Mitigation
Mitigation
Overview
Origin Protection Mitigation API
Version information
Version : 1.0.0.BETA
License information
Terms of service : https://www.nexusguard.com/
URI scheme
Host : {your_basic_domain}
BasePath : /api
Schemes : HTTPS
Paths
Create an IP set.
POST /spe/customer/{customer_id}/op/mitigation/template/ip_set
Description
Create an IP set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Customer ID. Can be obtained by invoking this API for customer_id. | string |
| Query | access_token required |
API access token for authentication. | string |
| Body | body required |
IP set configuration. | body |
| Name | Description | Schema |
|---|---|---|
| enable_country required |
Source country enabled status, 0 = off, 1 = on. | integer |
| ip_set_desc optional |
IP set description. | string |
| ip_set_name required |
IP set name. | string |
| ip_type required |
IP address family for the template: ipv4 or ipv6. | string |
| source_countries required |
Source countries. | < string > array |
| source_ips required |
Source IPs. | < string > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response body with result data or error information. | Response 200 |
| Name | Schema |
|---|---|
| code optional |
integer |
| msg optional |
string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
IP set ID. | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get an IP set.
GET /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}
Description
Get an IP set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Customer ID. Can be obtained by invoking this API for customer_id. | string |
| Path | ip_set_id required |
IP set ID. Can be obtained by invoking this API for ip_set_id. | string |
| Query | access_token required |
API access token for authentication. | string |
| Query | ip_type optional |
IP address family for the template, ipv4 or ipv6. Default is ipv4. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response body with result data or error information. | Response 200 |
| Name | Schema |
|---|---|
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| enable_country optional |
Source country enabled status, 0 = off, 1 = on. | integer |
| ip_set_desc optional |
IP set description. | string |
| ip_set_name optional |
IP set name. | string |
| ip_type optional |
IP address family for the template, ipv4 or ipv6. | string |
| source_countries optional |
Source countries. | < string > array |
| source_ips optional |
Source IPs. | < string > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit an IP set.
PUT /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}
Description
Edit an IP set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Customer ID. Can be obtained by invoking this API for customer_id. | string |
| Path | ip_set_id required |
IP set ID. Can be obtained by invoking this API for ip_set_id. | string |
| Query | access_token required |
API access token for authentication. | string |
| Body | body required |
IP set configuration. | body |
| Name | Description | Schema |
|---|---|---|
| enable_country optional |
Source country enabled status, 0 = off, 1 = on. | integer |
| ip_set_desc optional |
IP set description. | string |
| ip_set_name required |
IP set name. | string |
| ip_type optional |
IP address family for the template: ipv4 or ipv6. Default: ipv4. | string |
| source_countries optional |
Source countries. | < string > array |
| source_ips optional |
Source IPs. | < string > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response body with result data or error information. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete an IP set.
DELETE /spe/customer/{customer_id}/op/mitigation/template/ip_set/{ip_set_id}
Description
Delete an IP set.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Customer ID. Can be obtained by invoking this API for customer_id. | string |
| Path | ip_set_id required |
IP set ID. Can be obtained by invoking this API for ip_set_id. | string |
| Query | access_token required |
API access token for authentication. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response body with result data or error information. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get IP set templates for allow/block list policy.
GET /spe/customer/{customer_id}/op/mitigation/template/ip_sets
Description
Get IP set templates for allow/block list policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Customer ID. Can be obtained by invoking this API for customer_id. | string |
| Query | access_token required |
API access token for authentication. | string |
| Query | ip_type optional |
IP address family for the template, ipv4 or ipv6. Default is ipv4. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response body with result data or error information. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Numeric error code; 0 indicates success. | integer |
| msg optional |
Human-readable error or status message. | string |
| result optional |
< result > array |
| Name | Description | Schema |
|---|---|---|
| enable_country optional |
Source country enabled status, 0 = off, 1 = on. | integer |
| ip_set_desc optional |
IP set description. | string |
| ip_set_id optional |
IP set ID. | string |
| ip_set_name optional |
IP set name. | string |
| ip_type optional |
IP address family for the template, ipv4 or ipv6. | string |
| source_countries optional |
< string > array | |
| source_ips optional |
< string > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Set allow list/block list source IP and source countries.
POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list
Description
Put source IP and source countries into allow list or block list.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | source_ips required |
Put the IPs you want to add to either the blacklist or whitelist. | < string > array |
| FormData | src_countries required |
Put the source countries to either blacklist or whitelist. The value of countries is taken from configuration options. | < string > array |
| FormData | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get mitigation black and white list.
GET /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list
Description
Traffic from the allow listed IPs can bypass all other policies and be allowed to enter. Traffic from the block listed IPs is denied to enter and dropped directly.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| Query | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| source_countries optional |
The source countries of traffic. | < string > array |
| source_ips optional |
Source IP. | < string > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policy for allow list or block list.
POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/allow-block-list/switch
Description
Change the mitigation policy for allow list or block list.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| FormData | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policy of the policy for bogons.
POST /spe/customer/{customer_id}/op/site/{site_id}/mitigation/bogons/switch
Description
Change the mitigation policy of the policy for bogons.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| FormData | type required |
The bogons types include martian_address, land_attack. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of bogons switch.
GET /spe/customer/{customer_id}/op/site/{site_id}/mitigation/bogons/switch
Description
Get the info of bogons switch.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| Query | type required |
blacklist/whitelist type. in (blacklist, whitelist). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| land_attack optional |
The property of the land_attack. | land_attack |
| martian_address optional |
The property of the martian address. | martian_address |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the land_attack switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the martian_address switch is disabled whereas 1 means it is enabled. |
integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the info of FlexFilter/advanced payload filtering for mitigation.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering
Description
Gets the info of FlexFilter/advanced payload filtering for mitigation.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
< result > array |
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. | string |
| bps_limit optional |
ratelimit in bps. | string |
| filter_id optional |
Unique identifier of advanceed rule. | string |
| filter_name optional |
The name of the policies. | string |
| payload_string optional |
The string of the payload. | payload_string |
| port optional |
The port number of the data packet. | port |
| pps_limit optional |
ratelimit in pps. | string |
| protocol optional |
The protocol of the data packet. | protocol |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| string optional |
Key word or phrase to look for in a payload. | < string > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| ports optional |
The lists of the port numbers. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| type optional |
Currently, tcp, udp and ip supported protocol for the data packet can be used. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Add the policies for the FlexFilter/advanced payload filtering.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/filter
Description
Add the policies for the FlexFilter/advanced payload filtering.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
Action to take when a match is found. You can choose pass, drop and rateLimit.Selecting Rate Limit allows to define a limit of bandwidth all such data packets can use. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | filter_name required |
The name of the policies created. | string |
| FormData | payload_string optional |
If the “payload_string_enabled” is switched on, the key word or phrase must be provided to be looked for in a payload. | < string > array |
| FormData | payload_string_enabled optional |
0 means the switch of the payload string is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. |
integer |
| FormData | port optional |
If the “port_enabled” is switched on, the port number either for the source or destination port of the data packet must be provided , with the exception of protocol is ‘ip’. | < integer > array |
| FormData | port_enabled optional |
0 means the port switch is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled, with the exception of protocol is ‘ip’. |
integer |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | protocol optional |
If protocol_enabled is switched on, the type of protocol must be provided. Currently, tcp, udp and ip supported protocol for the data packet can be used. | string |
| FormData | protocol_enabled optional |
0 means the switch of the protocol is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | This is the returned result. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID, an unique identifier assigned to each FlexFilter/Advanced Payload Filtering. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the info of policies for FlexFilter/advanced payload filtering for mitigation.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}
Description
Gets the info of policies for FlexFilter/advanced payload filtering for mitigation.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of advanceed filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. | string |
| bps_limit optional |
ratelimit in bps. | string |
| filter_name optional |
The name of the policies. | string |
| payload_string optional |
The payload of the string. | payload_string |
| port optional |
The port number of the data packet. | port |
| pps_limit optional |
ratelimit in pps. | string |
| protocol optional |
The protocol of the data packet. | protocol |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| string optional |
The key word or phase to be lookedfor in a payload. | < string > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| ports optional |
The list of the port number. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| type optional |
Currently, tcp, udp and ip supported protocol for the data packet can be used. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit FlexFilter/Advanced Payload Filtering.
PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}
Description
Edit FlexFilter/Advanced Payload Filtering.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of advanceed filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | filter_name required |
The name of the policies created. | string |
| FormData | payload_string optional |
If “payload_string_enabled” is switched on, the key word or phase must be provided to be looked for in a payload. | < string > array |
| FormData | payload_string_enabled optional |
0 means the switch for the payload string is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. |
integer |
| FormData | port optional |
If the “port_enable” is switched on, the port number of the data packet must be provided. The port number can be either source or destination port | < integer > array |
| FormData | port_enabled optional |
0 means the port switch is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. |
integer |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | protocol optional |
If the “port_enable” is switched on, the name of protocol of the data packet must be provided. Currently, this function supports TCP, UDP and IP protocol. | string |
| FormData | protocol_enabled optional |
0 means the switch for the protocol is disabled whereas 1 means it is enabled.At least one of the protocol_enabled, port_enabled, and payload_string_enabled must be enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete policies for FlexFilter/advanced payload filtering.
DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/advanced-payload-filtering/{filter_id}
Description
Delete policies for FlexFilter/advanced payload filtering.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of advanceed filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Set allow list/block list source IP and source countries.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list
Description
Put source IP and source countries into allow list or block list.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | source_ips required |
Put the IPs you want to add to either the blacklist or whitelist. | < string > array |
| FormData | src_countries required |
Put the source countries to either blacklist or whitelist. The value of countries is taken from configuration options. | < string > array |
| FormData | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get mitigation black and white list.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list
Description
Traffic from the allow listed IPs can bypass all other policies and be allowed to enter. Traffic from the block listed IPs is denied to enter and dropped directly.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| Query | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| source_countries optional |
The source countries of traffic. | < string > array |
| source_ips optional |
Source IP. | < string > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policy for allow list or block list.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/allow-block-list/switch
Description
Change the mitigation policy for allow list or block list.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| FormData | type required |
allow list/block list type. in (allow_list, block_list). | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of FlexFilter/basic network filtering for mitigation.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering
Description
Get the info of FlexFilter/basic network filtering for mitigation.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| common_rule_sets optional |
The filter sets. | < common_rule_sets > array |
| custom_rule_set optional |
Custom Filters. | custom_rule_set |
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| rule_set_desc optional |
More details about the purpose of the policy. | string |
| rule_set_id optional |
Unique identifier of common rule. | string |
| rule_set_name optional |
The name of the policy. | string |
| Name | Description | Schema |
|---|---|---|
| action optional |
Either rate limiting, dropping or letting the traffic pass are taken. | string |
| bps_limit optional |
ratelimit in bps. | integer |
| dst_ip optional |
IP Address of the recipient. | < string > array |
| dst_port optional |
Port number to which the data packet is sent. | < integer > array |
| is_enabled optional |
0 means it is disabled and 1 means enabled. |
integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
ratelimit in pps. | integer |
| protocol optional |
Protocol of the data packet. | string |
| rule_desc optional |
More details about the purpose of the policy. | string |
| rule_id optional |
Unique identifier of custom rule. | integer |
| rule_name optional |
The name of the policy | string |
| src_ip optional |
IP address of the sender, as it is shown in the data packet. | < string > array |
| src_port optional |
Port number from which the data packet is sent | < integer > array |
| tcp_flags optional |
In TCP connection, flags are used to indicate a particular state of connection or to provide some additional useful information. | < string > array |
| ttl optional |
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. | integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Add rules for the FlexFilter/basic network filtering/ custom filters.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter
Description
Add rules for the FlexFilter/basic network filtering/ custom filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | dst_ip optional |
IP Address of the recipient. | < string > array |
| FormData | dst_port optional |
Port number to which the data packet is sent. | < integer > array |
| FormData | icmp_code optional |
When ICMP_type is required for ICMP-unreach, ICMP-Redirect or ICMP-Paramprob, when ICMP-unreach is 0-15, ICMP-redirect is 0-3, and ICMP-paramprob is 0-2. | integer |
| FormData | icmp_type optional |
When the protocols value is required for ICMP, the value can be custom or from the filter_ICMP_type field that returns the result from config options. When custom, the range is an integer between 0 and 255. | string |
| FormData | package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | protocol required |
Protocol of the data packet. Currently, tcp, udp and icmp are supported. | string |
| FormData | rule_desc optional |
More details about the purpose of the policy. | string |
| FormData | rule_name required |
The name of the policy created. | string |
| FormData | src_ip optional |
IP address of the sender, as it is shown in the data packet. | < string > array |
| FormData | src_port optional |
Port number from which the data packet is sent. | < integer > array |
| FormData | tcp_flags optional |
When the protocol is TCP, its value is retrieved from the filter_tcp_flags in the configuration options. | < string > array |
| FormData | ttl optional |
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. It is set to a value between zero and 255. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | This is the returned result. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| rule_id optional |
Rule ID, an unique identifier assigned to each FlexFilter Custom Filters. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of the policy for flex filer/basic network filtering and custom filters for mitigation.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}
Description
Get the info of the policy for flex filer/basic network filtering and custom filters for mitigation.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | rule_id required |
Unique identifier of custom rule. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| action optional |
Either rate limiting, dropping or letting the traffic pass are taken. | string |
| bps_limit optional |
ratelimit in bps. | string |
| dst_ip optional |
IP Address of the recipient. | < string > array |
| dst_port optional |
Port number to which the data packet is sent. | < integer > array |
| icmp_code optional |
ICMP Code. | string |
| icmp_type optional |
The filters for ICMP. | string |
| is_enabled optional |
0 means it is disabled and 1 means enabled. |
integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
ratelimit in pps. | string |
| protocol optional |
Protocol of the data packet. | string |
| rule_desc optional |
More details about the purpose of the policy. | string |
| rule_id optional |
Unique identifier of a policy. | string |
| rule_name optional |
The name of the policy | string |
| src_ip optional |
IP address of the sender, as it is shown in the data packet. | < string > array |
| src_port optional |
Port number from which the data packet is sent | < integer > array |
| tcp_flags optional |
In TCP connection, flags are used to indicate a particular state of connection or to provide some additional useful information. | < string > array |
| ttl optional |
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the rules for FlexFilter/basic network filtering/custom filters.
PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}
Description
Edit the rules for FlexFilter/basic network filtering/custom filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | rule_id required |
Unique identifier of a rule. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
You can select “pass”, “drop” or “ratelimit”. Selecting the ratelimit can allow you to define the capacity of the bandwidth that data packets can consume. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | dst_ip optional |
IP Address of the recipient. | < string > array |
| FormData | dst_port optional |
Port number to which the data packet is sent. | < integer > array |
| FormData | icmp_code optional |
When ICMP_type is required for ICMP-unreach, ICMP-Redirect or ICMP-Paramprob, when ICMP-unreach is 0-15, ICMP-redirect is 0-3, and ICMP-paramprob is 0-2. | integer |
| FormData | icmp_type optional |
When the protocols value is required for ICMP, the value can be custom or from the filter_ICMP_type field that returns the result from config options. When custom, the range is an integer between 0 and 255. | string |
| FormData | package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | protocol required |
Protocol of the data packet. Currently, tcp, udp and icmp are supported. | string |
| FormData | rule_desc optional |
More details about the purpose of the policy. | string |
| FormData | rule_name required |
Unique identifier of a policy created. | string |
| FormData | src_ip optional |
IP address of the sender, as it is shown in the data packet. | < string > array |
| FormData | src_port optional |
Port number from which the data packet is sent. | < integer > array |
| FormData | tcp_flags optional |
When the protocol is TCP, its value is retrieved from the filter_tcp_flags in the configuration options. | < string > array |
| FormData | ttl optional |
Time-to-live (TTL) is a value in an IP packet that tells a network router whether or not the packet has been in the network too long and should be discarded. It is set to a value between zero and 255. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Deletes FlexFilter/ basic network filtering/ custom filters.
DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}
Description
Deletes FlexFilter/ basic network filtering/ custom filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | rule_id required |
Unique identifier of custom rule. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the status of the switch of the FlexFilter/ basic network filtering/custom filters.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/custom-filter/{rule_id}/switch
Description
Change the status of the switch of the FlexFilter/ basic network filtering/custom filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | rule_id required |
Unique identifier of custom rule. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch of basic network filtering is disabled whereas 1 means it is enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policy for the FlexFilter/filter sets.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/filter-sets
Description
Edit the policy for the FlexFilter/filter sets.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | rule_set_id required |
Enter the rule id you want to add. | < string > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Changes the status of the switch for the policies for FlexFilter/basic network filtering.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/basic-network-filtering/switch
Description
Changes the status of the switch for the policies for FlexFilter/basic network filtering.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch of the basic network filtering is disabled whereas 1 means it is enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
It is used to edit Traffic Policies.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing
Description
It is used to edit Traffic Policies.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | threshold_bps required |
Threshold values in bps.must be a number or K, M, G format. | string |
| FormData | threshold_pps required |
Threshold values in pps.must be a number or K, M, G format. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get mitigation traffic policing info.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing
Description
Get mitigation traffic policing info.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the mitigation policy for zombie is disabled whereas 1 means it is enabled. |
integer |
| threshold_bps optional |
Threshold values in bps. | string |
| threshold_pps optional |
Threshold values in pps. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
It is a switch to change the status of Traffic Policing/Filter Policing.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/filter-policing/switch
Description
It is a switch to change the status of Traffic Policing/Filter Policing.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the filter policy is disabled whereas 1 means it is enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of the policy of ICMP flood.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood
Description
Get the info of the policy of ICMP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| custom_icmp_filter optional |
The info of customizable ICMP filters. | custom_icmp_filter |
| icmp_fragmentation optional |
The info of ICMP fragmentation. | icmp_fragmentation |
| Name | Description | Schema |
|---|---|---|
| default optional |
The default ICMP filters. | default |
| filters optional |
The list of customizable ICMP filters. | < filters > array |
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
pass or ratelimit. | string |
| bps_limit optional |
The ratelimit in bps. | string |
| filter_name optional |
The name of the filter. | string |
| icmp_length optional |
The length of ICMP to be dropped must range between 1 to 1500. | integer |
| icmp_type optional |
The type of icmp filters. | integer |
| pps_limit optional |
The ratelimit in pps. | string |
| Name | Description | Schema |
|---|---|---|
| action optional |
pass or ratelimit. | string |
| bps_limit optional |
The ratelimit in bps. | string |
| filter_id optional |
Unique identifier of custom filter. | string |
| filter_name optional |
The name of filters. | string |
| icmp_length optional |
The length of ICMP you want to drop. | integer |
| icmp_type optional |
The type of ICMP. | integer |
| pps_limit optional |
The ratelimit in pps. | string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Add filters for ICMP flood/Customizable protocol filters.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter
Description
Add filters for ICMP flood/Customizable protocol filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
pass or ratelimit. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | filter_name required |
The name of the filters. | string |
| FormData | icmp_length required |
The size of the data packet, must be 1-1500. | integer |
| FormData | icmp_type required |
The type of icmp, the value of “icmp_filter_types” is taken from configuration options. | integer |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | This is the returned result. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_id optional |
Filter ID, an unique identifier assigned to each Custom ICMP Filter. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the policies for the filters for ICMP flood/customizable ICMP.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}
Description
Gets the policies for the filters for ICMP flood/customizable ICMP.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of custom filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| action optional |
pass or ratelimit. | string |
| bps_limit optional |
The ratelimit in bps. | string |
| filter_name optional |
The name of the filter | string |
| icmp_length optional |
The length of ICMP you can drop. | integer |
| icmp_type optional |
The type of icmp. | integer |
| pps_limit optional |
The ratelimit in pps. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policies of the filters for ICMP flood/Customizable protocol.
PUT /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}
Description
Edit the policies of the filters for ICMP flood/Customizable protocol.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of custom filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
pass or ratelimit. | string |
| FormData | bps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
| FormData | filter_name required |
The name of the filter. | string |
| FormData | icmp_length required |
The length of ICMP you can drop must range between 1 to 1500. | integer |
| FormData | icmp_type required |
The type of icmp, the value of “icmp_filter_types” is taken from configuration options. | integer |
| FormData | pps_limit optional |
The rate limit whose must be a number or K, M, G format must be provided when the ratelimit is switched on. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete the policies for the filter for ICMP flood/Customizable protocol.
DELETE /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/icmp-filter/{filter_id}
Description
Delete the policies for the filter for ICMP flood/Customizable protocol.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | filter_id required |
Unique identifier of custom filter. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Changes the status of the policy for ICMP flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/icmp-flood/switch
Description
Changes the status of the policy for ICMP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| FormData | module required |
The type of icmp flood includes icmp_fragmentation,custom_icmp_filter. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of anti-flood and IP food.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood
Description
Get the info of anti-flood and IP food.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| custom_protocol_filter optional |
The property of the customizable protocol filters. | custom_protocol_filter |
| ip_fragmentation optional |
The property of the IP fragmentation. | ip_fragmentation |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch of the customizable protocol filters is disabled whereas 1 means it is enabled. |
integer |
| protocol optional |
The list of the protocol. | < string > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch of IP fragmentation is disabled whereas 1 means it is enabled. |
integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policy for the customizable protocol filters.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood/protocol
Description
Edit the policy for the customizable protocol filters.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | protocols required |
The value of “ip_protocol_number” you want to add is taken from the configuration options. | < integer > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Changes of the status of the policy for anti-flood/IP flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/ip-flood/switch
Description
Changes of the status of the policy for anti-flood/IP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch for the policy for IP flood is disabled whereas 1 means it is enabled. |
integer |
| FormData | module required |
IP Flood type. in (ip_fragmentation,custom_protocol_filter). ip_fragmentation means it is IP Fragmentation and custom_protocol_filter means Custom Protocol Filter. |
string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Set manual mitigation configuration.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/manual-mitigation-configuration
Description
Set manual mitigation configuration for a host.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Body | body required |
Manual mitigation configuration. | manual_mitigation_configuration |
manual_mitigation_configuration
| Name | Description | Schema |
|---|---|---|
| allow_block_list optional |
Allow list and block list configuration for source traffic. | allow_block_list |
| anti_flood optional |
Anti-flood policy: L3/L4 modules, L7 profiles, and aggregate protocol caps. | anti_flood |
| bogons optional |
Bogon and invalid address protections. | bogons |
| customer_id optional |
Customer identifier. | string |
| flex_filter optional |
Flex filters: payload, ACL, smart filter, TCP option sets. | flex_filter |
| host_id optional |
Host identifier. | string |
| network_id optional |
Network identifier. | string |
| ntif optional |
Network Threat Intelligence Feed categories and actions. Not supported for IPv6. | ntif |
| site_id optional |
Site identifier. | string |
| traffic_policing optional |
Traffic policing cap (bps/pps) for the host. | traffic_policing |
| zombie optional |
Zombie host detection (host vs network scope). Not supported for IPv6. | zombie |
| Name | Description | Schema |
|---|---|---|
| allow_list optional |
Trusted sources permitted when allow-list policy is enabled. | allow_list |
| block_list optional |
Sources to block or rate-limit when block-list policy is enabled. | block_list |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. Required when mode is 2. | string |
| mode optional |
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. Required when mode is 2. | string |
| mode optional |
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| l3l4 optional |
l3l4 | |
| l7 optional |
Application-layer filter profiles (HTTP, TLS, SIP, QUIC, custom TCP). | l7 |
| protocol optional |
Per-protocol aggregate rate limits at host scope. | protocol |
| Name | Description | Schema |
|---|---|---|
| icmp optional |
ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported. | icmp |
| ip optional |
IP-layer sanity and flood mitigation. | ip |
| tcp optional |
TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters. | tcp |
| udp optional |
UDP flood amplification handling. | udp |
| Name | Description | Schema |
|---|---|---|
| all_icmp_packet optional |
Drop all ICMP traffic when enabled. | all_icmp_packet |
| icmp_custom_filter optional |
icmp_custom_filter | |
| icmp_fragmentation optional |
ICMP fragmentation handling. | icmp_fragmentation |
| large_ping optional |
Drop oversized ICMP echo requests. | large_ping |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = drop all ICMP traffic . | integer |
| Name | Description | Schema |
|---|---|---|
| default optional |
Default ICMP filter applied when no custom rule matches. | default |
| filters optional |
< filters > array | |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit, pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Can not be edited. Length : 1 - 40 Pattern : "^[A-Za-z0-9_-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit,pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_description optional |
Filter description. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| icmp_type optional |
ICMP type number. Minimum value : 0 Maximum value : 31 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| custom_protocol_filter optional |
Filter on specific IP protocol numbers. | custom_protocol_filter |
| ip_fragmentation optional |
IP fragmentation handling. | ip_fragmentation |
| ip_invalid optional |
Drop packets failing basic IP validity checks. | ip_invalid |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| protocol_numbers optional |
Per-protocol aggregate rate limits at host scope. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_fragmentation optional |
TCP fragmentation mitigation. | tcp_fragmentation |
| tcp_malformed optional |
Invalid TCP flags, SYN, and option handling. | tcp_malformed |
| tcp_rewrite_mss_size optional |
SYN MSS validation. | tcp_rewrite_mss_size |
| tcp_syn_anti_spoofing optional |
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. | tcp_syn_anti_spoofing |
| tcp_syn_exclude_syn_ack_and_syn_ack_ecn optional |
Drop SYN-ACK and SYN-ACK-ECN packets. | tcp_syn_exclude_syn_ack_and_syn_ack_ecn |
| tcp_with_well_known_ports optional |
Drop invalid or sensitive destination-port packets. | tcp_with_well_known_ports |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_invalid_flags optional |
Illegal or suspicious TCP flag combinations. | tcp_invalid_flags |
| tcp_long_header optional |
Malformed or oversized SYN options. | tcp_long_header |
| tcp_syn_with_data optional |
SYN segments with non-zero payload. | tcp_syn_with_data |
| tcp_syn_with_reserved_flags optional |
Reserved TCP flag bits. | tcp_syn_with_reserved_flags |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
Size threshold in bytes (meaning depends on parent module). Minimum value : 34 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| graceful_challenges optional |
Graceful challenges. | graceful_challenges |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| rate_limit_per_connection optional |
Rate limit per connection. | rate_limit_per_connection |
| tcp_3_way_handshake_challenges optional |
TCP 3-way handshake challenges. | tcp_3_way_handshake_challenges |
| tcp_data optional |
TCP data validation. | tcp_data |
| tcp_retransmission optional |
TCP retransmission validation. | tcp_retransmission |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| duration optional |
Duration in seconds. Range: 10-150. Minimum value : 10 Maximum value : 150 |
integer |
| is_enabled optional |
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. | integer |
| timeout optional |
Timeout duration in seconds. Range: 10-3600. Minimum value : 60 Maximum value : 600 |
integer |
tcp_3_way_handshake_challenges
| Name | Description | Schema |
|---|---|---|
| mode optional |
0 = tcp retransmission, 1 = tcp data, 2 = auto. | integer |
| Name | Description | Schema |
|---|---|---|
| server_ip_validation optional |
Server IP validation. | server_ip_validation |
| traffic_policing optional |
Traffic policing. | traffic_policing |
| Name | Description | Schema |
|---|---|---|
| bot_mitigation optional |
Bot mitigation validation. | bot_mitigation |
| spoofed_carpet_bombing_mitigation optional |
Spoofed carpet bombing mitigation validation. | spoofed_carpet_bombing_mitigation |
| tcp_fast_open optional |
TCP fast open validation. | tcp_fast_open |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
spoofed_carpet_bombing_mitigation
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| suspicious_receiver_ip_rate_limit optional |
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| total_rate_limit optional |
Total rate limit in packets per second. Range: 100-4000000000. Minimum value : 100 Maximum value : 4000000000 |
integer |
| validated_server_ip_rate_limit optional |
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| validation_mode optional |
0 = half open, 1 = full open. | integer |
| validation_trust_mode optional |
0 = host, 1 = network. | integer |
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| ntp_amplification optional |
ntp_amplification | |
| snmp_amplification optional |
snmp_amplification | |
| ssdp_flood optional |
SSDP flood handling. | ssdp_flood |
| udp_contain_all_zero_data optional |
UDP contain all zero data handling. | udp_contain_all_zero_data |
| udp_flood_amplification optional |
udp_flood_amplification | |
| udp_fragmentation optional |
UDP fragmentation handling. | udp_fragmentation |
| udp_malformed optional |
UDP malformed handling. | udp_malformed |
| udp_with_port_number_lt_1024 optional |
UDP with port number less than 1024 handling. | udp_with_port_number_lt_1024 |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| ntp_response_length optional |
NTP response length handling. | ntp_response_length |
| ntp_response_monlist_drop optional |
NTP response MONLIST drop handling. | ntp_response_monlist_drop |
| ntp_response_rate_limit optional |
NTP response rate limit handling. | ntp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the NTP response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| snmp_response_rate_limit optional |
SNMP response rate limit handling. | snmp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| zero_data_min_length optional |
The minimum length of the zero data payload. Minimum value : 42 Maximum value : 128 |
integer |
| Name | Description | Schema |
|---|---|---|
| dns_query_length optional |
DNS query length handling. | dns_query_length |
| dns_query_rate_limit optional |
DNS query rate limit handling. | dns_query_rate_limit |
| dns_response_length optional |
DNS response length handling. | dns_response_length |
| dns_response_rate_limit optional |
DNS response rate limit handling. | dns_response_rate_limit |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
The size of the DNS query. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
The size of the DNS response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| udp_packet_contain_no_data optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| custom optional |
Custom L7 (TCP) filter profiles for this host. | custom |
| http optional |
HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled. | http |
| quic optional |
QUIC L7 filter profiles for this host. | quic |
| sip optional |
SIP L7 filter profiles for this host. | sip |
| tls optional |
TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled. | tls |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of Custom L7 (TCP) filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total Connection Moudle configuration.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Schema |
|---|---|
| profile optional |
< profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| http_authentication optional |
HTTP Authentication Module configuration.origin_field:authentication. | http_authentication |
| http_slow_rate optional |
HTTP Slow Rate Module configuration.origin_field:slow_attack. | http_slow_rate |
| is_enabled optional |
Filter status. Values: 0 = on, 1 = off. |
integer |
| tcp_connection optional |
TCP Connection Module configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| model optional |
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-86400).origin_field:block_duration. Minimum value : 1 Maximum value : 86400 |
integer |
| body optional |
HTTP Slow Body Module configuration. | body |
| header optional |
HTTP Slow Header Module configuration. | header |
| is_enabled optional |
Enable status mode. Values: 1 = Block, 2 = Block RST. |
integer |
| new_session_per_minute optional |
New Session per minute,range in (1-65535).origin_field:session_threshold. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| calc_avg_packet optional |
Number of TCP packets to carry a single HTTP request,range in (3-20).origin_field:calc_avg_packet. Minimum value : 3 Maximum value : 20 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| min_avg_length optional |
Smallest allowed TCP packet size of a splited HTTP request,range in (1-1500).origin_field:min_avg_length. Minimum value : 1 Maximum value : 1500 |
integer |
| timeout_interval optional |
Time interval between two packets (milliseconds),range in (1000-10000).origin_field:timeout_interval. Minimum value : 1000 Maximum value : 10000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet_size optional |
Packet length(bytes),range in (64-1500).origin_field:packet_size. Minimum value : 64 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration.origin_field:slow_rate_connection. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total Connection Moudle configuration.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration(seconds), range in (10-60).origin_field:banned_period. Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds) range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds) range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Total Connection per second,range in (100 - 4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
QUIC Malformed Packet Detection configuration. | malformed |
| quic_flood_protection optional |
QUIC Session Protection configuration.origin_field:protect. | quic_flood_protection |
| quic_ratelimit optional |
QUIC Ratelimit Module configuration.origin_field:traffic_rate_limit. | quic_ratelimit |
| Name | Description | Schema |
|---|---|---|
| handshake_min_len optional |
Minimum length (bytes) for handshake packets, range in (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| initial_min_len optional |
Minimum length (bytes) for initial packets, range in (1200-65535). Minimum value : 1200 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| support_version optional |
Supported QUIC versions:[‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. | < string > array |
| version_negotiation_min_len optional |
Minimum length (bytes) for version negotiation packets, range in (12-65535). Minimum value : 12 Maximum value : 65535 |
integer |
| zero_rtt_min_len optional |
Minimum length (bytes) for 0-RTT packets, range in (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| 0rtt_replay_attack_protection optional |
0-RTT replay attack protection configuration. | 0rtt_replay_attack_protection |
| authentication optional |
Authentication configuration. | authentication |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_source_ip optional |
Session (Per source IP) Module configuration.origin_field:new_session_limit. | new_session_per_source_ip |
| ratelimit_per_session optional |
Ratelimit (Per Session) Module configuration. origin_field:five_tuple_session. | ratelimit_per_session |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300). Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. |
integer |
| packet_per_second optional |
Packets per second threshold, range in (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| mode optional |
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. |
integer |
| session_scope optional |
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. | integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300).origin_field:action_duration. Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_second optional |
New sessions per second, range in (1-65535).origin_field:max_new_session. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. |
integer |
| session_check_duration optional |
Session check duration (seconds), range in (20-40).origin_field:check_time. Minimum value : 20 Maximum value : 40 |
integer |
| session_timeout optional |
Idle session timeout (seconds), range in (60-600).origin_field:idle_session_timeout. Minimum value : 60 Maximum value : 600 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packets optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_tcp_port optional |
TCP Port list. | < integer > array |
| filter_udp_port optional |
UDP Port list. | < integer > array |
| invite optional |
SIP INVITE message configuration. | invite |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed_is_enabled optional |
SIP Malformed enable status. Values: 0 = off, 1 = drop. |
integer |
| register optional |
SIP REGISTER Requst message configuration. | register |
| retransmission_is_enabled optional |
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. |
integer |
| tcp_connection optional |
TCP Connection protection configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Source IP average window size threshold.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range in (10-60).origin_field:banned_period. Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile optional |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
SSL/TLS Malformed Packet Detection configuration. | malformed |
| ratelimit optional |
SSL/TLS Ratelimit (Per Profile) configuration.origin_field:traffic_shaping. | ratelimit |
| renegotiation optional |
SSL/TLS Renegotiation configuration. | renegotiation |
| session optional |
SSL/TLS Session configuration. | session |
| tcp_connection optional |
Connection protection configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| clienthello_length_limit_non_v_1_3 optional |
ClientHello length (bytes) limit for non-TLS 1.3, range in (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| clienthello_length_limit_v_1_3 optional |
ClientHello length (bytes) limit for TLS 1.3, range in (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| Name | Description | Schema |
|---|---|---|
| non_tls optional |
Ratelimit for non TLS1.2 and TLS1.3 traffic. | non_tls |
| tls optional |
Ratelimit for TLS1.2 and TLS1.3 traffic. | tls |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| blocklist_duration optional |
Blocklist duration (seconds), range in (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300).origin_field:build_banned_period. Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = block. |
integer |
| new_session_per_second optional |
New session per second, range in (1-65535).origin_field:build_threshold. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Connection protection enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
This rule checks for slow rate connections from the same source IP address.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Avg.Window Size (bytes),range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Ban duration (seconds), range in (10-60). Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| tcp_ratelimit optional |
Host-level TCP bps/pps cap. | tcp_ratelimit |
| udp_ratelimit optional |
Host-level UDP bps/pps cap. | udp_ratelimit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| land_attack optional |
Mitigate LAND-style same src/dst attacks. | land_attack |
| martian_address optional |
Drop martian or reserved addresses. | martian_address |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| acl_filter optional |
ACL common and custom rule sets. | acl_filter |
| payload_filter optional |
Advanced payload filtering rules. | payload_filter |
| smart_filter optional |
Smart filter heuristic toggles. Not supported for IPv6. | smart_filter |
| Name | Description | Schema |
|---|---|---|
| acl_filter_rules optional |
Host-specific custom ACL rule set. | < acl_filter_rules > array |
| acl_filter_sets optional |
Shared ACL rule sets attached to the host. | < acl_filter_sets > array |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule.Can updated whern ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. | enum (any, tcp, udp, icmp, custom) |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| Name | Description | Schema |
|---|---|---|
| rule_set_desc optional |
Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_set_id required |
string | |
| rule_set_name optional |
Length : 1 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| Name | Description | Schema |
|---|---|---|
| filters optional |
List of user-defined filter rule objects. | < filters > array |
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. | enum (ratelimit, pass, drop) |
| bps_limit optional |
ratelimit in bps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique identifier of advanced rule. | string |
| filter_name optional |
The name of the policies. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| payload_string optional |
The string of the payload. | < string > array |
| port optional |
The lists of the port numbers. | < integer > array |
| pps_limit optional |
ratelimit in pps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the data packet. | enum (tcp, udp, ip, any) |
| Name | Description | Schema |
|---|---|---|
| amplification optional |
Amplification attack detection. | integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| threat_intelligence optional |
Threat intelligence integration. | integer |
| traffic_generator optional |
Traffic generator / lab source handling. | integer |
| Name | Description | Schema |
|---|---|---|
| anonymizer optional |
Anonymizer / proxy NTIF subgroups. | anonymizer |
| botnet optional |
Botnet-related NTIF subgroups. | botnet |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Schema |
|---|---|
| proxy optional |
proxy |
| tor optional |
tor |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Schema |
|---|---|
| dark_spider optional |
dark_spider |
| ddos optional |
ddos |
| malware optional |
malware |
| reputation optional |
reputation |
| scanner optional |
scanner |
| spam optional |
spam |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| flex_zombie optional |
< flex_zombie > array | |
| is_enabled optional |
0 = off, 1 = on . | integer |
| zombie_host optional |
Per-host zombie thresholds and action. | zombie_host |
| zombie_network optional |
Per-network zombie thresholds and action. | zombie_network |
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. | enum (pass, ratelimit, block) |
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| bps_limit optional |
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dip_prefix optional |
The IP Netmask of the destination IP address of the rule.Should be updated when ‘dip’ or ‘dip_dport’ mode is selected. Minimum value : 24 Maximum value : 32 |
integer |
| dst_ip optional |
< string > array | |
| dst_port optional |
< integer > array | |
| icmp_code optional |
The ICMP code of the rule.Should be updated when ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule.Should be updated when ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. | enum (any, tcp, udp, icmp) |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sip_prefix optional |
The IP Netmask of the source IP address of the rule.Should be updated when ‘sip’ or ‘sip_sport’ or ‘sip_dport’ mode is selected. Minimum value : 24 Maximum value : 32 |
integer |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| zombie_mode optional |
The mode of the rule.Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Default is sip. | enum (sip, dip, sip_sport, dip_dport, sip_dport) |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = off, 1 = on . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
application/json
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get mitigation policy.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/manual-mitigation-configuration
Description
Get mitigation policy for a host.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Full manual mitigation policy for a host: allow/block lists, anti-flood (L3/L4/L7), flex filters, zombie detection, traffic policing, NTIF, and bogon filtering. POST body: all policy sections must be present; nested objects use strict closed content (no extra properties). Identifiers and type are required; site_name / network_name / host_name are optional display fields. |
manual_mitigation_configuration |
manual_mitigation_configuration
| Name | Description | Schema |
|---|---|---|
| allow_block_list optional |
Allow list and block list configuration for source traffic. | allow_block_list |
| anti_flood optional |
Anti-flood policy: L3/L4 modules, L7 profiles, and aggregate protocol caps. | anti_flood |
| bogons optional |
Bogon and invalid address protections. | bogons |
| customer_id optional |
Customer identifier. | string |
| flex_filter optional |
Flex filters: payload, ACL, smart filter, TCP option sets. | flex_filter |
| host_id optional |
Host identifier. | string |
| network_id optional |
Network identifier. | string |
| ntif optional |
Network Threat Intelligence Feed categories and actions. Not supported for IPv6. | ntif |
| site_id optional |
Site identifier. | string |
| traffic_policing optional |
Traffic policing cap (bps/pps) for the host. | traffic_policing |
| zombie optional |
Zombie host detection (host vs network scope). Not supported for IPv6. | zombie |
| Name | Description | Schema |
|---|---|---|
| allow_list optional |
Trusted sources permitted when allow-list policy is enabled. | allow_list |
| block_list optional |
Sources to block or rate-limit when block-list policy is enabled. | block_list |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. Required when mode is 2. | string |
| mode optional |
Allow list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based allow-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2 such as US, CN; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| ip_set_id optional |
Referenced IP set ID. Required when mode is 2. | string |
| mode optional |
Block list mode: 0 = off; 1 = on (custom — user-defined entries); 2 = on using a specified template set. |
integer |
| source_countries optional |
String array of country or region codes for geo-based block-list matching. Each item is one code (e.g. ISO 3166-1 alpha-2; product-specific region codes may apply). | < enum (AF, AP, AX, AL, DZ, AS, AD, AO, AI, AQ, AG, AR, AM, AW, AU, AT, AZ, BH, BD, BB, BY, BE, BZ, BJ, BM, BT, BO, BQ, BA, BW, BV, BR, IO, BN, BG, BF, BI, CV, KH, CM, CA, KY, CF, TD, CL, CN, CX, CC, CO, KM, CK, CR, HR, CU, CW, CY, CZ, CD, DK, DJ, DM, DO, TL, EC, EG, SV, GQ, ER, EE, ET, FK, FO, FJ, FI, FR, GF, PF, TF, GA, GM, GE, DE, GH, GI, GR, GL, GD, GP, GU, GT, GG, GN, GW, GY, HT, HM, VA, HN, HK, HU, IS, IN, ID, IR, IQ, IE, IM, IL, IT, CI, JM, JP, JE, JO, KZ, KE, KI, KW, KG, LA, LV, LB, LS, LR, LY, LI, LT, LU, MO, MK, MG, MW, MY, MV, ML, MT, MH, MQ, MR, MU, YT, MX, FM, MD, MC, MN, ME, MS, MA, MZ, MM, NA, NR, NP, NL, NC, NZ, NI, NE, NG, NU, NF, KP, MP, NO, OM, PK, PW, PA, PG, PY, PE, PH, PN, PL, PT, PR, QA, RS, CG, RE, RO, RU, RW, BL, SH, KN, LC, MF, PM, VC, WS, SM, ST, SA, SN, SC, SL, SG, SX, SK, SI, SB, SO, ZA, GS, KR, SS, ES, LK, SD, SR, SJ, SZ, SE, CH, SY, TW, TJ, TH, BS, TG, TK, TO, TT, TN, TR, TM, TC, TV, UG, UA, AE, GB, TZ, UM, US, UY, UZ, VU, VE, VN, VG, VI, WF, PS, EH, YE, ZM, ZW) > array |
| source_ips optional |
List of source IPv4/IPv6 addresses or CIDR prefixes for this list. | < string > array |
| Name | Description | Schema |
|---|---|---|
| l3l4 optional |
l3l4 | |
| l7 optional |
Application-layer filter profiles (HTTP, TLS, SIP, QUIC, custom TCP). | l7 |
| protocol optional |
Per-protocol aggregate rate limits at host scope. | protocol |
| Name | Description | Schema |
|---|---|---|
| icmp optional |
ICMP flood, fragmentation, and custom ICMP filters. IPv6 is not supported. | icmp |
| ip optional |
IP-layer sanity and flood mitigation. | ip |
| tcp optional |
TCP flood, malformed TCP, SYN flood, session protect, and custom TCP filters. | tcp |
| udp optional |
UDP flood amplification handling. | udp |
| Name | Description | Schema |
|---|---|---|
| all_icmp_packet optional |
Drop all ICMP traffic when enabled. | all_icmp_packet |
| icmp_custom_filter optional |
icmp_custom_filter | |
| icmp_fragmentation optional |
ICMP fragmentation handling. | icmp_fragmentation |
| large_ping optional |
Drop oversized ICMP echo requests. | large_ping |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = drop all ICMP traffic . | integer |
| Name | Description | Schema |
|---|---|---|
| default optional |
Default ICMP filter applied when no custom rule matches. | default |
| filters optional |
< filters > array | |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit, pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Can not be edited. Length : 1 - 40 Pattern : "^[A-Za-z0-9_-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. ratelimit,pass). | enum (ratelimit, pass) |
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_description optional |
Filter description. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Unique filter profile ID. | string |
| filter_name optional |
Filter display or internal name. Length : 2 - 40 Pattern : "^[A-Za-z0-9_-]+$" |
string |
| icmp_length optional |
ICMP payload length threshold (bytes). Minimum value : 1 Maximum value : 1500 |
integer |
| icmp_type optional |
ICMP type number. Minimum value : 0 Maximum value : 31 |
integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix.1-4000000000 or number with unit K/M/G (e.g. 1K, 2 M, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| custom_protocol_filter optional |
Filter on specific IP protocol numbers. | custom_protocol_filter |
| ip_fragmentation optional |
IP fragmentation handling. | ip_fragmentation |
| ip_invalid optional |
Drop packets failing basic IP validity checks. | ip_invalid |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| protocol_numbers optional |
Per-protocol aggregate rate limits at host scope. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_fragmentation optional |
TCP fragmentation mitigation. | tcp_fragmentation |
| tcp_malformed optional |
Invalid TCP flags, SYN, and option handling. | tcp_malformed |
| tcp_rewrite_mss_size optional |
SYN MSS validation. | tcp_rewrite_mss_size |
| tcp_syn_anti_spoofing optional |
SYN flood protection: auth, trust, session limits, and SYN-ACK flood. | tcp_syn_anti_spoofing |
| tcp_syn_exclude_syn_ack_and_syn_ack_ecn optional |
Drop SYN-ACK and SYN-ACK-ECN packets. | tcp_syn_exclude_syn_ack_and_syn_ack_ecn |
| tcp_with_well_known_ports optional |
Drop invalid or sensitive destination-port packets. | tcp_with_well_known_ports |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| tcp_invalid_flags optional |
Illegal or suspicious TCP flag combinations. | tcp_invalid_flags |
| tcp_long_header optional |
Malformed or oversized SYN options. | tcp_long_header |
| tcp_syn_with_data optional |
SYN segments with non-zero payload. | tcp_syn_with_data |
| tcp_syn_with_reserved_flags optional |
Reserved TCP flag bits. | tcp_syn_with_reserved_flags |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
Size threshold in bytes (meaning depends on parent module). Minimum value : 34 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| graceful_challenges optional |
Graceful challenges. | graceful_challenges |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| rate_limit_per_connection optional |
Rate limit per connection. | rate_limit_per_connection |
| tcp_3_way_handshake_challenges optional |
TCP 3-way handshake challenges. | tcp_3_way_handshake_challenges |
| tcp_data optional |
TCP data validation. | tcp_data |
| tcp_retransmission optional |
TCP retransmission validation. | tcp_retransmission |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| duration optional |
Duration in seconds. Range: 10-150. Minimum value : 10 Maximum value : 150 |
integer |
| is_enabled optional |
0 = off, 1 = low rate_limit 500 pps, 2 = medium rate_limit 2000 pps, 3 = high rate_limit 4000 pps. | integer |
| timeout optional |
Timeout duration in seconds. Range: 10-3600. Minimum value : 60 Maximum value : 600 |
integer |
tcp_3_way_handshake_challenges
| Name | Description | Schema |
|---|---|---|
| mode optional |
0 = tcp retransmission, 1 = tcp data, 2 = auto. | integer |
| Name | Description | Schema |
|---|---|---|
| server_ip_validation optional |
Server IP validation. | server_ip_validation |
| traffic_policing optional |
Traffic policing. | traffic_policing |
| Name | Description | Schema |
|---|---|---|
| bot_mitigation optional |
Bot mitigation validation. | bot_mitigation |
| spoofed_carpet_bombing_mitigation optional |
Spoofed carpet bombing mitigation validation. | spoofed_carpet_bombing_mitigation |
| tcp_fast_open optional |
TCP fast open validation. | tcp_fast_open |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
spoofed_carpet_bombing_mitigation
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| suspicious_receiver_ip_rate_limit optional |
Suspicious receiver IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| total_rate_limit optional |
Total rate limit in packets per second. Range: 100-4000000000. Minimum value : 100 Maximum value : 4000000000 |
integer |
| validated_server_ip_rate_limit optional |
Validated server IP rate limit in packets per second. Range: 100-4000000000. Must be less than or equal to total_rate_limit. Minimum value : 100 Maximum value : 4000000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| validation_mode optional |
0 = half open, 1 = full open. | integer |
| validation_trust_mode optional |
0 = host, 1 = network. | integer |
tcp_syn_exclude_syn_ack_and_syn_ack_ecn
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| ntp_amplification optional |
ntp_amplification | |
| snmp_amplification optional |
snmp_amplification | |
| ssdp_flood optional |
SSDP flood handling. | ssdp_flood |
| udp_contain_all_zero_data optional |
UDP contain all zero data handling. | udp_contain_all_zero_data |
| udp_flood_amplification optional |
udp_flood_amplification | |
| udp_fragmentation optional |
UDP fragmentation handling. | udp_fragmentation |
| udp_malformed optional |
UDP malformed handling. | udp_malformed |
| udp_with_port_number_lt_1024 optional |
UDP with port number less than 1024 handling. | udp_with_port_number_lt_1024 |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| ntp_response_length optional |
NTP response length handling. | ntp_response_length |
| ntp_response_monlist_drop optional |
NTP response MONLIST drop handling. | ntp_response_monlist_drop |
| ntp_response_rate_limit optional |
NTP response rate limit handling. | ntp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| size optional |
The size of the NTP response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| snmp_response_rate_limit optional |
SNMP response rate limit handling. | snmp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled. | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| zero_data_min_length optional |
The minimum length of the zero data payload. Minimum value : 42 Maximum value : 128 |
integer |
| Name | Description | Schema |
|---|---|---|
| dns_query_length optional |
DNS query length handling. | dns_query_length |
| dns_query_rate_limit optional |
DNS query rate limit handling. | dns_query_rate_limit |
| dns_response_length optional |
DNS response length handling. | dns_response_length |
| dns_response_rate_limit optional |
DNS response rate limit handling. | dns_response_rate_limit |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
The size of the DNS query. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| size optional |
The size of the DNS response. Minimum value : 42 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| udp_packet_contain_no_data optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| custom optional |
Custom L7 (TCP) filter profiles for this host. | custom |
| http optional |
HTTP-related options under TCP SYN flood (profiles, port limit). Supported when TCP Anti-Spoofing is enabled. | http |
| quic optional |
QUIC L7 filter profiles for this host. | quic |
| sip optional |
SIP L7 filter profiles for this host. | sip |
| tls optional |
TLS L7 filter profiles for this host. Supported when TCP Anti-Spoofing is enabled. | tls |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of Custom L7 (TCP) filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_desc optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| tcp_connection optional |
TCP Connection Module configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total Connection Moudle configuration.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Schema |
|---|---|
| profile optional |
< profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. | string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| http_authentication optional |
HTTP Authentication Module configuration.origin_field:authentication. | http_authentication |
| http_slow_rate optional |
HTTP Slow Rate Module configuration.origin_field:slow_attack. | http_slow_rate |
| is_enabled optional |
Filter status. Values: 0 = on, 1 = off. |
integer |
| tcp_connection optional |
TCP Connection Module configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| model optional |
Authentication mode. Values: 1 = HTTP ‘HTTP 302⁄307 Redirect’, 2 = HTTP ‘HTTP Meta Refresh’, 3 = JavaScript ‘JavaScript’. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-86400).origin_field:block_duration. Minimum value : 1 Maximum value : 86400 |
integer |
| body optional |
HTTP Slow Body Module configuration. | body |
| header optional |
HTTP Slow Header Module configuration. | header |
| is_enabled optional |
Enable status mode. Values: 1 = Block, 2 = Block RST. |
integer |
| new_session_per_minute optional |
New Session per minute,range in (1-65535).origin_field:session_threshold. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| calc_avg_packet optional |
Number of TCP packets to carry a single HTTP request,range in (3-20).origin_field:calc_avg_packet. Minimum value : 3 Maximum value : 20 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| min_avg_length optional |
Smallest allowed TCP packet size of a splited HTTP request,range in (1-1500).origin_field:min_avg_length. Minimum value : 1 Maximum value : 1500 |
integer |
| timeout_interval optional |
Time interval between two packets (milliseconds),range in (1000-10000).origin_field:timeout_interval. Minimum value : 1000 Maximum value : 10000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet_size optional |
Packet length(bytes),range in (64-1500).origin_field:packet_size. Minimum value : 64 Maximum value : 1500 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Slow Rate Connection Module configuration.origin_field:slow_rate_connection. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP Half Open Connection Module configuration.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP Idle Connection Module configuration.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP New Connection Module configuration.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total Connection Moudle configuration.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration(seconds), range in (10-60).origin_field:banned_period. Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds) range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration(seconds) range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Total Connection per second,range in (100 - 4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
QUIC Malformed Packet Detection configuration. | malformed |
| quic_flood_protection optional |
QUIC Session Protection configuration.origin_field:protect. | quic_flood_protection |
| quic_ratelimit optional |
QUIC Ratelimit Module configuration.origin_field:traffic_rate_limit. | quic_ratelimit |
| Name | Description | Schema |
|---|---|---|
| handshake_min_len optional |
Minimum length (bytes) for handshake packets, range in (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| initial_min_len optional |
Minimum length (bytes) for initial packets, range in (1200-65535). Minimum value : 1200 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| support_version optional |
Supported QUIC versions:[‘v1’, ‘v2’, ‘draft27’,‘draft28’,‘draft29’,‘draft30’,‘draft31’,‘draft32’,‘draft33’,‘draft34’]. | < string > array |
| version_negotiation_min_len optional |
Minimum length (bytes) for version negotiation packets, range in (12-65535). Minimum value : 12 Maximum value : 65535 |
integer |
| zero_rtt_min_len optional |
Minimum length (bytes) for 0-RTT packets, range in (10-65535). Minimum value : 10 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| 0rtt_replay_attack_protection optional |
0-RTT replay attack protection configuration. | 0rtt_replay_attack_protection |
| authentication optional |
Authentication configuration. | authentication |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_source_ip optional |
Session (Per source IP) Module configuration.origin_field:new_session_limit. | new_session_per_source_ip |
| ratelimit_per_session optional |
Ratelimit (Per Session) Module configuration. origin_field:five_tuple_session. | ratelimit_per_session |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300). Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit, 2 = block. |
integer |
| packet_per_second optional |
Packets per second threshold, range in (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| mode optional |
Authentication mode. Values: 0 = ‘Retransmission’, 1 = ‘Retry + Token’. |
integer |
| session_scope optional |
Session scope. 0 means ‘New Session Only’, 1 means ‘New andExisting Session’. | integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300).origin_field:action_duration. Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| new_session_per_second optional |
New sessions per second, range in (1-65535).origin_field:max_new_session. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = low level, 2 = medium level, 3 = high level. |
integer |
| session_check_duration optional |
Session check duration (seconds), range in (20-40).origin_field:check_time. Minimum value : 20 Maximum value : 40 |
integer |
| session_timeout optional |
Idle session timeout (seconds), range in (60-600).origin_field:idle_session_timeout. Minimum value : 60 Maximum value : 600 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packets optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile required |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_tcp_port optional |
TCP Port list. | < integer > array |
| filter_udp_port optional |
UDP Port list. | < integer > array |
| invite optional |
SIP INVITE message configuration. | invite |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed_is_enabled optional |
SIP Malformed enable status. Values: 0 = off, 1 = drop. |
integer |
| register optional |
SIP REGISTER Requst message configuration. | register |
| retransmission_is_enabled optional |
UDP Retransmission Authentication enable status. Values: 0 = off, 1 = drop. |
integer |
| tcp_connection optional |
TCP Connection protection configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = rate limit. |
integer |
| tcp optional |
TCP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| udp optional |
UDP message size limit, range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
Source IP average window size threshold.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Sessions per second,range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Block duration (seconds), range in (10-60).origin_field:banned_period. Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Half-open connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Idle connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
New connections per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| profile optional |
List of L7 filter profile objects returned by policy APIs. | < profile > array |
| Name | Description | Schema |
|---|---|---|
| filter_description optional |
Filter description, length 0-100 characters. Length : 0 - 100 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| filter_id required |
Filter Profile ID. Length : 1 - 40 |
string |
| filter_name optional |
Filter name; letters, digits, underscore, hyphen, and space; length 1-40 characters. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| filter_port optional |
TCP Port list. | < integer > array |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| malformed optional |
SSL/TLS Malformed Packet Detection configuration. | malformed |
| ratelimit optional |
SSL/TLS Ratelimit (Per Profile) configuration.origin_field:traffic_shaping. | ratelimit |
| renegotiation optional |
SSL/TLS Renegotiation configuration. | renegotiation |
| session optional |
SSL/TLS Session configuration. | session |
| tcp_connection optional |
Connection protection configuration.origin_field:connection_protect. | tcp_connection |
| Name | Description | Schema |
|---|---|---|
| clienthello_length_limit_non_v_1_3 optional |
ClientHello length (bytes) limit for non-TLS 1.3, range in (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| clienthello_length_limit_v_1_3 optional |
ClientHello length (bytes) limit for TLS 1.3, range in (64-1400). Minimum value : 64 Maximum value : 1400 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| Name | Description | Schema |
|---|---|---|
| non_tls optional |
Ratelimit for non TLS1.2 and TLS1.3 traffic. | non_tls |
| tls optional |
Ratelimit for TLS1.2 and TLS1.3 traffic. | tls |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| bandwidth optional |
Bandwidth limit (Mbps), range in (1-4095). Minimum value : 1 Maximum value : 4095 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = on. |
integer |
| packet optional |
Packet rate limit (pps), range in (1-1000000). Minimum value : 1 Maximum value : 1000000 |
integer |
| Name | Description | Schema |
|---|---|---|
| blocklist_duration optional |
Blocklist duration (seconds), range in (1-65535). Minimum value : 1 Maximum value : 65535 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = drop. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Block duration (seconds), range in (1-300).origin_field:build_banned_period. Minimum value : 1 Maximum value : 300 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = block. |
integer |
| new_session_per_second optional |
New session per second, range in (1-65535).origin_field:build_threshold. Minimum value : 1 Maximum value : 65535 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Connection protection enable status. Values: 0 = off, 1 = on. |
integer |
| slow_rate_connection optional |
This rule checks for slow rate connections from the same source IP address.origin_field:src_ip_avg_window_size_threshold. | slow_rate_connection |
| source_ip_half_open_connection optional |
Source IP half-open connection rate limiting.origin_field:src_ip_half_open_rate. | source_ip_half_open_connection |
| source_ip_idle_connection optional |
Source IP idle connection rate limiting.origin_field:src_ip_idle_connection_rate. | source_ip_idle_connection |
| source_ip_new_connection optional |
Source IP connection rate limiting.origin_field:src_ip_connection_rate. | source_ip_new_connection |
| total_connection optional |
Total connection rate limiting.origin_field:total_connection_rate. | total_connection |
| Name | Description | Schema |
|---|---|---|
| avg_window_size optional |
Avg.Window Size (bytes),range in (1-65535).origin_field:session_per_second. Minimum value : 1 Maximum value : 65535 |
integer |
| block_duration optional |
Ban duration (seconds), range in (10-60). Minimum value : 10 Maximum value : 60 |
integer |
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = block. |
integer |
source_ip_half_open_connection
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| half_open_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP half-open connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| idle_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| is_enabled optional |
Source IP idle connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Ban duration (seconds), range in (10-600).origin_field:banned_period. Minimum value : 10 Maximum value : 600 |
integer |
| is_enabled optional |
Source IP connection rate limiting enable status. Values: 0 = off, 1 = monitor, 2 = rate limit, 3 = block. |
integer |
| new_connection_per_second optional |
Sessions per second,range in (5-1000).origin_field:session_per_second. Minimum value : 5 Maximum value : 1000 |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
Enable status. Values: 0 = off, 1 = monitor, 2 = rate limit. |
integer |
| total_connection_per_second optional |
Sessions per second,range in (100-4294967295).origin_field:session_per_second. Minimum value : 100 Maximum value : 4294967295 |
integer |
| Name | Description | Schema |
|---|---|---|
| tcp_ratelimit optional |
Host-level TCP bps/pps cap. | tcp_ratelimit |
| udp_ratelimit optional |
Host-level UDP bps/pps cap. | udp_ratelimit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
Bandwidth cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
Packet rate cap as numeric string, optional K/M/G suffix. Plain or K/M: 1-4000000000; G suffix: 1G-4G. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| land_attack optional |
Mitigate LAND-style same src/dst attacks. | land_attack |
| martian_address optional |
Drop martian or reserved addresses. | martian_address |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| acl_filter optional |
ACL common and custom rule sets. | acl_filter |
| payload_filter optional |
Advanced payload filtering rules. | payload_filter |
| smart_filter optional |
Smart filter heuristic toggles. Not supported for IPv6. | smart_filter |
| Name | Description | Schema |
|---|---|---|
| acl_filter_rules optional |
Host-specific custom ACL rule set. | < acl_filter_rules > array |
| acl_filter_sets optional |
Shared ACL rule sets attached to the host. | < acl_filter_sets > array |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. | enum (ratelimit, pass, drop) |
| bps_limit optional |
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dst_ip optional |
< string > array | |
| dst_port optional |
The destination port of the rule. Can be updated when the protocol is any, tcp or udp. | < integer > array |
| icmp_code optional |
The ICMP code of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule.Can updated whern ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| package_length optional |
The package length of the rule. Can be updated regardless of the selected protocol. | < string > array |
| pps_limit optional |
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. | enum (any, tcp, udp, icmp, custom) |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| Name | Description | Schema |
|---|---|---|
| rule_set_desc optional |
Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_set_id required |
string | |
| rule_set_name optional |
Length : 1 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| Name | Description | Schema |
|---|---|---|
| filters optional |
List of user-defined filter rule objects. | < filters > array |
| Name | Description | Schema |
|---|---|---|
| action optional |
An action will be taken when they match. | enum (ratelimit, pass, drop) |
| bps_limit optional |
ratelimit in bps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| filter_id required |
Unique identifier of advanced rule. | string |
| filter_name optional |
The name of the policies. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| payload_string optional |
The string of the payload. | < string > array |
| port optional |
The lists of the port numbers. | < integer > array |
| pps_limit optional |
ratelimit in pps. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the data packet. | enum (tcp, udp, ip, any) |
| Name | Description | Schema |
|---|---|---|
| amplification optional |
Amplification attack detection. | integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| threat_intelligence optional |
Threat intelligence integration. | integer |
| traffic_generator optional |
Traffic generator / lab source handling. | integer |
| Name | Description | Schema |
|---|---|---|
| anonymizer optional |
Anonymizer / proxy NTIF subgroups. | anonymizer |
| botnet optional |
Botnet-related NTIF subgroups. | botnet |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| Name | Schema |
|---|---|
| proxy optional |
proxy |
| tor optional |
tor |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Schema |
|---|---|
| dark_spider optional |
dark_spider |
| ddos optional |
ddos |
| malware optional |
malware |
| reputation optional |
reputation |
| scanner optional |
scanner |
| spam optional |
spam |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| action optional |
Mitigation action (e.g. off, monitor, drop). | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M suffix: 1-4000000000; G suffix: 1G-4G only (e.g. 1K, 2 M, 4G, 4 G). Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| flex_zombie optional |
< flex_zombie > array | |
| is_enabled optional |
0 = off, 1 = on . | integer |
| zombie_host optional |
Per-host zombie thresholds and action. | zombie_host |
| zombie_network optional |
Per-network zombie thresholds and action. | zombie_network |
| Name | Description | Schema |
|---|---|---|
| action optional |
The action of the rule. | enum (pass, ratelimit, block) |
| bps_limit optional |
The rate limit in bps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| dip_prefix optional |
The IP Netmask of the destination IP address of the rule.Should be updated when ‘dip’ or ‘dip_dport’ mode is selected. Minimum value : 24 Maximum value : 32 |
integer |
| dst_ip optional |
< string > array | |
| dst_port optional |
< integer > array | |
| icmp_code optional |
The ICMP code of the rule.Should be updated when ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 255 |
integer |
| icmp_type optional |
The ICMP type of the rule.Should be updated when ‘icmp’ protocol is selected. Minimum value : 0 Maximum value : 31 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| pps_limit optional |
The rate limit in pps of the rule.Should be updated when ‘ratelimit’ action is selected. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| protocol optional |
The protocol of the rule. | enum (any, tcp, udp, icmp) |
| rule_desc optional |
The description of the rule. Length : 0 - 128 Pattern : "^[A-Za-z0-9_ -]*$" |
string |
| rule_id required |
The unique identifier of the rule. | string |
| rule_name optional |
The name of the rule. Length : 2 - 40 Pattern : "^[A-Za-z0-9_ -]+$" |
string |
| sip_prefix optional |
The IP Netmask of the source IP address of the rule.Should be updated when ‘sip’ or ‘sip_sport’ or ‘sip_dport’ mode is selected. Minimum value : 24 Maximum value : 32 |
integer |
| sort_order optional |
The sort order of the rule. | integer |
| src_ip optional |
< string > array | |
| src_port optional |
< integer > array | |
| ttl optional |
The TTL of the rule. Minimum value : 0 Maximum value : 255 |
integer |
| zombie_mode optional |
The mode of the rule.Mode values: sip - Source IP, dip - Destination IP, sip_sport - Source IP and Source Port, dip_dport - Destination IP and Destination Port, sip_dport - Source IP and Destination Port. Default is sip. | enum (sip, dip, sip_sport, dip_dport, sip_dport) |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = disabled, 1 = enabled . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| Name | Description | Schema |
|---|---|---|
| block_duration optional |
Blocklist duration in seconds after a trigger. Minimum value : 10 Maximum value : 120 |
integer |
| is_enabled optional |
0 = off, 1 = on . | integer |
| mode optional |
Mitigation action (e.g. ratelimit, block). | enum (ratelimit, block) |
| threshold_bps optional |
Trigger threshold in bps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
| threshold_pps optional |
Trigger threshold in pps (string with optional K/M/G). Plain or K/M: 1-4000000000; G suffix: 1G-4G only. Pattern : "^(?:(?:(?:4000000000)\|(?:[1-3][0-9]{9})\|(?:[1-9][0-9]{0,8}))(?:[KMkm]\|\\s+[KMkm])?\|[1-4](?:[Gg]\|\\s+[Gg]))$" |
string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get the info of mitigation for TCP flood.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood
Description
Get the info of mitigation for TCP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| malformed_tcp_packets optional |
The info of the malformed TCP packets. | malformed_tcp_packets |
| tcp_fragmentation optional |
The info of TCP fragmentation. | tcp_fragmentation |
| tcp_rate_limit optional |
The info of TCP rate limit. | tcp_rate_limit |
| tcp_syn_flood optional |
The info of TCP syn flood. | tcp_syn_flood |
| tcp_syn_mss optional |
The info of TCP syn mss. | tcp_syn_mss |
| Name | Schema |
|---|---|
| invalid_tcp_flag optional |
invalid_tcp_flag |
| invalid_tcp_reserved_flag optional |
invalid_tcp_reserved_flag |
| invalid_tcp_syn_option optional |
invalid_tcp_syn_option |
| invalid_tcp_syn_payload optional |
invalid_tcp_syn_payload |
| tcp_syn optional |
tcp_syn |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| size optional |
The size of the TCP from the option. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| size optional |
The size of the payload. | integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
The ratelimit in bps. | string |
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| pps_limit optional |
The ratelimit in pps. | string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| session_check optional |
session_check | |
| session_timeout optional |
session_timeout | |
| syn_authentication optional |
syn_authentication |
| Name | Description | Schema |
|---|---|---|
| seconds optional |
The amount of time, in seconds, to wait before checking an SYN session. | integer |
| Name | Description | Schema |
|---|---|---|
| seconds optional |
The minimum time, in seconds, for the SYN-packet retransmission to consider the retransmission to be valid. | integer |
| Name | Description | Schema |
|---|---|---|
| strict_mode optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| syn_auth optional |
The model of TCP syn authentication. | string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| size optional |
The size of the maximum segment. | integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit TCP Flood/Malformed TCP packets.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/packets
Description
Edit TCP Flood/Malformed TCP packets.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | module required |
TCP flood/malformed TCP packets type. in (payload、option). | string |
| FormData | size required |
The size of string must range between 0 and 1500. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policy for TCP flood or malformed TCP packets.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/packets/switch
Description
Change the mitigation policy for TCP flood or malformed TCP packets.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means TCP flood switch is disabled whereas 1 mean it is enabled. |
integer |
| FormData | module required |
The type of TCP flood switch consists of invalid_tcp_flag,invalid_tcp_reserved_flag,tcp_syn,invalid_tcp_syn_payload,invalid_tcp_syn_option. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit TCP Flood/TCP rate limit.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/rate-limit
Description
Edit TCP Flood/TCP rate limit.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | bps_limit required |
The ratelimit in bps.must be a number or K, M, G format. | string |
| FormData | pps_limit required |
The ratelimit in pps.must be a number or K, M, G format. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the status of the policies for TCP flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/switch
Description
Change the status of the policies for TCP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| FormData | module required |
The switch for the type of icmp flood includes tcp_rate_limit,tcp_fragmentation,tcp_syn_mss,tcp_syn_flood. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit TCP Flood/TCP SYN Flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/syn-flood
Description
Edit TCP Flood/TCP SYN Flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | session_check_seconds optional |
The amount of time, in seconds, to wait before checking an SYN session. It is set to a value between 10 and 255. | integer |
| FormData | session_timeout_seconds optional |
The minimum time, in seconds, for the SYN-packet retransmission to consider the retransmission to be valid. It is set to a value between 60 and 600. | integer |
| FormData | strict_mode optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit TCP Flood/TCP SYN MSS.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-flood/syn-mss
Description
Edit TCP Flood/TCP SYN MSS.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | size required |
The size of string must range between 34 and 1500. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policy for the FlexFilter/filter sets.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/filter-sets
Description
Edit the policy for the FlexFilter/filter sets.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | filter_set_id required |
Enter the filter set id you want to add.Currently only supports adding one option. | < string > array |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policy for the FlexFilter/tcp option filter sets.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/policy
Description
Edit the policy for the FlexFilter/tcp option filter sets.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | This is the returned result. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| filter_sets optional |
< filter_sets > array | |
| is_enabled optional |
Status of the tcp option filter. ‘0’ means off, ‘1’ means on. | integer |
| Name | Description | Schema |
|---|---|---|
| filter_set_desc optional |
More details about the purpose of the policy. | string |
| filter_set_id optional |
Unique identifier of filter set. | string |
| filter_set_name optional |
The name of the policy. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Changes the status of the switch for the policies for FlexFilter/basic network filtering.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/tcp-option/switch
Description
Changes the status of the switch for the policies for FlexFilter/basic network filtering.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch of the basic network filtering is disabled whereas 1 means it is enabled. |
integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get traffic statistics for a specific host.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/traffic
Description
Retrieve bandwidth and packet rate statistics for a specific host in the network.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | period optional |
Time period for which traffic statistics are requested. Valid values: hour, day, week, month, default is hour. |
enum (hour, day, week, month) |
| Query | unit optional |
Unit of time for which traffic statistics are requested. Valid values: bps, pps, bytes,‘packets’. |
enum (bps, pps, bytes, packets) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Traffic statistics data | result |
| Name | Description | Schema |
|---|---|---|
| data optional |
Traffic statistics data | data |
| time optional |
Timestamp for the traffic statistics data | < integer > array |
| Name | Description | Schema |
|---|---|---|
| bps optional |
Traffic statistics data in bits per second | bps |
| bytes optional |
Traffic statistics data in bytes | bytes |
| packets optional |
Traffic statistics data in packets | packets |
| pps optional |
Traffic statistics data in packets per second | pps |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the info of the mitigation of TCP Flood.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood
Description
Gets the info of the mitigation of TCP Flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| dns_flood_amplification optional |
The info of DNS flood and its amplification. | dns_flood_amplification |
| no_data_payload optional |
The info of No data payload. | no_data_payload |
| ntp_amplification optional |
The info of NTP amplification. | ntp_amplification |
| snmp_amplification optional |
The info of SNMP amplification. | snmp_amplification |
| ssdp_flood optional |
The info of SSDP flood. | ssdp_flood |
| udp_fragmentation optional |
The info of UDP fragmentation. | udp_fragmentation |
| udp_rate_limit optional |
The info about the rate limit of UDP. | udp_rate_limit |
| zero_data_payload optional |
The info of Zero data payload. | zero_data_payload |
| Name | Schema |
|---|---|
| dns_query_length optional |
dns_query_length |
| dns_query_rate_limit optional |
dns_query_rate_limit |
| dns_response_length optional |
dns_response_length |
| dns_response_rate_limit optional |
dns_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| size optional |
The size of the DNS query. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
ratelimit in bps. | string |
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| pps_limit optional |
ratelimit in pps. | string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| size optional |
The size of the DNS response. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
ratelimit in bps. | string |
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| pps_limit optional |
ratelimit in pps. | string |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 it is enabled. |
integer |
| Name | Schema |
|---|---|
| ntp_response_length optional |
ntp_response_length |
| ntp_response_rate_limit optional |
ntp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| size optional |
The size of the NTP response. | integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
ratelimit in bps. | string |
| is_enabled optional |
State of the switch. 0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| pps_limit optional |
ratelimit in pps. | string |
| Name | Schema |
|---|---|
| snmp_response_rate_limit optional |
snmp_response_rate_limit |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
ratelimit in bps. | string |
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| pps_limit optional |
ratelimit in pps. | string |
| Name | Schema |
|---|---|
| drop_ssdp optional |
drop_ssdp |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas ‘1” means it is enabled. |
integer |
| Name | Description | Schema |
|---|---|---|
| bps_limit optional |
ratelimit in bps. | string |
| is_enabled optional |
0 means the switch is disabled whereas ‘1” means it is enabled. |
integer |
| pps_limit optional |
ratelimit in pps. | string |
| Name | Schema |
|---|---|
| drop_ssdp optional |
drop_ssdp |
| Name | Description | Schema |
|---|---|---|
| is_enabled optional |
0 means the switch is disabled whereas 1 mean it is enabled. |
integer |
| zero_payload_length optional |
The length of the zero payload. | integer |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the info of submodule of the UDP flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/policy
Description
Edit the info of submodule of the UDP flood including DNS Flood & Amplification) & NTP Amplification & SNMP Amplification.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | bps_limit optional |
When the module is dns_query_rate_limit,udp_rate_limit or dns_response_rate_limit, the unit of rate limit must be K, M and G. | string |
| FormData | module required |
The switch for the type of UDP flood module includes dns_query_length,dns_query_rate_limit,dns_response_length,dns_response_rate_limit,ntp_response_length,ntp_response_rate_limit,snmp_response_rate_limit,udp_rate_limit. | string |
| FormData | pps_limit optional |
When the module is dns_query_rate_limit,udp_rate_limit or dns_response_rate_limit, the unit of rate limit must be K, M and G. | string |
| FormData | size optional |
When the module is selected as dns_query_length or dns_response_length, the size must range between 1 and 1500. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policies for UDP flood submodule.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/policy/switch
Description
Change the mitigation policies for UDP flood submodule.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the sub switch for the policies for the UDP flood is disabled whereas 1 means it is enabled. |
integer |
| FormData | module required |
The switch for the type of UDP flood module includes dns_query_length,dns_query_rate_limit,dns_response_length,dns_response_rate_limit,ntp_response_length,ntp_response_rate_limit,snmp_response_rate_limit,drop_ssdp. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Change the mitigation policies for UDP flood.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/switch
Description
Change the mitigation policies for UDP flood.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the switch for the policies of UDP flood is disabled whereas 1 means it is enabled. |
integer |
| FormData | module required |
The policies for UDP flood can handle udp_fragmentation,no_data_payload,udp_rate_limit,zero_data_payload. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Edit the policies for UDP flood/UDP zero data payload.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/udp-flood/zero-data-payload
Description
Edit the policies for UDP flood/UDP zero data payload.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | length required |
Length of the zero payload.Max matched length of zero data payload is limited 1-128 bytes. | integer |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
It is used to edit the filter for Zombie
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie
Description
It is used to edit the filter for Zombie
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | action required |
ratelimit or blacklist. | string |
| FormData | blacklist_timeout required |
Blacklist timeout. | integer |
| FormData | threshold_bps required |
Threshold values in bps.must be a number or K, M, G format. | string |
| FormData | threshold_pps required |
Threshold values in pps.must be a number or K, M, G format. | string |
| FormData | zombie_type required |
Zombie level. zombie_host or zombie_network. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the info of the policy for zombie.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie
Description
Gets the info of the policy for zombie.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
result |
| Name | Description | Schema |
|---|---|---|
| zombie_host optional |
Host level configuration. | zombie_host |
| zombie_network optional |
Network level configuration. | zombie_network |
| Name | Description | Schema |
|---|---|---|
| action optional |
ratelimit or blacklist. | string |
| blacklist_timeout optional |
Blacklist timeout. | integer |
| is_enabled optional |
0 means the switch is disabled whereas 1 means it is enabled. |
integer |
| threshold_bps optional |
Threshold values in bps. | string |
| threshold_pps optional |
Threshold values in pps. | string |
| Name | Description | Schema |
|---|---|---|
| action optional |
ratelimit or blacklist. | string |
| blacklist_timeout optional |
Blacklist timeout. | integer |
| is_enabled optional |
State of the switch. 0 means it is disabled and 1 means enabled. |
integer |
| threshold_bps optional |
Threshold values in bps. | string |
| threshold_pps optional |
Threshold values in pps. | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
It is used to change the status of Zombie.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/mitigation/zombie/switch
Description
It is used to change the status of Zombie.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API.Can be obtained by invoking this API. | string |
| FormData | is_enabled required |
0 means the mitigation policy for zombie is disabled whereas 1 means it is enabled. |
integer |
| FormData | zombie_type required |
Zombie level. zombie_host or zombie_network. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Get traffic statistics for specific hosts.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/mitigation/host-traffic
Description
Retrieve bandwidth and packet rate statistics for a specific host in the network.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | host_ids required |
Unique identifier of hosts. if empty, all hosts will be returned. 1-100 hosts are supported. | < string > array(multi) |
| Query | period optional |
Time period for which traffic statistics are requested. Valid values: hour, day, week, month. |
enum (hour, day, week, month) |
| Query | traffic_metrics optional |
Units of traffic metrics to be returned. Valid values: bps, pps, bytes, packets. |
< enum (bps, pps, bytes, packets) > array(multi) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Traffic statistics data | result |
| Name | Description | Schema |
|---|---|---|
| host_id optional |
Unique identifier of a host. | host_id |
| Name | Description | Schema |
|---|---|---|
| data optional |
Traffic statistics data | data |
| host_ip optional |
< string > array | |
| time optional |
Timestamp for the traffic statistics data | < integer > array |
| Name | Description | Schema |
|---|---|---|
| bps optional |
Traffic statistics data in bits per second | bps |
| bytes optional |
Traffic statistics data in bytes | bytes |
| packets optional |
Traffic statistics data in packets | packets |
| pps optional |
Traffic statistics data in packets per second | pps |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
| Name | Description | Schema |
|---|---|---|
| drop optional |
Dropped traffic data | < integer > array |
| pass optional |
Passed traffic data. | < integer > array |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Security
ApiKeyAuth
Type : apiKey
Name : access_token
In : QUERY