ControlPolicyProps
Properties for defining a ControlPolicy.
See https://www.alibabacloud.com/help/ros/developer-reference/aliyun-cloudfw-controlpolicy
Initializer
import com.aliyun.ros.cdk.cloudfw.ControlPolicyProps;
ControlPolicyProps.builder()
.aclAction(java.lang.String)
.aclAction(IResolvable)
.description(java.lang.String)
.description(IResolvable)
.destination(java.lang.String)
.destination(IResolvable)
.destinationType(java.lang.String)
.destinationType(IResolvable)
.direction(java.lang.String)
.direction(IResolvable)
.newOrder(java.lang.Number)
.newOrder(IResolvable)
.proto(java.lang.String)
.proto(IResolvable)
.source(java.lang.String)
.source(IResolvable)
.sourceType(java.lang.String)
.sourceType(IResolvable)
// .applicationName(java.lang.String)
// .applicationName(IResolvable)
// .applicationNameList(IResolvable)
// .applicationNameList(java.util.List<java.lang.String)
// .applicationNameList(IResolvable>)
// .destPort(java.lang.String)
// .destPort(IResolvable)
// .destPortGroup(java.lang.String)
// .destPortGroup(IResolvable)
// .destPortType(java.lang.String)
// .destPortType(IResolvable)
// .domainResolveType(java.lang.String)
// .domainResolveType(IResolvable)
// .endTime(java.lang.Number)
// .endTime(IResolvable)
// .ipVersion(java.lang.String)
// .ipVersion(IResolvable)
// .regionId(java.lang.String)
// .regionId(IResolvable)
// .release(java.lang.Boolean)
// .release(IResolvable)
// .repeatDays(IResolvable)
// .repeatDays(java.util.List<java.lang.Number)
// .repeatDays(IResolvable>)
// .repeatEndTime(java.lang.String)
// .repeatEndTime(IResolvable)
// .repeatStartTime(java.lang.String)
// .repeatStartTime(IResolvable)
// .repeatType(java.lang.String)
// .repeatType(IResolvable)
// .startTime(java.lang.Number)
// .startTime(IResolvable)
.build();
Properties
| Name | Type | Description |
|---|---|---|
aclAction | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property aclAction: Traffic access control policy set by the cloud of a firewall. |
description | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property description: Security access control policy description information. |
destination | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property destination: Security Access Control destination address policy. |
destinationType | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property destinationType: Security Access Control destination address type of policy. |
direction | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property direction: Security access control traffic direction policies. |
newOrder | java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable | Property newOrder: Security access control priority policy in force. |
proto | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property proto: The protocol type of the traffic in the access control policy. |
source | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property source: Security access control source address policy. |
sourceType | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property sourceType: Security access control source address type of policy. |
applicationName | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property applicationName: The application type that the access control policy supports. |
applicationNameList | com.aliyun.ros.cdk.core.IResolvable OR java.util.List | Property applicationNameList: List of application types supported by the access control policy. |
destPort | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property destPort: The destination port in the access control policy. |
destPortGroup | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property destPortGroup: Security access control policy access traffic destination port address book name. |
destPortType | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property destPortType: Security access control policy access destination port traffic type. |
domainResolveType | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property domainResolveType: The domain name resolution method of the access control policy. |
endTime | java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable | Property endTime: The end time of the policy validity period for an access control policy. |
ipVersion | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property ipVersion: IP version. |
regionId | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property regionId: Region ID. |
release | java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable | Property release: The enabled state of the access control policy. |
repeatDays | com.aliyun.ros.cdk.core.IResolvable OR java.util.List | Property repeatDays: A collection of repeated dates of policy validity for an access control policy. |
repeatEndTime | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property repeatEndTime: The repeated end time of the policy validity period for an access control policy. |
repeatStartTime | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property repeatStartTime: The repeated start time of the policy validity period for an access control policy. |
repeatType | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property repeatType: The repetition type of the policy validity period for an access control policy. |
startTime | java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable | Property startTime: The start time of the policy validity period for an access control policy. |
aclActionRequired
public java.lang.Object getAclAction();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property aclAction: Traffic access control policy set by the cloud of a firewall.
accept: Release drop: rejected log: Observation
descriptionRequired
public java.lang.Object getDescription();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property description: Security access control policy description information.
destinationRequired
public java.lang.Object getDestination();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property destination: Security Access Control destination address policy.
When DestinationType is net, Destination purpose CIDR. For example: 1.2.3.4/24 When DestinationType as a group, Destination for the purpose of the address book name. For example: db_group When DestinationType for the domain, Destination for the purpose of a domain name. For example:. * Aliyuncs.com When DestinationType as location, Destination area for the purpose (see below position encoding specific regions). For example: [ "BJ11", "ZB"]
destinationTypeRequired
public java.lang.Object getDestinationType();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property destinationType: Security Access Control destination address type of policy.
net: Destination network segment (CIDR) group: destination address book domain: The purpose domain location: The purpose area
directionRequired
public java.lang.Object getDirection();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property direction: Security access control traffic direction policies.
in: internal and external traffic access control out: within the flow of external access control
newOrderRequired
public java.lang.Object getNewOrder();
- Type: java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable
Property newOrder: Security access control priority policy in force.
Priority number increments sequentially from 1, lower the priority number, the higher the priority. Description -1 indicates the lowest priority.
protoRequired
public java.lang.Object getProto();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property proto: The protocol type of the traffic in the access control policy.
Valid values:
- ANY (any protocol)
- TCP
- UDP
- ICMP
If the traffic direction is
outand the destination is a domain-based threat intelligence or cloud service address book, you can set the protocol only toTCP. The supported applications are HTTP, HTTPS, SMTP, SMTPS, and SSL.
sourceRequired
public java.lang.Object getSource();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property source: Security access control source address policy.
When SourceType for the net, Source is the source CIDR. For example: 1.2.3.0/24 When SourceType as a group, Source name for the source address book. For example: db_group When SourceType as location, Source source region (specific region position encoder see below). For example, [ "BJ11", "ZB"]
sourceTypeRequired
public java.lang.Object getSourceType();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property sourceType: Security access control source address type of policy.
net: Source segment (CIDR) group: source address book location: the source area
applicationNameOptional
public java.lang.Object getApplicationName();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property applicationName: The application type that the access control policy supports.
Valid values:
- FTP
- HTTP
- HTTPS
- Memcache
- MongoDB
- MQTT
- MySQL
- RDP
- Redis
- SMTP
- SMTPS
- SSH
- SSL_No_Cert
- SSL
- VNC
- ANY (all application types)
The available application types depend on the protocol type (
Proto). If you setPrototoTCP, you can setApplicationNameto any of the listed application types. If you setPrototoUDP,ICMP, orANY, you can setApplicationNameonly toANY. Specify eitherApplicationNameListorApplicationName.
applicationNameListOptional
public java.lang.Object getApplicationNameList();
- Type: com.aliyun.ros.cdk.core.IResolvable OR java.util.List
Property applicationNameList: List of application types supported by the access control policy.
destPortOptional
public java.lang.Object getDestPort();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property destPort: The destination port in the access control policy.
Valid values:
- If
ProtoisICMP, leave this parameter empty.
If the protocol type is ICMP, you cannot control access based on the destination port.
- If
ProtoisTCP,UDP, orANY, andDestPortTypeisgroup, leave this parameter empty.
If you set
DestPortTypetogroup(port address book), you do not need to specify a destination port number. The port address book contains all the destination ports that the policy manages.
- If
ProtoisTCP,UDP, orANY, andDestPortTypeisport, set this parameter to the destination port number.
destPortGroupOptional
public java.lang.Object getDestPortGroup();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property destPortGroup: Security access control policy access traffic destination port address book name.
Description DestPortType is group, set the item.
destPortTypeOptional
public java.lang.Object getDestPortType();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property destPortType: Security access control policy access destination port traffic type.
port: Port group: port address book
domainResolveTypeOptional
public java.lang.Object getDomainResolveType();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property domainResolveType: The domain name resolution method of the access control policy.
Value:
- FQDN: Based on FQDN
- DNS: Based on DNS dynamic resolution
- FQDN_AND_DNS: Based on FQDN and DNS dynamic resolution
endTimeOptional
public java.lang.Object getEndTime();
- Type: java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable
Property endTime: The end time of the policy validity period for an access control policy.
It is represented in a second-level timestamp format. It must be the whole hour or half hour, and at least half an hour greater than the start time. Notes: When RepeatType is Permanent, EndTime is empty. When RepeatType is None, Daily, Weekly, Monthly, EndTime must havea value, and you need to set the end time.
ipVersionOptional
public java.lang.Object getIpVersion();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property ipVersion: IP version.
Valid values:
- 4: IPv4
- 6: IPv6
regionIdOptional
public java.lang.Object getRegionId();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property regionId: Region ID.
Default to cn-hangzhou.
releaseOptional
public java.lang.Object getRelease();
- Type: java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable
Property release: The enabled state of the access control policy.
This policy is enabled by default when it is created. Valid values:
- true: Access control policy is enabled
- false: Access control policy is not enabled
repeatDaysOptional
public java.lang.Object getRepeatDays();
- Type: com.aliyun.ros.cdk.core.IResolvable OR java.util.List
Property repeatDays: A collection of repeated dates of policy validity for an access control policy.
When RepeatType is Permanent, None, and Daily, RepeatDays is an empty set. For example: [] When RepeatType is Weekly, RepeatDays cannot be empty. Example: [0, 6] Notes: When RepeatType is set to Weekly, RepeatDays is not allowed. When RepeatType is Monthly, RepeatDays cannot be empty. Examples: [1, 31] Notes: When RepeatType is set to Monthly, RepeatDays is not allowed to repeat.
repeatEndTimeOptional
public java.lang.Object getRepeatEndTime();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property repeatEndTime: The repeated end time of the policy validity period for an access control policy.
For example: 08:00, must be the hour or half time, and less than the repeat start time at least half an hour. Notes: When RepeatType is Permanent and None, RepeatEndTime is empty. When RepeatType is Daily, Weekly, or Monthly, RepeatEndTime musthave a value, and you need to set the repeat end time.
repeatStartTimeOptional
public java.lang.Object getRepeatStartTime();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property repeatStartTime: The repeated start time of the policy validity period for an access control policy.
For example: 08:00, must be the hour or half time, and less than the repeat end time at least half an hour. Notes: When RepeatType is Permanent and None, RepeatStartTime is empty. When RepeatType is Daily, Weekly, or Monthly, RepeatStartTime must have a value, and you need to set the repeat start time.
repeatTypeOptional
public java.lang.Object getRepeatType();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property repeatType: The repetition type of the policy validity period for an access control policy.
Valid values:
- Permanent (default)
- None
- Daily
- Weekly
- Monthly.
startTimeOptional
public java.lang.Object getStartTime();
- Type: java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable
Property startTime: The start time of the policy validity period for an access control policy.
It is represented in a second-level timestamp format. It must be the whole hour or half hour, and at least half an hour less than the end time. Notes: When RepeatType is Permanent, StartTime is empty. When RepeatType is None, Daily, Weekly, Monthly, StartTime must have a value, and you need to set the start time.