Auto Mitigation
Auto Mitigation
Overview
Auto Mitigation APIs for Network Protection under /spe/np.
Policy modules use a dual-path model: GET returns the full policy (including nested lists for display); POST applies incremental updates via *PolicyInput schemas (only include fields to change). List-style sub-items (filters, flex-zombie rules, ACL custom rules, payload filters, L7 filters) are managed via dedicated CRUD APIs, not policy POST.
Version information
Version : 1.0.0.BETA
License information
Terms of service : https://www.nexusguard.com/
URI scheme
Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS
Paths
Create an IP set template.
POST /spe/np/auto-mitigation/template/ip-set
Description
Creates an SPE-level IP set template shared across auto-mitigation profiles for the allow/block list policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | ip_set required |
IP set template payload. | IpSetInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Created IP set ID. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get an IP set template.
GET /spe/np/auto-mitigation/template/ip-set/{ip_set_id}
Description
Returns a single IP set template by ID.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | ip_set_id required |
IP set ID. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | ip_type optional |
IP address family: ipv4 or ipv6. | enum (ipv4, ipv6) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
IpSetSummary |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update an IP set template.
PUT /spe/np/auto-mitigation/template/ip-set/{ip_set_id}
Description
Updates an IP set template for allow/block list policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | ip_set_id required |
IP set ID. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | ip_set required |
IP set template payload. | IpSetInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete an IP set template.
DELETE /spe/np/auto-mitigation/template/ip-set/{ip_set_id}
Description
Deletes an IP set template.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | ip_set_id required |
IP set ID. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get IP set templates for allow/block list policy.
GET /spe/np/auto-mitigation/template/ip-sets
Description
Returns SPE-level IP set templates shared across auto-mitigation profiles for building allow/block list policies. No profile_id is required.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | ip_type optional |
IP address family, ipv4 or ipv6. Default is ipv4. | enum (ipv4, ipv6) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
< IpSetSummary > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Allow/block list policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/allow-block-list
Description
Incrementally updates the allow/block list policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
Allow/block list policy. | AllowBlockListPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Allow/block list policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/allow-block-list
Description
Returns the allow/block list policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AllowBlockListPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update ICMP anti-flood policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp
Description
Incrementally updates ICMP anti-flood policy settings. Include only fields or sub-objects to change; omitted fields are preserved. Custom ICMP filters are managed via ICMP filter CRUD APIs.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
ICMP anti-flood policy. | AntiFloodL3L4IcmpPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get ICMP anti-flood policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp
Description
Returns the ICMP anti-flood policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AntiFloodL3L4IcmpPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create ICMP custom anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter
Description
Creates a custom ICMP anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
ICMP filter configuration. | IcmpFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID, a unique identifier assigned to each custom ICMP filter. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get ICMP custom anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}
Description
Returns a custom ICMP anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Custom ICMP filter ID. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
IcmpFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update ICMP custom anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}
Description
Updates a custom ICMP anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Custom ICMP filter ID. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
ICMP filter configuration. | IcmpFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete ICMP custom anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}
Description
Deletes a custom ICMP anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Custom ICMP filter ID. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get ICMP custom anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filters
Description
Returns the custom ICMP anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
ICMP custom filters | < IcmpFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update IP-layer anti-flood policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/ip
Description
Incrementally updates the IP-layer anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
IP-layer anti-flood policy. | AntiFloodL3L4IpPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get IP-layer anti-flood policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/ip
Description
Returns the IP-layer anti-flood policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AntiFloodL3L4IpPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update TCP anti-flood policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/tcp
Description
Incrementally updates the TCP anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
TCP anti-flood policy. | AntiFloodL3L4TcpPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get TCP anti-flood policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/tcp
Description
Returns the TCP anti-flood policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AntiFloodL3L4TcpPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update UDP anti-flood policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/udp
Description
Incrementally updates the UDP anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
UDP anti-flood policy. | AntiFloodL3L4UdpPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get UDP anti-flood policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/udp
Description
Returns the UDP anti-flood policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AntiFloodL3L4UdpPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create Custom L7 anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter
Description
Creates a Custom L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
L7 filter create payload. | CustomFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Custom L7 anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}
Description
Returns a Custom L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the Custom L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
CustomFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Custom L7 anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}
Description
Updates a Custom L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the Custom L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
Custom L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. | CustomFilter |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete Custom L7 anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}
Description
Deletes a Custom L7 anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the Custom L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Custom L7 anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filters
Description
Returns the Custom L7 anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Custom filters | < CustomFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create HTTP L7 anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter
Description
Creates a HTTP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
L7 filter create payload. | HttpFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get HTTP L7 anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}
Description
Returns a HTTP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the HTTP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
HttpFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update HTTP L7 anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}
Description
Updates a HTTP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the HTTP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
HTTP L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. | HttpFilter |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete HTTP L7 anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}
Description
Deletes a HTTP L7 anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the HTTP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get HTTP L7 anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filters
Description
Returns the HTTP L7 anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
HTTP filters | < HttpFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create QUIC L7 anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter
Description
Creates a QUIC L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
L7 filter create payload. | QuicFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get QUIC L7 anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}
Description
Returns a QUIC L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the QUIC L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
QuicFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update QUIC L7 anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}
Description
Updates a QUIC L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the QUIC L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
QUIC L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. | QuicFilter |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete QUIC L7 anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}
Description
Deletes a QUIC L7 anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the QUIC L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get QUIC L7 anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filters
Description
Returns the QUIC L7 anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
QUIC filters | < QuicFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create SIP L7 anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter
Description
Creates a SIP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
L7 filter create payload. | SipFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get SIP L7 anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}
Description
Returns a SIP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the SIP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
SipFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update SIP L7 anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}
Description
Updates a SIP L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the SIP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
SIP L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. | SipFilter |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete SIP L7 anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}
Description
Deletes a SIP L7 anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the SIP L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get SIP L7 anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filters
Description
Returns the SIP L7 anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
SIP filters | < SipFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create TLS L7 anti-flood filter.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter
Description
Creates a TLS L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
L7 filter create payload. | TlsFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get TLS L7 anti-flood filter.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}
Description
Returns a TLS L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the TLS L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
TlsFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update TLS L7 anti-flood filter.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}
Description
Updates a TLS L7 anti-flood filter for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the TLS L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
TLS L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. | TlsFilter |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete TLS L7 anti-flood filter.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}
Description
Deletes a TLS L7 anti-flood filter from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the TLS L7 anti-flood filter. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get TLS L7 anti-flood filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filters
Description
Returns the TLS L7 anti-flood filters for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
TLS filters | < TlsFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Bogon and invalid address protections.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/bogons
Description
Incrementally updates the bogon and invalid address protection policy. Include only fields or sub-objects to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
Bogon and invalid address protections. | BogonsPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Bogon and invalid address protections.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/bogons
Description
Returns the bogon and invalid address protection policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
BogonsPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update FlexFilter ACL filter policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter
Description
Incrementally updates FlexFilter ACL filter policy (enable flag and attached ACL filter sets). Include only fields to change; omitted fields are preserved. The acl_filter_sets array supports incremental attach/detach of site-level ACL template sets. Custom ACL rules are managed via custom-filter CRUD APIs.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
FlexFilter ACL filter policy. | FlexFilterAclFilterPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter ACL filter policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter
Description
Returns the FlexFilter ACL filter policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
FlexFilterAclFilterPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create FlexFilter ACL custom filter rule.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter
Description
Creates a custom ACL filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
Custom ACL filter rule create payload. | FlexFilterAclCustomRuleInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| rule_id optional |
Rule ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter ACL custom filter rule.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}
Description
Returns a custom ACL filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the custom ACL rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
FlexFilterAclCustomRule |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update FlexFilter ACL custom filter rule.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}
Description
Updates a custom ACL filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the custom ACL rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
Custom ACL filter rule update payload. rule_id is provided in the path. | FlexFilterAclCustomRuleUpdateInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete FlexFilter ACL custom filter rule.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}
Description
Deletes a custom ACL filter rule from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the custom ACL rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter ACL custom filter rules.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filters
Description
Returns the custom ACL filter rules for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
< FlexFilterAclCustomRule > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter payload filter policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter
Description
Returns the FlexFilter payload filter policy for the auto-mitigation profile. Individual rules are managed via payload-filter CRUD APIs.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
FlexFilterPayloadFilterPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create FlexFilter payload filter rule.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter
Description
Creates a payload filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
Payload filter rule configuration. | PayloadFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID, a unique identifier assigned to each payload filter rule. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter payload filter rule.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}
Description
Returns a payload filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the payload filter rule. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
PayloadFilter |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update FlexFilter payload filter rule.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}
Description
Updates a payload filter rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the payload filter rule. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | filter required |
Payload filter rule configuration. | PayloadFilterInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete FlexFilter payload filter rule.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}
Description
Deletes a payload filter rule from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | filter_id required |
Unique identifier of the payload filter rule. | string |
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get FlexFilter payload filters.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filters
Description
Returns the payload filter rules for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
Payload filter rules | < PayloadFilter > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Network Threat Intelligence Feed policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/ntif
Description
Incrementally updates the NTIF policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved. Not supported for IPv6.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
Network Threat Intelligence Feed policy. | NtifPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Network Threat Intelligence Feed policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/ntif
Description
Returns the Network Threat Intelligence Feed policy for the auto-mitigation profile. Not supported for IPv6.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
NtifPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Traffic policing cap policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/traffic-policing
Description
Incrementally updates the traffic policing cap policy for the auto-mitigation profile. Include only fields to change; omitted fields are preserved.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
Traffic policing cap policy. | TrafficPolicingPolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Traffic policing cap policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/traffic-policing
Description
Returns the traffic policing cap policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
TrafficPolicingPolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update Zombie host detection policy.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie
Description
Incrementally updates zombie host/network detection settings. Include only fields or sub-objects to change; omitted fields are preserved. Flex zombie rules are managed via flex-zombie CRUD APIs.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | policy required |
Zombie host detection policy. | ZombiePolicyInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get Zombie host detection policy.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie
Description
Returns the zombie host detection policy for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
ZombiePolicy |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create flex zombie rule.
POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie
Description
Creates a flex zombie rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
Flex zombie rule configuration. | FlexZombieRuleInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| rule_id optional |
Rule ID | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get flex zombie rule.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}
Description
Returns a flex zombie rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the flex zombie rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
FlexZombieRule |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update flex zombie rule.
PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}
Description
Updates a flex zombie rule for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the flex zombie rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
Flex zombie rule configuration. | FlexZombieRuleInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete flex zombie rule.
DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}
Description
Deletes a flex zombie rule from the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | rule_id required |
Unique identifier of the flex zombie rule. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get flex zombie rules.
GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombies
Description
Returns the flex zombie rules for the auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
< FlexZombieRule > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get an ACL filter set with rules.
GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}
Description
Returns one site-level ACL rule set for the site, including its rules.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_set_id required |
ACL rule set ID. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
AclSetSummary |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update an ACL filter set.
PUT /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}
Description
Updates a site-level ACL rule set name and description.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_set_id required |
string | |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | acl_set required |
AclSetInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete an ACL filter set.
DELETE /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}
Description
Deletes a site-level ACL rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_set_id required |
string | |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get an ACL rule.
GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}
Description
Returns one ACL rule from the specified site-level ACL rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_id required |
ACL rule ID. | string |
| Path | rule_set_id required |
ACL rule set ID. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
AclRule |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update an ACL rule.
PUT /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}
Description
Updates an ACL rule in the specified site-level rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_id required |
string | |
| Path | rule_set_id required |
string | |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
AclRuleInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete an ACL rule.
DELETE /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}
Description
Deletes an ACL rule from the specified site-level rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_id required |
string | |
| Path | rule_set_id required |
string | |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Add an ACL rule to a rule set.
POST /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rules
Description
Adds a rule to the specified site-level ACL rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_set_id required |
string | |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | rule required |
AclRuleInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
result |
| Name | Schema |
|---|---|
| rule_id optional |
string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
List ACL rules in a rule set.
GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rules
Description
Returns all ACL rules in the specified site-level ACL rule set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | rule_set_id required |
ACL rule set ID. | string |
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
< AclRule > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Create an ACL filter set.
POST /spe/np/site/{site_id}/auto-mitigation/template/acl-sets
Description
Creates a site-level ACL rule set for the Network Protection site, shared across auto-mitigation profiles for the FlexFilter policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | acl_set required |
AclSetInput |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
result |
| Name | Schema |
|---|---|
| rule_set_id optional |
string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get ACL filter set list.
GET /spe/np/site/{site_id}/auto-mitigation/template/acl-sets
Description
Returns site-level ACL rule sets for the Network Protection site, shared across auto-mitigation profiles, including embedded rules for the FlexFilter policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | site_id required |
Network Protection site identifier. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
< AclSetSummary > array |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update a Network Protection auto-mitigation profile name.
POST /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}
Description
Updates the profile name for an auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site ID. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| FormData | description optional |
Description. | string |
| FormData | profile_name required |
Profile name. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get a Network Protection auto-mitigation profile.
GET /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}
Description
Returns detailed information for an auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site ID. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| description optional |
Description of an auto-mitigation profile. | string |
| profile_id optional |
Unique identifier of an auto-mitigation profile. | string |
| profile_name optional |
Name of an auto-mitigation profile. | string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete a Network Protection auto-mitigation profile.
DELETE /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}
Description
Deletes an auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site ID. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Clone a Network Protection auto-mitigation profile.
POST /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}/clone
Description
Clones an auto-mitigation profile.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | profile_id required |
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. | string |
| Path | site_id required |
Network Protection site ID. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
Consumes
application/x-www-form-urlencoded
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the Network Protection auto-mitigation profile list.
GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles
Description
Returns auto-mitigation profiles for selecting network-level or host-level templates in the NetShield Overview.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | site_id required |
Network Protection site ID. Obtain from GET /spe/np/sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
| result optional |
< result > array |
| Name | Description | Schema |
|---|---|---|
| description optional |
Description of an auto-mitigation profile. Length : 0 - 100 |
string |
| profile_id optional |
Unique identifier of an auto-mitigation profile. | string |
| profile_name optional |
Name of an auto-mitigation profile. Length : 2 - 40 |
string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Definitions
AclRule
ACL rule in a site-level ACL rule set.
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id optional |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| tcp_flags optional |
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
AclRuleInput
| Name | Description | Schema |
|---|---|---|
| action required |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol required |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_name required |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| tcp_flags optional |
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
AclSetInput
| Name | Description | Schema |
|---|---|---|
| rule_set_desc optional |
The description of the rule set. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_set_name required |
The name of the rule set. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
AclSetSummary
| Name | Description | Schema |
|---|---|---|
| ip_type optional |
IP address family, ipv4 or ipv6. | enum (ipv4, ipv6) |
| rule_set_desc optional |
string | |
| rule_set_id optional |
string | |
| rule_set_name optional |
string | |
| rules optional |
< AclRule > array |
AllowBlockListIpSet
Referenced IP set template details. Present when allow/block list mode is 2.
| Name | Description | Schema |
|---|---|---|
| ip_set_desc optional |
More details about the purpose of the policy. | string |
| ip_set_id optional |
Unique identifier of ip set. | string |
| ip_set_name optional |
The name of the policy. | string |
| source_countries optional |
< string > array | |
| source_ips optional |
< string > array |
AllowBlockListPolicy
Allow list and block list configuration for source traffic.
| Name | Description | Schema |
|---|---|---|
| allow_list optional |
Trusted sources permitted when allow-list policy is enabled. | allow_list |
| block_list optional |
Sources to block or rate-limit when block-list policy is enabled. | block_list |
| Name | Description | Schema |
|---|---|---|
| ip_set optional |
AllowBlockListIpSet | |
| mode optional |
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| ip_set optional |
AllowBlockListIpSet | |
| mode optional |
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
AllowBlockListPolicyInput
Allow/block list policy incremental update payload. Include only top-level fields or sub-objects to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| allow_list optional |
Trusted sources permitted when allow-list policy is enabled. | allow_list |
| block_list optional |
Sources to block or rate-limit when block-list policy is enabled. | block_list |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. | string |
| mode optional |
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. | string |
| mode optional |
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
AntiFloodL3L4IcmpPolicy
ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported.
| Name | Description | Schema |
|---|---|---|
| all_icmp_packet optional |
Drop all ICMP traffic when enabled. | all_icmp_packet |
| icmp_custom_filter optional |
Custom ICMP type/code rules with a default profile. | icmp_custom_filter |
| icmp_fragmentation optional |
ICMP fragmentation handling. | icmp_fragmentation |
| large_ping optional |
Drop oversized ICMP echo requests. | large_ping |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = drop all ICMP traffic . | integer |
| Name | Description | Schema |
|---|---|---|
| default optional |
Default ICMP filter applied when no custom rule matches. | default |
| filters optional |
Custom ICMP filters. Managed via ICMP filter CRUD APIs. | < filters > array |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit, pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Can not be edited. Length : 1 - 40 Pattern : "^[A-Za-z0-9_.-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| action optional |
pass or ratelimit. | enum (pass, ratelimit) |
| bps_limit optional |
Rate limit in bits per second (bps). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_description optional |
Filter description. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| icmp_length optional |
ICMP payload length to drop (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| icmp_type optional |
ICMP type number. Minimum value : 0 Maximum value : 31 |
integer |
| pps_limit optional |
Rate limit in packets per second (pps). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4IcmpPolicyInput
ICMP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Custom filters are managed via ICMP filter CRUD APIs; do not include icmp_custom_filter.filters in this request.
| Name | Description | Schema |
|---|---|---|
| all_icmp_packet optional |
Drop all ICMP traffic when enabled. | all_icmp_packet |
| icmp_custom_filter optional |
Custom ICMP type/code rules with a default profile. | icmp_custom_filter |
| icmp_fragmentation optional |
ICMP fragmentation handling. | icmp_fragmentation |
| large_ping optional |
Drop oversized ICMP echo requests. | large_ping |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = drop all ICMP traffic . | integer |
| Name | Description | Schema |
|---|---|---|
| default optional |
Default ICMP filter applied when no custom rule matches. | default |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit, pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Can not be edited. Length : 1 - 40 Pattern : "^[A-Za-z0-9_.-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4IpPolicy
IP-layer sanity and flood mitigation.
| Name | Description | Schema |
|---|---|---|
| custom_protocol_filter optional |
Filter on specific IP protocol numbers. | custom_protocol_filter |
| ip_fragmentation optional |
IP fragmentation handling. | ip_fragmentation |
| ip_invalid optional |
Drop packets failing basic IP validity checks. | ip_invalid |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| protocol_numbers optional |
Per-protocol aggregate rate limits at host scope. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4IpPolicyInput
IP-layer anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| custom_protocol_filter optional |
Filter on specific IP protocol numbers. | custom_protocol_filter |
| ip_fragmentation optional |
IP fragmentation handling. | ip_fragmentation |
| ip_invalid optional |
Drop packets failing basic IP validity checks. | ip_invalid |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| protocol_numbers optional |
Per-protocol aggregate rate limits at host scope. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4TcpPolicy
TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters.
| Name | Description | Schema |
|---|---|---|
| tcp_fragmentation optional |
TCP fragmentation mitigation. | tcp_fragmentation |
| tcp_malformed optional |
Invalid TCP flags, SYN, and option handling. | tcp_malformed |
| tcp_rewrite_mss_size optional |
SYN MSS validation. | tcp_rewrite_mss_size |
| tcp_syn_anti_spoofing optional |
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. | tcp_syn_anti_spoofing |
| tcp_syn_exclude_syn_ack_and_syn_ack_ecn optional |
Drop SYN-ACK and SYN-ACK-ECN packets. | tcp_syn_exclude_syn_ack_and_syn_ack_ecn |
| tcp_with_well_known_ports optional |
Drop invalid or sensitive destination-port packets. | tcp_with_well_known_ports |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_invalid_flags optional |
Illegal or suspicious TCP flag combinations. | tcp_invalid_flags |
| tcp_long_header optional |
Malformed or oversized SYN options. | tcp_long_header |
| tcp_syn_with_data optional |
SYN segments with non-zero payload. | tcp_syn_with_data |
| tcp_syn_with_reserved_flags optional |
Reserved TCP flag bits. | tcp_syn_with_reserved_flags |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
Size threshold in bytes (meaning depends on parent module). Minimum value : 34 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| graceful_challenges optional |
Graceful challenges. | graceful_challenges |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| rate_limit_per_connection optional |
Rate limit per connection. | rate_limit_per_connection |
| tcp_3_way_handshake_challenges optional |
TCP 3-way handshake challenges. | tcp_3_way_handshake_challenges |
| tcp_data optional |
TCP data validation. | tcp_data |
| tcp_retransmission optional |
TCP retransmission validation. | tcp_retransmission |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| duration optional |
Duration in seconds. Range: 10-150. Minimum value : 10 Maximum value : 150 |
integer |
| is_enabled optional |
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. | integer |
| timeout optional |
Timeout duration in seconds. Range: 10-3600. Minimum value : 60 Maximum value : 600 |
integer |
tcp_3_way_handshake_challenges
| Name | Description | Schema |
|---|---|---|
| mode optional |
0 = tcp retransmission, 1 = tcp data, 2 = auto. | integer |
| Name | Description | Schema |
|---|---|---|
| server_ip_validation optional |
Server IP validation. | server_ip_validation |
| traffic_policing optional |
Traffic policing. | traffic_policing |
| Name | Description | Schema |
|---|---|---|
| bot_mitigation optional |
Bot mitigation validation. | bot_mitigation |
| spoofed_carpet_bombing_mitigation optional |
Spoofed carpet bombing mitigation validation. | spoofed_carpet_bombing_mitigation |
| tcp_fast_open optional |
TCP fast open validation. | tcp_fast_open |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
spoofed_carpet_bombing_mitigation
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| suspicious_receiver_ip_rate_limit optional |
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| total_rate_limit optional |
Total rate limit in packets per second. Range: 100-4000000000. Minimum value : 100 Maximum value : 4000000000 |
integer |
| validated_server_ip_rate_limit optional |
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| validation_mode optional |
0 = half open, 1 = full open. | integer |
| validation_trust_mode optional |
0 = host, 1 = network. | integer |
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4TcpPolicyInput
TCP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| tcp_fragmentation optional |
TCP fragmentation mitigation. | tcp_fragmentation |
| tcp_malformed optional |
Invalid TCP flags, SYN, and option handling. | tcp_malformed |
| tcp_rewrite_mss_size optional |
SYN MSS validation. | tcp_rewrite_mss_size |
| tcp_syn_anti_spoofing optional |
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. | tcp_syn_anti_spoofing |
| tcp_syn_exclude_syn_ack_and_syn_ack_ecn optional |
Drop SYN-ACK and SYN-ACK-ECN packets. | tcp_syn_exclude_syn_ack_and_syn_ack_ecn |
| tcp_with_well_known_ports optional |
Drop invalid or sensitive destination-port packets. | tcp_with_well_known_ports |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_invalid_flags optional |
Illegal or suspicious TCP flag combinations. | tcp_invalid_flags |
| tcp_long_header optional |
Malformed or oversized SYN options. | tcp_long_header |
| tcp_syn_with_data optional |
SYN segments with non-zero payload. | tcp_syn_with_data |
| tcp_syn_with_reserved_flags optional |
Reserved TCP flag bits. | tcp_syn_with_reserved_flags |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
Size threshold in bytes (meaning depends on parent module). Minimum value : 34 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| graceful_challenges optional |
Graceful challenges. | graceful_challenges |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| rate_limit_per_connection optional |
Rate limit per connection. | rate_limit_per_connection |
| tcp_3_way_handshake_challenges optional |
TCP 3-way handshake challenges. | tcp_3_way_handshake_challenges |
| tcp_data optional |
TCP data validation. | tcp_data |
| tcp_retransmission optional |
TCP retransmission validation. | tcp_retransmission |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| duration optional |
Duration in seconds. Range: 10-150. Minimum value : 10 Maximum value : 150 |
integer |
| is_enabled optional |
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. | integer |
| timeout optional |
Timeout duration in seconds. Range: 10-3600. Minimum value : 60 Maximum value : 600 |
integer |
tcp_3_way_handshake_challenges
| Name | Description | Schema |
|---|---|---|
| mode optional |
0 = tcp retransmission, 1 = tcp data, 2 = auto. | integer |
| Name | Description | Schema |
|---|---|---|
| server_ip_validation optional |
Server IP validation. | server_ip_validation |
| traffic_policing optional |
Traffic policing. | traffic_policing |
| Name | Description | Schema |
|---|---|---|
| bot_mitigation optional |
Bot mitigation validation. | bot_mitigation |
| spoofed_carpet_bombing_mitigation optional |
Spoofed carpet bombing mitigation validation. | spoofed_carpet_bombing_mitigation |
| tcp_fast_open optional |
TCP fast open validation. | tcp_fast_open |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
spoofed_carpet_bombing_mitigation
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| suspicious_receiver_ip_rate_limit optional |
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| total_rate_limit optional |
Total rate limit in packets per second. Range: 100-4000000000. Minimum value : 100 Maximum value : 4000000000 |
integer |
| validated_server_ip_rate_limit optional |
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| validation_mode optional |
0 = half open, 1 = full open. | integer |
| validation_trust_mode optional |
0 = host, 1 = network. | integer |
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4UdpPolicy
UDP flood amplification handling.
| Name | Description | Schema |
|---|---|---|
| ntp_amplification optional |
ntp_amplification | |
| snmp_amplification optional |
snmp_amplification | |
| ssdp_flood optional |
SSDP flood handling. | ssdp_flood |
| udp_contain_all_zero_data optional |
UDP contain all zero data handling. | udp_contain_all_zero_data |
| udp_flood_amplification optional |
udp_flood_amplification | |
| udp_fragmentation optional |
UDP fragmentation handling. | udp_fragmentation |
| udp_malformed optional |
UDP malformed handling. | udp_malformed |
| udp_with_port_number_lt_1024 optional |
UDP with port number less than 1024 handling. | udp_with_port_number_lt_1024 |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| ntp_response_length optional |
NTP response length handling. | ntp_response_length |
| ntp_response_monlist_drop optional |
NTP response MONLIST drop handling. | ntp_response_monlist_drop |
| ntp_response_rate_limit optional |
NTP response rate limit handling. | ntp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the NTP response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| snmp_response_rate_limit optional |
SNMP response rate limit handling. | snmp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| zero_data_min_length optional |
The minimum length of the zero data payload. Minimum value : 42 Maximum value : 128 |
integer |
| Name | Description | Schema |
|---|---|---|
| dns_query_length optional |
DNS query length handling. | dns_query_length |
| dns_query_rate_limit optional |
DNS query rate limit handling. | dns_query_rate_limit |
| dns_response_length optional |
DNS response length handling. | dns_response_length |
| dns_response_rate_limit optional |
DNS response rate limit handling. | dns_response_rate_limit |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the DNS query. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the DNS response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| udp_packet_contain_no_data optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL3L4UdpPolicyInput
UDP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| ntp_amplification optional |
ntp_amplification | |
| snmp_amplification optional |
snmp_amplification | |
| ssdp_flood optional |
SSDP flood handling. | ssdp_flood |
| udp_contain_all_zero_data optional |
UDP contain all zero data handling. | udp_contain_all_zero_data |
| udp_flood_amplification optional |
udp_flood_amplification | |
| udp_fragmentation optional |
UDP fragmentation handling. | udp_fragmentation |
| udp_malformed optional |
UDP malformed handling. | udp_malformed |
| udp_with_port_number_lt_1024 optional |
UDP with port number less than 1024 handling. | udp_with_port_number_lt_1024 |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| ntp_response_length optional |
NTP response length handling. | ntp_response_length |
| ntp_response_monlist_drop optional |
NTP response MONLIST drop handling. | ntp_response_monlist_drop |
| ntp_response_rate_limit optional |
NTP response rate limit handling. | ntp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the NTP response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| snmp_response_rate_limit optional |
SNMP response rate limit handling. | snmp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| zero_data_min_length optional |
The minimum length of the zero data payload. Minimum value : 42 Maximum value : 128 |
integer |
| Name | Description | Schema |
|---|---|---|
| dns_query_length optional |
DNS query length handling. | dns_query_length |
| dns_query_rate_limit optional |
DNS query rate limit handling. | dns_query_rate_limit |
| dns_response_length optional |
DNS response length handling. | dns_response_length |
| dns_response_rate_limit optional |
DNS response rate limit handling. | dns_response_rate_limit |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the DNS query. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the DNS response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| udp_packet_contain_no_data optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
AntiFloodL7CustomPolicy
Custom L7 (TCP) filter profiles for this host.
| Name | Description | Schema |
|---|---|---|
| profile required |
List of Custom L7 (TCP) filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration | source_ip_new_connection |
| total_connection optional |
Total Connection Module configuration | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
AntiFloodL7HttpPolicy
HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled.
| Name | Schema |
|---|---|
| profile optional |
< profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| http_authentication optional |
HTTP Authentication Module configuration | http_authentication |
| http_slow_rate optional |
HTTP Slow Rate Module configuration | http_slow_rate |
| is_enabled optional |
Filter status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| model optional |
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-86400) Minimum value : 1 Maximum value : 86400 |
integer |
| body optional |
HTTP Slow Body Module configuration. | body |
| header optional |
HTTP Slow Header Module configuration. | header |
| new_session_per_minute optional |
New sessions per minute, range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| calc_avg_packet optional |
Number of TCP packets to carry a single HTTP request, range (3-20) Minimum value : 3 Maximum value : 20 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| min_avg_length optional |
Smallest allowed TCP packet size of a split HTTP request, range (1-1500) Minimum value : 1 Maximum value : 1500 |
integer |
| timeout_interval optional |
Time interval between two packets (milliseconds), range (1000-10000) Minimum value : 1000 Maximum value : 10000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet_size optional |
Packet length (bytes), range (64-1500) Minimum value : 64 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration | source_ip_new_connection |
| total_connection optional |
Total Connection Module configuration | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-60) Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds) range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds) range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Total connections per second, range (100-4294967295). Minimum value : 100 Maximum value : 4294967295 |
integer |
AntiFloodL7QuicPolicy
QUIC L7 filter profiles for this host.
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
QUIC Malformed Packet Detection configuration. | malformed |
| quic_flood_protection optional |
QUIC Session Protection configuration | quic_flood_protection |
| quic_ratelimit optional |
QUIC Ratelimit Module configuration | quic_ratelimit |
| Name | Description | Schema |
|---|---|---|
| handshake_min_len optional |
Minimum length (bytes) for handshake packets, range (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| initial_min_len optional |
Minimum length (bytes) for initial packets, range (1200-65535). Minimum value : 1200 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| support_version optional |
Supported QUIC versions:[‘all’,‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. | < enum (all, v1, v2, draft27, draft28, draft29, draft30, draft31, draft32, draft33, draft34) > array |
| version_negotiation_min_len optional |
Minimum length (bytes) for version negotiation packets, range (12-65535). Minimum value : 12 Maximum value : 65535 |
integer |
| zero_rtt_min_len optional |
Minimum length (bytes) for 0-RTT packets, range (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| 0rtt_replay_attack_protection optional |
0-RTT replay attack protection configuration. | 0rtt_replay_attack_protection |
| authentication optional |
Authentication configuration. | authentication |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_source_ip optional |
Session (Per source IP) Module configuration | new_session_per_source_ip |
| ratelimit_per_session optional |
Ratelimit (Per Session) Module configuration. | ratelimit_per_session |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300). Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. |
integer |
| packet_per_second optional |
Packets per second threshold, range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| mode optional |
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. |
integer |
| session_scope optional |
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. | integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300) Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_second optional |
New sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. |
integer |
| session_check_duration optional |
Session check duration (seconds), range (20-40) Minimum value : 20 Maximum value : 40 |
integer |
| session_timeout optional |
Idle session timeout (seconds), range (60-600) Minimum value : 60 Maximum value : 600 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packets optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
AntiFloodL7SipPolicy
SIP L7 filter profiles for this host.
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_tcp_port optional |
TCP Port list. | < integer > array |
| filter_udp_port optional |
UDP Port list. | < integer > array |
| invite optional |
SIP INVITE message configuration. | invite |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed_is_enabled optional |
SIP Malformed enable status. Values: 0 = off, 1 = drop. |
integer |
| register optional |
SIP REGISTER Requst message configuration. | register |
| retransmission_is_enabled optional |
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. |
integer |
| tcp_connection optional |
TCP Connection protection configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Source IP average window size threshold | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-60) Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
AntiFloodL7TlsPolicy
TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled.
| Name | Description | Schema |
|---|---|---|
| profile optional |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
SSL/TLS Malformed Packet Detection configuration. | malformed |
| ratelimit optional |
SSL/TLS Ratelimit (Per Profile) configuration | ratelimit |
| renegotiation optional |
SSL/TLS Renegotiation configuration. | renegotiation |
| session optional |
SSL/TLS Session configuration. | session |
| tcp_connection optional |
Connection protection configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| clienthello_length_limit_non_v_1_3 optional |
ClientHello length (bytes) limit for non-TLS 1.3, range (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| clienthello_length_limit_v_1_3 optional |
ClientHello length (bytes) limit for TLS 1.3, range (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| Name | Description | Schema |
|---|---|---|
| non_tls optional |
Ratelimit for non TLS1.2 and TLS1.3 traffic. | non_tls |
| tls optional |
Ratelimit for TLS1.2 and TLS1.3 traffic. | tls |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| blocklist_duration optional |
Blocklist duration (seconds), range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300) Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = block. |
integer |
| new_session_per_second optional |
New session per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Connection protection enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
This rule checks for slow rate connections from the same source IP address | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Average window Size (bytes), range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Ban duration (seconds), range (10-60). Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
BogonsPolicy
Bogon and invalid address protections.
| Name | Description | Schema |
|---|---|---|
| land_attack optional |
Mitigate LAND-style same src/dst attacks. | land_attack |
| martian_address optional |
Drop martian or reserved addresses. | martian_address |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
BogonsPolicyInput
Bogon and invalid address protection incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| land_attack optional |
Mitigate LAND-style same src/dst attacks. | land_attack |
| martian_address optional |
Drop martian or reserved addresses. | martian_address |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
CustomFilter
Custom Filter configuration.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id optional |
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration | source_ip_new_connection |
| total_connection optional |
Total Connection Module configuration | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
CustomFilterInput
CustomFilter create payload.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_name required |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port required |
TCP Port list. | < integer > array |
FlexFilterAclCustomRule
Custom ACL filter rule attached to the profile.
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
FlexFilterAclCustomRuleInput
FlexFilter ACL custom rule create payload.
| Name | Description | Schema |
|---|---|---|
| action required |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol required |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_name required |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
FlexFilterAclCustomRuleUpdateInput
FlexFilter ACL custom rule update payload.
| Name | Description | Schema |
|---|---|---|
| action required |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol required |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_name required |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
FlexFilterAclFilterPolicy
Site-level ACL common and custom rule sets.
| Name | Description | Schema |
|---|---|---|
| acl_filter_rules optional |
Site-specific custom ACL rules. | < acl_filter_rules > array |
| acl_filter_sets optional |
Site-level ACL filter sets attached to the profile. | < acl_filter_sets > array |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| rule_set_desc optional |
Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_set_id required |
string | |
| rule_set_name optional |
Length : 1 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
FlexFilterAclFilterPolicyInput
FlexFilter ACL filter policy incremental update payload. Include only fields to change; omitted fields are preserved. The acl_filter_sets array supports incremental attach/detach of site-level ACL template sets. Custom ACL rules are managed via custom-filter CRUD APIs; do not include acl_filter_rules in this request.
| Name | Description | Schema |
|---|---|---|
| acl_filter_sets optional |
Site-level ACL filter sets attached to the profile. | < acl_filter_sets > array |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Schema |
|---|---|
| rule_set_id required |
string |
FlexFilterPayloadFilterPolicy
Advanced payload filtering rules.
| Name | Description | Schema |
|---|---|---|
| filters optional |
List of payload filter rules. Managed via payload-filter CRUD APIs. | < filters > array |
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
ratelimit in bps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique identifier of advanced rule. | string |
| filter_name optional |
The name of the policies. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| payload_string optional |
The string of the payload. | < string > array |
| port optional |
The lists of the port numbers. | < integer > array |
| pps_limit optional |
ratelimit in pps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the data packet. Allowed values: tcp, udp, ip, any. | enum (tcp, udp, ip, any) |
FlexZombieRule
Flex zombie rule.
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. Allowed values: pass, ratelimit, block. | enum (pass, ratelimit, block) |
| block_duration optional |
The duration of the block in seconds. Required when the action is block. Minimum value : 10 Maximum value : 120 |
integer |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit or block. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dip_prefix optional |
Destination IP netmask for the rule. Required when zombie_mode is dip or dip_dport. Minimum value : 24 Maximum value : 32 |
integer |
| dst_ip optional |
< string > array | |
| dst_port optional |
< integer > array | |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit or block. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sip_prefix optional |
Source IP netmask for the rule. Required when zombie_mode is sip, sip_sport, or sip_dport. Minimum value : 24 Maximum value : 32 |
integer |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| tcp_flags optional |
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| zombie_mode optional |
The mode of the rule. Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Required when the action is ratelimit or block. Default is sip. Default : "sip" |
enum (sip, dip, sip_sport, dip_dport, sip_dport) |
FlexZombieRuleInput
Flex zombie rule input for create and update.
| Name | Description | Schema |
|---|---|---|
| action required |
The action of the rule. Allowed values: pass, ratelimit, block. | enum (pass, ratelimit, block) |
| block_duration optional |
The duration of the block in seconds. Required when the action is block. Minimum value : 10 Maximum value : 120 |
integer |
| bps_limit optional |
The rate limit in bps of the rule. Required when the action is ratelimit or block. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dip_prefix optional |
Destination IP netmask for the rule. Required when zombie_mode is dip or dip_dport. Minimum value : 24 Maximum value : 32 |
integer |
| dst_ip optional |
< string > array | |
| dst_port optional |
< integer > array | |
| icmp_code optional |
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule. Required when the action is ratelimit or block. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol required |
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead. Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$" |
string |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_name required |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sip_prefix optional |
Source IP netmask for the rule. Required when zombie_mode is sip, sip_sport, or sip_dport. Minimum value : 24 Maximum value : 32 |
integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| tcp_flags optional |
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| zombie_mode optional |
The mode of the rule. Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Required when the action is ratelimit or block. Default is sip. Default : "sip" |
enum (sip, dip, sip_sport, dip_dport, sip_dport) |
HttpFilter
Http L7 filter profile.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id optional |
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| http_authentication optional |
HTTP Authentication Module configuration | http_authentication |
| http_slow_rate optional |
HTTP Slow Rate Module configuration | http_slow_rate |
| is_enabled optional |
Filter status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| model optional |
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-86400) Minimum value : 1 Maximum value : 86400 |
integer |
| body optional |
HTTP Slow Body Module configuration. | body |
| header optional |
HTTP Slow Header Module configuration. | header |
| is_enabled optional |
Enable status mode. Values: 1 = Block, 2 = Block RST. |
integer |
| new_session_per_minute optional |
New sessions per minute, range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| calc_avg_packet optional |
Number of TCP packets to carry a single HTTP request, range (3-20) Minimum value : 3 Maximum value : 20 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| min_avg_length optional |
Smallest allowed TCP packet size of a split HTTP request, range (1-1500) Minimum value : 1 Maximum value : 1500 |
integer |
| timeout_interval optional |
Time interval between two packets (milliseconds), range (1000-10000) Minimum value : 1000 Maximum value : 10000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet_size optional |
Packet length (bytes), range (64-1500) Minimum value : 64 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration | source_ip_new_connection |
| total_connection optional |
Total Connection Module configuration | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-60) Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds) range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds) range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Total connections per second, range (100-4294967295). Minimum value : 100 Maximum value : 4294967295 |
integer |
HttpFilterInput
HttpFilter create payload.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_name required |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port required |
TCP Port list. | < integer > array |
IcmpFilter
| Name | Description | Schema |
|---|---|---|
| action optional |
pass or ratelimit. | enum (pass, ratelimit) |
| bps_limit optional |
Rate limit in bits per second (bps). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_description optional |
Filter description. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| icmp_length optional |
ICMP payload length to drop (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| icmp_type optional |
ICMP type number. Minimum value : 0 Maximum value : 31 |
integer |
| pps_limit optional |
Rate limit in packets per second (pps). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
IcmpFilterInput
| Name | Description | Schema |
|---|---|---|
| action required |
Action when filter matches: pass or ratelimit. | enum (pass, ratelimit) |
| bps_limit optional |
Rate limit in bps must be 1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4G). Required when action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_name required |
Filter name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| icmp_length required |
Packet size in bytes (1–1500). Minimum value : 1 Maximum value : 1500 |
integer |
| icmp_type required |
ICMP type number. Minimum value : 0 Maximum value : 31 |
integer |
| pps_limit optional |
Rate limit in pps must be 1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4G). Required when action is ratelimit. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
IpSetInput
| Name | Description | Schema |
|---|---|---|
| enable_country optional |
Source country enabled status. 0 = off, 1 = on. | integer |
| ip_set_desc optional |
Optional policy description. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| ip_set_name required |
Policy name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| ip_type required |
IP address family for the template, ipv4 or ipv6. | enum (ipv4, ipv6) |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
IpSetSummary
| Name | Description | Schema |
|---|---|---|
| enable_country optional |
Source country enabled status. 0 = off, 1 = on. | integer |
| ip_set_desc optional |
Optional policy description. | string |
| ip_set_id optional |
IP set ID. | string |
| ip_set_name optional |
Policy name. | string |
| ip_type optional |
IP address family for the template, ipv4 or ipv6. | enum (ipv4, ipv6) |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| src_country_count optional |
integer | |
| src_ip_count optional |
integer |
NtifPolicy
Network Threat Intelligence Feed categories and actions. Not supported for IPv6.
| Name | Description | Schema |
|---|---|---|
| anonymizer optional |
Anonymizer / proxy NTIF subgroups. | anonymizer |
| botnet optional |
Botnet-related NTIF subgroups. | botnet |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Schema |
|---|---|
| proxy optional |
proxy |
| tor optional |
tor |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Schema |
|---|---|
| dark_spider optional |
dark_spider |
| ddos optional |
ddos |
| malware optional |
malware |
| reputation optional |
reputation |
| scanner optional |
scanner |
| spam optional |
spam |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
NtifPolicyInput
NTIF policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Not supported for IPv6.
| Name | Description | Schema |
|---|---|---|
| anonymizer optional |
Anonymizer / proxy NTIF subgroups. | anonymizer |
| botnet optional |
Botnet-related NTIF subgroups. | botnet |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Schema |
|---|---|
| proxy optional |
proxy |
| tor optional |
tor |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Schema |
|---|---|
| dark_spider optional |
dark_spider |
| ddos optional |
ddos |
| malware optional |
malware |
| reputation optional |
reputation |
| scanner optional |
scanner |
| spam optional |
spam |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. | integer |
PayloadFilter
Advanced payload filtering rule.
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
ratelimit in bps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique identifier of advanced rule. | string |
| filter_name optional |
The name of the policies. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| payload_string optional |
The string of the payload. | < string > array |
| port optional |
The lists of the port numbers. | < integer > array |
| pps_limit optional |
ratelimit in pps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the data packet. Allowed values: tcp, udp, ip, any. | enum (tcp, udp, ip, any) |
PayloadFilterInput
Payload filter rule create/update payload.
| Name | Description | Schema |
|---|---|---|
| action required |
An action will be taken when they match. Allowed values: ratelimit, pass, drop. | enum (ratelimit, pass, drop) |
| bps_limit optional |
ratelimit in bps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_name required |
The name of the policies. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| payload_string optional |
The string of the payload. | < string > array |
| port optional |
The lists of the port numbers. | < integer > array |
| pps_limit optional |
ratelimit in pps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the data packet. Allowed values: tcp, udp, ip, any. | enum (tcp, udp, ip, any) |
QuicFilter
QUIC Filter configuration.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id optional |
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
UDP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
QUIC Malformed Packet Detection configuration. | malformed |
| quic_flood_protection optional |
QUIC Session Protection configuration | quic_flood_protection |
| quic_ratelimit optional |
QUIC Ratelimit Module configuration | quic_ratelimit |
| Name | Description | Schema |
|---|---|---|
| handshake_min_len optional |
Minimum length (bytes) for handshake packets, range (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| initial_min_len optional |
Minimum length (bytes) for initial packets, range (1200-65535). Minimum value : 1200 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| support_version optional |
Supported QUIC versions:[‘all’,‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. | < enum (all, v1, v2, draft27, draft28, draft29, draft30, draft31, draft32, draft33, draft34) > array |
| version_negotiation_min_len optional |
Minimum length (bytes) for version negotiation packets, range (12-65535). Minimum value : 12 Maximum value : 65535 |
integer |
| zero_rtt_min_len optional |
Minimum length (bytes) for 0-RTT packets, range (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| 0rtt_replay_attack_protection optional |
0-RTT replay attack protection configuration. | 0rtt_replay_attack_protection |
| authentication optional |
Authentication configuration. | authentication |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_source_ip optional |
Session (Per source IP) Module configuration | new_session_per_source_ip |
| ratelimit_per_session optional |
Ratelimit (Per Session) Module configuration. | ratelimit_per_session |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300). Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. |
integer |
| packet_per_second optional |
Packets per second threshold, range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| mode optional |
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. |
integer |
| session_scope optional |
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. | integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300) Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_second optional |
New sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. |
integer |
| session_check_duration optional |
Session check duration (seconds), range (20-40) Minimum value : 20 Maximum value : 40 |
integer |
| session_timeout optional |
Idle session timeout (seconds), range (60-600) Minimum value : 60 Maximum value : 600 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packets optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
QuicFilterInput
QuicFilter create payload.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_name required |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port required |
UDP Port list. | < integer > array |
Result
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code. 0 indicates success. | integer |
| msg optional |
Error message. | string |
SipFilter
SIP Filter configuration.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id optional |
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_tcp_port optional |
TCP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. | < integer > array |
| filter_udp_port optional |
UDP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. | < integer > array |
| invite optional |
SIP INVITE message configuration. | invite |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed_is_enabled optional |
SIP Malformed enable status. Values: 0 = off, 1 = drop. |
integer |
| register optional |
SIP REGISTER Requst message configuration. | register |
| retransmission_is_enabled optional |
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. |
integer |
| tcp_connection optional |
TCP Connection protection configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Source IP average window size threshold | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range (10-60) Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
SipFilterInput
SipFilter create payload. At least one of filter_tcp_port or filter_udp_port is required.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_name required |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_tcp_port optional |
TCP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. | < integer > array |
| filter_udp_port optional |
UDP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. | < integer > array |
TlsFilter
SSL/TLS Filter configuration.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id optional |
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
SSL/TLS Malformed Packet Detection configuration. | malformed |
| ratelimit optional |
SSL/TLS Ratelimit (Per Profile) configuration | ratelimit |
| renegotiation optional |
SSL/TLS Renegotiation configuration. | renegotiation |
| session optional |
SSL/TLS Session configuration. | session |
| tcp_connection optional |
Connection protection configuration | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| clienthello_length_limit_non_v_1_3 optional |
ClientHello length (bytes) limit for non-TLS 1.3, range (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| clienthello_length_limit_v_1_3 optional |
ClientHello length (bytes) limit for TLS 1.3, range (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| Name | Description | Schema |
|---|---|---|
| non_tls optional |
Ratelimit for non TLS1.2 and TLS1.3 traffic. | non_tls |
| tls optional |
Ratelimit for TLS1.2 and TLS1.3 traffic. | tls |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| blocklist_duration optional |
Blocklist duration (seconds), range (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range (1-300) Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = block. |
integer |
| new_session_per_second optional |
New session per second, range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Connection protection enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
This rule checks for slow rate connections from the same source IP address | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Average window Size (bytes), range (1-65535) Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Ban duration (seconds), range (10-60). Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range (10-600) Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
Sessions per second, range (5-1000) Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second, range (100-4294967295) Minimum value : 100 Maximum value : 4294967295 |
integer |
TlsFilterInput
TlsFilter create payload.
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_name required |
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ .-]+$" |
string |
| filter_port required |
TCP Port list. | < integer > array |
TrafficPolicingPolicy
Traffic policing cap (bps/pps) for the host.
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
TrafficPolicingPolicyInput
Traffic policing cap incremental update payload. Include only fields to change; omitted fields are preserved.
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
ZombiePolicy
Zombie host detection (host vs network scope). Not supported for IPv6.
| Name | Description | Schema |
|---|---|---|
| flex_zombie optional |
Flex zombie rules attached to the profile. | < FlexZombieRule > array |
| is_enabled optional |
0 = off, 1 = on . | integer |
| zombie_host optional |
Per-host zombie thresholds and action. | zombie_host |
| zombie_network optional |
Per-network zombie thresholds and action. | zombie_network |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = off, 1 = on . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
ZombiePolicyInput
Zombie host detection policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Flex zombie rules are managed via flex-zombie CRUD APIs; do not include flex_zombie in this request.
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = off, 1 = on . | integer |
| zombie_host optional |
Per-host zombie thresholds and action. | zombie_host |
| zombie_network optional |
Per-network zombie thresholds and action. | zombie_network |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = off, 1 = on . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
Security
ApiKeyAuth
Type : apiKey
Name : access_token
In : QUERY