☰

Mitigation

Mitigation

Overview

Origin Protection Mitigation API

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : {your_basic_domain}
BasePath : /api
Schemes : HTTPS

Paths

Create an IP set.

POST /spe/customer/{customer_id}/op/mitigation/template/ip_set

Description

Create an IP set.

Parameters

Type Name Description Schema
Path customer_id
required
Customer ID. Can be obtained by invoking this API for customer_id. string
Query access_token
required
API access token for authentication. string
Body body
required
IP set configuration. body

body

Name Description Schema
enable_country
required
Source country enabled status, 0 = off, 1 = on. integer
ip_set_desc
optional
IP set description. string
ip_set_name
required
IP set name. string
ip_type
required
IP address family for the template: ipv4 or ipv6. string
source_countries
required
Source countries. < string > array
source_ips
required
Source IPs. < string > array

Responses

HTTP Code Description Schema
200 Response body with result data or error information. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
result

result

Name Description Schema
ip_set_id
optional
IP set ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get an IP set.

GET /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}

Description

Get an IP set.

Parameters

Type Name Description Schema
Path customer_id
required
Customer ID. Can be obtained by invoking this API for customer_id. string
Path ip_set_id
required
IP set ID. Can be obtained by invoking this API for ip_set_id. string
Query access_token
required
API access token for authentication. string
Query ip_type
optional
IP address family for the template, ipv4 or ipv6. Default is ipv4. string

Responses

HTTP Code Description Schema
200 Response body with result data or error information. Response 200

Response 200

Name Schema
result
optional
result

result

Name Description Schema
enable_country
optional
Source country enabled status, 0 = off, 1 = on. integer
ip_set_desc
optional
IP set description. string
ip_set_name
optional
IP set name. string
ip_type
optional
IP address family for the template, ipv4 or ipv6. string
source_countries
optional
Source countries. < string > array
source_ips
optional
Source IPs. < string > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit an IP set.

PUT /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}

Description

Edit an IP set.

Parameters

Type Name Description Schema
Path customer_id
required
Customer ID. Can be obtained by invoking this API for customer_id. string
Path ip_set_id
required
IP set ID. Can be obtained by invoking this API for ip_set_id. string
Query access_token
required
API access token for authentication. string
Body body
required
IP set configuration. body

body

Name Description Schema
enable_country
optional
Source country enabled status, 0 = off, 1 = on. integer
ip_set_desc
optional
IP set description. string
ip_set_name
required
IP set name. string
ip_type
optional
IP address family for the template: ipv4 or ipv6. Default: ipv4. string
source_countries
optional
Source countries. < string > array
source_ips
optional
Source IPs. < string > array

Responses

HTTP Code Description Schema
200 Response body with result data or error information. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete an IP set.

DELETE /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}

Description

Delete an IP set.

Parameters

Type Name Description Schema
Path customer_id
required
Customer ID. Can be obtained by invoking this API for customer_id. string
Path ip_set_id
required
IP set ID. Can be obtained by invoking this API for ip_set_id. string
Query access_token
required
API access token for authentication. string

Responses

HTTP Code Description Schema
200 Response body with result data or error information. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get IP set templates for allow/block list policy.

GET /spe/customer/{customer_id}/op/mitigation/template/ip_sets

Description

Get IP set templates for allow/block list policy.

Parameters

Type Name Description Schema
Path customer_id
required
Customer ID. Can be obtained by invoking this API for customer_id. string
Query access_token
required
API access token for authentication. string
Query ip_type
optional
IP address family for the template, ipv4 or ipv6. Default is ipv4. string

Responses

HTTP Code Description Schema
200 Response body with result data or error information. Response 200

Response 200

Name Description Schema
code
optional
Numeric error code; 0 indicates success. integer
msg
optional
Human-readable error or status message. string
result
optional
< result > array

result

Name Description Schema
enable_country
optional
Source country enabled status, 0 = off, 1 = on. integer
ip_set_desc
optional
IP set description. string
ip_set_id
optional
IP set ID. string
ip_set_name
optional
IP set name. string
ip_type
optional
IP address family for the template, ipv4 or ipv6. string
source_countries
optional
< string > array
source_ips
optional
< string > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Set allow list/block list source IP and source countries.

POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list

Description

Put source IP and source countries into allow list or block list.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData source_ips
required
Put the IPs you want to add to either the blacklist or whitelist. < string > array
FormData src_countries
required
Put the source countries to either blacklist or whitelist. The value of countries is taken from configuration options. < string > array
FormData type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get mitigation black and white list.

GET /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list

Description

Traffic from the allow listed IPs can bypass all other policies and be allowed to enter. Traffic from the block listed IPs is denied to enter and dropped directly.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
Query type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
source_countries
optional
The source countries of traffic. < string > array
source_ips
optional
Source IP. < string > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policy for allow list or block list.

POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list/switch

Description

Change the mitigation policy for allow list or block list.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch is disabled whereas 1 means it is enabled. integer
FormData type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policy of the policy for bogons.

POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/bogons/switch

Description

Change the mitigation policy of the policy for bogons.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch is disabled whereas 1 means it is enabled. integer
FormData type
required
The bogons types include martian_address, land_attack. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of bogons switch.

GET /spe/customer/{customer_id}/op/site/{site_id}/mitigation/bogons/switch

Description

Get the info of bogons switch.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
Query type
required
blacklist/whitelist type. in (blacklist, whitelist). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
land_attack
optional
The property of the land_attack. land_attack
martian_address
optional
The property of the martian address. martian_address

land_attack

Name Description Schema
is_enabled
optional
0 means the land_attack switch is disabled whereas 1 means it is enabled. integer

martian_address

Name Description Schema
is_enabled
optional
0 means the martian_address switch is disabled whereas 1 means it is enabled. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the info of FlexFilter/advanced payload filtering for mitigation.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering

Description

Gets the info of FlexFilter/advanced payload filtering for mitigation.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
< result > array

result

Name Description Schema
action
optional
An action will be taken when they match. string
bps_limit
optional
ratelimit in bps. string
filter_id
optional
Unique identifier of advanceed rule. string
filter_name
optional
The name of the policies. string
payload_string
optional
The string of the payload. payload_string
port
optional
The port number of the data packet. port
pps_limit
optional
ratelimit in pps. string
protocol
optional
The protocol of the data packet. protocol

payload_string

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
string
optional
Key word or phrase to look for in a payload. < string > array

port

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
ports
optional
The lists of the port numbers. < integer > array

protocol

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
type
optional
Currently, tcp, udp and ip supported protocol for the data packet can be used. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Add the policies for the FlexFilter/advanced payload filtering.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/filter

Description

Add the policies for the FlexFilter/advanced payload filtering.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
Action to take when a match is found. You can choose pass, drop and rateLimit.Selecting Rate Limit allows to define a limit of bandwidth all such data packets can use. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData filter_name
required
The name of the policies created. string
FormData payload_string
optional
If the “payload_string_enabled” is switched on, the key word or phrase must be provided to be looked for in a payload. < string > array
FormData payload_string_enabled
optional
0 means the switch of the payload string is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. integer
FormData port
optional
If the “port_enabled” is switched on, the port number either for the source or destination port of the data packet must be provided , with the exception of protocol is ‘ip’. < integer > array
FormData port_enabled
optional
0 means the port switch is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled, with the exception of protocol is ‘ip’. integer
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData protocol
optional
If protocol_enabled is switched on, the type of protocol must be provided. Currently, tcp, udp and ip supported protocol for the data packet can be used. string
FormData protocol_enabled
optional
0 means the switch of the protocol is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. integer

Responses

HTTP Code Description Schema
200 This is the returned result. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID, an unique identifier assigned to each FlexFilter/Advanced Payload Filtering. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the info of policies for FlexFilter/advanced payload filtering for mitigation.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}

Description

Gets the info of policies for FlexFilter/advanced payload filtering for mitigation.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of advanceed filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
action
optional
An action will be taken when they match. string
bps_limit
optional
ratelimit in bps. string
filter_name
optional
The name of the policies. string
payload_string
optional
The payload of the string. payload_string
port
optional
The port number of the data packet. port
pps_limit
optional
ratelimit in pps. string
protocol
optional
The protocol of the data packet. protocol

payload_string

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
string
optional
The key word or phase to be lookedfor in a payload. < string > array

port

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
ports
optional
The list of the port number. < integer > array

protocol

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
type
optional
Currently, tcp, udp and ip supported protocol for the data packet can be used. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit FlexFilter/Advanced Payload Filtering.

PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}

Description

Edit FlexFilter/Advanced Payload Filtering.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of advanceed filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData filter_name
required
The name of the policies created. string
FormData payload_string
optional
If “payload_string_enabled” is switched on, the key word or phase must be provided to be looked for in a payload. < string > array
FormData payload_string_enabled
optional
0 means the switch for the payload string is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. integer
FormData port
optional
If the “port_enable” is switched on, the port number of the data packet must be provided. The port number can be either source or destination port < integer > array
FormData port_enabled
optional
0 means the port switch is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. integer
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData protocol
optional
If the “port_enable” is switched on, the name of protocol of the data packet must be provided. Currently, this function supports TCP, UDP and IP protocol. string
FormData protocol_enabled
optional
0 means the switch for the protocol is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete policies for FlexFilter/advanced payload filtering.

DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}

Description

Delete policies for FlexFilter/advanced payload filtering.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of advanceed filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Set allow list/block list source IP and source countries.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list

Description

Put source IP and source countries into allow list or block list.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData source_ips
required
Put the IPs you want to add to either the blacklist or whitelist. < string > array
FormData src_countries
required
Put the source countries to either blacklist or whitelist. The value of countries is taken from configuration options. < string > array
FormData type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get mitigation black and white list.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list

Description

Traffic from the allow listed IPs can bypass all other policies and be allowed to enter. Traffic from the block listed IPs is denied to enter and dropped directly.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
Query type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
source_countries
optional
The source countries of traffic. < string > array
source_ips
optional
Source IP. < string > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policy for allow list or block list.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list/switch

Description

Change the mitigation policy for allow list or block list.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch is disabled whereas 1 means it is enabled. integer
FormData type
required
allow list/block list type. in (allow_list, block_list). string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of FlexFilter/basic network filtering for mitigation.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering

Description

Get the info of FlexFilter/basic network filtering for mitigation.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
common_rule_sets
optional
The filter sets. < common_rule_sets > array
custom_rule_set
optional
Custom Filters. custom_rule_set
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

common_rule_sets

Name Description Schema
rule_set_desc
optional
More details about the purpose of the policy. string
rule_set_id
optional
Unique identifier of common rule. string
rule_set_name
optional
The name of the policy. string

custom_rule_set

Name Description Schema
action
optional
Either rate limiting, dropping or letting the traffic pass are taken. string
bps_limit
optional
ratelimit in bps. integer
dst_ip
optional
IP Address of the recipient. < string > array
dst_port
optional
Port number to which the data packet is sent. < integer > array
is_enabled
optional
0 means it is disabled and 1 means enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
ratelimit in pps. integer
protocol
optional
Protocol of the data packet. string
rule_desc
optional
More details about the purpose of the policy. string
rule_id
optional
Unique identifier of custom rule. integer
rule_name
optional
The name of the policy string
src_ip
optional
IP address of the sender, as it is shown in the data packet. < string > array
src_port
optional
Port number from which the data packet is sent < integer > array
tcp_flags
optional
In TCP connection, flags are used to indicate a particular state of connection or to provide some additional useful information. < string > array
ttl
optional
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Add rules for the FlexFilter/basic network filtering/ custom filters.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter

Description

Add rules for the FlexFilter/basic network filtering/ custom filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData dst_ip
optional
IP Address of the recipient. < string > array
FormData dst_port
optional
Port number to which the data packet is sent. < integer > array
FormData icmp_code
optional
When ICMP_type is required for ICMP-unreach, ICMP-Redirect or ICMP-Paramprob, when ICMP-unreach is 0-15, ICMP-redirect is 0-3, and ICMP-paramprob is 0-2. integer
FormData icmp_type
optional
When the protocols value is required for ICMP, the value can be custom or from the filter_ICMP_type field that returns the result from config options. When custom, the range is an integer between 0 and 255. string
FormData package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData protocol
required
Protocol of the data packet. Currently, tcp, udp and icmp are supported. string
FormData rule_desc
optional
More details about the purpose of the policy. string
FormData rule_name
required
The name of the policy created. string
FormData src_ip
optional
IP address of the sender, as it is shown in the data packet. < string > array
FormData src_port
optional
Port number from which the data packet is sent. < integer > array
FormData tcp_flags
optional
When the protocol is TCP, its value is retrieved from the filter_tcp_flags in the configuration options. < string > array
FormData ttl
optional
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. It is set to a value between zero and 255. integer

Responses

HTTP Code Description Schema
200 This is the returned result. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
rule_id
optional
Rule ID, an unique identifier assigned to each FlexFilter Custom Filters. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of the policy for flex filer/basic network filtering and custom filters for mitigation.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}

Description

Get the info of the policy for flex filer/basic network filtering and custom filters for mitigation.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path rule_id
required
Unique identifier of custom rule. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
action
optional
Either rate limiting, dropping or letting the traffic pass are taken. string
bps_limit
optional
ratelimit in bps. string
dst_ip
optional
IP Address of the recipient. < string > array
dst_port
optional
Port number to which the data packet is sent. < integer > array
icmp_code
optional
ICMP Code. string
icmp_type
optional
The filters for ICMP. string
is_enabled
optional
0 means it is disabled and 1 means enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
ratelimit in pps. string
protocol
optional
Protocol of the data packet. string
rule_desc
optional
More details about the purpose of the policy. string
rule_id
optional
Unique identifier of a policy. string
rule_name
optional
The name of the policy string
src_ip
optional
IP address of the sender, as it is shown in the data packet. < string > array
src_port
optional
Port number from which the data packet is sent < integer > array
tcp_flags
optional
In TCP connection, flags are used to indicate a particular state of connection or to provide some additional useful information. < string > array
ttl
optional
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the rules for FlexFilter/basic network filtering/custom filters.

PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}

Description

Edit the rules for FlexFilter/basic network filtering/custom filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path rule_id
required
Unique identifier of a rule. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData dst_ip
optional
IP Address of the recipient. < string > array
FormData dst_port
optional
Port number to which the data packet is sent. < integer > array
FormData icmp_code
optional
When ICMP_type is required for ICMP-unreach, ICMP-Redirect or ICMP-Paramprob, when ICMP-unreach is 0-15, ICMP-redirect is 0-3, and ICMP-paramprob is 0-2. integer
FormData icmp_type
optional
When the protocols value is required for ICMP, the value can be custom or from the filter_ICMP_type field that returns the result from config options. When custom, the range is an integer between 0 and 255. string
FormData package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData protocol
required
Protocol of the data packet. Currently, tcp, udp and icmp are supported. string
FormData rule_desc
optional
More details about the purpose of the policy. string
FormData rule_name
required
Unique identifier of a policy created. string
FormData src_ip
optional
IP address of the sender, as it is shown in the data packet. < string > array
FormData src_port
optional
Port number from which the data packet is sent. < integer > array
FormData tcp_flags
optional
When the protocol is TCP, its value is retrieved from the filter_tcp_flags in the configuration options. < string > array
FormData ttl
optional
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. It is set to a value between zero and 255. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes FlexFilter/ basic network filtering/ custom filters.

DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}

Description

Deletes FlexFilter/ basic network filtering/ custom filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path rule_id
required
Unique identifier of custom rule. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the status of the switch of the FlexFilter/ basic network filtering/custom filters.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}/switch

Description

Change the status of the switch of the FlexFilter/ basic network filtering/custom filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path rule_id
required
Unique identifier of custom rule. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch of basic network filtering is disabled whereas 1 means it is enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policy for the FlexFilter/filter sets.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/filter-sets

Description

Edit the policy for the FlexFilter/filter sets.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData rule_set_id
required
Enter the rule id you want to add. < string > array

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Changes the status of the switch for the policies for FlexFilter/basic network filtering.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/switch

Description

Changes the status of the switch for the policies for FlexFilter/basic network filtering.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch of the basic network filtering is disabled whereas 1 means it is enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

It is used to edit Traffic Policies.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing

Description

It is used to edit Traffic Policies.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData threshold_bps
required
Threshold values in bps.must be a number or K, M, G format. string
FormData threshold_pps
required
Threshold values in pps.must be a number or K, M, G format. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get mitigation traffic policing info.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing

Description

Get mitigation traffic policing info.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
is_enabled
optional
0 means the mitigation policy for zombie is disabled whereas 1 means it is enabled. integer
threshold_bps
optional
Threshold values in bps. string
threshold_pps
optional
Threshold values in pps. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

It is a switch to change the status of Traffic Policing/Filter Policing.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing/switch

Description

It is a switch to change the status of Traffic Policing/Filter Policing.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the filter policy is disabled whereas 1 means it is enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of the policy of ICMP flood.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood

Description

Get the info of the policy of ICMP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
custom_icmp_filter
optional
The info of customizable ICMP filters. custom_icmp_filter
icmp_fragmentation
optional
The info of ICMP fragmentation. icmp_fragmentation

custom_icmp_filter

Name Description Schema
default
optional
The default ICMP filters. default
filters
optional
The list of customizable ICMP filters. < filters > array
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

default

Name Description Schema
action
optional
pass or ratelimit. string
bps_limit
optional
The ratelimit in bps. string
filter_name
optional
The name of the filter. string
icmp_length
optional
The length of ICMP to be dropped must range between 1 to 1500. integer
icmp_type
optional
The type of icmp filters. integer
pps_limit
optional
The ratelimit in pps. string

filters

Name Description Schema
action
optional
pass or ratelimit. string
bps_limit
optional
The ratelimit in bps. string
filter_id
optional
Unique identifier of custom filter. string
filter_name
optional
The name of filters. string
icmp_length
optional
The length of ICMP you want to drop. integer
icmp_type
optional
The type of ICMP. integer
pps_limit
optional
The ratelimit in pps. string

icmp_fragmentation

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Add filters for ICMP flood/Customizable protocol filters.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter

Description

Add filters for ICMP flood/Customizable protocol filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
pass or ratelimit. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData filter_name
required
The name of the filters. string
FormData icmp_length
required
The size of the data packet, must be 1-1500. integer
FormData icmp_type
required
The type of icmp, the value of “icmp_filter_types” is taken from configuration options. integer
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string

Responses

HTTP Code Description Schema
200 This is the returned result. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID, an unique identifier assigned to each Custom ICMP Filter. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the policies for the filters for ICMP flood/customizable ICMP.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}

Description

Gets the policies for the filters for ICMP flood/customizable ICMP.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of custom filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
action
optional
pass or ratelimit. string
bps_limit
optional
The ratelimit in bps. string
filter_name
optional
The name of the filter string
icmp_length
optional
The length of ICMP you can drop. integer
icmp_type
optional
The type of icmp. integer
pps_limit
optional
The ratelimit in pps. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policies of the filters for ICMP flood/Customizable protocol.

PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}

Description

Edit the policies of the filters for ICMP flood/Customizable protocol.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of custom filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
pass or ratelimit. string
FormData bps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string
FormData filter_name
required
The name of the filter. string
FormData icmp_length
required
The length of ICMP you can drop must range between 1 to 1500. integer
FormData icmp_type
required
The type of icmp, the value of “icmp_filter_types” is taken from configuration options. integer
FormData pps_limit
optional
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete the policies for the filter for ICMP flood/Customizable protocol.

DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}

Description

Delete the policies for the filter for ICMP flood/Customizable protocol.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path filter_id
required
Unique identifier of custom filter. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Changes the status of the policy for ICMP flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/switch

Description

Changes the status of the policy for ICMP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch is disabled whereas 1 means it is enabled. integer
FormData module
required
The type of icmp flood includes icmp_fragmentation,custom_icmp_filter. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of anti-flood and IP food.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood

Description

Get the info of anti-flood and IP food.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
custom_protocol_filter
optional
The property of the customizable protocol filters. custom_protocol_filter
ip_fragmentation
optional
The property of the IP fragmentation. ip_fragmentation

custom_protocol_filter

Name Description Schema
is_enabled
optional
0 means the switch of the customizable protocol filters is disabled whereas 1 means it is enabled. integer
protocol
optional
The list of the protocol. < string > array

ip_fragmentation

Name Description Schema
is_enabled
optional
0 means the switch of IP fragmentation is disabled whereas 1 means it is enabled. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policy for the customizable protocol filters.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood/protocol

Description

Edit the policy for the customizable protocol filters.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData protocols
required
The value of “ip_protocol_number” you want to add is taken from the configuration options. < integer > array

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Changes of the status of the policy for anti-flood/IP flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood/switch

Description

Changes of the status of the policy for anti-flood/IP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch for the policy for IP flood is disabled whereas 1 means it is enabled. integer
FormData module
required
IP Flood type. in (ip_fragmentation,custom_protocol_filter). ip_fragmentation means it is IP Fragmentation and custom_protocol_filter means Custom Protocol Filter. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Set manual mitigation configuration.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/manual-mitigation-configuration

Description

Set manual mitigation configuration for a host.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body body
required
Manual mitigation configuration. manual_mitigation_configuration

manual_mitigation_configuration

Name Description Schema
allow_block_list
optional
Allow list and block list configuration for source traffic. allow_block_list
anti_flood
optional
Anti-flood policy: L3/L4 modules, L7 profiles, and aggregate protocol caps. anti_flood
bogons
optional
Bogon and invalid address protections. bogons
customer_id
optional
Customer identifier. string
flex_filter
optional
Flex filters: payload, ACL, smart filter, TCP option sets. flex_filter
host_id
optional
Host identifier. string
network_id
optional
Network identifier. string
ntif
optional
Network Threat Intelligence Feed categories and actions. Not supported for IPv6. ntif
site_id
optional
Site identifier. string
traffic_policing
optional
Traffic policing cap (bps/pps) for the host. traffic_policing
zombie
optional
Zombie host detection (host vs network scope). Not supported for IPv6. zombie

allow_block_list

Name Description Schema
allow_list
optional
Trusted sources permitted when allow-list policy is enabled. allow_list
block_list
optional
Sources to block or rate-limit when block-list policy is enabled. block_list

allow_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. Required when mode is 2. string
mode
optional
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

block_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. Required when mode is 2. string
mode
optional
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

anti_flood

Name Description Schema
l3l4
optional
l3l4
l7
optional
Application-layer filter profiles (HTTP, TLS, SIP, QUIC, custom TCP). l7
protocol
optional
Per-protocol aggregate rate limits at host scope. protocol

l3l4

Name Description Schema
icmp
optional
ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported. icmp
ip
optional
IP-layer sanity and flood mitigation. ip
tcp
optional
TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters. tcp
udp
optional
UDP flood amplification handling. udp

icmp

Name Description Schema
all_icmp_packet
optional
Drop all ICMP traffic when enabled. all_icmp_packet
icmp_custom_filter
optional
icmp_custom_filter
icmp_fragmentation
optional
ICMP fragmentation handling. icmp_fragmentation
large_ping
optional
Drop oversized ICMP echo requests. large_ping

all_icmp_packet

Name Description Schema
is_enabled
optional
0 = disabled, 1 = drop all ICMP traffic . integer

icmp_custom_filter

Name Description Schema
default
optional
Default ICMP filter applied when no custom rule matches. default
filters
optional
< filters > array
is_enabled
optional
0 = disabled, 1 = enabled . integer

default

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit, pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name. Can not be edited.
Length : 1 - 40
Pattern : "^[A-Za-z0-9_-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

filters

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit,pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_description
optional
Filter description.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
icmp_type
optional
ICMP type number.
Minimum value : 0
Maximum value : 31
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

icmp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

large_ping

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

ip

Name Description Schema
custom_protocol_filter
optional
Filter on specific IP protocol numbers. custom_protocol_filter
ip_fragmentation
optional
IP fragmentation handling. ip_fragmentation
ip_invalid
optional
Drop packets failing basic IP validity checks. ip_invalid

custom_protocol_filter

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
protocol_numbers
optional
Per-protocol aggregate rate limits at host scope. < integer > array

ip_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

ip_invalid

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp

Name Description Schema
tcp_fragmentation
optional
TCP fragmentation mitigation. tcp_fragmentation
tcp_malformed
optional
Invalid TCP flags, SYN, and option handling. tcp_malformed
tcp_rewrite_mss_size
optional
SYN MSS validation. tcp_rewrite_mss_size
tcp_syn_anti_spoofing
optional
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. tcp_syn_anti_spoofing
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
optional
Drop SYN-ACK and SYN-ACK-ECN packets. tcp_syn_exclude_syn_ack_and_syn_ack_ecn
tcp_with_well_known_ports
optional
Drop invalid or sensitive destination-port packets. tcp_with_well_known_ports

tcp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_malformed

Name Description Schema
tcp_invalid_flags
optional
Illegal or suspicious TCP flag combinations. tcp_invalid_flags
tcp_long_header
optional
Malformed or oversized SYN options. tcp_long_header
tcp_syn_with_data
optional
SYN segments with non-zero payload. tcp_syn_with_data
tcp_syn_with_reserved_flags
optional
Reserved TCP flag bits. tcp_syn_with_reserved_flags

tcp_invalid_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_long_header

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_syn_with_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_syn_with_reserved_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_rewrite_mss_size

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
Size threshold in bytes (meaning depends on parent module).
Minimum value : 34
Maximum value : 1500
integer

tcp_syn_anti_spoofing

Name Description Schema
graceful_challenges
optional
Graceful challenges. graceful_challenges
is_enabled
optional
0 = disabled, 1 = enabled . integer
rate_limit_per_connection
optional
Rate limit per connection. rate_limit_per_connection
tcp_3_way_handshake_challenges
optional
TCP 3-way handshake challenges. tcp_3_way_handshake_challenges
tcp_data
optional
TCP data validation. tcp_data
tcp_retransmission
optional
TCP retransmission validation. tcp_retransmission

graceful_challenges

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

rate_limit_per_connection

Name Description Schema
duration
optional
Duration in seconds. Range: 10-150.
Minimum value : 10
Maximum value : 150
integer
is_enabled
optional
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. integer
timeout
optional
Timeout duration in seconds. Range: 10-3600.
Minimum value : 60
Maximum value : 600
integer

tcp_3_way_handshake_challenges

Name Description Schema
mode
optional
0 = tcp retransmission, 1 = tcp data, 2 = auto. integer

tcp_data

Name Description Schema
server_ip_validation
optional
Server IP validation. server_ip_validation
traffic_policing
optional
Traffic policing. traffic_policing

server_ip_validation

Name Description Schema
bot_mitigation
optional
Bot mitigation validation. bot_mitigation
spoofed_carpet_bombing_mitigation
optional
Spoofed carpet bombing mitigation validation. spoofed_carpet_bombing_mitigation
tcp_fast_open
optional
TCP fast open validation. tcp_fast_open

bot_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

spoofed_carpet_bombing_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_fast_open

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

traffic_policing

Name Description Schema
suspicious_receiver_ip_rate_limit
optional
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer
total_rate_limit
optional
Total rate limit in packets per second. Range: 100-4000000000.
Minimum value : 100
Maximum value : 4000000000
integer
validated_server_ip_rate_limit
optional
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer

tcp_retransmission

Name Description Schema
validation_mode
optional
0 = half open, 1 = full open. integer
validation_trust_mode
optional
0 = host, 1 = network. integer

tcp_syn_exclude_syn_ack_and_syn_ack_ecn

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_with_well_known_ports

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp

Name Description Schema
ntp_amplification
optional
ntp_amplification
snmp_amplification
optional
snmp_amplification
ssdp_flood
optional
SSDP flood handling. ssdp_flood
udp_contain_all_zero_data
optional
UDP contain all zero data handling. udp_contain_all_zero_data
udp_flood_amplification
optional
udp_flood_amplification
udp_fragmentation
optional
UDP fragmentation handling. udp_fragmentation
udp_malformed
optional
UDP malformed handling. udp_malformed
udp_with_port_number_lt_1024
optional
UDP with port number less than 1024 handling. udp_with_port_number_lt_1024

ntp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
ntp_response_length
optional
NTP response length handling. ntp_response_length
ntp_response_monlist_drop
optional
NTP response MONLIST drop handling. ntp_response_monlist_drop
ntp_response_rate_limit
optional
NTP response rate limit handling. ntp_response_rate_limit

ntp_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the NTP response.
Minimum value : 42
Maximum value : 1500
integer

ntp_response_monlist_drop

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ntp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

snmp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
snmp_response_rate_limit
optional
SNMP response rate limit handling. snmp_response_rate_limit

snmp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ssdp_flood

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp_contain_all_zero_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
zero_data_min_length
optional
The minimum length of the zero data payload.
Minimum value : 42
Maximum value : 128
integer

udp_flood_amplification

Name Description Schema
dns_query_length
optional
DNS query length handling. dns_query_length
dns_query_rate_limit
optional
DNS query rate limit handling. dns_query_rate_limit
dns_response_length
optional
DNS response length handling. dns_response_length
dns_response_rate_limit
optional
DNS response rate limit handling. dns_response_rate_limit
is_enabled
optional
0 = disabled, 1 = enabled . integer

dns_query_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
The size of the DNS query.
Minimum value : 42
Maximum value : 1500
integer

dns_query_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

dns_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
The size of the DNS response.
Minimum value : 42
Maximum value : 1500
integer

dns_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp_malformed

Name Description Schema
udp_packet_contain_no_data
optional
0 = disabled, 1 = enabled . integer

udp_with_port_number_lt_1024

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

l7

Name Description Schema
custom
optional
Custom L7 (TCP) filter profiles for this host. custom
http
optional
HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled. http
quic
optional
QUIC L7 filter profiles for this host. quic
sip
optional
SIP L7 filter profiles for this host. sip
tls
optional
TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled. tls

custom

Name Description Schema
profile
required
List of Custom L7 (TCP) filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration.origin_field:connection_protect. tcp_connection

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total Connection Moudle configuration.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

http

Name Schema
profile
optional
< profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
http_authentication
optional
HTTP Authentication Module configuration.origin_field:authentication. http_authentication
http_slow_rate
optional
HTTP Slow Rate Module configuration.origin_field:slow_attack. http_slow_rate
is_enabled
optional
Filter status. Values: 0 = on, 1 = off. integer
tcp_connection
optional
TCP Connection Module configuration.origin_field:connection_protect. tcp_connection

http_authentication

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
model
optional
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. integer

http_slow_rate

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-86400).origin_field:block_duration.
Minimum value : 1
Maximum value : 86400
integer
body
optional
HTTP Slow Body Module configuration. body
header
optional
HTTP Slow Header Module configuration. header
is_enabled
optional
Enable status mode. Values: 1 = Block, 2 = Block RST. integer
new_session_per_minute
optional
New Session per minute,range in (1-65535).origin_field:session_threshold.
Minimum value : 1
Maximum value : 65535
integer

body

Name Description Schema
calc_avg_packet
optional
Number of TCP packets to carry a single HTTP request,range in (3-20).origin_field:calc_avg_packet.
Minimum value : 3
Maximum value : 20
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
min_avg_length
optional
Smallest allowed TCP packet size of a splited HTTP request,range in (1-1500).origin_field:min_avg_length.
Minimum value : 1
Maximum value : 1500
integer
timeout_interval
optional
Time interval between two packets (milliseconds),range in (1000-10000).origin_field:timeout_interval.
Minimum value : 1000
Maximum value : 10000
integer

header

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet_size
optional
Packet length(bytes),range in (64-1500).origin_field:packet_size.
Minimum value : 64
Maximum value : 1500
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration.origin_field:slow_rate_connection. slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total Connection Moudle configuration.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration(seconds), range in (10-60).origin_field:banned_period.
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration(seconds) range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration(seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration(seconds) range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Total Connection per second,range in (100 - 4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

quic

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
QUIC Malformed Packet Detection configuration. malformed
quic_flood_protection
optional
QUIC Session Protection configuration.origin_field:protect. quic_flood_protection
quic_ratelimit
optional
QUIC Ratelimit Module configuration.origin_field:traffic_rate_limit. quic_ratelimit

malformed

Name Description Schema
handshake_min_len
optional
Minimum length (bytes) for handshake packets, range in (10-65535).
Minimum value : 10
Maximum value : 65535
integer
initial_min_len
optional
Minimum length (bytes) for initial packets, range in (1200-65535).
Minimum value : 1200
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer
support_version
optional
Supported QUIC versions:[‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. < string > array
version_negotiation_min_len
optional
Minimum length (bytes) for version negotiation packets, range in (12-65535).
Minimum value : 12
Maximum value : 65535
integer
zero_rtt_min_len
optional
Minimum length (bytes) for 0-RTT packets, range in (10-65535).
Minimum value : 10
Maximum value : 65535
integer

quic_flood_protection

Name Description Schema
0rtt_replay_attack_protection
optional
0-RTT replay attack protection configuration. 0rtt_replay_attack_protection
authentication
optional
Authentication configuration. authentication
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_source_ip
optional
Session (Per source IP) Module configuration.origin_field:new_session_limit. new_session_per_source_ip
ratelimit_per_session
optional
Ratelimit (Per Session) Module configuration. origin_field:five_tuple_session. ratelimit_per_session

0rtt_replay_attack_protection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. integer
packet_per_second
optional
Packets per second threshold, range in (1-65535).
Minimum value : 1
Maximum value : 65535
integer

authentication

Name Description Schema
mode
optional
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. integer
session_scope
optional
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. integer

new_session_per_source_ip

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).origin_field:action_duration.
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_second
optional
New sessions per second, range in (1-65535).origin_field:max_new_session.
Minimum value : 1
Maximum value : 65535
integer

ratelimit_per_session

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. integer
session_check_duration
optional
Session check duration (seconds), range in (20-40).origin_field:check_time.
Minimum value : 20
Maximum value : 40
integer
session_timeout
optional
Idle session timeout (seconds), range in (60-600).origin_field:idle_session_timeout.
Minimum value : 60
Maximum value : 600
integer

quic_ratelimit

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packets
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

sip

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_tcp_port
optional
TCP Port list. < integer > array
filter_udp_port
optional
UDP Port list. < integer > array
invite
optional
SIP INVITE message configuration. invite
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed_is_enabled
optional
SIP Malformed enable status. Values: 0 = off, 1 = drop. integer
register
optional
SIP REGISTER Requst message configuration. register
retransmission_is_enabled
optional
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. integer
tcp_connection
optional
TCP Connection protection configuration.origin_field:connection_protect. tcp_connection

invite

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

register

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Source IP average window size threshold.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total connection rate limiting.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range in (10-60).origin_field:banned_period.
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

tls

Name Description Schema
profile
optional
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
SSL/TLS Malformed Packet Detection configuration. malformed
ratelimit
optional
SSL/TLS Ratelimit (Per Profile) configuration.origin_field:traffic_shaping. ratelimit
renegotiation
optional
SSL/TLS Renegotiation configuration. renegotiation
session
optional
SSL/TLS Session configuration. session
tcp_connection
optional
Connection protection configuration.origin_field:connection_protect. tcp_connection

malformed

Name Description Schema
clienthello_length_limit_non_v_1_3
optional
ClientHello length (bytes) limit for non-TLS 1.3, range in (64-1400).
Minimum value : 64
Maximum value : 1400
integer
clienthello_length_limit_v_1_3
optional
ClientHello length (bytes) limit for TLS 1.3, range in (64-1400).
Minimum value : 64
Maximum value : 1400
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer

ratelimit

Name Description Schema
non_tls
optional
Ratelimit for non TLS1.2 and TLS1.3 traffic. non_tls
tls
optional
Ratelimit for TLS1.2 and TLS1.3 traffic. tls

non_tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

renegotiation

Name Description Schema
blocklist_duration
optional
Blocklist duration (seconds), range in (1-65535).
Minimum value : 1
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer

session

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).origin_field:build_banned_period.
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = block. integer
new_session_per_second
optional
New session per second, range in (1-65535).origin_field:build_threshold.
Minimum value : 1
Maximum value : 65535
integer

tcp_connection

Name Description Schema
is_enabled
optional
Connection protection enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
This rule checks for slow rate connections from the same source IP address.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total connection rate limiting.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Avg.Window Size (bytes),range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Ban duration (seconds), range in (10-60).
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

protocol

Name Description Schema
tcp_ratelimit
optional
Host-level TCP bps/pps cap. tcp_ratelimit
udp_ratelimit
optional
Host-level UDP bps/pps cap. udp_ratelimit

tcp_ratelimit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_ratelimit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

bogons

Name Description Schema
land_attack
optional
Mitigate LAND-style same src/dst attacks. land_attack
martian_address
optional
Drop martian or reserved addresses. martian_address

land_attack

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

martian_address

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

flex_filter

Name Description Schema
acl_filter
optional
ACL common and custom rule sets. acl_filter
payload_filter
optional
Advanced payload filtering rules. payload_filter
smart_filter
optional
Smart filter heuristic toggles. Not supported for IPv6. smart_filter

acl_filter

Name Description Schema
acl_filter_rules
optional
Host-specific custom ACL rule set. < acl_filter_rules > array
acl_filter_sets
optional
Shared ACL rule sets attached to the host. < acl_filter_sets > array
is_enabled
optional
0 = disabled, 1 = enabled . integer

acl_filter_rules

Name Description Schema
action
optional
The action of the rule. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule.Can updated whern ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. enum (any, tcp, udp, icmp, custom)
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

acl_filter_sets

Name Description Schema
rule_set_desc
optional
Pattern : "^[A-Za-z0-9_ -]*$" string
rule_set_id
required
string
rule_set_name
optional
Length : 1 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string

payload_filter

Name Description Schema
filters
optional
List of user-defined filter rule objects. < filters > array

filters

Name Description Schema
action
optional
An action will be taken when they match. enum (ratelimit, pass, drop)
bps_limit
optional
ratelimit in bps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique identifier of advanced rule. string
filter_name
optional
The name of the policies.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
payload_string
optional
The string of the payload. < string > array
port
optional
The lists of the port numbers. < integer > array
pps_limit
optional
ratelimit in pps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the data packet. enum (tcp, udp, ip, any)

smart_filter

Name Description Schema
amplification
optional
Amplification attack detection. integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
threat_intelligence
optional
Threat intelligence integration. integer
traffic_generator
optional
Traffic generator / lab source handling. integer

ntif

Name Description Schema
anonymizer
optional
Anonymizer / proxy NTIF subgroups. anonymizer
botnet
optional
Botnet-related NTIF subgroups. botnet
is_enabled
optional
0 = disabled, 1 = enabled . integer

anonymizer

Name Schema
proxy
optional
proxy
tor
optional
tor

proxy

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

tor

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

botnet

Name Schema
dark_spider
optional
dark_spider
ddos
optional
ddos
malware
optional
malware
reputation
optional
reputation
scanner
optional
scanner
spam
optional
spam

dark_spider

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

ddos

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

malware

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

reputation

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

scanner

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

spam

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

traffic_policing

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie

Name Description Schema
flex_zombie
optional
< flex_zombie > array
is_enabled
optional
0 = off, 1 = on . integer
zombie_host
optional
Per-host zombie thresholds and action. zombie_host
zombie_network
optional
Per-network zombie thresholds and action. zombie_network

flex_zombie

Name Description Schema
action
optional
The action of the rule. enum (pass, ratelimit, block)
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
bps_limit
optional
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dip_prefix
optional
The IP Netmask of the destination IP address of the rule.Should be updated when ‘dip’ or ‘dip_dport’ mode is selected.
Minimum value : 24
Maximum value : 32
integer
dst_ip
optional
< string > array
dst_port
optional
< integer > array
icmp_code
optional
The ICMP code of the rule.Should be updated when ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule.Should be updated when ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. enum (any, tcp, udp, icmp)
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sip_prefix
optional
The IP Netmask of the source IP address of the rule.Should be updated when ‘sip’ or ‘sip_sport’ or ‘sip_dport’ mode is selected.
Minimum value : 24
Maximum value : 32
integer
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer
zombie_mode
optional
The mode of the rule.Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Default is sip. enum (sip, dip, sip_sport, dip_dport, sip_dport)

zombie_host

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie_network

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = off, 1 = on . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get mitigation policy.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/manual-mitigation-configuration

Description

Get mitigation policy for a host.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Full manual mitigation policy for a host: allow/block lists, anti-flood (L3/L4/L7), flex filters, zombie detection, traffic policing, NTIF, and bogon filtering. POST body: all policy sections must be present; nested objects use strict closed content (no extra properties). Identifiers and type are required; site_name / network_name / host_name are optional display fields. manual_mitigation_configuration

manual_mitigation_configuration

Name Description Schema
allow_block_list
optional
Allow list and block list configuration for source traffic. allow_block_list
anti_flood
optional
Anti-flood policy: L3/L4 modules, L7 profiles, and aggregate protocol caps. anti_flood
bogons
optional
Bogon and invalid address protections. bogons
customer_id
optional
Customer identifier. string
flex_filter
optional
Flex filters: payload, ACL, smart filter, TCP option sets. flex_filter
host_id
optional
Host identifier. string
network_id
optional
Network identifier. string
ntif
optional
Network Threat Intelligence Feed categories and actions. Not supported for IPv6. ntif
site_id
optional
Site identifier. string
traffic_policing
optional
Traffic policing cap (bps/pps) for the host. traffic_policing
zombie
optional
Zombie host detection (host vs network scope). Not supported for IPv6. zombie

allow_block_list

Name Description Schema
allow_list
optional
Trusted sources permitted when allow-list policy is enabled. allow_list
block_list
optional
Sources to block or rate-limit when block-list policy is enabled. block_list

allow_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. Required when mode is 2. string
mode
optional
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

block_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. Required when mode is 2. string
mode
optional
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

anti_flood

Name Description Schema
l3l4
optional
l3l4
l7
optional
Application-layer filter profiles (HTTP, TLS, SIP, QUIC, custom TCP). l7
protocol
optional
Per-protocol aggregate rate limits at host scope. protocol

l3l4

Name Description Schema
icmp
optional
ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported. icmp
ip
optional
IP-layer sanity and flood mitigation. ip
tcp
optional
TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters. tcp
udp
optional
UDP flood amplification handling. udp

icmp

Name Description Schema
all_icmp_packet
optional
Drop all ICMP traffic when enabled. all_icmp_packet
icmp_custom_filter
optional
icmp_custom_filter
icmp_fragmentation
optional
ICMP fragmentation handling. icmp_fragmentation
large_ping
optional
Drop oversized ICMP echo requests. large_ping

all_icmp_packet

Name Description Schema
is_enabled
optional
0 = disabled, 1 = drop all ICMP traffic . integer

icmp_custom_filter

Name Description Schema
default
optional
Default ICMP filter applied when no custom rule matches. default
filters
optional
< filters > array
is_enabled
optional
0 = disabled, 1 = enabled . integer

default

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit, pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name. Can not be edited.
Length : 1 - 40
Pattern : "^[A-Za-z0-9_-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

filters

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit,pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_description
optional
Filter description.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
icmp_type
optional
ICMP type number.
Minimum value : 0
Maximum value : 31
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

icmp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

large_ping

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

ip

Name Description Schema
custom_protocol_filter
optional
Filter on specific IP protocol numbers. custom_protocol_filter
ip_fragmentation
optional
IP fragmentation handling. ip_fragmentation
ip_invalid
optional
Drop packets failing basic IP validity checks. ip_invalid

custom_protocol_filter

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
protocol_numbers
optional
Per-protocol aggregate rate limits at host scope. < integer > array

ip_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

ip_invalid

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp

Name Description Schema
tcp_fragmentation
optional
TCP fragmentation mitigation. tcp_fragmentation
tcp_malformed
optional
Invalid TCP flags, SYN, and option handling. tcp_malformed
tcp_rewrite_mss_size
optional
SYN MSS validation. tcp_rewrite_mss_size
tcp_syn_anti_spoofing
optional
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. tcp_syn_anti_spoofing
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
optional
Drop SYN-ACK and SYN-ACK-ECN packets. tcp_syn_exclude_syn_ack_and_syn_ack_ecn
tcp_with_well_known_ports
optional
Drop invalid or sensitive destination-port packets. tcp_with_well_known_ports

tcp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_malformed

Name Description Schema
tcp_invalid_flags
optional
Illegal or suspicious TCP flag combinations. tcp_invalid_flags
tcp_long_header
optional
Malformed or oversized SYN options. tcp_long_header
tcp_syn_with_data
optional
SYN segments with non-zero payload. tcp_syn_with_data
tcp_syn_with_reserved_flags
optional
Reserved TCP flag bits. tcp_syn_with_reserved_flags

tcp_invalid_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_long_header

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_syn_with_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_syn_with_reserved_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_rewrite_mss_size

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
Size threshold in bytes (meaning depends on parent module).
Minimum value : 34
Maximum value : 1500
integer

tcp_syn_anti_spoofing

Name Description Schema
graceful_challenges
optional
Graceful challenges. graceful_challenges
is_enabled
optional
0 = disabled, 1 = enabled . integer
rate_limit_per_connection
optional
Rate limit per connection. rate_limit_per_connection
tcp_3_way_handshake_challenges
optional
TCP 3-way handshake challenges. tcp_3_way_handshake_challenges
tcp_data
optional
TCP data validation. tcp_data
tcp_retransmission
optional
TCP retransmission validation. tcp_retransmission

graceful_challenges

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

rate_limit_per_connection

Name Description Schema
duration
optional
Duration in seconds. Range: 10-150.
Minimum value : 10
Maximum value : 150
integer
is_enabled
optional
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. integer
timeout
optional
Timeout duration in seconds. Range: 10-3600.
Minimum value : 60
Maximum value : 600
integer

tcp_3_way_handshake_challenges

Name Description Schema
mode
optional
0 = tcp retransmission, 1 = tcp data, 2 = auto. integer

tcp_data

Name Description Schema
server_ip_validation
optional
Server IP validation. server_ip_validation
traffic_policing
optional
Traffic policing. traffic_policing

server_ip_validation

Name Description Schema
bot_mitigation
optional
Bot mitigation validation. bot_mitigation
spoofed_carpet_bombing_mitigation
optional
Spoofed carpet bombing mitigation validation. spoofed_carpet_bombing_mitigation
tcp_fast_open
optional
TCP fast open validation. tcp_fast_open

bot_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

spoofed_carpet_bombing_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_fast_open

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

traffic_policing

Name Description Schema
suspicious_receiver_ip_rate_limit
optional
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer
total_rate_limit
optional
Total rate limit in packets per second. Range: 100-4000000000.
Minimum value : 100
Maximum value : 4000000000
integer
validated_server_ip_rate_limit
optional
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer

tcp_retransmission

Name Description Schema
validation_mode
optional
0 = half open, 1 = full open. integer
validation_trust_mode
optional
0 = host, 1 = network. integer

tcp_syn_exclude_syn_ack_and_syn_ack_ecn

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

tcp_with_well_known_ports

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp

Name Description Schema
ntp_amplification
optional
ntp_amplification
snmp_amplification
optional
snmp_amplification
ssdp_flood
optional
SSDP flood handling. ssdp_flood
udp_contain_all_zero_data
optional
UDP contain all zero data handling. udp_contain_all_zero_data
udp_flood_amplification
optional
udp_flood_amplification
udp_fragmentation
optional
UDP fragmentation handling. udp_fragmentation
udp_malformed
optional
UDP malformed handling. udp_malformed
udp_with_port_number_lt_1024
optional
UDP with port number less than 1024 handling. udp_with_port_number_lt_1024

ntp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
ntp_response_length
optional
NTP response length handling. ntp_response_length
ntp_response_monlist_drop
optional
NTP response MONLIST drop handling. ntp_response_monlist_drop
ntp_response_rate_limit
optional
NTP response rate limit handling. ntp_response_rate_limit

ntp_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the NTP response.
Minimum value : 42
Maximum value : 1500
integer

ntp_response_monlist_drop

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ntp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

snmp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
snmp_response_rate_limit
optional
SNMP response rate limit handling. snmp_response_rate_limit

snmp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ssdp_flood

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp_contain_all_zero_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
zero_data_min_length
optional
The minimum length of the zero data payload.
Minimum value : 42
Maximum value : 128
integer

udp_flood_amplification

Name Description Schema
dns_query_length
optional
DNS query length handling. dns_query_length
dns_query_rate_limit
optional
DNS query rate limit handling. dns_query_rate_limit
dns_response_length
optional
DNS response length handling. dns_response_length
dns_response_rate_limit
optional
DNS response rate limit handling. dns_response_rate_limit
is_enabled
optional
0 = disabled, 1 = enabled . integer

dns_query_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
The size of the DNS query.
Minimum value : 42
Maximum value : 1500
integer

dns_query_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

dns_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
size
optional
The size of the DNS response.
Minimum value : 42
Maximum value : 1500
integer

dns_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

udp_malformed

Name Description Schema
udp_packet_contain_no_data
optional
0 = disabled, 1 = enabled . integer

udp_with_port_number_lt_1024

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

l7

Name Description Schema
custom
optional
Custom L7 (TCP) filter profiles for this host. custom
http
optional
HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled. http
quic
optional
QUIC L7 filter profiles for this host. quic
sip
optional
SIP L7 filter profiles for this host. sip
tls
optional
TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled. tls

custom

Name Description Schema
profile
required
List of Custom L7 (TCP) filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_desc
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration.origin_field:connection_protect. tcp_connection

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total Connection Moudle configuration.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

http

Name Schema
profile
optional
< profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
http_authentication
optional
HTTP Authentication Module configuration.origin_field:authentication. http_authentication
http_slow_rate
optional
HTTP Slow Rate Module configuration.origin_field:slow_attack. http_slow_rate
is_enabled
optional
Filter status. Values: 0 = on, 1 = off. integer
tcp_connection
optional
TCP Connection Module configuration.origin_field:connection_protect. tcp_connection

http_authentication

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
model
optional
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. integer

http_slow_rate

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-86400).origin_field:block_duration.
Minimum value : 1
Maximum value : 86400
integer
body
optional
HTTP Slow Body Module configuration. body
header
optional
HTTP Slow Header Module configuration. header
is_enabled
optional
Enable status mode. Values: 1 = Block, 2 = Block RST. integer
new_session_per_minute
optional
New Session per minute,range in (1-65535).origin_field:session_threshold.
Minimum value : 1
Maximum value : 65535
integer

body

Name Description Schema
calc_avg_packet
optional
Number of TCP packets to carry a single HTTP request,range in (3-20).origin_field:calc_avg_packet.
Minimum value : 3
Maximum value : 20
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
min_avg_length
optional
Smallest allowed TCP packet size of a splited HTTP request,range in (1-1500).origin_field:min_avg_length.
Minimum value : 1
Maximum value : 1500
integer
timeout_interval
optional
Time interval between two packets (milliseconds),range in (1000-10000).origin_field:timeout_interval.
Minimum value : 1000
Maximum value : 10000
integer

header

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet_size
optional
Packet length(bytes),range in (64-1500).origin_field:packet_size.
Minimum value : 64
Maximum value : 1500
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration.origin_field:slow_rate_connection. slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total Connection Moudle configuration.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration(seconds), range in (10-60).origin_field:banned_period.
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration(seconds) range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration(seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration(seconds) range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Total Connection per second,range in (100 - 4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

quic

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
QUIC Malformed Packet Detection configuration. malformed
quic_flood_protection
optional
QUIC Session Protection configuration.origin_field:protect. quic_flood_protection
quic_ratelimit
optional
QUIC Ratelimit Module configuration.origin_field:traffic_rate_limit. quic_ratelimit

malformed

Name Description Schema
handshake_min_len
optional
Minimum length (bytes) for handshake packets, range in (10-65535).
Minimum value : 10
Maximum value : 65535
integer
initial_min_len
optional
Minimum length (bytes) for initial packets, range in (1200-65535).
Minimum value : 1200
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer
support_version
optional
Supported QUIC versions:[‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. < string > array
version_negotiation_min_len
optional
Minimum length (bytes) for version negotiation packets, range in (12-65535).
Minimum value : 12
Maximum value : 65535
integer
zero_rtt_min_len
optional
Minimum length (bytes) for 0-RTT packets, range in (10-65535).
Minimum value : 10
Maximum value : 65535
integer

quic_flood_protection

Name Description Schema
0rtt_replay_attack_protection
optional
0-RTT replay attack protection configuration. 0rtt_replay_attack_protection
authentication
optional
Authentication configuration. authentication
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_source_ip
optional
Session (Per source IP) Module configuration.origin_field:new_session_limit. new_session_per_source_ip
ratelimit_per_session
optional
Ratelimit (Per Session) Module configuration. origin_field:five_tuple_session. ratelimit_per_session

0rtt_replay_attack_protection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. integer
packet_per_second
optional
Packets per second threshold, range in (1-65535).
Minimum value : 1
Maximum value : 65535
integer

authentication

Name Description Schema
mode
optional
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. integer
session_scope
optional
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. integer

new_session_per_source_ip

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).origin_field:action_duration.
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_second
optional
New sessions per second, range in (1-65535).origin_field:max_new_session.
Minimum value : 1
Maximum value : 65535
integer

ratelimit_per_session

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. integer
session_check_duration
optional
Session check duration (seconds), range in (20-40).origin_field:check_time.
Minimum value : 20
Maximum value : 40
integer
session_timeout
optional
Idle session timeout (seconds), range in (60-600).origin_field:idle_session_timeout.
Minimum value : 60
Maximum value : 600
integer

quic_ratelimit

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packets
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

sip

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_tcp_port
optional
TCP Port list. < integer > array
filter_udp_port
optional
UDP Port list. < integer > array
invite
optional
SIP INVITE message configuration. invite
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed_is_enabled
optional
SIP Malformed enable status. Values: 0 = off, 1 = drop. integer
register
optional
SIP REGISTER Requst message configuration. register
retransmission_is_enabled
optional
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. integer
tcp_connection
optional
TCP Connection protection configuration.origin_field:connection_protect. tcp_connection

invite

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

register

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Source IP average window size threshold.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total connection rate limiting.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second,range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range in (10-60).origin_field:banned_period.
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

tls

Name Description Schema
profile
optional
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
SSL/TLS Malformed Packet Detection configuration. malformed
ratelimit
optional
SSL/TLS Ratelimit (Per Profile) configuration.origin_field:traffic_shaping. ratelimit
renegotiation
optional
SSL/TLS Renegotiation configuration. renegotiation
session
optional
SSL/TLS Session configuration. session
tcp_connection
optional
Connection protection configuration.origin_field:connection_protect. tcp_connection

malformed

Name Description Schema
clienthello_length_limit_non_v_1_3
optional
ClientHello length (bytes) limit for non-TLS 1.3, range in (64-1400).
Minimum value : 64
Maximum value : 1400
integer
clienthello_length_limit_v_1_3
optional
ClientHello length (bytes) limit for TLS 1.3, range in (64-1400).
Minimum value : 64
Maximum value : 1400
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer

ratelimit

Name Description Schema
non_tls
optional
Ratelimit for non TLS1.2 and TLS1.3 traffic. non_tls
tls
optional
Ratelimit for TLS1.2 and TLS1.3 traffic. tls

non_tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range in (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range in (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

renegotiation

Name Description Schema
blocklist_duration
optional
Blocklist duration (seconds), range in (1-65535).
Minimum value : 1
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer

session

Name Description Schema
block_duration
optional
Block duration (seconds), range in (1-300).origin_field:build_banned_period.
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = block. integer
new_session_per_second
optional
New session per second, range in (1-65535).origin_field:build_threshold.
Minimum value : 1
Maximum value : 65535
integer

tcp_connection

Name Description Schema
is_enabled
optional
Connection protection enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
This rule checks for slow rate connections from the same source IP address.origin_field:src_ip_avg_window_size_threshold. slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting.origin_field:src_ip_connection_rate. source_ip_new_connection
total_connection
optional
Total connection rate limiting.origin_field:total_connection_rate. total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Avg.Window Size (bytes),range in (1-65535).origin_field:session_per_second.
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Ban duration (seconds), range in (10-60).
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range in (10-600).origin_field:banned_period.
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
Sessions per second,range in (5-1000).origin_field:session_per_second.
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second,range in (100-4294967295).origin_field:session_per_second.
Minimum value : 100
Maximum value : 4294967295
integer

protocol

Name Description Schema
tcp_ratelimit
optional
Host-level TCP bps/pps cap. tcp_ratelimit
udp_ratelimit
optional
Host-level UDP bps/pps cap. udp_ratelimit

tcp_ratelimit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_ratelimit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

bogons

Name Description Schema
land_attack
optional
Mitigate LAND-style same src/dst attacks. land_attack
martian_address
optional
Drop martian or reserved addresses. martian_address

land_attack

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

martian_address

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer

flex_filter

Name Description Schema
acl_filter
optional
ACL common and custom rule sets. acl_filter
payload_filter
optional
Advanced payload filtering rules. payload_filter
smart_filter
optional
Smart filter heuristic toggles. Not supported for IPv6. smart_filter

acl_filter

Name Description Schema
acl_filter_rules
optional
Host-specific custom ACL rule set. < acl_filter_rules > array
acl_filter_sets
optional
Shared ACL rule sets attached to the host. < acl_filter_sets > array
is_enabled
optional
0 = disabled, 1 = enabled . integer

acl_filter_rules

Name Description Schema
action
optional
The action of the rule. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule.Can updated whern ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. enum (any, tcp, udp, icmp, custom)
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

acl_filter_sets

Name Description Schema
rule_set_desc
optional
Pattern : "^[A-Za-z0-9_ -]*$" string
rule_set_id
required
string
rule_set_name
optional
Length : 1 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string

payload_filter

Name Description Schema
filters
optional
List of user-defined filter rule objects. < filters > array

filters

Name Description Schema
action
optional
An action will be taken when they match. enum (ratelimit, pass, drop)
bps_limit
optional
ratelimit in bps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique identifier of advanced rule. string
filter_name
optional
The name of the policies.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
is_enabled
optional
0 = disabled, 1 = enabled . integer
payload_string
optional
The string of the payload. < string > array
port
optional
The lists of the port numbers. < integer > array
pps_limit
optional
ratelimit in pps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the data packet. enum (tcp, udp, ip, any)

smart_filter

Name Description Schema
amplification
optional
Amplification attack detection. integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
threat_intelligence
optional
Threat intelligence integration. integer
traffic_generator
optional
Traffic generator / lab source handling. integer

ntif

Name Description Schema
anonymizer
optional
Anonymizer / proxy NTIF subgroups. anonymizer
botnet
optional
Botnet-related NTIF subgroups. botnet
is_enabled
optional
0 = disabled, 1 = enabled . integer

anonymizer

Name Schema
proxy
optional
proxy
tor
optional
tor

proxy

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

tor

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

botnet

Name Schema
dark_spider
optional
dark_spider
ddos
optional
ddos
malware
optional
malware
reputation
optional
reputation
scanner
optional
scanner
spam
optional
spam

dark_spider

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

ddos

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

malware

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

reputation

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

scanner

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

spam

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). integer

traffic_policing

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled . integer
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie

Name Description Schema
flex_zombie
optional
< flex_zombie > array
is_enabled
optional
0 = off, 1 = on . integer
zombie_host
optional
Per-host zombie thresholds and action. zombie_host
zombie_network
optional
Per-network zombie thresholds and action. zombie_network

flex_zombie

Name Description Schema
action
optional
The action of the rule. enum (pass, ratelimit, block)
bps_limit
optional
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dip_prefix
optional
The IP Netmask of the destination IP address of the rule.Should be updated when ‘dip’ or ‘dip_dport’ mode is selected.
Minimum value : 24
Maximum value : 32
integer
dst_ip
optional
< string > array
dst_port
optional
< integer > array
icmp_code
optional
The ICMP code of the rule.Should be updated when ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule.Should be updated when ‘icmp’ protocol is selected.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
pps_limit
optional
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. enum (any, tcp, udp, icmp)
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sip_prefix
optional
The IP Netmask of the source IP address of the rule.Should be updated when ‘sip’ or ‘sip_sport’ or ‘sip_dport’ mode is selected.
Minimum value : 24
Maximum value : 32
integer
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer
zombie_mode
optional
The mode of the rule.Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Default is sip. enum (sip, dip, sip_sport, dip_dport, sip_dport)

zombie_host

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = disabled, 1 = enabled . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie_network

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = off, 1 = on . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the info of mitigation for TCP flood.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood

Description

Get the info of mitigation for TCP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
malformed_tcp_packets
optional
The info of the malformed TCP packets. malformed_tcp_packets
tcp_fragmentation
optional
The info of TCP fragmentation. tcp_fragmentation
tcp_rate_limit
optional
The info of TCP rate limit. tcp_rate_limit
tcp_syn_flood
optional
The info of TCP syn flood. tcp_syn_flood
tcp_syn_mss
optional
The info of TCP syn mss. tcp_syn_mss

malformed_tcp_packets

Name Schema
invalid_tcp_flag
optional
invalid_tcp_flag
invalid_tcp_reserved_flag
optional
invalid_tcp_reserved_flag
invalid_tcp_syn_option
optional
invalid_tcp_syn_option
invalid_tcp_syn_payload
optional
invalid_tcp_syn_payload
tcp_syn
optional
tcp_syn

invalid_tcp_flag

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

invalid_tcp_reserved_flag

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

invalid_tcp_syn_option

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
size
optional
The size of the TCP from the option. integer

invalid_tcp_syn_payload

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
size
optional
The size of the payload. integer

tcp_syn

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

tcp_fragmentation

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

tcp_rate_limit

Name Description Schema
bps_limit
optional
The ratelimit in bps. string
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
pps_limit
optional
The ratelimit in pps. string

tcp_syn_flood

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
session_check
optional
session_check
session_timeout
optional
session_timeout
syn_authentication
optional
syn_authentication

session_check

Name Description Schema
seconds
optional
The amount of time, in seconds, to wait before checking an SYN session. integer

session_timeout

Name Description Schema
seconds
optional
The minimum time, in seconds, for the SYN-packet retransmission to consider the retransmission to be valid. integer

syn_authentication

Name Description Schema
strict_mode
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
syn_auth
optional
The model of TCP syn authentication. string

tcp_syn_mss

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
size
optional
The size of the maximum segment. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit TCP Flood/Malformed TCP packets.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/packets

Description

Edit TCP Flood/Malformed TCP packets.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData module
required
TCP flood/malformed TCP packets type. in (payload、option). string
FormData size
required
The size of string must range between 0 and 1500. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policy for TCP flood or malformed TCP packets.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/packets/switch

Description

Change the mitigation policy for TCP flood or malformed TCP packets.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means TCP flood switch is disabled whereas 1 mean it is enabled. integer
FormData module
required
The type of TCP flood switch consists of invalid_tcp_flag,invalid_tcp_reserved_flag,tcp_syn,invalid_tcp_syn_payload,invalid_tcp_syn_option. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit TCP Flood/TCP rate limit.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/rate-limit

Description

Edit TCP Flood/TCP rate limit.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData bps_limit
required
The ratelimit in bps.must be a number or K, M, G format. string
FormData pps_limit
required
The ratelimit in pps.must be a number or K, M, G format. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the status of the policies for TCP flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/switch

Description

Change the status of the policies for TCP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch is disabled whereas 1 means it is enabled. integer
FormData module
required
The switch for the type of icmp flood includes tcp_rate_limit,tcp_fragmentation,tcp_syn_mss,tcp_syn_flood. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit TCP Flood/TCP SYN Flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/syn-flood

Description

Edit TCP Flood/TCP SYN Flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData session_check_seconds
optional
The amount of time, in seconds, to wait before checking an SYN session. It is set to a value between 10 and 255. integer
FormData session_timeout_seconds
optional
The minimum time, in seconds, for the SYN-packet retransmission to consider the retransmission to be valid. It is set to a value between 60 and 600. integer
FormData strict_mode
optional
0 means the switch is disabled whereas 1 means it is enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit TCP Flood/TCP SYN MSS.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/syn-mss

Description

Edit TCP Flood/TCP SYN MSS.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData size
required
The size of string must range between 34 and 1500. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policy for the FlexFilter/filter sets.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/filter-sets

Description

Edit the policy for the FlexFilter/filter sets.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData filter_set_id
required
Enter the filter set id you want to add.Currently only supports adding one option. < string > array

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policy for the FlexFilter/tcp option filter sets.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/policy

Description

Edit the policy for the FlexFilter/tcp option filter sets.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 This is the returned result. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
filter_sets
optional
< filter_sets > array
is_enabled
optional
Status of the tcp option filter. ‘0’ means off, ‘1’ means on. integer

filter_sets

Name Description Schema
filter_set_desc
optional
More details about the purpose of the policy. string
filter_set_id
optional
Unique identifier of filter set. string
filter_set_name
optional
The name of the policy. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Changes the status of the switch for the policies for FlexFilter/basic network filtering.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/switch

Description

Changes the status of the switch for the policies for FlexFilter/basic network filtering.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch of the basic network filtering is disabled whereas 1 means it is enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get traffic statistics for a specific host.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/traffic

Description

Retrieve bandwidth and packet rate statistics for a specific host in the network.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query period
optional
Time period for which traffic statistics are requested. Valid values: hour, day, week, month, default is hour. enum (hour, day, week, month)
Query unit
optional
Unit of time for which traffic statistics are requested. Valid values: bps, pps, bytes,‘packets’. enum (bps, pps, bytes, packets)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Traffic statistics data result

result

Name Description Schema
data
optional
Traffic statistics data data
time
optional
Timestamp for the traffic statistics data < integer > array

data

Name Description Schema
bps
optional
Traffic statistics data in bits per second bps
bytes
optional
Traffic statistics data in bytes bytes
packets
optional
Traffic statistics data in packets packets
pps
optional
Traffic statistics data in packets per second pps

bps

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

bytes

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

packets

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

pps

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the info of the mitigation of TCP Flood.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood

Description

Gets the info of the mitigation of TCP Flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
dns_flood_amplification
optional
The info of DNS flood and its amplification. dns_flood_amplification
no_data_payload
optional
The info of No data payload. no_data_payload
ntp_amplification
optional
The info of NTP amplification. ntp_amplification
snmp_amplification
optional
The info of SNMP amplification. snmp_amplification
ssdp_flood
optional
The info of SSDP flood. ssdp_flood
udp_fragmentation
optional
The info of UDP fragmentation. udp_fragmentation
udp_rate_limit
optional
The info about the rate limit of UDP. udp_rate_limit
zero_data_payload
optional
The info of Zero data payload. zero_data_payload

dns_flood_amplification

Name Schema
dns_query_length
optional
dns_query_length
dns_query_rate_limit
optional
dns_query_rate_limit
dns_response_length
optional
dns_response_length
dns_response_rate_limit
optional
dns_response_rate_limit

dns_query_length

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
size
optional
The size of the DNS query. integer

dns_query_rate_limit

Name Description Schema
bps_limit
optional
ratelimit in bps. string
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
pps_limit
optional
ratelimit in pps. string

dns_response_length

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
size
optional
The size of the DNS response. integer

dns_response_rate_limit

Name Description Schema
bps_limit
optional
ratelimit in bps. string
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
pps_limit
optional
ratelimit in pps. string

no_data_payload

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 it is enabled. integer

ntp_amplification

Name Schema
ntp_response_length
optional
ntp_response_length
ntp_response_rate_limit
optional
ntp_response_rate_limit

ntp_response_length

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
size
optional
The size of the NTP response. integer

ntp_response_rate_limit

Name Description Schema
bps_limit
optional
ratelimit in bps. string
is_enabled
optional
State of the switch. 0 means the switch is disabled whereas 1 mean it is enabled. integer
pps_limit
optional
ratelimit in pps. string

snmp_amplification

Name Schema
snmp_response_rate_limit
optional
snmp_response_rate_limit

snmp_response_rate_limit

Name Description Schema
bps_limit
optional
ratelimit in bps. string
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
pps_limit
optional
ratelimit in pps. string

ssdp_flood

Name Schema
drop_ssdp
optional
drop_ssdp

drop_ssdp

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer

udp_fragmentation

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas ‘1” means it is enabled. integer

udp_rate_limit

Name Description Schema
bps_limit
optional
ratelimit in bps. string
is_enabled
optional
0 means the switch is disabled whereas ‘1” means it is enabled. integer
pps_limit
optional
ratelimit in pps. string

zero_data_payload

Name Schema
drop_ssdp
optional
drop_ssdp

drop_ssdp

Name Description Schema
is_enabled
optional
0 means the switch is disabled whereas 1 mean it is enabled. integer
zero_payload_length
optional
The length of the zero payload. integer

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the info of submodule of the UDP flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/policy

Description

Edit the info of submodule of the UDP flood including DNS Flood & Amplification) & NTP Amplification & SNMP Amplification.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData bps_limit
optional
When the module is dns_query_rate_limit,udp_rate_limit or dns_response_rate_limit, the unit of rate limit must be K, M and G. string
FormData module
required
The switch for the type of UDP flood module includes dns_query_length,dns_query_rate_limit,dns_response_length,dns_response_rate_limit,ntp_response_length,ntp_response_rate_limit,snmp_response_rate_limit,udp_rate_limit. string
FormData pps_limit
optional
When the module is dns_query_rate_limit,udp_rate_limit or dns_response_rate_limit, the unit of rate limit must be K, M and G. string
FormData size
optional
When the module is selected as dns_query_length or dns_response_length, the size must range between 1 and 1500. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policies for UDP flood submodule.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/policy/switch

Description

Change the mitigation policies for UDP flood submodule.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the sub switch for the policies for the UDP flood is disabled whereas 1 means it is enabled. integer
FormData module
required
The switch for the type of UDP flood module includes dns_query_length,dns_query_rate_limit,dns_response_length,dns_response_rate_limit,ntp_response_length,ntp_response_rate_limit,snmp_response_rate_limit,drop_ssdp. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Change the mitigation policies for UDP flood.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/switch

Description

Change the mitigation policies for UDP flood.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the switch for the policies of UDP flood is disabled whereas 1 means it is enabled. integer
FormData module
required
The policies for UDP flood can handle udp_fragmentation,no_data_payload,udp_rate_limit,zero_data_payload. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Edit the policies for UDP flood/UDP zero data payload.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/zero-data-payload

Description

Edit the policies for UDP flood/UDP zero data payload.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData length
required
Length of the zero payload.Max matched length of zero data payload is limited 1-128 bytes. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

It is used to edit the filter for Zombie

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie

Description

It is used to edit the filter for Zombie

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData action
required
ratelimit or blacklist. string
FormData blacklist_timeout
required
Blacklist timeout. integer
FormData threshold_bps
required
Threshold values in bps.must be a number or K, M, G format. string
FormData threshold_pps
required
Threshold values in pps.must be a number or K, M, G format. string
FormData zombie_type
required
Zombie level. zombie_host or zombie_network. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the info of the policy for zombie.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie

Description

Gets the info of the policy for zombie.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
result

result

Name Description Schema
zombie_host
optional
Host level configuration. zombie_host
zombie_network
optional
Network level configuration. zombie_network

zombie_host

Name Description Schema
action
optional
ratelimit or blacklist. string
blacklist_timeout
optional
Blacklist timeout. integer
is_enabled
optional
0 means the switch is disabled whereas 1 means it is enabled. integer
threshold_bps
optional
Threshold values in bps. string
threshold_pps
optional
Threshold values in pps. string

zombie_network

Name Description Schema
action
optional
ratelimit or blacklist. string
blacklist_timeout
optional
Blacklist timeout. integer
is_enabled
optional
State of the switch. 0 means it is disabled and 1 means enabled. integer
threshold_bps
optional
Threshold values in bps. string
threshold_pps
optional
Threshold values in pps. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

It is used to change the status of Zombie.

POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie/switch

Description

It is used to change the status of Zombie.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API.Can be obtained by invoking this API. string
FormData is_enabled
required
0 means the mitigation policy for zombie is disabled whereas 1 means it is enabled. integer
FormData zombie_type
required
Zombie level. zombie_host or zombie_network. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get traffic statistics for specific hosts.

GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/mitigation/host-traffic

Description

Retrieve bandwidth and packet rate statistics for a specific host in the network.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query host_ids
required
Unique identifier of hosts. if empty, all hosts will be returned. 1-100 hosts are supported. < string > array(multi)
Query period
optional
Time period for which traffic statistics are requested. Valid values: hour, day, week, month. enum (hour, day, week, month)
Query traffic_metrics
optional
Units of traffic metrics to be returned. Valid values: bps, pps, bytes, packets. < enum (bps, pps, bytes, packets) > array(multi)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Traffic statistics data result

result

Name Description Schema
host_id
optional
Unique identifier of a host. host_id

host_id

Name Description Schema
data
optional
Traffic statistics data data
host_ip
optional
< string > array
time
optional
Timestamp for the traffic statistics data < integer > array

data

Name Description Schema
bps
optional
Traffic statistics data in bits per second bps
bytes
optional
Traffic statistics data in bytes bytes
packets
optional
Traffic statistics data in packets packets
pps
optional
Traffic statistics data in packets per second pps

bps

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

bytes

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

packets

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

pps

Name Description Schema
drop
optional
Dropped traffic data < integer > array
pass
optional
Passed traffic data. < integer > array

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY