rule-set rule action-group¶
Configure action-group
action-group Specification¶
Parameter Value Type Configuration Resource Element Name action-group Element URI /axapi/v3/rule-set/{name}/rule/{name}/action-group Element Attributes action-group_attributes Partition Visibility shared Schema action-group schema
Operations Allowed:
Operation | Method | URI | Payload | |
---|---|---|---|---|
Create Object | POST | /axapi/v3/rule-set/{name}/rule/{name}/action-group | ||
Get Object | GET | /axapi/v3/rule-set/{name}/rule/{name}/action-group | ||
Modify Object | POST | /axapi/v3/rule-set/{name}/rule/{name}/action-group | ||
Replace Object | PUT | /axapi/v3/rule-set/{name}/rule/{name}/action-group | ||
Delete Object | DELETE | /axapi/v3/rule-set/{name}/rule/{name}/action-group |
action-group attributes¶
cgnv6
Description Apply CGNv6 policy
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: cgnv6,listen-on-port, forward, ipsec, and ipsec-group are mutually exclusive
cgnv6-ds-lite
Description ‘lsn-lid’: Apply specified CGNv6 LSN LID;
Type: string
Supported Values: lsn-lid
cgnv6-ds-lite-lsn-lid
Description LSN LID
Type: number
Range: 1-1023
cgnv6-lsn-lid
Description LSN LID
Type: number
Range: 1-1023
cgnv6-policy
Description ‘lsn-lid’: Apply specified CGNv6 LSN LID; ‘fixed-nat’: Apply CGNv6 Fixed NAT; ‘ds-lite’: Apply CGNv6 DS-Lite;
Type: string
Supported Values: lsn-lid, fixed-nat, ds-lite
deny-fw-log
Description Logging template name
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/fw/template/logging
deny-log
Description Enable logging
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
deny-log-template-type
Description ‘fw-logging-template’: Logging with specified fw template;
Type: string
Supported Values: fw-logging-template
dscp-number
Description DSCP Number
Type: number
Range: 0-63
Mutual Exclusion: dscp-number and dscp-value are mutually exclusive
dscp-value
Description ‘default’: Default dscp (000000); ‘af11’: AF11 (001010); ‘af12’: AF12 (001100); ‘af13’: AF13 (001110); ‘af21’: AF21 (010010); ‘af22’: AF22 (010100); ‘af23’: AF23 (010110); ‘af31’: AF31 (011010); ‘af32’: AF32 (011100); ‘af33’: AF33 (011110); ‘af41’: AF41 (100010); ‘af42’: AF42 (100100); ‘af43’: AF43 (100110); ‘cs1’: CS1 (001000); ‘cs2’: CS2 (010000); ‘cs3’: CS3 (011000); ‘cs4’: CS4 (100000); ‘cs5’: CS5 (101000); ‘cs6’: CS6 (110000); ‘cs7’: CS7 (111000); ‘ef’: EF (101110);
Type: string
Supported Values: default, af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs1, cs2, cs3, cs4, cs5, cs6, cs7, ef
Mutual Exclusion: dscp-value and dscp-number are mutually exclusive
forward
Description Forward packet
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: forward,ipsec, ipsec-group, and cgnv6 are mutually exclusive
inspect-payload
Description Enable DS-Lite tunnel inspection
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
ipsec
Description Apply IPsec encapsulation
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: ipsec,permit-log, listen-on-port, forward, ipsec-group, cgnv6, and permit-respond-to-user-mac are mutually exclusive
ipsec-group
Description Apply IPsec Group encapsulation
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: ipsec-group,permit-log, listen-on-port, forward, ipsec, and cgnv6 are mutually exclusive
listen-on-port
Description Listen on port
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: listen-on-port,ipsec, ipsec-group, and cgnv6 are mutually exclusive
logging-template-list
Type: Listpermit-limit-policy
Description Limit policy Template
Type: number
Range: 1-1023
Reference Object: /axapi/v3/template/limit-policy
permit-log
Description Enable logging
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: permit-log, ipsec, and ipsec-group are mutually exclusive
permit-respond-to-user-mac
Description Use the user’s source MAC for the next hop rather than the routing table (default:off)
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
Mutual Exclusion: permit-respond-to-user-mac and ipsec are mutually exclusive
reset-fw-log
Description Logging template name
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/fw/template/logging
reset-log
Description Enable logging
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
reset-log-template-type
Description ‘fw-logging-template’: Logging with specified fw template;
Type: string
Supported Values: fw-logging-template
reset-respond-to-user-mac
Description Use the user’s source MAC for the next hop rather than the routing table (default:off)
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
set-dscp
Description DSCP setting
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
type
Description ‘permit’: permit; ‘deny’: deny; ‘reset’: reset;
Type: string
Supported Values: permit, deny, reset
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
vpn-ipsec-group-name
Description VPN IPsec Group name
Type: string
Maximum Length: 31 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/vpn/ipsec-group
vpn-ipsec-name
Description VPN IPsec name
Type: string
Maximum Length: 31 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/vpn/ipsec
logging-template-list¶
Specification Value Type list Block object keys permit-cgnv6-log
Description Logging template name
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/cgnv6/template/logging
permit-fw-log
Description Logging template name
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/fw/template/logging
permit-log-template-type
Description ‘fw-logging-template’: Logging with specified fw template; ‘cgnv6-logging-template’: Logging with specified cgnv6 template; ‘netflow-monitor’: Logging with specified netflow/ipfix monitor;
Type: string
Supported Values: fw-logging-template, cgnv6-logging-template, netflow-monitor
permit-netflow-log
Description Name of netflow monitor
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Reference Object: /axapi/v3/netflow/monitor