☰

Auto Mitigation

Auto Mitigation

Overview

Auto Mitigation APIs for Network Protection under /spe/np.

Policy modules use a dual-path model: GET returns the full policy (including nested lists for display); POST applies incremental updates via *PolicyInput schemas (only include fields to change). List-style sub-items (filters, flex-zombie rules, ACL custom rules, payload filters, L7 filters) are managed via dedicated CRUD APIs, not policy POST.

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS

Paths

Create an IP set template.

POST /spe/np/auto-mitigation/template/ip-set

Description

Creates an SPE-level IP set template shared across auto-mitigation profiles for the allow/block list policy.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body ip_set
required
IP set template payload. IpSetInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
result

result

Name Description Schema
ip_set_id
optional
Created IP set ID. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get an IP set template.

GET /spe/np/auto-mitigation/template/ip-set/{ip_set_id}

Description

Returns a single IP set template by ID.

Parameters

Type Name Description Schema
Path ip_set_id
required
IP set ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
optional
IP address family: ipv4 or ipv6. enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
IpSetSummary

Produces

Security

Type Name
apiKey ApiKeyAuth

Update an IP set template.

PUT /spe/np/auto-mitigation/template/ip-set/{ip_set_id}

Description

Updates an IP set template for allow/block list policy.

Parameters

Type Name Description Schema
Path ip_set_id
required
IP set ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body ip_set
required
IP set template payload. IpSetInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete an IP set template.

DELETE /spe/np/auto-mitigation/template/ip-set/{ip_set_id}

Description

Deletes an IP set template.

Parameters

Type Name Description Schema
Path ip_set_id
required
IP set ID. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get IP set templates for allow/block list policy.

GET /spe/np/auto-mitigation/template/ip-sets

Description

Returns SPE-level IP set templates shared across auto-mitigation profiles for building allow/block list policies. No profile_id is required.

Parameters

Type Name Description Schema
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query ip_type
optional
IP address family, ipv4 or ipv6. Default is ipv4. enum (ipv4, ipv6)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
< IpSetSummary > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Allow/block list policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/allow-block-list

Description

Incrementally updates the allow/block list policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
Allow/block list policy. AllowBlockListPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Allow/block list policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/allow-block-list

Description

Returns the allow/block list policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AllowBlockListPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update ICMP anti-flood policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp

Description

Incrementally updates ICMP anti-flood policy settings. Include only fields or sub-objects to change; omitted fields are preserved. Custom ICMP filters are managed via ICMP filter CRUD APIs.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
ICMP anti-flood policy. AntiFloodL3L4IcmpPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get ICMP anti-flood policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp

Description

Returns the ICMP anti-flood policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AntiFloodL3L4IcmpPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Create ICMP custom anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter

Description

Creates a custom ICMP anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
ICMP filter configuration. IcmpFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID, a unique identifier assigned to each custom ICMP filter. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get ICMP custom anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}

Description

Returns a custom ICMP anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Custom ICMP filter ID. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
IcmpFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update ICMP custom anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}

Description

Updates a custom ICMP anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Custom ICMP filter ID. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
ICMP filter configuration. IcmpFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete ICMP custom anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filter/{filter_id}

Description

Deletes a custom ICMP anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Custom ICMP filter ID. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get ICMP custom anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/icmp/filters

Description

Returns the custom ICMP anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
ICMP custom filters < IcmpFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Update IP-layer anti-flood policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/ip

Description

Incrementally updates the IP-layer anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
IP-layer anti-flood policy. AntiFloodL3L4IpPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get IP-layer anti-flood policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/ip

Description

Returns the IP-layer anti-flood policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AntiFloodL3L4IpPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update TCP anti-flood policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/tcp

Description

Incrementally updates the TCP anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
TCP anti-flood policy. AntiFloodL3L4TcpPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get TCP anti-flood policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/tcp

Description

Returns the TCP anti-flood policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AntiFloodL3L4TcpPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update UDP anti-flood policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/udp

Description

Incrementally updates the UDP anti-flood policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
UDP anti-flood policy. AntiFloodL3L4UdpPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get UDP anti-flood policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l3l4/udp

Description

Returns the UDP anti-flood policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AntiFloodL3L4UdpPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Create Custom L7 anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter

Description

Creates a Custom L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
L7 filter create payload. CustomFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Custom L7 anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}

Description

Returns a Custom L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the Custom L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
CustomFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Custom L7 anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}

Description

Updates a Custom L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the Custom L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
Custom L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. CustomFilter

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete Custom L7 anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filter/{filter_id}

Description

Deletes a Custom L7 anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the Custom L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Custom L7 anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/custom/filters

Description

Returns the Custom L7 anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Custom filters < CustomFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Create HTTP L7 anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter

Description

Creates a HTTP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
L7 filter create payload. HttpFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get HTTP L7 anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}

Description

Returns a HTTP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the HTTP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
HttpFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update HTTP L7 anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}

Description

Updates a HTTP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the HTTP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
HTTP L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. HttpFilter

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete HTTP L7 anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filter/{filter_id}

Description

Deletes a HTTP L7 anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the HTTP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get HTTP L7 anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/http/filters

Description

Returns the HTTP L7 anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
HTTP filters < HttpFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Create QUIC L7 anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter

Description

Creates a QUIC L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
L7 filter create payload. QuicFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get QUIC L7 anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}

Description

Returns a QUIC L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the QUIC L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
QuicFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update QUIC L7 anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}

Description

Updates a QUIC L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the QUIC L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
QUIC L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. QuicFilter

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete QUIC L7 anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filter/{filter_id}

Description

Deletes a QUIC L7 anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the QUIC L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get QUIC L7 anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/quic/filters

Description

Returns the QUIC L7 anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
QUIC filters < QuicFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Create SIP L7 anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter

Description

Creates a SIP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
L7 filter create payload. SipFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get SIP L7 anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}

Description

Returns a SIP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the SIP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
SipFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update SIP L7 anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}

Description

Updates a SIP L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the SIP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
SIP L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. SipFilter

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete SIP L7 anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filter/{filter_id}

Description

Deletes a SIP L7 anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the SIP L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get SIP L7 anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/sip/filters

Description

Returns the SIP L7 anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
SIP filters < SipFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Create TLS L7 anti-flood filter.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter

Description

Creates a TLS L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
L7 filter create payload. TlsFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get TLS L7 anti-flood filter.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}

Description

Returns a TLS L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the TLS L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
TlsFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update TLS L7 anti-flood filter.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}

Description

Updates a TLS L7 anti-flood filter for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the TLS L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
TLS L7 anti-flood filter configuration. filter_id is provided in the path and is optional in the request body. TlsFilter

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete TLS L7 anti-flood filter.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filter/{filter_id}

Description

Deletes a TLS L7 anti-flood filter from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the TLS L7 anti-flood filter. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get TLS L7 anti-flood filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/anti-flood/l7/tls/filters

Description

Returns the TLS L7 anti-flood filters for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
TLS filters < TlsFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Bogon and invalid address protections.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/bogons

Description

Incrementally updates the bogon and invalid address protection policy. Include only fields or sub-objects to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
Bogon and invalid address protections. BogonsPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Bogon and invalid address protections.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/bogons

Description

Returns the bogon and invalid address protection policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
BogonsPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update FlexFilter ACL filter policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter

Description

Incrementally updates FlexFilter ACL filter policy (enable flag and attached ACL filter sets). Include only fields to change; omitted fields are preserved. The acl_filter_sets array supports incremental attach/detach of site-level ACL template sets. Custom ACL rules are managed via custom-filter CRUD APIs.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
FlexFilter ACL filter policy. FlexFilterAclFilterPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter ACL filter policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter

Description

Returns the FlexFilter ACL filter policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
FlexFilterAclFilterPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Create FlexFilter ACL custom filter rule.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter

Description

Creates a custom ACL filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
Custom ACL filter rule create payload. FlexFilterAclCustomRuleInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
rule_id
optional
Rule ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter ACL custom filter rule.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}

Description

Returns a custom ACL filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the custom ACL rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
FlexFilterAclCustomRule

Produces

Security

Type Name
apiKey ApiKeyAuth

Update FlexFilter ACL custom filter rule.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}

Description

Updates a custom ACL filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the custom ACL rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
Custom ACL filter rule update payload. rule_id is provided in the path. FlexFilterAclCustomRuleUpdateInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete FlexFilter ACL custom filter rule.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filter/{rule_id}

Description

Deletes a custom ACL filter rule from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the custom ACL rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter ACL custom filter rules.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/acl-filter/custom-filters

Description

Returns the custom ACL filter rules for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
< FlexFilterAclCustomRule > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter payload filter policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter

Description

Returns the FlexFilter payload filter policy for the auto-mitigation profile. Individual rules are managed via payload-filter CRUD APIs.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
FlexFilterPayloadFilterPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Create FlexFilter payload filter rule.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter

Description

Creates a payload filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
Payload filter rule configuration. PayloadFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
filter_id
optional
Filter ID, a unique identifier assigned to each payload filter rule. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter payload filter rule.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}

Description

Returns a payload filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the payload filter rule. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
PayloadFilter

Produces

Security

Type Name
apiKey ApiKeyAuth

Update FlexFilter payload filter rule.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}

Description

Updates a payload filter rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the payload filter rule. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body filter
required
Payload filter rule configuration. PayloadFilterInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete FlexFilter payload filter rule.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filter/{filter_id}

Description

Deletes a payload filter rule from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path filter_id
required
Unique identifier of the payload filter rule. string
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get FlexFilter payload filters.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/flex-filter/payload-filter/filters

Description

Returns the payload filter rules for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
Payload filter rules < PayloadFilter > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Network Threat Intelligence Feed policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/ntif

Description

Incrementally updates the NTIF policy for the auto-mitigation profile. Include only fields or sub-objects to change; omitted fields are preserved. Not supported for IPv6.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
Network Threat Intelligence Feed policy. NtifPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Network Threat Intelligence Feed policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/ntif

Description

Returns the Network Threat Intelligence Feed policy for the auto-mitigation profile. Not supported for IPv6.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
NtifPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Traffic policing cap policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/traffic-policing

Description

Incrementally updates the traffic policing cap policy for the auto-mitigation profile. Include only fields to change; omitted fields are preserved.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
Traffic policing cap policy. TrafficPolicingPolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Traffic policing cap policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/traffic-policing

Description

Returns the traffic policing cap policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
TrafficPolicingPolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Update Zombie host detection policy.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie

Description

Incrementally updates zombie host/network detection settings. Include only fields or sub-objects to change; omitted fields are preserved. Flex zombie rules are managed via flex-zombie CRUD APIs.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body policy
required
Zombie host detection policy. ZombiePolicyInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get Zombie host detection policy.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie

Description

Returns the zombie host detection policy for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
ZombiePolicy

Produces

Security

Type Name
apiKey ApiKeyAuth

Create flex zombie rule.

POST /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie

Description

Creates a flex zombie rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
Flex zombie rule configuration. FlexZombieRuleInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
rule_id
optional
Rule ID string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get flex zombie rule.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}

Description

Returns a flex zombie rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the flex zombie rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
FlexZombieRule

Produces

Security

Type Name
apiKey ApiKeyAuth

Update flex zombie rule.

PUT /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}

Description

Updates a flex zombie rule for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the flex zombie rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
Flex zombie rule configuration. FlexZombieRuleInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete flex zombie rule.

DELETE /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombie/{rule_id}

Description

Deletes a flex zombie rule from the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path rule_id
required
Unique identifier of the flex zombie rule. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get flex zombie rules.

GET /spe/np/site/{site_id}/auto-mitigation/profile/{profile_id}/zombie/flex-zombies

Description

Returns the flex zombie rules for the auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto mitigation profile identifier. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
< FlexZombieRule > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Get an ACL filter set with rules.

GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}

Description

Returns one site-level ACL rule set for the site, including its rules.

Parameters

Type Name Description Schema
Path rule_set_id
required
ACL rule set ID. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
AclSetSummary

Produces

Security

Type Name
apiKey ApiKeyAuth

Update an ACL filter set.

PUT /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}

Description

Updates a site-level ACL rule set name and description.

Parameters

Type Name Description Schema
Path rule_set_id
required
string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body acl_set
required
AclSetInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete an ACL filter set.

DELETE /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}

Description

Deletes a site-level ACL rule set.

Parameters

Type Name Description Schema
Path rule_set_id
required
string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get an ACL rule.

GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}

Description

Returns one ACL rule from the specified site-level ACL rule set.

Parameters

Type Name Description Schema
Path rule_id
required
ACL rule ID. string
Path rule_set_id
required
ACL rule set ID. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
AclRule

Produces

Security

Type Name
apiKey ApiKeyAuth

Update an ACL rule.

PUT /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}

Description

Updates an ACL rule in the specified site-level rule set.

Parameters

Type Name Description Schema
Path rule_id
required
string
Path rule_set_id
required
string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
AclRuleInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete an ACL rule.

DELETE /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rule/{rule_id}

Description

Deletes an ACL rule from the specified site-level rule set.

Parameters

Type Name Description Schema
Path rule_id
required
string
Path rule_set_id
required
string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Add an ACL rule to a rule set.

POST /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rules

Description

Adds a rule to the specified site-level ACL rule set.

Parameters

Type Name Description Schema
Path rule_set_id
required
string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body rule
required
AclRuleInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
result

result

Name Schema
rule_id
optional
string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

List ACL rules in a rule set.

GET /spe/np/site/{site_id}/auto-mitigation/template/acl-set/{rule_set_id}/rules

Description

Returns all ACL rules in the specified site-level ACL rule set.

Parameters

Type Name Description Schema
Path rule_set_id
required
ACL rule set ID. string
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
< AclRule > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Create an ACL filter set.

POST /spe/np/site/{site_id}/auto-mitigation/template/acl-sets

Description

Creates a site-level ACL rule set for the Network Protection site, shared across auto-mitigation profiles for the FlexFilter policy.

Parameters

Type Name Description Schema
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Body acl_set
required
AclSetInput

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
result

result

Name Schema
rule_set_id
optional
string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get ACL filter set list.

GET /spe/np/site/{site_id}/auto-mitigation/template/acl-sets

Description

Returns site-level ACL rule sets for the Network Protection site, shared across auto-mitigation profiles, including embedded rules for the FlexFilter policy.

Parameters

Type Name Description Schema
Path site_id
required
Network Protection site identifier. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Schema
code
optional
integer
msg
optional
string
result
optional
< AclSetSummary > array

Produces

Security

Type Name
apiKey ApiKeyAuth

Update a Network Protection auto-mitigation profile name.

POST /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}

Description

Updates the profile name for an auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site ID. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
FormData description
optional
Description. string
FormData profile_name
required
Profile name. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get a Network Protection auto-mitigation profile.

GET /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}

Description

Returns detailed information for an auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site ID. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
result

result

Name Description Schema
description
optional
Description of an auto-mitigation profile. string
profile_id
optional
Unique identifier of an auto-mitigation profile. string
profile_name
optional
Name of an auto-mitigation profile. string

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete a Network Protection auto-mitigation profile.

DELETE /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}

Description

Deletes an auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site ID. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Clone a Network Protection auto-mitigation profile.

POST /spe/np/site/{site_id}/policy/mitigation/auto-profile/{profile_id}/clone

Description

Clones an auto-mitigation profile.

Parameters

Type Name Description Schema
Path profile_id
required
Auto-mitigation profile ID. Obtain from GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles. string
Path site_id
required
Network Protection site ID. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Get the Network Protection auto-mitigation profile list.

GET /spe/np/site/{site_id}/policy/mitigation/auto-profiles

Description

Returns auto-mitigation profiles for selecting network-level or host-level templates in the NetShield Overview.

Parameters

Type Name Description Schema
Path site_id
required
Network Protection site ID. Obtain from GET /spe/np/sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string
result
optional
< result > array

result

Name Description Schema
description
optional
Description of an auto-mitigation profile.
Length : 0 - 100
string
profile_id
optional
Unique identifier of an auto-mitigation profile. string
profile_name
optional
Name of an auto-mitigation profile.
Length : 2 - 40
string

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

AclRule

ACL rule in a site-level ACL rule set.

Name Description Schema
action
optional
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
optional
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
src_ip
optional
< string > array
src_port
optional
< integer > array
tcp_flags
optional
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

AclRuleInput

Name Description Schema
action
required
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
required
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_name
required
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
src_ip
optional
< string > array
src_port
optional
< integer > array
tcp_flags
optional
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

AclSetInput

Name Description Schema
rule_set_desc
optional
The description of the rule set.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_set_name
required
The name of the rule set.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string

AclSetSummary

Name Description Schema
ip_type
optional
IP address family, ipv4 or ipv6. enum (ipv4, ipv6)
rule_set_desc
optional
string
rule_set_id
optional
string
rule_set_name
optional
string
rules
optional
< AclRule > array

AllowBlockListIpSet

Referenced IP set template details. Present when allow/block list mode is 2.

Name Description Schema
ip_set_desc
optional
More details about the purpose of the policy. string
ip_set_id
optional
Unique identifier of ip set. string
ip_set_name
optional
The name of the policy. string
source_countries
optional
< string > array
source_ips
optional
< string > array

AllowBlockListPolicy

Allow list and block list configuration for source traffic.

Name Description Schema
allow_list
optional
Trusted sources permitted when allow-list policy is enabled. allow_list
block_list
optional
Sources to block or rate-limit when block-list policy is enabled. block_list

allow_list

Name Description Schema
ip_set
optional
AllowBlockListIpSet
mode
optional
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

block_list

Name Description Schema
ip_set
optional
AllowBlockListIpSet
mode
optional
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

AllowBlockListPolicyInput

Allow/block list policy incremental update payload. Include only top-level fields or sub-objects to change; omitted fields are preserved.

Name Description Schema
allow_list
optional
Trusted sources permitted when allow-list policy is enabled. allow_list
block_list
optional
Sources to block or rate-limit when block-list policy is enabled. block_list

allow_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. string
mode
optional
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

block_list

Name Description Schema
ip_set_id
optional
Referenced IP set ID. string
mode
optional
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. integer
source_countries
optional
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

AntiFloodL3L4IcmpPolicy

ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported.

Name Description Schema
all_icmp_packet
optional
Drop all ICMP traffic when enabled. all_icmp_packet
icmp_custom_filter
optional
Custom ICMP type/code rules with a default profile. icmp_custom_filter
icmp_fragmentation
optional
ICMP fragmentation handling. icmp_fragmentation
large_ping
optional
Drop oversized ICMP echo requests. large_ping

all_icmp_packet

Name Description Schema
is_enabled
optional
0 = disabled, 1 = drop all ICMP traffic . integer

icmp_custom_filter

Name Description Schema
default
optional
Default ICMP filter applied when no custom rule matches. default
filters
optional
Custom ICMP filters. Managed via ICMP filter CRUD APIs. < filters > array
is_enabled
optional
0 = disabled, 1 = enabled. integer

default

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit, pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name. Can not be edited.
Length : 1 - 40
Pattern : "^[A-Za-z0-9_.-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

filters

Name Description Schema
action
optional
pass or ratelimit. enum (pass, ratelimit)
bps_limit
optional
Rate limit in bits per second (bps).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_description
optional
Filter description.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
icmp_length
optional
ICMP payload length to drop (bytes).
Minimum value : 1
Maximum value : 1500
integer
icmp_type
optional
ICMP type number.
Minimum value : 0
Maximum value : 31
integer
pps_limit
optional
Rate limit in packets per second (pps).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

icmp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

large_ping

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4IcmpPolicyInput

ICMP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Custom filters are managed via ICMP filter CRUD APIs; do not include icmp_custom_filter.filters in this request.

Name Description Schema
all_icmp_packet
optional
Drop all ICMP traffic when enabled. all_icmp_packet
icmp_custom_filter
optional
Custom ICMP type/code rules with a default profile. icmp_custom_filter
icmp_fragmentation
optional
ICMP fragmentation handling. icmp_fragmentation
large_ping
optional
Drop oversized ICMP echo requests. large_ping

all_icmp_packet

Name Description Schema
is_enabled
optional
0 = disabled, 1 = drop all ICMP traffic . integer

icmp_custom_filter

Name Description Schema
default
optional
Default ICMP filter applied when no custom rule matches. default
is_enabled
optional
0 = disabled, 1 = enabled. integer

default

Name Description Schema
action
optional
Mitigation action (e.g. ratelimit, pass). enum (ratelimit, pass)
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name. Can not be edited.
Length : 1 - 40
Pattern : "^[A-Za-z0-9_.-]+$"
string
icmp_length
optional
ICMP payload length threshold (bytes).
Minimum value : 1
Maximum value : 1500
integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

icmp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

large_ping

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4IpPolicy

IP-layer sanity and flood mitigation.

Name Description Schema
custom_protocol_filter
optional
Filter on specific IP protocol numbers. custom_protocol_filter
ip_fragmentation
optional
IP fragmentation handling. ip_fragmentation
ip_invalid
optional
Drop packets failing basic IP validity checks. ip_invalid

custom_protocol_filter

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
protocol_numbers
optional
Per-protocol aggregate rate limits at host scope. < integer > array

ip_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ip_invalid

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4IpPolicyInput

IP-layer anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.

Name Description Schema
custom_protocol_filter
optional
Filter on specific IP protocol numbers. custom_protocol_filter
ip_fragmentation
optional
IP fragmentation handling. ip_fragmentation
ip_invalid
optional
Drop packets failing basic IP validity checks. ip_invalid

custom_protocol_filter

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
protocol_numbers
optional
Per-protocol aggregate rate limits at host scope. < integer > array

ip_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ip_invalid

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4TcpPolicy

TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters.

Name Description Schema
tcp_fragmentation
optional
TCP fragmentation mitigation. tcp_fragmentation
tcp_malformed
optional
Invalid TCP flags, SYN, and option handling. tcp_malformed
tcp_rewrite_mss_size
optional
SYN MSS validation. tcp_rewrite_mss_size
tcp_syn_anti_spoofing
optional
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. tcp_syn_anti_spoofing
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
optional
Drop SYN-ACK and SYN-ACK-ECN packets. tcp_syn_exclude_syn_ack_and_syn_ack_ecn
tcp_with_well_known_ports
optional
Drop invalid or sensitive destination-port packets. tcp_with_well_known_ports

tcp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_malformed

Name Description Schema
tcp_invalid_flags
optional
Illegal or suspicious TCP flag combinations. tcp_invalid_flags
tcp_long_header
optional
Malformed or oversized SYN options. tcp_long_header
tcp_syn_with_data
optional
SYN segments with non-zero payload. tcp_syn_with_data
tcp_syn_with_reserved_flags
optional
Reserved TCP flag bits. tcp_syn_with_reserved_flags

tcp_invalid_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_long_header

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_syn_with_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_syn_with_reserved_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_rewrite_mss_size

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
Size threshold in bytes (meaning depends on parent module).
Minimum value : 34
Maximum value : 1500
integer

tcp_syn_anti_spoofing

Name Description Schema
graceful_challenges
optional
Graceful challenges. graceful_challenges
is_enabled
optional
0 = disabled, 1 = enabled. integer
rate_limit_per_connection
optional
Rate limit per connection. rate_limit_per_connection
tcp_3_way_handshake_challenges
optional
TCP 3-way handshake challenges. tcp_3_way_handshake_challenges
tcp_data
optional
TCP data validation. tcp_data
tcp_retransmission
optional
TCP retransmission validation. tcp_retransmission

graceful_challenges

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

rate_limit_per_connection

Name Description Schema
duration
optional
Duration in seconds. Range: 10-150.
Minimum value : 10
Maximum value : 150
integer
is_enabled
optional
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. integer
timeout
optional
Timeout duration in seconds. Range: 10-3600.
Minimum value : 60
Maximum value : 600
integer

tcp_3_way_handshake_challenges

Name Description Schema
mode
optional
0 = tcp retransmission, 1 = tcp data, 2 = auto. integer

tcp_data

Name Description Schema
server_ip_validation
optional
Server IP validation. server_ip_validation
traffic_policing
optional
Traffic policing. traffic_policing

server_ip_validation

Name Description Schema
bot_mitigation
optional
Bot mitigation validation. bot_mitigation
spoofed_carpet_bombing_mitigation
optional
Spoofed carpet bombing mitigation validation. spoofed_carpet_bombing_mitigation
tcp_fast_open
optional
TCP fast open validation. tcp_fast_open

bot_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

spoofed_carpet_bombing_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_fast_open

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

traffic_policing

Name Description Schema
suspicious_receiver_ip_rate_limit
optional
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer
total_rate_limit
optional
Total rate limit in packets per second. Range: 100-4000000000.
Minimum value : 100
Maximum value : 4000000000
integer
validated_server_ip_rate_limit
optional
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer

tcp_retransmission

Name Description Schema
validation_mode
optional
0 = half open, 1 = full open. integer
validation_trust_mode
optional
0 = host, 1 = network. integer

tcp_syn_exclude_syn_ack_and_syn_ack_ecn

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_with_well_known_ports

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4TcpPolicyInput

TCP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.

Name Description Schema
tcp_fragmentation
optional
TCP fragmentation mitigation. tcp_fragmentation
tcp_malformed
optional
Invalid TCP flags, SYN, and option handling. tcp_malformed
tcp_rewrite_mss_size
optional
SYN MSS validation. tcp_rewrite_mss_size
tcp_syn_anti_spoofing
optional
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. tcp_syn_anti_spoofing
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
optional
Drop SYN-ACK and SYN-ACK-ECN packets. tcp_syn_exclude_syn_ack_and_syn_ack_ecn
tcp_with_well_known_ports
optional
Drop invalid or sensitive destination-port packets. tcp_with_well_known_ports

tcp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_malformed

Name Description Schema
tcp_invalid_flags
optional
Illegal or suspicious TCP flag combinations. tcp_invalid_flags
tcp_long_header
optional
Malformed or oversized SYN options. tcp_long_header
tcp_syn_with_data
optional
SYN segments with non-zero payload. tcp_syn_with_data
tcp_syn_with_reserved_flags
optional
Reserved TCP flag bits. tcp_syn_with_reserved_flags

tcp_invalid_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_long_header

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_syn_with_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_syn_with_reserved_flags

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_rewrite_mss_size

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
Size threshold in bytes (meaning depends on parent module).
Minimum value : 34
Maximum value : 1500
integer

tcp_syn_anti_spoofing

Name Description Schema
graceful_challenges
optional
Graceful challenges. graceful_challenges
is_enabled
optional
0 = disabled, 1 = enabled. integer
rate_limit_per_connection
optional
Rate limit per connection. rate_limit_per_connection
tcp_3_way_handshake_challenges
optional
TCP 3-way handshake challenges. tcp_3_way_handshake_challenges
tcp_data
optional
TCP data validation. tcp_data
tcp_retransmission
optional
TCP retransmission validation. tcp_retransmission

graceful_challenges

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

rate_limit_per_connection

Name Description Schema
duration
optional
Duration in seconds. Range: 10-150.
Minimum value : 10
Maximum value : 150
integer
is_enabled
optional
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. integer
timeout
optional
Timeout duration in seconds. Range: 10-3600.
Minimum value : 60
Maximum value : 600
integer

tcp_3_way_handshake_challenges

Name Description Schema
mode
optional
0 = tcp retransmission, 1 = tcp data, 2 = auto. integer

tcp_data

Name Description Schema
server_ip_validation
optional
Server IP validation. server_ip_validation
traffic_policing
optional
Traffic policing. traffic_policing

server_ip_validation

Name Description Schema
bot_mitigation
optional
Bot mitigation validation. bot_mitigation
spoofed_carpet_bombing_mitigation
optional
Spoofed carpet bombing mitigation validation. spoofed_carpet_bombing_mitigation
tcp_fast_open
optional
TCP fast open validation. tcp_fast_open

bot_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

spoofed_carpet_bombing_mitigation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_fast_open

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

traffic_policing

Name Description Schema
suspicious_receiver_ip_rate_limit
optional
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer
total_rate_limit
optional
Total rate limit in packets per second. Range: 100-4000000000.
Minimum value : 100
Maximum value : 4000000000
integer
validated_server_ip_rate_limit
optional
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit.
Minimum value : 100
Maximum value : 4000000000
integer

tcp_retransmission

Name Description Schema
validation_mode
optional
0 = half open, 1 = full open. integer
validation_trust_mode
optional
0 = host, 1 = network. integer

tcp_syn_exclude_syn_ack_and_syn_ack_ecn

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

tcp_with_well_known_ports

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4UdpPolicy

UDP flood amplification handling.

Name Description Schema
ntp_amplification
optional
ntp_amplification
snmp_amplification
optional
snmp_amplification
ssdp_flood
optional
SSDP flood handling. ssdp_flood
udp_contain_all_zero_data
optional
UDP contain all zero data handling. udp_contain_all_zero_data
udp_flood_amplification
optional
udp_flood_amplification
udp_fragmentation
optional
UDP fragmentation handling. udp_fragmentation
udp_malformed
optional
UDP malformed handling. udp_malformed
udp_with_port_number_lt_1024
optional
UDP with port number less than 1024 handling. udp_with_port_number_lt_1024

ntp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
ntp_response_length
optional
NTP response length handling. ntp_response_length
ntp_response_monlist_drop
optional
NTP response MONLIST drop handling. ntp_response_monlist_drop
ntp_response_rate_limit
optional
NTP response rate limit handling. ntp_response_rate_limit

ntp_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the NTP response.
Minimum value : 42
Maximum value : 1500
integer

ntp_response_monlist_drop

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ntp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

snmp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
snmp_response_rate_limit
optional
SNMP response rate limit handling. snmp_response_rate_limit

snmp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ssdp_flood

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

udp_contain_all_zero_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
zero_data_min_length
optional
The minimum length of the zero data payload.
Minimum value : 42
Maximum value : 128
integer

udp_flood_amplification

Name Description Schema
dns_query_length
optional
DNS query length handling. dns_query_length
dns_query_rate_limit
optional
DNS query rate limit handling. dns_query_rate_limit
dns_response_length
optional
DNS response length handling. dns_response_length
dns_response_rate_limit
optional
DNS response rate limit handling. dns_response_rate_limit
is_enabled
optional
0 = disabled, 1 = enabled. integer

dns_query_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the DNS query.
Minimum value : 42
Maximum value : 1500
integer

dns_query_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

dns_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the DNS response.
Minimum value : 42
Maximum value : 1500
integer

dns_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

udp_malformed

Name Description Schema
udp_packet_contain_no_data
optional
0 = disabled, 1 = enabled. integer

udp_with_port_number_lt_1024

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL3L4UdpPolicyInput

UDP anti-flood policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.

Name Description Schema
ntp_amplification
optional
ntp_amplification
snmp_amplification
optional
snmp_amplification
ssdp_flood
optional
SSDP flood handling. ssdp_flood
udp_contain_all_zero_data
optional
UDP contain all zero data handling. udp_contain_all_zero_data
udp_flood_amplification
optional
udp_flood_amplification
udp_fragmentation
optional
UDP fragmentation handling. udp_fragmentation
udp_malformed
optional
UDP malformed handling. udp_malformed
udp_with_port_number_lt_1024
optional
UDP with port number less than 1024 handling. udp_with_port_number_lt_1024

ntp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
ntp_response_length
optional
NTP response length handling. ntp_response_length
ntp_response_monlist_drop
optional
NTP response MONLIST drop handling. ntp_response_monlist_drop
ntp_response_rate_limit
optional
NTP response rate limit handling. ntp_response_rate_limit

ntp_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the NTP response.
Minimum value : 42
Maximum value : 1500
integer

ntp_response_monlist_drop

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

ntp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

snmp_amplification

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
snmp_response_rate_limit
optional
SNMP response rate limit handling. snmp_response_rate_limit

snmp_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ssdp_flood

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

udp_contain_all_zero_data

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
zero_data_min_length
optional
The minimum length of the zero data payload.
Minimum value : 42
Maximum value : 128
integer

udp_flood_amplification

Name Description Schema
dns_query_length
optional
DNS query length handling. dns_query_length
dns_query_rate_limit
optional
DNS query rate limit handling. dns_query_rate_limit
dns_response_length
optional
DNS response length handling. dns_response_length
dns_response_rate_limit
optional
DNS response rate limit handling. dns_response_rate_limit
is_enabled
optional
0 = disabled, 1 = enabled. integer

dns_query_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the DNS query.
Minimum value : 42
Maximum value : 1500
integer

dns_query_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

dns_response_length

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
size
optional
The size of the DNS response.
Minimum value : 42
Maximum value : 1500
integer

dns_response_rate_limit

Name Description Schema
bps_limit
optional
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
pps_limit
optional
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

udp_fragmentation

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

udp_malformed

Name Description Schema
udp_packet_contain_no_data
optional
0 = disabled, 1 = enabled. integer

udp_with_port_number_lt_1024

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

AntiFloodL7CustomPolicy

Custom L7 (TCP) filter profiles for this host.

Name Description Schema
profile
required
List of Custom L7 (TCP) filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration tcp_connection

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration source_ip_new_connection
total_connection
optional
Total Connection Module configuration total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

AntiFloodL7HttpPolicy

HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled.

Name Schema
profile
optional
< profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
http_authentication
optional
HTTP Authentication Module configuration http_authentication
http_slow_rate
optional
HTTP Slow Rate Module configuration http_slow_rate
is_enabled
optional
Filter status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration tcp_connection

http_authentication

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
model
optional
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. integer

http_slow_rate

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-86400)
Minimum value : 1
Maximum value : 86400
integer
body
optional
HTTP Slow Body Module configuration. body
header
optional
HTTP Slow Header Module configuration. header
new_session_per_minute
optional
New sessions per minute, range (1-65535).
Minimum value : 1
Maximum value : 65535
integer

body

Name Description Schema
calc_avg_packet
optional
Number of TCP packets to carry a single HTTP request, range (3-20)
Minimum value : 3
Maximum value : 20
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
min_avg_length
optional
Smallest allowed TCP packet size of a split HTTP request, range (1-1500)
Minimum value : 1
Maximum value : 1500
integer
timeout_interval
optional
Time interval between two packets (milliseconds), range (1000-10000)
Minimum value : 1000
Maximum value : 10000
integer

header

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet_size
optional
Packet length (bytes), range (64-1500)
Minimum value : 64
Maximum value : 1500
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration source_ip_new_connection
total_connection
optional
Total Connection Module configuration total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-60)
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds) range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds) range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Total connections per second, range (100-4294967295).
Minimum value : 100
Maximum value : 4294967295
integer

AntiFloodL7QuicPolicy

QUIC L7 filter profiles for this host.

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
QUIC Malformed Packet Detection configuration. malformed
quic_flood_protection
optional
QUIC Session Protection configuration quic_flood_protection
quic_ratelimit
optional
QUIC Ratelimit Module configuration quic_ratelimit

malformed

Name Description Schema
handshake_min_len
optional
Minimum length (bytes) for handshake packets, range (10-65535).
Minimum value : 10
Maximum value : 65535
integer
initial_min_len
optional
Minimum length (bytes) for initial packets, range (1200-65535).
Minimum value : 1200
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer
support_version
optional
Supported QUIC versions:[‘all’,‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. < enum (all, v1, v2, draft27, draft28, draft29, draft30, draft31, draft32, draft33, draft34) > array
version_negotiation_min_len
optional
Minimum length (bytes) for version negotiation packets, range (12-65535).
Minimum value : 12
Maximum value : 65535
integer
zero_rtt_min_len
optional
Minimum length (bytes) for 0-RTT packets, range (10-65535).
Minimum value : 10
Maximum value : 65535
integer

quic_flood_protection

Name Description Schema
0rtt_replay_attack_protection
optional
0-RTT replay attack protection configuration. 0rtt_replay_attack_protection
authentication
optional
Authentication configuration. authentication
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_source_ip
optional
Session (Per source IP) Module configuration new_session_per_source_ip
ratelimit_per_session
optional
Ratelimit (Per Session) Module configuration. ratelimit_per_session

0rtt_replay_attack_protection

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300).
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. integer
packet_per_second
optional
Packets per second threshold, range (1-65535).
Minimum value : 1
Maximum value : 65535
integer

authentication

Name Description Schema
mode
optional
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. integer
session_scope
optional
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. integer

new_session_per_source_ip

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300)
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_second
optional
New sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer

ratelimit_per_session

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. integer
session_check_duration
optional
Session check duration (seconds), range (20-40)
Minimum value : 20
Maximum value : 40
integer
session_timeout
optional
Idle session timeout (seconds), range (60-600)
Minimum value : 60
Maximum value : 600
integer

quic_ratelimit

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packets
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

AntiFloodL7SipPolicy

SIP L7 filter profiles for this host.

Name Description Schema
profile
required
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_tcp_port
optional
TCP Port list. < integer > array
filter_udp_port
optional
UDP Port list. < integer > array
invite
optional
SIP INVITE message configuration. invite
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed_is_enabled
optional
SIP Malformed enable status. Values: 0 = off, 1 = drop. integer
register
optional
SIP REGISTER Requst message configuration. register
retransmission_is_enabled
optional
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. integer
tcp_connection
optional
TCP Connection protection configuration tcp_connection

invite

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

register

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Source IP average window size threshold slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting source_ip_new_connection
total_connection
optional
Total connection rate limiting total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-60)
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

AntiFloodL7TlsPolicy

TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled.

Name Description Schema
profile
optional
List of L7 filter profile objects returned by policy APIs. < profile > array

profile

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Filter Profile ID.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
SSL/TLS Malformed Packet Detection configuration. malformed
ratelimit
optional
SSL/TLS Ratelimit (Per Profile) configuration ratelimit
renegotiation
optional
SSL/TLS Renegotiation configuration. renegotiation
session
optional
SSL/TLS Session configuration. session
tcp_connection
optional
Connection protection configuration tcp_connection

malformed

Name Description Schema
clienthello_length_limit_non_v_1_3
optional
ClientHello length (bytes) limit for non-TLS 1.3, range (64-1400).
Minimum value : 64
Maximum value : 1400
integer
clienthello_length_limit_v_1_3
optional
ClientHello length (bytes) limit for TLS 1.3, range (64-1400).
Minimum value : 64
Maximum value : 1400
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer

ratelimit

Name Description Schema
non_tls
optional
Ratelimit for non TLS1.2 and TLS1.3 traffic. non_tls
tls
optional
Ratelimit for TLS1.2 and TLS1.3 traffic. tls

non_tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

renegotiation

Name Description Schema
blocklist_duration
optional
Blocklist duration (seconds), range (1-65535).
Minimum value : 1
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer

session

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300)
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = block. integer
new_session_per_second
optional
New session per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer

tcp_connection

Name Description Schema
is_enabled
optional
Connection protection enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
This rule checks for slow rate connections from the same source IP address slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting source_ip_new_connection
total_connection
optional
Total connection rate limiting total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Average window Size (bytes), range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Ban duration (seconds), range (10-60).
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

BogonsPolicy

Bogon and invalid address protections.

Name Description Schema
land_attack
optional
Mitigate LAND-style same src/dst attacks. land_attack
martian_address
optional
Drop martian or reserved addresses. martian_address

land_attack

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

martian_address

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

BogonsPolicyInput

Bogon and invalid address protection incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved.

Name Description Schema
land_attack
optional
Mitigate LAND-style same src/dst attacks. land_attack
martian_address
optional
Drop martian or reserved addresses. martian_address

land_attack

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

martian_address

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer

CustomFilter

Custom Filter configuration.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
optional
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration tcp_connection

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration source_ip_new_connection
total_connection
optional
Total Connection Module configuration total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

CustomFilterInput

CustomFilter create payload.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_name
required
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
required
TCP Port list. < integer > array

FlexFilterAclCustomRule

Custom ACL filter rule attached to the profile.

Name Description Schema
action
optional
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

FlexFilterAclCustomRuleInput

FlexFilter ACL custom rule create payload.

Name Description Schema
action
required
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
required
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_name
required
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

FlexFilterAclCustomRuleUpdateInput

FlexFilter ACL custom rule update payload.

Name Description Schema
action
required
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
required
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_name
required
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

FlexFilterAclFilterPolicy

Site-level ACL common and custom rule sets.

Name Description Schema
acl_filter_rules
optional
Site-specific custom ACL rules. < acl_filter_rules > array
acl_filter_sets
optional
Site-level ACL filter sets attached to the profile. < acl_filter_sets > array
is_enabled
optional
0 = disabled, 1 = enabled. integer

acl_filter_rules

Name Description Schema
action
optional
The action of the rule. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dst_ip
optional
< string > array
dst_port
optional
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. < integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer

acl_filter_sets

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
rule_set_desc
optional
Pattern : "^[A-Za-z0-9_ -]*$" string
rule_set_id
required
string
rule_set_name
optional
Length : 1 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string

FlexFilterAclFilterPolicyInput

FlexFilter ACL filter policy incremental update payload. Include only fields to change; omitted fields are preserved. The acl_filter_sets array supports incremental attach/detach of site-level ACL template sets. Custom ACL rules are managed via custom-filter CRUD APIs; do not include acl_filter_rules in this request.

Name Description Schema
acl_filter_sets
optional
Site-level ACL filter sets attached to the profile. < acl_filter_sets > array
is_enabled
optional
0 = disabled, 1 = enabled. integer

acl_filter_sets

Name Schema
rule_set_id
required
string

FlexFilterPayloadFilterPolicy

Advanced payload filtering rules.

Name Description Schema
filters
optional
List of payload filter rules. Managed via payload-filter CRUD APIs. < filters > array

filters

Name Description Schema
action
optional
An action will be taken when they match. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
ratelimit in bps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique identifier of advanced rule. string
filter_name
optional
The name of the policies.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
payload_string
optional
The string of the payload. < string > array
port
optional
The lists of the port numbers. < integer > array
pps_limit
optional
ratelimit in pps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the data packet. Allowed values: tcp, udp, ip, any. enum (tcp, udp, ip, any)

FlexZombieRule

Flex zombie rule.

Name Description Schema
action
optional
The action of the rule. Allowed values: pass, ratelimit, block. enum (pass, ratelimit, block)
block_duration
optional
The duration of the block in seconds. Required when the action is block.
Minimum value : 10
Maximum value : 120
integer
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit or block.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dip_prefix
optional
Destination IP netmask for the rule. Required when zombie_mode is dip or dip_dport.
Minimum value : 24
Maximum value : 32
integer
dst_ip
optional
< string > array
dst_port
optional
< integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit or block.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_id
required
The unique identifier of the rule. string
rule_name
optional
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sip_prefix
optional
Source IP netmask for the rule. Required when zombie_mode is sip, sip_sport, or sip_dport.
Minimum value : 24
Maximum value : 32
integer
sort_order
optional
The sort order of the rule. integer
src_ip
optional
< string > array
src_port
optional
< integer > array
tcp_flags
optional
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer
zombie_mode
optional
The mode of the rule. Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Required when the action is ratelimit or block. Default is sip.
Default : "sip"
enum (sip, dip, sip_sport, dip_dport, sip_dport)

FlexZombieRuleInput

Flex zombie rule input for create and update.

Name Description Schema
action
required
The action of the rule. Allowed values: pass, ratelimit, block. enum (pass, ratelimit, block)
block_duration
optional
The duration of the block in seconds. Required when the action is block.
Minimum value : 10
Maximum value : 120
integer
bps_limit
optional
The rate limit in bps of the rule. Required when the action is ratelimit or block.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
dip_prefix
optional
Destination IP netmask for the rule. Required when zombie_mode is dip or dip_dport.
Minimum value : 24
Maximum value : 32
integer
dst_ip
optional
< string > array
dst_port
optional
< integer > array
icmp_code
optional
The ICMP code of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 255
integer
icmp_type
optional
The ICMP type of the rule. Valid only when protocol is icmp; ignored/rejected for other protocols.
Minimum value : 0
Maximum value : 31
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
package_length
optional
The package length of the rule. Can be updated regardless of the selected protocol. < string > array
pps_limit
optional
The rate limit in pps of the rule. Required when the action is ratelimit or block.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
required
The protocol of the rule. Allowed values: any, tcp, udp, icmp, or a custom IANA protocol number as a decimal string (0-255). Numeric values 1 (icmp), 6 (tcp), and 17 (udp) must use the named strings instead.
Pattern : "^(any\|tcp\|udp\|icmp\|(0\|[2-5]\|[7-9]\|1[0-6]\|1[89]\|[2-9][0-9]\|1[0-9]{2}\|2[0-4][0-9]\|25[0-5]))$"
string
rule_desc
optional
The description of the rule.
Length : 0 - 128
Pattern : "^[A-Za-z0-9_ -]*$"
string
rule_name
required
The name of the rule.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
sip_prefix
optional
Source IP netmask for the rule. Required when zombie_mode is sip, sip_sport, or sip_dport.
Minimum value : 24
Maximum value : 32
integer
src_ip
optional
< string > array
src_port
optional
< integer > array
tcp_flags
optional
< enum (r1, r2, r3, ns, cwr, ece, urg, ack, psh, rst, syn, fin) > array
ttl
optional
The TTL of the rule.
Minimum value : 0
Maximum value : 255
integer
zombie_mode
optional
The mode of the rule. Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Required when the action is ratelimit or block. Default is sip.
Default : "sip"
enum (sip, dip, sip_sport, dip_dport, sip_dport)

HttpFilter

Http L7 filter profile.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
optional
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
http_authentication
optional
HTTP Authentication Module configuration http_authentication
http_slow_rate
optional
HTTP Slow Rate Module configuration http_slow_rate
is_enabled
optional
Filter status. Values: 0 = off, 1 = on. integer
tcp_connection
optional
TCP Connection Module configuration tcp_connection

http_authentication

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
model
optional
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. integer

http_slow_rate

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-86400)
Minimum value : 1
Maximum value : 86400
integer
body
optional
HTTP Slow Body Module configuration. body
header
optional
HTTP Slow Header Module configuration. header
is_enabled
optional
Enable status mode. Values: 1 = Block, 2 = Block RST. integer
new_session_per_minute
optional
New sessions per minute, range (1-65535).
Minimum value : 1
Maximum value : 65535
integer

body

Name Description Schema
calc_avg_packet
optional
Number of TCP packets to carry a single HTTP request, range (3-20)
Minimum value : 3
Maximum value : 20
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
min_avg_length
optional
Smallest allowed TCP packet size of a split HTTP request, range (1-1500)
Minimum value : 1
Maximum value : 1500
integer
timeout_interval
optional
Time interval between two packets (milliseconds), range (1000-10000)
Minimum value : 1000
Maximum value : 10000
integer

header

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet_size
optional
Packet length (bytes), range (64-1500)
Minimum value : 64
Maximum value : 1500
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Slow Rate Connection Module configuration slow_rate_connection
source_ip_half_open_connection
optional
Source IP Half Open Connection Module configuration source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP Idle Connection Module configuration source_ip_idle_connection
source_ip_new_connection
optional
Source IP New Connection Module configuration source_ip_new_connection
total_connection
optional
Total Connection Module configuration total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-60)
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds) range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds) range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Total connections per second, range (100-4294967295).
Minimum value : 100
Maximum value : 4294967295
integer

HttpFilterInput

HttpFilter create payload.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_name
required
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
required
TCP Port list. < integer > array

IcmpFilter

Name Description Schema
action
optional
pass or ratelimit. enum (pass, ratelimit)
bps_limit
optional
Rate limit in bits per second (bps).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_description
optional
Filter description.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
required
Unique filter profile ID. string
filter_name
optional
Filter display or internal name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
icmp_length
optional
ICMP payload length to drop (bytes).
Minimum value : 1
Maximum value : 1500
integer
icmp_type
optional
ICMP type number.
Minimum value : 0
Maximum value : 31
integer
pps_limit
optional
Rate limit in packets per second (pps).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

IcmpFilterInput

Name Description Schema
action
required
Action when filter matches: pass or ratelimit. enum (pass, ratelimit)
bps_limit
optional
Rate limit in bps must be 1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4G). Required when action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_name
required
Filter name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
icmp_length
required
Packet size in bytes (1–1500).
Minimum value : 1
Maximum value : 1500
integer
icmp_type
required
ICMP type number.
Minimum value : 0
Maximum value : 31
integer
pps_limit
optional
Rate limit in pps must be 1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4G). Required when action is ratelimit.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

IpSetInput

Name Description Schema
enable_country
optional
Source country enabled status. 0 = off, 1 = on. integer
ip_set_desc
optional
Optional policy description.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
ip_set_name
required
Policy name.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ -]+$"
string
ip_type
required
IP address family for the template, ipv4 or ipv6. enum (ipv4, ipv6)
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array

IpSetSummary

Name Description Schema
enable_country
optional
Source country enabled status. 0 = off, 1 = on. integer
ip_set_desc
optional
Optional policy description. string
ip_set_id
optional
IP set ID. string
ip_set_name
optional
Policy name. string
ip_type
optional
IP address family for the template, ipv4 or ipv6. enum (ipv4, ipv6)
source_countries
optional
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array
source_ips
optional
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. < string > array
src_country_count
optional
integer
src_ip_count
optional
integer

NtifPolicy

Network Threat Intelligence Feed categories and actions. Not supported for IPv6.

Name Description Schema
anonymizer
optional
Anonymizer / proxy NTIF subgroups. anonymizer
botnet
optional
Botnet-related NTIF subgroups. botnet
is_enabled
optional
0 = disabled, 1 = enabled. integer

anonymizer

Name Schema
proxy
optional
proxy
tor
optional
tor

proxy

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

tor

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

botnet

Name Schema
dark_spider
optional
dark_spider
ddos
optional
ddos
malware
optional
malware
reputation
optional
reputation
scanner
optional
scanner
spam
optional
spam

dark_spider

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

ddos

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

malware

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

reputation

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

scanner

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

spam

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

NtifPolicyInput

NTIF policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Not supported for IPv6.

Name Description Schema
anonymizer
optional
Anonymizer / proxy NTIF subgroups. anonymizer
botnet
optional
Botnet-related NTIF subgroups. botnet
is_enabled
optional
0 = disabled, 1 = enabled. integer

anonymizer

Name Schema
proxy
optional
proxy
tor
optional
tor

proxy

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

tor

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

botnet

Name Schema
dark_spider
optional
dark_spider
ddos
optional
ddos
malware
optional
malware
reputation
optional
reputation
scanner
optional
scanner
spam
optional
spam

dark_spider

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

ddos

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

malware

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

reputation

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

scanner

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

spam

Name Description Schema
action
optional
Mitigation action (e.g. off, monitor, drop). Allowed values: 0, 1, 2. integer

PayloadFilter

Advanced payload filtering rule.

Name Description Schema
action
optional
An action will be taken when they match. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
ratelimit in bps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_id
required
Unique identifier of advanced rule. string
filter_name
optional
The name of the policies.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
payload_string
optional
The string of the payload. < string > array
port
optional
The lists of the port numbers. < integer > array
pps_limit
optional
ratelimit in pps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the data packet. Allowed values: tcp, udp, ip, any. enum (tcp, udp, ip, any)

PayloadFilterInput

Payload filter rule create/update payload.

Name Description Schema
action
required
An action will be taken when they match. Allowed values: ratelimit, pass, drop. enum (ratelimit, pass, drop)
bps_limit
optional
ratelimit in bps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
filter_name
required
The name of the policies.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
is_enabled
optional
0 = disabled, 1 = enabled. integer
payload_string
optional
The string of the payload. < string > array
port
optional
The lists of the port numbers. < integer > array
pps_limit
optional
ratelimit in pps.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
protocol
optional
The protocol of the data packet. Allowed values: tcp, udp, ip, any. enum (tcp, udp, ip, any)

QuicFilter

QUIC Filter configuration.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
optional
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead.
Length : 1 - 40
string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
UDP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
QUIC Malformed Packet Detection configuration. malformed
quic_flood_protection
optional
QUIC Session Protection configuration quic_flood_protection
quic_ratelimit
optional
QUIC Ratelimit Module configuration quic_ratelimit

malformed

Name Description Schema
handshake_min_len
optional
Minimum length (bytes) for handshake packets, range (10-65535).
Minimum value : 10
Maximum value : 65535
integer
initial_min_len
optional
Minimum length (bytes) for initial packets, range (1200-65535).
Minimum value : 1200
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer
support_version
optional
Supported QUIC versions:[‘all’,‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. < enum (all, v1, v2, draft27, draft28, draft29, draft30, draft31, draft32, draft33, draft34) > array
version_negotiation_min_len
optional
Minimum length (bytes) for version negotiation packets, range (12-65535).
Minimum value : 12
Maximum value : 65535
integer
zero_rtt_min_len
optional
Minimum length (bytes) for 0-RTT packets, range (10-65535).
Minimum value : 10
Maximum value : 65535
integer

quic_flood_protection

Name Description Schema
0rtt_replay_attack_protection
optional
0-RTT replay attack protection configuration. 0rtt_replay_attack_protection
authentication
optional
Authentication configuration. authentication
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_source_ip
optional
Session (Per source IP) Module configuration new_session_per_source_ip
ratelimit_per_session
optional
Ratelimit (Per Session) Module configuration. ratelimit_per_session

0rtt_replay_attack_protection

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300).
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. integer
packet_per_second
optional
Packets per second threshold, range (1-65535).
Minimum value : 1
Maximum value : 65535
integer

authentication

Name Description Schema
mode
optional
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. integer
session_scope
optional
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. integer

new_session_per_source_ip

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300)
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
new_session_per_second
optional
New sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer

ratelimit_per_session

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. integer
session_check_duration
optional
Session check duration (seconds), range (20-40)
Minimum value : 20
Maximum value : 40
integer
session_timeout
optional
Idle session timeout (seconds), range (60-600)
Minimum value : 60
Maximum value : 600
integer

quic_ratelimit

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packets
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

QuicFilterInput

QuicFilter create payload.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_name
required
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
required
UDP Port list. < integer > array

Result

Name Description Schema
code
optional
Error code. 0 indicates success. integer
msg
optional
Error message. string

SipFilter

SIP Filter configuration.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
optional
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_tcp_port
optional
TCP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. < integer > array
filter_udp_port
optional
UDP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. < integer > array
invite
optional
SIP INVITE message configuration. invite
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed_is_enabled
optional
SIP Malformed enable status. Values: 0 = off, 1 = drop. integer
register
optional
SIP REGISTER Requst message configuration. register
retransmission_is_enabled
optional
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. integer
tcp_connection
optional
TCP Connection protection configuration tcp_connection

invite

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

register

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = rate limit. integer
tcp
optional
TCP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer
udp
optional
UDP message size limit, range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tcp_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
Source IP average window size threshold slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting source_ip_new_connection
total_connection
optional
Total connection rate limiting total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Sessions per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Block duration (seconds), range (10-60)
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Half-open connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Idle connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Block duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
New connections per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

SipFilterInput

SipFilter create payload. At least one of filter_tcp_port or filter_udp_port is required.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_name
required
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_tcp_port
optional
TCP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. < integer > array
filter_udp_port
optional
UDP Port list. At least one of filter_tcp_port or filter_udp_port is required; when present, must be non-empty. < integer > array

TlsFilter

SSL/TLS Filter configuration.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_id
optional
Filter Profile ID. Returned in GET responses. Optional in update request bodies; use the path parameter instead. string
filter_name
optional
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
optional
TCP Port list. < integer > array
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
malformed
optional
SSL/TLS Malformed Packet Detection configuration. malformed
ratelimit
optional
SSL/TLS Ratelimit (Per Profile) configuration ratelimit
renegotiation
optional
SSL/TLS Renegotiation configuration. renegotiation
session
optional
SSL/TLS Session configuration. session
tcp_connection
optional
Connection protection configuration tcp_connection

malformed

Name Description Schema
clienthello_length_limit_non_v_1_3
optional
ClientHello length (bytes) limit for non-TLS 1.3, range (64-1400).
Minimum value : 64
Maximum value : 1400
integer
clienthello_length_limit_v_1_3
optional
ClientHello length (bytes) limit for TLS 1.3, range (64-1400).
Minimum value : 64
Maximum value : 1400
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer

ratelimit

Name Description Schema
non_tls
optional
Ratelimit for non TLS1.2 and TLS1.3 traffic. non_tls
tls
optional
Ratelimit for TLS1.2 and TLS1.3 traffic. tls

non_tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

tls

Name Description Schema
bandwidth
optional
Bandwidth limit (Mbps), range (1-4095).
Minimum value : 1
Maximum value : 4095
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = on. integer
packet
optional
Packet rate limit (pps), range (1-1000000).
Minimum value : 1
Maximum value : 1000000
integer

renegotiation

Name Description Schema
blocklist_duration
optional
Blocklist duration (seconds), range (1-65535).
Minimum value : 1
Maximum value : 65535
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = drop. integer

session

Name Description Schema
block_duration
optional
Block duration (seconds), range (1-300)
Minimum value : 1
Maximum value : 300
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = block. integer
new_session_per_second
optional
New session per second, range (1-65535)
Minimum value : 1
Maximum value : 65535
integer

tcp_connection

Name Description Schema
is_enabled
optional
Connection protection enable status. Values: 0 = off, 1 = on. integer
slow_rate_connection
optional
This rule checks for slow rate connections from the same source IP address slow_rate_connection
source_ip_half_open_connection
optional
Source IP half-open connection rate limiting source_ip_half_open_connection
source_ip_idle_connection
optional
Source IP idle connection rate limiting source_ip_idle_connection
source_ip_new_connection
optional
Source IP connection rate limiting source_ip_new_connection
total_connection
optional
Total connection rate limiting total_connection

slow_rate_connection

Name Description Schema
avg_window_size
optional
Average window Size (bytes), range (1-65535)
Minimum value : 1
Maximum value : 65535
integer
block_duration
optional
Ban duration (seconds), range (10-60).
Minimum value : 10
Maximum value : 60
integer
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = block. integer

source_ip_half_open_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
half_open_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_idle_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
idle_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer
is_enabled
optional
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer

source_ip_new_connection

Name Description Schema
block_duration
optional
Ban duration (seconds), range (10-600)
Minimum value : 10
Maximum value : 600
integer
is_enabled
optional
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. integer
new_connection_per_second
optional
Sessions per second, range (5-1000)
Minimum value : 5
Maximum value : 1000
integer

total_connection

Name Description Schema
is_enabled
optional
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. integer
total_connection_per_second
optional
Sessions per second, range (100-4294967295)
Minimum value : 100
Maximum value : 4294967295
integer

TlsFilterInput

TlsFilter create payload.

Name Description Schema
filter_description
optional
Filter description, length 0-100 characters.
Length : 0 - 100
Pattern : "^[A-Za-z0-9_ -]*$"
string
filter_name
required
Filter name; letters, digits, underscore, hyphen, period, and space; length 1-40 characters.
Length : 2 - 40
Pattern : "^[A-Za-z0-9_ .-]+$"
string
filter_port
required
TCP Port list. < integer > array

TrafficPolicingPolicy

Traffic policing cap (bps/pps) for the host.

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

TrafficPolicingPolicyInput

Traffic policing cap incremental update payload. Include only fields to change; omitted fields are preserved.

Name Description Schema
is_enabled
optional
0 = disabled, 1 = enabled. integer
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G).
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ZombiePolicy

Zombie host detection (host vs network scope). Not supported for IPv6.

Name Description Schema
flex_zombie
optional
Flex zombie rules attached to the profile. < FlexZombieRule > array
is_enabled
optional
0 = off, 1 = on . integer
zombie_host
optional
Per-host zombie thresholds and action. zombie_host
zombie_network
optional
Per-network zombie thresholds and action. zombie_network

zombie_host

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie_network

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = off, 1 = on . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

ZombiePolicyInput

Zombie host detection policy incremental update payload. Include only fields or sub-objects to change; omitted fields are preserved. Flex zombie rules are managed via flex-zombie CRUD APIs; do not include flex_zombie in this request.

Name Description Schema
is_enabled
optional
0 = off, 1 = on . integer
zombie_host
optional
Per-host zombie thresholds and action. zombie_host
zombie_network
optional
Per-network zombie thresholds and action. zombie_network

zombie_host

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = disabled, 1 = enabled. integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

zombie_network

Name Description Schema
block_duration
optional
Blocklist duration in seconds after a trigger.
Minimum value : 10
Maximum value : 120
integer
is_enabled
optional
0 = off, 1 = on . integer
mode
optional
Mitigation action (e.g. ratelimit, block). enum (ratelimit, block)
threshold_bps
optional
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string
threshold_pps
optional
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only.
Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$"
string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY