☰

Mitigation Group

Bastions Mitigation Profile

Overview

Bastions mitigation profile API for mitigation groups and BGP communities.

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS

Paths

Adds a BGP community.

POST /spe/bastions/mitigation_profile/bgp_communities

Description

Creates a BGP community. Maximum 20 per slot_key.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body bgp_community
required
Request payload. bgp_community

bgp_community

Name Description Schema
bgp_community_name
required
bgp community name. Required when slot_key=slotx; omit or empty when slot_key=slot0. string
blackhole_community
required
Blackhole BGP community values. < string > array
mitigation_community
optional
Mitigation community. < string > array
slot_key
required
Slot key, two valid values are supported, it is slotx or slot0. enum (slotx, slot0)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
bgp_community_id
optional
BGP community ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets BGP community list.

GET /spe/bastions/mitigation_profile/bgp_communities

Description

Lists BGP communities for the given slot_key. Supports slotx and slot0. slotx represents the slot1–slot8 group (distinct from slot0). For slot0, only one BGP community record exists (auto-initialized on first access); when editing slot0, blackhole_community is required.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query slot_key
optional
Slot key filter. slotx or slot0, default slotx; see API description for slotx vs slot0 behavior. enum (slotx, slot0)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
bgp_community_list
optional
BGP community profile list. < bgp_community_list > array

bgp_community_list

Name Description Schema
bgp_community_id
optional
BGP community profile ID. string
bgp_community_name
optional
BGP community profile name. string
blackhole_community
optional
Blackhole BGP community values. < string > array
mitigation_community
optional
Mitigation BGP community values. < string > array
slot
optional
Slot key, slotx or slot0; see API description for slotx vs slot0 behavior. enum (slotx, slot0)

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates a BGP community.

PUT /spe/bastions/mitigation_profile/bgp_communities/{bgp_community_id}

Description

Updates name and community values. Name editable only for slotx. For slot0, only blackhole_community is required; mitigation_community is empty.

Parameters

Type Name Description Schema
Path bgp_community_id
required
string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body bgp_community
required
Request payload. bgp_community

bgp_community

Name Description Schema
bgp_community_name
optional
BGP community profile name. string
blackhole_community
required
Blackhole BGP community values. < string > array
mitigation_community
optional
Mitigation BGP community values. < string > array

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes a BGP community.

DELETE /spe/bastions/mitigation_profile/bgp_communities/{bgp_community_id}

Description

Deletes BGP community if not referenced by a mitigation group.

Parameters

Type Name Description Schema
Path bgp_community_id
required
string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Adds a mitigation group.

POST /spe/bastions/mitigation_profile/mitigation_groups

Description

Creates a mitigation group for slot1-8.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body mitigation_group
required
Mitigation group configuration. Values for netshield_peer, traffic_collector_peer, bgp_community_id, and flowspec fields must be taken from the corresponding fields in GET /spe/bastions/mitigation_profile/mitigation_groups/options (use the same ip_type). At least one of netshield_peer or traffic_collector_peer must contain peer selections; both empty is rejected by the backend. These mitigation groups are referenced when creating or editing a Clean Pipe Network Protection site. mitigation_group

mitigation_group

Name Description Schema
bgp_community_id
required
BGP community profile ID. Use bgp_community_id from an item in result.bgp_community in GET /spe/bastions/mitigation_profile/mitigation_groups/options. string
diversion_mode
required
0=Route, 1=FlowSpec, 2=Route and FlowSpec. When set to 1 or 2, flowspec must be provided. Use value from result.flowspec.diversion_mode in GET /spe/bastions/mitigation_profile/mitigation_groups/options. integer
flowspec
optional
FlowSpec diversion configuration. Required when diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec). traffic_collector_peer values must come from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] flowspec
ip_type
required
IP type (ipv4 or ipv6). Must match the ip_type used when calling GET /spe/bastions/mitigation_profile/mitigation_groups/options. enum (ipv4, ipv6)
mitigation_group_desc
optional
Mitigation group description. string
mitigation_group_name
required
Mitigation group name. string
netshield_peer
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Keys and peer_id values must come from result.netshield_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] < string, < string > array > map
pops
optional
Selected IDC/PoP List and not empty when scope is pop. IDC/PoP values must be from result.pops field when calling GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] < string > array
scope
optional
Scope specifies the range of the mitigation group. It accepts two valid values: global and pop, global indicates that the scope covers all POPs, while pop limits the scope to a specified POP.Default value is global.
Default : "global"
enum (global, pop)
slot_key
required
Slot key, only one valid value is supported, it is slotx, which means a set of slot1-slot8. enum (slotx)
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Keys and peer_id values must come from result.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. [Conditionally required] < string, < string > array > map

flowspec

Name Description Schema
diversion_target
optional
Diversion target. diversion_target
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Select peer groups from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. < string, < string > array > map

diversion_target

Name Description Schema
redirect_target
optional
FlowSpec redirect target. Required when diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec) string
route_distinguisher
optional
Route distinguisher value. Required when route_distinguisher_enabled is enabled. [Conditionally required] string
route_distinguisher_enabled
optional
0=route distinguisher disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
mitigation_group_id
optional
Mitigation group ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets mitigation group list.

GET /spe/bastions/mitigation_profile/mitigation_groups

Description

Lists mitigation groups for slot1-8. slot_key must be slotx, which means a set of slot1-slot8.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
IP address family: ipv4 or ipv6. Default ipv4. enum (ipv4, ipv6)
Query slot_key
required
Slot key. Only one valid value is supported, it is slotx, which means a set of slot1-slot8. enum (slotx)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
max_quota
optional
Max quota, a configurable value, its default is 20, which sets the maximum number of mitigation groups that can be created..
Minimum value : 0
integer
mitigation_group_list
optional
Mitigation group list. < mitigation_group_list > array
used_quota
optional
Used quota, indicates the number of mitigation groups currently in use. The minimum value is 0, and the maximum value is determined by Max quota (default is 20).
Minimum value : 0
integer

mitigation_group_list

Name Description Schema
bgp_community_id
optional
BGP community profile ID. string
diversion_mode
optional
Diversion mode (0=Route, 1=FlowSpec, 2=Route and FlowSpec). integer
flowspec
optional
FlowSpec diversion configuration. flowspec
ip_type
optional
IP type (ipv4 or ipv6). string
mitigation_group_desc
optional
Mitigation group description. string
mitigation_group_id
optional
Mitigation group ID. string
mitigation_group_name
optional
Mitigation group name. string
netshield_peer
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. < string, netshield_peer > map
pops
optional
Selected IDC/PoP List when scope is pop. IDC/PoP must contain available BGP peers. < string > array
scope
optional
Scope type (global or pop) enum (global, pop)
slot
optional
Slot key, only slotx. enum (slotx)
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. < string, traffic_collector_peer > map

flowspec

Name Description Schema
diversion_target
optional
Diversion target. diversion_target
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. < string, traffic_collector_peer > map

diversion_target

Name Description Schema
redirect_target
optional
FlowSpec redirect target. string
route_distinguisher
optional
Route distinguisher value. string
route_distinguisher_enabled
optional
0=route distinguisher disabled, 1=enabled. integer

traffic_collector_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

netshield_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

traffic_collector_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets mitigation group options.

GET /spe/bastions/mitigation_profile/mitigation_groups/options

Description

Returns peers, BGP communities, and FlowSpec diversion options for creating a group. Peer options are from slot1–slot8 only (slot0 is excluded).

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
required
IP address family: ipv4 or ipv6. Default ipv4. enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
bgp_community
optional
BGP community profile. < bgp_community > array
flowspec
optional
FlowSpec diversion configuration. flowspec
netshield_peer
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes only enabled bgp_netshield peers on slot1–slot8 (slot0 excluded). < string, netshield_peer > map
pops
optional
Available IDC/PoP List containing BGP peers when scope is pop. < pops > array
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. Includes only enabled bgp_traffic_collector peers added under traffic collectors. Peers under this map are the available options when diversion_mode=0 (Route) or diversion_mode=2 (Route and FlowSpec). < string, traffic_collector_peer > map

bgp_community

Name Description Schema
bgp_community_id
optional
BGP community profile ID. string
bgp_community_name
optional
BGP community profile name. string
blackhole_community
optional
Blackhole BGP community values. < string > array
mitigation_community
optional
Mitigation BGP community values. < string > array

flowspec

Name Description Schema
diversion_mode
optional
Diversion mode (0=Route, 1=FlowSpec, 2=Route and FlowSpec). < diversion_mode > array
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Values are traffic collector peer groups. Available peer options for FlowSpec when diversion_mode=1 (FlowSpec) or diversion_mode=2 (Route and FlowSpec). Includes only bgp_traffic_collector peers with flowspec_enabled=1, set via POST /spe/bastions/resource/idc/{pop_id}/peers/{peer_id}/flowspec. < string, traffic_collector_peer > map

diversion_mode

Name Description Schema
name
optional
Display diversion mode name. string
value
optional
Filter value. integer

traffic_collector_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

netshield_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

pops

Name Description Schema
has_flow_peer
optional
0=no flow peer, 1=have flow peer. integer
idc
optional
PoP name. string
name
optional
PoP display name. string

traffic_collector_peer

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets slot0 mitigation group.

GET /spe/bastions/mitigation_profile/mitigation_groups/slot0

Description

Returns or initializes default slot0 mitigation group with BGP community and NetShield peers.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query slot_key
optional
Slot Key. Default slot0. enum (slot0)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Response payload. result

result

Name Description Schema
mitigation_group
optional
Slot0 mitigation group configuration. mitigation_group

mitigation_group

Name Description Schema
bgp_community_id
optional
BGP community profile ID. string
netshield_peer_ipv4
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes bgp_netshield IPv4 peers added under all pops. < string, netshield_peer_ipv4 > map
netshield_peer_ipv6
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Values are NetShield peer groups. Includes bgp_netshield IPv6 peers added under all pops. < string, netshield_peer_ipv6 > map
slot
optional
Slot key, only slot0. enum (slot0)

netshield_peer_ipv4

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

netshield_peer_ipv6

Name Description Schema
name
optional
PoP display name. string
peers
optional
Peers available under this PoP. < peers > array

peers

Name Description Schema
peer_id
optional
Peer ID. string
peer_name
optional
Peer name. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Updates a mitigation group.

PUT /spe/bastions/mitigation_profile/mitigation_groups/{mitigation_group_id}

Description

Updates peers, BGP community, description, and FlowSpec settings.

Parameters

Type Name Description Schema
Path mitigation_group_id
required
Mitigation group ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body mitigation_group
required
Mitigation group configuration. Values for netshield_peer, traffic_collector_peer, bgp_community_id, and flowspec fields must be taken from the corresponding fields in GET /spe/bastions/mitigation_profile/mitigation_groups/options (use the same ip_type as the mitigation group being updated). At least one of netshield_peer or traffic_collector_peer must contain peer selections; both empty is rejected by the backend. mitigation_group

mitigation_group

Name Description Schema
bgp_community_id
required
BGP community profile ID. Use bgp_community_id from an item in result.bgp_community in GET /spe/bastions/mitigation_profile/mitigation_groups/options. string
flowspec
optional
FlowSpec diversion configuration. traffic_collector_peer values must come from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. flowspec
mitigation_group_desc
optional
Mitigation group description. string
mitigation_group_name
required
Mitigation group name. string
netshield_peer
optional
Map keyed by IDC/PoP id (dynamic, e.g. nxg_hk_g2, nxg_hk_r650). Keys and peer_id values must come from result.netshield_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. < string, < string > array > map
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Keys and peer_id values must come from result.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. < string, < string > array > map

flowspec

Name Description Schema
diversion_target
optional
Diversion target. diversion_target
traffic_collector_peer
optional
Map keyed by IDC/PoP id (dynamic). Select peer_id values from result.flowspec.traffic_collector_peer in GET /spe/bastions/mitigation_profile/mitigation_groups/options. Required when the mitigation group’s diversion_mode is 1 (FlowSpec) or 2 (Route and FlowSpec). [Conditionally required] < string, < string > array > map

diversion_target

Name Description Schema
redirect_target
optional
FlowSpec redirect target. string
route_distinguisher
optional
Route distinguisher value. string
route_distinguisher_enabled
optional
0=route distinguisher disabled, 1=enabled. integer

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Deletes a mitigation group.

DELETE /spe/bastions/mitigation_profile/mitigation_groups/{mitigation_group_id}

Description

Deletes mitigation group by ID.

Parameters

Type Name Description Schema
Path mitigation_group_id
required
string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. SuccessResponse

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

SuccessResponse

Success response without business payload.

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY