions/resource/idc/{pop_id}/routers/options for the selected version (e.g. 2055, 6343, 4739). integer
resampling
optional
Flow resampling rate. resampling is an integer in the range 0–2147483647 when configured and must be greater than sampling, default is 0 when not assigned.
Minimum value : 0
Maximum value : 2147483647
integer
sampling
optional
Flow sampling rate. unset when sampling_type is auto, 1–2147483647 when custom.
Minimum value : 1
Maximum value : 2147483647
integer
sampling_type
required
The sampling_type accepts two valid values: auto and custom. When set to auto, the sampling rate is automatically detected, and no values are required for sampling or resampling. When set to custom, a custom sampling rate is assigned, and resampling must be greater than sampling. enum (auto, custom)
version
required
Flow version. Use a flow_version.*.key value from GET /spe/bastions/resource/idc/{pop_id}/routers/options (e.g. netflow_v5, netflow_v9, sflow_v5, ipfix). enum (netflow_v5, netflow_v9, sflow_v5, ipfix)

netflow_time_correction

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
offset
optional
Time offset. Must be an integer in the range -300 to 300 (inclusive).
Minimum value : -300
Maximum value : 300
integer
type
optional
The type accepts two valid values: auto and custom. When set to auto, time is automatically corrected, and no values are required for offset. When set to custom, a custom offset is assigned. enum (auto, custom)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles router flow.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/flow/switch

Description

Toggles router flow.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates router SNMP.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/snmp

Description

Updates SNMP configuration.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body snmp
required
Request payload. snmp

snmp

Name Description Schema
snmp
required
SNMP query configuration. snmp

snmp

Name Description Schema
community
required
SNMP community string. string
is_enabled
required
0=disabled, 1=enabled. integer
query_ip
required
SNMP query target IPv4 address only. string
version
required
SNMP version, only support v2c version. enum (v2c)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles router SNMP.

POST /spe/bastions/resource/idc/{pop_id}/routers/{router_id}/snmp/switch

Description

Toggles router SNMP.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path router_id
required
Router ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets mitigation slot list.

GET /spe/bastions/resource/idc/{pop_id}/slots

Description

Gets mitigation slot list for the IDC. Initializes slots if not present.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
slot_id
optional
Slot record ID. string
slots
optional
Sub-slot list. API response is an object keyed by slot_key (e.g. slot0–slot8); each item is one slot. object

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles slot IPv6.

POST /spe/bastions/resource/idc/{pop_id}/slots/ipv6

Description

Enables or disables IPv6 on a slot key (slot0, slot1–slot8 allowed). Slot IPv6 is synchronized with out_vlan IPv6: enabling slot IPv6 also enables IPv6 on the outbound VLAN (out_vlan) for that slot.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. Slot IPv6 status is synchronized with out_vlan IPv6; when slot IPv6 is enabled, out_vlan IPv6 is enabled as well. integer
slot_id
required
Slot record ID. Use result.slot_id from GET /spe/bastions/resource/idc/{pop_id}/slots. string
slot_key
required
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets mitigation port list.

GET /spe/bastions/resource/idc/{pop_id}/slots/mitigation_ports

Description

Returns available mitigation ports keyed by port identifier for adding or editing slot VLANs on R650. Submit mitigation_port and mitigation_port_type from the selected entry. MX7000 standalone uses /slots/ports instead.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query scope
required
Scope for mitigation ports, only supports value available. enum (available)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Available mitigation ports for R650 slot VLAN configuration. result

result

Name Description Schema
mitigation_ports
optional
Map keyed by mitigation port identifier (e.g. M01, M02). Each value is one port entry for VLAN mitigation_port selection. < string, mitigation_ports > map

mitigation_ports

Name Description Schema
ethernet_port
optional
Bound Ethernet switch port numbers. < string > array
lag
optional
1=LAG port, 0=non-LAG (NO-LAG). integer
mitigation_port
optional
Mitigation port identifier (e.g. M01, M04). Submit as mitigation_port when adding/editing VLAN. string
mitigation_port_type
optional
Mitigation port type. Submit as mitigation_port_type when adding/editing VLAN. enum (NO-LAG, LAG-SA, LAG-HA)
mode
optional
Port mode. active for LAG-SA; static for NO-LAG. enum (active, static)

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets port list.

GET /spe/bastions/resource/idc/{pop_id}/slots/ports

Description

Returns fixed MX7000 standalone Ethernet port options (A/B) and default mitigation port type. Used only on MX7000 devices; R650 does not call this API.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Fixed candidate values for MX7000 standalone slot VLAN port selection. Values are stable and do not vary by IDC. result

result

Name Description Schema
mitigation_port
optional
Mitigation port on MX7000 standalone. Always empty string; use port_list (A/B) instead. enum ()
mitigation_port_type
optional
Default mitigation port type for MX7000 standalone VLAN forms. LAG-SA for standalone mode, LAG-HA for high-availability mode. enum (LAG-SA, LAG-HA)
port_list
optional
MX7000 standalone Ethernet port identifiers. Always [“A”, “B”] for SA mode. < enum (A, B) > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets VLAN creation options.

GET /spe/bastions/resource/idc/{pop_id}/slots/vlan_options

Description

Gets available tunnel IP tuples for adding a VLAN.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query slot_key
required
Slot key, e.g. slot0, slot1. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
tunnel_ip_tuples
optional
Available GRE tunnel IP tuples. tunnel_ip_tuples

tunnel_ip_tuples

Name Description Schema
ipv4
optional
IPv4 address. ipv4
ipv6
optional
IPv6 address. ipv6

ipv4

Name Description Schema
ip_tuple_id
optional
Tunnel IP tuple ID. integer
local_ip
optional
GRE local IP pair. string
remote_ip
optional
GRE remote IP pair. string

ipv6

Name Description Schema
ip_tuple_id
optional
Tunnel IP tuple ID. integer
local_ip
optional
GRE local IP pair. string
remote_ip
optional
GRE remote IP pair. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Adds a VLAN.

POST /spe/bastions/resource/idc/{pop_id}/slots/vlans

Description

Adds in_vlan or out_vlan on a sub-slot. slot0 allows in_vlan only (no out_vlan). slot1–slot8 allow both in_vlan and out_vlan. For out_vlan, set gre_is_enabled: 0=standard VLAN (next_hop_ipv4/next_hop_ipv6), 1=GRE VLAN (gre_tunnel_ipv4_tuple_id, gre_tunnel_ipv6_tuple_id when slot IPv6 is on, gre_dst_ipv4, sa_ipv4; vrrp/r1/r2 may be empty strings). R650: mitigation_port and mitigation_port_type from get_mitigation_ports; omit port. MX7000 SA: port A or B from get_port_list; mitigation_port is empty. GRE out_vlan add example: slot_key=slot3, vlan_type=out_vlan, gre_is_enabled=1, gre_tunnel_ipv4_tuple_id=361, gre_tunnel_ipv6_tuple_id=362, next_hop_ipv4=192.168.1.253, gre_dst_ipv4=192.168.1.254, sa_ipv4=192.168.1.1⁄24, mitigation_port=M01, mitigation_port_type=LAG-SA.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body vlan
required
VLAN create request body. vlan

vlan

Name Description Schema
gre_dst_ipv4
optional
GRE destination IPv4 (out_vlan, gre_is_enabled=1). Often adjacent to next_hop_ipv4 (e.g. 192.168.1.254). [Conditionally required] string
gre_dst_ipv6
optional
GRE destination IPv6 (out_vlan, gre_is_enabled=1). Empty string if unused. [Conditionally required] string
gre_is_enabled
optional
Outbound VLAN mode when vlan_type=out_vlan. 0=standard VLAN (next_hop), 1=GRE VLAN (gre tunnel fields). Once set on create, gre_is_enabled cannot be changed on edit; updates must keep the original value. Required when vlan_type is out_vlan. integer
gre_tunnel_ipv4_tuple_id
optional
GRE tunnel IPv4 tuple ID from GET /spe/bastions/resource/idc/{pop_id}/slots/vlan_options. Required when gre_is_enabled=1 (e.g. 361). [Conditionally required] integer
gre_tunnel_ipv6_tuple_id
optional
GRE tunnel IPv6 tuple ID from GET /spe/bastions/resource/idc/{pop_id}/slots/vlan_options. Required when gre_is_enabled=1 and sub-slot IPv6 is enabled; send 0 otherwise. [Conditionally required] integer
mitigation_port
optional
Mitigation port (e.g. M01, M03). From mitigation ports by GET /spe/bastions/resource/idc/{pop_id}/slots/mitigation_ports on R650; empty on MX7000 SA. [Conditionally required] string
mitigation_port_type
optional
Mitigation port type from mitigation ports by GET /spe/bastions/resource/idc/{pop_id}/slots/mitigation_ports on R650; default value is LAG-SA on MX7000 SA. [Conditionally required] enum (NO-LAG, LAG-SA, LAG-HA)
next_hop_ipv4
optional
Next-hop IPv4 (out_vlan only, no mask) (e.g. 192.168.1.253). Required when gre_is_enabled=0; also send for GRE out_vlan (gre_is_enabled=1). [Conditionally required] string
next_hop_ipv6
optional
Next-hop IPv6 (out_vlan only) (e.g. 2001:db8::4⁄120). Empty string if IPv6 disabled on slot. Special case: when vlan_type=out_vlan and gre_is_enabled=1, this field must be an IPv4 address, not IPv6. [Conditionally required] string
port
optional
MX7000 SA physical port A or B. Use a value from result.port_list in GET /spe/bastions/resource/idc/{pop_id}/slots/ports. Omit or send empty string on R650. [Conditionally required] enum (, A, B)
r1_ipv4
optional
R1 IPv4 with CIDR (e.g. 192.23.4.3⁄24). Empty string for mode SA, Required for mode HA. [Conditionally required] string
r1_ipv6
optional
R1 IPv6 with CIDR (e.g. 2001:db8::1⁄120). Empty string if unused, Required for mode HA with IPv6. [Conditionally required] string
r2_ipv4
optional
R2 IPv4 with CIDR (e.g. 192.23.4.4⁄24). Empty string for mode SA, Required for mode HA.[Conditionally required] string
r2_ipv6
optional
R2 IPv6 with CIDR (e.g. 2001:db8::2⁄120). Empty string if unused, Required for mode HA with IPv6.[Conditionally required] string
sa_ipv4
optional
Service IPv4 (CIDR) (e.g. 192.23.4.5⁄24). Required for mode SA. [Conditionally required] string
sa_ipv6
optional
Service IPv6 (CIDR) (e.g. 2001:db8::3⁄120). Empty string if unused, Required for mode SA with IPv6. [Conditionally required] string
slot_id
required
Slot record ID. Use result.slot_id from GET /spe/bastions/resource/idc/{pop_id}/slots. string
slot_key
required
Slot key (slot0–slot8). slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
vlan_id
required
VLAN ID (ranges 2–3999, except 800–999). integer
vlan_name
required
VLAN name. Must be 2–32 characters long and can contain letters, numbers, dots, underscores or hyphens. string
vlan_type
required
VLAN direction. out_vlan is not allowed on slot0. enum (in_vlan, out_vlan)
vrrp_ipv4
optional
VRRP IPv4 (host address). Use empty string for mode SA, Required for mode HA. [Conditionally required] string
vrrp_ipv6
optional
VRRP IPv6 (host address). Empty string if unused or for mode SA, Required for mode HA with IPv6. [Conditionally required] string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
vlan_uniq_id
optional
Vlan unique ID. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates a VLAN.

PUT /spe/bastions/resource/idc/{pop_id}/slots/vlans

Description

Updates an existing VLAN. slot0 cannot use out_vlan. out_vlan type is set via gre_is_enabled (0=standard VLAN, 1=GRE VLAN), same as on create. VLANs already bound to a peer cannot be modified; only unbound VLANs can be updated.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body vlan
required
VLAN update request body. vlan

vlan

Name Description Schema
gre_dst_ipv4
optional
GRE destination IPv4 (out_vlan, gre_is_enabled=1). Often adjacent to next_hop_ipv4 (e.g. 192.168.1.254). [Conditionally required] string
gre_dst_ipv6
optional
GRE destination IPv6 (out_vlan, gre_is_enabled=1). Empty string if unused. [Conditionally required] string
gre_is_enabled
optional
Outbound VLAN mode when vlan_type=out_vlan. 0=standard VLAN (next_hop), 1=GRE VLAN (gre tunnel fields). Cannot be changed on edit; must keep the original value. Required when vlan_type is out_vlan. integer
mitigation_port
optional
Mitigation port (e.g. M01, M03). From mitigation ports by GET /spe/bastions/resource/idc/{pop_id}/slots/mitigation_ports on R650; empty on MX7000 SA. [Conditionally required] string
mitigation_port_type
optional
Mitigation port type from mitigation ports by GET /spe/bastions/resource/idc/{pop_id}/slots/mitigation_ports on R650; default value is LAG-SA on MX7000 SA. [Conditionally required] enum (NO-LAG, LAG-SA, LAG-HA)
next_hop_ipv4
optional
Next-hop IPv4 (out_vlan only, no mask) (e.g. 192.168.1.253). Required when gre_is_enabled=0; also send for GRE out_vlan (gre_is_enabled=1). [Conditionally required] string
next_hop_ipv6
optional
Next-hop IPv6 (out_vlan only) (e.g. 2001:db8::4⁄120). Empty string if IPv6 disabled on slot. Special case: when vlan_type=out_vlan and gre_is_enabled=1, this field must be an IPv4 address, not IPv6. [Conditionally required] string
port
optional
MX7000 SA physical port A or B. Use a value from result.port_list in GET /spe/bastions/resource/idc/{pop_id}/slots/ports. Omit or send empty string on R650. [Conditionally required] enum (, A, B)
r1_ipv4
optional
R1 IPv4 with CIDR (e.g. 192.23.4.3⁄24). Empty string for mode SA, Required for mode HA. [Conditionally required] string
r1_ipv6
optional
R1 IPv6 with CIDR (e.g. 2001:db8::1⁄120). Empty string if unused, Required for mode HA with IPv6. [Conditionally required] string
r2_ipv4
optional
R2 IPv4 with CIDR (e.g. 192.23.4.4⁄24). Empty string for mode SA, Required for mode HA.[Conditionally required] string
r2_ipv6
optional
R2 IPv6 with CIDR (e.g. 2001:db8::2⁄120). Empty string if unused, Required for mode HA with IPv6.[Conditionally required] string
sa_ipv4
optional
Service IPv4 (CIDR) (e.g. 192.23.4.5⁄24). Required for mode SA. [Conditionally required] string
sa_ipv6
optional
Service IPv6 (CIDR) (e.g. 2001:db8::3⁄120). Empty string if unused, Required for mode SA with IPv6. [Conditionally required] string
slot_id
required
Slot record ID. Use result.slot_id from GET /spe/bastions/resource/idc/{pop_id}/slots. string
slot_key
required
Slot key (slot0–slot8). slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
vlan_id
required
VLAN ID (ranges 2–3999, except 800–999).
Minimum value : 2
Maximum value : 3999
integer
vlan_name
required
VLAN name. Must be 2–32 characters long and can contain letters, numbers, dots, underscores or hyphens. string
vlan_type
required
VLAN direction. out_vlan is not allowed on slot0. enum (in_vlan, out_vlan)
vlan_uniq_id
required
VLAN unique ID from vlan created, or use result.slots.{slot_key}.in_vlan.*.vlan_uniq_id from GET /spe/bastions/resource/idc/{pop_id}/slots (use out_vlan for outbound VLAN entries). integer
vrrp_ipv4
optional
VRRP IPv4 (host address). Use empty string for mode SA, Required for mode HA. [Conditionally required] string
vrrp_ipv6
optional
VRRP IPv6 (host address). Empty string if unused or for mode SA, Required for mode HA with IPv6. [Conditionally required] string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes a VLAN.

DELETE /spe/bastions/resource/idc/{pop_id}/slots/vlans

Description

Deletes a VLAN from a slot by vlan_uniq_id. slot0 cannot delete out_vlan. VLANs already bound to a peer cannot be deleted; only unbound VLANs can be removed.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
slot_id
required
Slot record ID. Use result.slot_id from GET /spe/bastions/resource/idc/{pop_id}/slots. string
slot_key
required
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
vlan_type
required
Vlan type. enum (in_vlan, out_vlan)
vlan_uniq_id
required
VLAN unique ID. Use result.slots.{slot_key}.in_vlan.*.vlan_uniq_id from GET /spe/bastions/resource/idc/{pop_id}/slots (use out_vlan for outbound VLAN entries). integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Toggles VLAN IPv6.

POST /spe/bastions/resource/idc/{pop_id}/slots/vlans/ipv6

Description

Enables or disables IPv6 on an inbound VLAN (in_vlan only). out_vlan IPv6 cannot be toggled independently; out_vlan IPv6 stays synchronized with slot IPv6.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body request
required
Request payload. request

request

Name Description Schema
is_enabled
required
0=disabled, 1=enabled. integer
slot_id
required
Slot record ID. Use result.slot_id from GET /spe/bastions/resource/idc/{pop_id}/slots. string
slot_key
required
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
vlan_type
required
Vlan type (only in_vlan is allowed). enum (in_vlan)
vlan_uniq_id
required
VLAN unique ID. Use result.slots.{slot_key}.in_vlan.*.vlan_uniq_id from GET /spe/bastions/resource/idc/{pop_id}/slots. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets slot VLAN list.

GET /spe/bastions/resource/idc/{pop_id}/slots/{slot_id}/{slot_key}/vlans

Description

Returns the inbound (in_vlan) list on a slot, including any peer already bound to each VLAN. Peer binding applies only to in_vlan entries; outbound (out_vlan) VLANs are not eligible for peer configuration. When selecting a VLAN for peer binding, use result.slot.in_vlan only.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path slot_id
required
string
Path slot_key
required
string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
slot
optional
Slot information for slot key (e.g. slot0, slot1).
Before adding a bgp_netshield peer, use this API to obtain the in_vlan list for the
current slot. If peer under a VLAN entry is empty, that VLAN is available for creating
a new peer; otherwise the response shows the existing peer details.
slot

slot

Name Description Schema
in_vlan
optional
Inbound VLAN list eligible for peer binding. < in_vlan > array
slot_key
optional
Slot key (e.g. slot0, slot1), slot0 supports in_vlan only; slot1–slot8 support in_vlan and out_vlan. string
slot_name
optional
Slot display name. string

in_vlan

Name Description Schema
peer
optional
Associated peer status on this VLAN. Empty peer object means a new peer can be created on this VLAN; a non-empty peer returns the existing peer details. If is_enabled=0 (disabled), the peer is omitted from the peers array in GET /spe/bastions/resource/idc/{pop_id}/peers (peer_info lists active peers only; disabled peers are excluded). peer
vlan_id
optional
VLAN ID. integer
vlan_ip_address
optional
Vlan IP address. string
vlan_name
optional
VLAN name. string
vlan_uniq_id
optional
VLAN unique ID. integer

peer

Name Description Schema
is_enabled
optional
0=disabled, 1=enabled. integer
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string
peer_type
optional
Peer type (only bgp_netshield is allowed). enum (bgp_netshield)
router
optional
Router. router

router

Name Description Schema
as_num
optional
BGP AS number. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
router_id
optional
Router ID. string
router_name
optional
Router name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets traffic collector.

GET /spe/bastions/resource/idc/{pop_id}/traffic_collectors/{traffic_collector_id}

Description

Traffic collector details for peer configuration.

Parameters

Type Name Description Schema
Path pop_id
required
IDC/PoP identifier name. string
Path traffic_collector_id
required
string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
peers
optional
Peer list grouped by type (bgp, flow, snmp). Returns traffic-director-related peers: bgp_traffic_collector, flow, and snmp. peers
traffic_collector
optional
Traffic collector BGP peer section. traffic_collector

peers

Name Description Schema
bgp
optional
BGP configuration. < bgp > array
flow
optional
Flow export configuration. < flow > array
snmp
optional
SNMP query configuration. < snmp > array

bgp

Name Description Schema
flowspec_enabled
optional
0=FlowSpec disabled, 1=enabled (traffic collector peer only). integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string
peer_type
optional
Peer type (bgp_traffic_collector). enum (bgp_traffic_collector)
router
optional
Router. router

router

Name Description Schema
as_num
optional
BGP AS number. 0=unset; 1–4294967295 when configured.
Minimum value : 0
Maximum value : 4294967295
integer
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
router_id
optional
Router ID. string
router_name
optional
Router name. string

flow

Name Description Schema
flowspec_enabled
optional
0=FlowSpec disabled, 1=enabled (traffic collector peer only). integer
is_enabled
optional
0=disabled, 1=enabled. integer
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string
peer_type
optional
Peer type (flow peer type only). Flow peer type do not support IPv6; use ipv4 only. enum (flow)
router
optional
Router. router

router

Name Description Schema
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
router_id
optional
Router ID. string
router_name
optional
Router name. string

snmp

Name Description Schema
flowspec_enabled
optional
0=FlowSpec disabled, 1=enabled (traffic collector peer only). integer
interface_list
optional
Interface list. < interface_list > array
is_enabled
optional
0=disabled, 1=enabled. integer
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string
peer_type
optional
Peer type (snmp peer type only). SNMP peer type do not support IPv6; use ipv4 only. enum (snmp)
router
optional
Router. router

interface_list

Name Description Schema
customer_id
optional
Customer ID. integer
site_id
optional
Site ID. integer
site_name
optional
Site name. string

router

Name Description Schema
ip_address
optional
IP address. string
ip_uniq_id
optional
Unique ID of the peer IP record. integer
password
optional
BGP password. string
router_id
optional
Router ID. string
router_name
optional
Router name. string

traffic_collector

Name Description Schema
as_number
optional
BGP AS number. string
collector_id
optional
Collector identifier. string
collector_ip
optional
Collector IP address. string
hostname
optional
Traffic collector hostname. string
ipv4
optional
IPv4 address. string
ipv6
optional
IPv6 address. string
traffic_collector_id
optional
Traffic collector ID. string
traffic_collector_name
optional
Traffic collector name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

SuccessResponse

Success response without business payload.

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY