NatFirewallControlPolicyProps
Properties for defining a NatFirewallControlPolicy
.
See https://www.alibabacloud.com/help/ros/developer-reference/aliyun-cloudfw-natfirewallcontrolpolicy
Initializer
using AlibabaCloud.SDK.ROS.CDK.Cloudfw;
new NatFirewallControlPolicyProps {
object AclAction,
object ApplicationNameList,
object Description,
object Destination,
object DestinationType,
object Direction,
object NatGatewayId,
object NewOrder,
object Proto,
object Source,
object SourceType,
object DestPort = null,
object DestPortGroup = null,
object DestPortType = null,
object DomainResolveType = null,
object EndTime = null,
object IpVersion = null,
object Release = null,
object RepeatDays = null,
object RepeatEndTime = null,
object RepeatStartTime = null,
object RepeatType = null,
object StartTime = null
};
Properties
Name | Type | Description |
---|---|---|
AclAction |
object |
Property aclAction: The action that Cloud Firewall performs on the traffic.Valid values: accept: allows the traffic. drop: denies the traffic. log: monitors the traffic. |
ApplicationNameList |
object |
Property applicationNameList: The application types supported by the access control policy. |
Description |
object |
Property description: The description of the access control policy. |
Destination |
object |
Property destination: The destination address in the access control policy. |
DestinationType |
object |
Property destinationType: The type of the destination address in the access control policy. |
Direction |
object |
Property direction: The direction of the traffic to which the access control policy applies. |
NatGatewayId |
object |
Property natGatewayId: The ID of the NAT gateway. |
NewOrder |
object |
Property newOrder: The priority of the access control policy. |
Proto |
object |
Property proto: The protocol type in the access control policy.Valid values: ANY: all types of protocols TCP UDP ICMP. |
Source |
object |
Property source: The source address in the access control policy.Valid values: If SourceType is set to net, the value of Source is a CIDR block.Example: 10.2.4.0\/24 If SourceType is set to group, the value of this parameter must be an address book name.Example: db_group. |
SourceType |
object |
Property sourceType: The type of the source address in the access control policy.Valid values: net: source CIDR block group: source address book. |
DestPort |
object |
Property destPort: The destination port in the access control policy. |
DestPortGroup |
object |
Property destPortGroup: The name of the destination port address book in the access control policy. |
DestPortType |
object |
Property destPortType: The type of the destination port in the access control policy. |
DomainResolveType |
object |
Property domainResolveType: The domain name resolution method of the access control policy. |
EndTime |
object |
Property endTime: The time when the access control policy stops taking effect. |
IpVersion |
object |
Property ipVersion: The IP version supported by the access control policy. |
Release |
object |
Property release: Specifies whether to enable the access control policy. |
RepeatDays |
object |
Property repeatDays: The days of a week or of a month on which the access control policy takes effect. |
RepeatEndTime |
object |
Property repeatEndTime: The point in time when the recurrence ends. |
RepeatStartTime |
object |
Property repeatStartTime: The point in time when the recurrence starts. |
RepeatType |
object |
Property repeatType: The recurrence type for the access control policy to take effect. |
StartTime |
object |
Property startTime: The time when the access control policy starts to take effect. |
AclAction
Required
public object AclAction { get; set; }
- Type: object
Property aclAction: The action that Cloud Firewall performs on the traffic.Valid values: accept: allows the traffic. drop: denies the traffic. log: monitors the traffic.
ApplicationNameList
Required
public object ApplicationNameList { get; set; }
- Type: object
Property applicationNameList: The application types supported by the access control policy.
Description
Required
public object Description { get; set; }
- Type: object
Property description: The description of the access control policy.
Destination
Required
public object Destination { get; set; }
- Type: object
Property destination: The destination address in the access control policy.
Valid values: If DestinationType is set to net, the value of this parameter is a CIDR block. Example: 1.2.XX.XX/24 If DestinationType is set to group, the value of this parameter is an address book. Example: db_group If DestinationType is set to domain, the value of this parameter is a domain name. Example: *.aliyuncs.com DestinationType is set to location, the value of this parameter is a location. Example: ["BJ11", "ZB"]
DestinationType
Required
public object DestinationType { get; set; }
- Type: object
Property destinationType: The type of the destination address in the access control policy.
Valid values: net: CIDR block group: address book domain: domain name
Direction
Required
public object Direction { get; set; }
- Type: object
Property direction: The direction of the traffic to which the access control policy applies.
Valid values: out: outbound traffic
NatGatewayId
Required
public object NatGatewayId { get; set; }
- Type: object
Property natGatewayId: The ID of the NAT gateway.
NewOrder
Required
public object NewOrder { get; set; }
- Type: object
Property newOrder: The priority of the access control policy.
The priority value starts from 1. A small priority value indicates a high priority.
Proto
Required
public object Proto { get; set; }
- Type: object
Property proto: The protocol type in the access control policy.Valid values: ANY: all types of protocols TCP UDP ICMP.
Source
Required
public object Source { get; set; }
- Type: object
Property source: The source address in the access control policy.Valid values: If SourceType is set to net, the value of Source is a CIDR block.Example: 10.2.4.0\/24 If SourceType is set to group, the value of this parameter must be an address book name.Example: db_group.
SourceType
Required
public object SourceType { get; set; }
- Type: object
Property sourceType: The type of the source address in the access control policy.Valid values: net: source CIDR block group: source address book.
DestPort
Optional
public object DestPort { get; set; }
- Type: object
Property destPort: The destination port in the access control policy.
Valid values: If Proto is set to ICMP, DestPort is automatically left empty. If Proto is set to TCP, UDP, or ANY and DestPortType is set to group, DestPort is empty. If Proto is set to TCP, UDP, or ANY and DestPortType is set to port, the value of DestPort is the destination port number.
DestPortGroup
Optional
public object DestPortGroup { get; set; }
- Type: object
Property destPortGroup: The name of the destination port address book in the access control policy.
DestPortType
Optional
public object DestPortType { get; set; }
- Type: object
Property destPortType: The type of the destination port in the access control policy.
Valid values: net: source CIDR block group: source address book
DomainResolveType
Optional
public object DomainResolveType { get; set; }
- Type: object
Property domainResolveType: The domain name resolution method of the access control policy.
Valid values: 0: fully qualified domain name (FQDN)-based resolution 1: Domain Name System (DNS)-based dynamic resolution 2: FQDN and DNS-based dynamic resolution
EndTime
Optional
public object EndTime { get; set; }
- Type: object
Property endTime: The time when the access control policy stops taking effect.
The value is a UNIX timestamp. Unit: seconds. The value must be on the hour or on the half hour, and at least 30 minutes later than the value of StartTime.
IpVersion
Optional
public object IpVersion { get; set; }
- Type: object
Property ipVersion: The IP version supported by the access control policy.
Valid values: 4: IPv4 (default)
Release
Optional
public object Release { get; set; }
- Type: object
Property release: Specifies whether to enable the access control policy.
By default, an access control policy is enabled after it is created. Valid values: true false
RepeatDays
Optional
public object RepeatDays { get; set; }
- Type: object
Property repeatDays: The days of a week or of a month on which the access control policy takes effect.
If RepeatType is set to Permanent, None, or Daily, RepeatDays is left empty. Example: []. If RepeatType is set to Weekly, RepeatDays must be specified. Example: [0, 6]. If RepeatType is set to Monthly, RepeatDays must be specified. Example: [1, 31].
RepeatEndTime
Optional
public object RepeatEndTime { get; set; }
- Type: object
Property repeatEndTime: The point in time when the recurrence ends.
Example: 23:30. The value must be on the hour or on the half hour, and at least 30 minutes later than the value of RepeatStartTime.
RepeatStartTime
Optional
public object RepeatStartTime { get; set; }
- Type: object
Property repeatStartTime: The point in time when the recurrence starts.
Example: 08:00. The value must be on the hour or on the half hour, and at least 30 minutes earlier than the value of RepeatEndTime.
RepeatType
Optional
public object RepeatType { get; set; }
- Type: object
Property repeatType: The recurrence type for the access control policy to take effect.
Valid values: Permanent (default): The policy always takes effect. None: The policy takes effect for only once. Daily: The policy takes effect on a daily basis. Weekly: The policy takes effect on a weekly basis. Monthly: The policy takes effect on a monthly basis.
StartTime
Optional
public object StartTime { get; set; }
- Type: object
Property startTime: The time when the access control policy starts to take effect.
The value is a UNIX timestamp. Unit: seconds. The value must be on the hour or on the half hour, and at least 30 minutes earlier than the value of EndTime.