ipv4FirewallTypeRule
Unique identifier.
Name of the firewall rule.
Possible values: non-empty and <= 60 characters
Description of the firewall rule.
Possible values: <= 255 characters
Rule type.
Possible values: [firewall]
trueFirewall action. If action is set to drop or reject, securityFeatures, qos, synchronizedSecurityHeartbeat, and emailScanning aren't saved.
Possible values: [accept, drop, reject]
acceptsourceZones objectrequired
Matching zones.
- anyZones
- selectedZones
Possible values: [true]
destinationZones objectrequired
Matching zones.
- anyZones
- selectedZones
Possible values: [true]
sourceNetworks objectrequired
Matching IPv4 networks.
- anyIpv4Networks
- selectedIpv4Networks
Possible values: [true]
destinationNetworks objectrequired
Matching IPv4 networks.
- anyIpv4Networks
- selectedIpv4Networks
Possible values: [true]
servicesOrGroups objectrequired
Matching services or groups.
- anyServicesOrGroups
- selectedServicesOrGroups
Possible values: [true]
userAuthentication object
User authentication settings. When userAuthentication is turned on, the firewall automatically assigns the user's traffic shaping policy.
usersOrGroups objectnullable
Matching users or groups.
- anyUsersOrGroups
- selectedUsersOrGroups
Possible values: [true]
Exclude users from accounting.
falseWeb authentication for unknown users.
falseexclusions object
Traffic excluded from IPv4 security scanning.
sourceZones object
Selected zones.
zones object[]
Possible values: non-empty and <= 60 characters
destinationZones object
Selected zones.
zones object[]
Possible values: non-empty and <= 60 characters
sourceNetworks object
Selected IPv4 networks.
countries object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
countryGroups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
fqdnAddresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
fqdnGroups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
ipv4Addresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
ipv4Groups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
macAddresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
destinationNetworks object
Selected IPv4 networks.
countries object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
countryGroups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
fqdnAddresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
fqdnGroups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
ipv4Addresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
ipv4Groups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
macAddresses object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
servicesOrGroups object
Selected service or group.
services object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
serviceGroups object[]
Possible values: <= 1024
Possible values: non-empty and <= 60 characters
synchronizedSecurityHeartbeat object
Heartbeat enforcement.
source object
Block traffic.
falseMinimum required heartbeat.
Possible values: [green, noRestriction, yellow]
noRestrictiondestination object
Block traffic.
falseMinimum required heartbeat.
Possible values: [green, noRestriction, yellow]
noRestrictionsecurityFeatures object
Security features. When webPolicy is null and scanHttpAndDecryptedHttps is false, set the following fields to false: webProxy, webCategoryBasedQosPolicy, blockQuicProtocol, decryptHTTPSWebProxyMode. When scanHttpAndDecryptedHttps is false, set zeroDayProtection to false. When applicationPolicy is null, set applicationBasedQosPolicy to false.
Application based QoS policy.
falseapplicationPolicy objectnullable
Reference to an object by name.
Possible values: non-empty and <= 60 characters
Block QUIC traffic.
falseDecrypt HTTPS traffic.
falseipsPolicy objectnullable
Reference to an object by name.
Possible values: non-empty and <= 60 characters
Scan FTP traffic.
falseScan HTTP and decrypted HTTPS.
falseScan with NDR active threat intelligence.
falseWeb category based QoS policy.
falsewebPolicy objectnullable
Reference to an object by name.
Possible values: non-empty and <= 60 characters
Use web proxy instead of DPI engine.
falseZero day protection.
falseemailScanning object
Email scanning.
Scan IMAP.
falseScan IMAPS.
falseScan POP3.
falseScan POP3S.
falseScan SMTP.
falseScan SMTPS.
falseqos object
Traffic shaping policy. When userAuthentication is turned on, the firewall automatically assigns the user's traffic shaping policy.
trafficShapingPolicy objectnullable
Reference to an object by name.
Possible values: non-empty and <= 60 characters
DSCP marking.
Possible values: [0-Best Effort, 1, 2, 3, 4, 5, 6, 7, 8-Class 1(CS1), 9, 10-Class 1,Gold(AF11), 11, 12-Class1,Silver(AF12), 13, 14-Class 1,Bronze(AF13), 15, 16-Class 2(CS2), 17, 18-Class 2,Gold(AF21), 19, 20-Class 2,Silver(AF22), 21, 22-Class 2,Bronze(AF23), 23, 24-Class 3(CS3), 25, 26-Class 3,Gold(AF31), 27, 28-Class 3,Silver(AF32), 29, 30-Class 3,Bronze(AF33), 31, 32-Class 4(CS4), 33, 34-Class 4,Gold(AF41), 35, 36-Class 4,Silver(AF42), 37, 38-Class 4,Bronze(AF43), 39, 40-Class 5(CS5), 41, 42, 43, 44, 45, 46-Expedited Forwarding(EF), 47, 48-Control(CS6), 49, 50, 51, 52, 53, 54, 55, 56-Control(CS7), 57, 58, 59, 60, 61, 62, 63]
Log firewall traffic.
falseschedule objectnullable
Reference to an object by name.
Possible values: non-empty and <= 60 characters
Date and time.
Date and time.
{
"name": "allow-lan-to-wan",
"ruleType": "firewall",
"enabled": true,
"action": "accept",
"sourceZones": {
"zones": [
{
"name": "lan"
}
]
},
"destinationZones": {
"zones": [
{
"name": "wan"
}
]
},
"sourceNetworks": {
"any": true
},
"destinationNetworks": {
"any": true
},
"servicesOrGroups": {
"services": [
{
"name": "https"
}
]
},
"synchronizedSecurityHeartbeat": {
"source": {
"blockClientsWithNoHeartbeat": false,
"minimumLevel": "noRestriction"
},
"destination": {
"blockClientsWithNoHeartbeat": false,
"minimumLevel": "noRestriction"
}
},
"securityFeatures": {
"webPolicy": null,
"webCategoryBasedQosPolicy": false,
"blockQuicProtocol": false,
"webProxy": false,
"scanHttpAndDecryptedHttps": true,
"decryptHTTPSWebProxyMode": true,
"zeroDayProtection": true,
"scanFtp": false,
"applicationPolicy": null,
"applicationBasedQosPolicy": false,
"ipsPolicy": {
"name": "lan-protection"
},
"scanWithNdrActiveThreatIntelligence": false
},
"emailScanning": {
"smtp": false,
"smtps": false,
"imap": false,
"imaps": false,
"pop3": false,
"pop3s": false
},
"qos": {
"trafficShapingPolicy": null,
"dscpMarking": "46-Expedited Forwarding(EF)"
},
"logTraffic": true,
"schedule": null
}