Skip to content

NatFirewallControlPolicyProps

Properties for defining a NatFirewallControlPolicy.

See https://www.alibabacloud.com/help/ros/developer-reference/aliyun-cloudfw-natfirewallcontrolpolicy

Initializer

using AlibabaCloud.SDK.ROS.CDK.Cloudfw;
new NatFirewallControlPolicyProps {
    object AclAction,
    object ApplicationNameList,
    object Description,
    object Destination,
    object DestinationType,
    object Direction,
    object NatGatewayId,
    object NewOrder,
    object Proto,
    object Source,
    object SourceType,
    object DestPort = null,
    object DestPortGroup = null,
    object DestPortType = null,
    object DomainResolveType = null,
    object EndTime = null,
    object IpVersion = null,
    object Release = null,
    object RepeatDays = null,
    object RepeatEndTime = null,
    object RepeatStartTime = null,
    object RepeatType = null,
    object StartTime = null
};

Properties

Name Type Description
AclAction object Property aclAction: The action that Cloud Firewall performs on the traffic.Valid values: accept: allows the traffic. drop: denies the traffic. log: monitors the traffic.
ApplicationNameList object Property applicationNameList: The application types supported by the access control policy.
Description object Property description: The description of the access control policy.
Destination object Property destination: The destination address in the access control policy.
DestinationType object Property destinationType: The type of the destination address in the access control policy.
Direction object Property direction: The direction of the traffic to which the access control policy applies.
NatGatewayId object Property natGatewayId: The ID of the NAT gateway.
NewOrder object Property newOrder: The priority of the access control policy.
Proto object Property proto: The protocol type in the access control policy.Valid values: ANY: all types of protocols TCP UDP ICMP.
Source object Property source: The source address in the access control policy.Valid values: If SourceType is set to net, the value of Source is a CIDR block.Example: 10.2.4.0\/24 If SourceType is set to group, the value of this parameter must be an address book name.Example: db_group.
SourceType object Property sourceType: The type of the source address in the access control policy.Valid values: net: source CIDR block group: source address book.
DestPort object Property destPort: The destination port in the access control policy.
DestPortGroup object Property destPortGroup: The name of the destination port address book in the access control policy.
DestPortType object Property destPortType: The type of the destination port in the access control policy.
DomainResolveType object Property domainResolveType: The domain name resolution method of the access control policy.
EndTime object Property endTime: The time when the access control policy stops taking effect.
IpVersion object Property ipVersion: The IP version supported by the access control policy.
Release object Property release: Specifies whether to enable the access control policy.
RepeatDays object Property repeatDays: The days of a week or of a month on which the access control policy takes effect.
RepeatEndTime object Property repeatEndTime: The point in time when the recurrence ends.
RepeatStartTime object Property repeatStartTime: The point in time when the recurrence starts.
RepeatType object Property repeatType: The recurrence type for the access control policy to take effect.
StartTime object Property startTime: The time when the access control policy starts to take effect.

AclActionRequired

public object AclAction { get; set; }
  • Type: object

Property aclAction: The action that Cloud Firewall performs on the traffic.Valid values: accept: allows the traffic. drop: denies the traffic. log: monitors the traffic.


ApplicationNameListRequired

public object ApplicationNameList { get; set; }
  • Type: object

Property applicationNameList: The application types supported by the access control policy.


DescriptionRequired

public object Description { get; set; }
  • Type: object

Property description: The description of the access control policy.


DestinationRequired

public object Destination { get; set; }
  • Type: object

Property destination: The destination address in the access control policy.

Valid values: If DestinationType is set to net, the value of this parameter is a CIDR block. Example: 1.2.XX.XX/24 If DestinationType is set to group, the value of this parameter is an address book. Example: db_group If DestinationType is set to domain, the value of this parameter is a domain name. Example: *.aliyuncs.com DestinationType is set to location, the value of this parameter is a location. Example: ["BJ11", "ZB"]


DestinationTypeRequired

public object DestinationType { get; set; }
  • Type: object

Property destinationType: The type of the destination address in the access control policy.

Valid values: net: CIDR block group: address book domain: domain name


DirectionRequired

public object Direction { get; set; }
  • Type: object

Property direction: The direction of the traffic to which the access control policy applies.

Valid values: out: outbound traffic


NatGatewayIdRequired

public object NatGatewayId { get; set; }
  • Type: object

Property natGatewayId: The ID of the NAT gateway.


NewOrderRequired

public object NewOrder { get; set; }
  • Type: object

Property newOrder: The priority of the access control policy.

The priority value starts from 1. A small priority value indicates a high priority.


ProtoRequired

public object Proto { get; set; }
  • Type: object

Property proto: The protocol type in the access control policy.Valid values: ANY: all types of protocols TCP UDP ICMP.


SourceRequired

public object Source { get; set; }
  • Type: object

Property source: The source address in the access control policy.Valid values: If SourceType is set to net, the value of Source is a CIDR block.Example: 10.2.4.0\/24 If SourceType is set to group, the value of this parameter must be an address book name.Example: db_group.


SourceTypeRequired

public object SourceType { get; set; }
  • Type: object

Property sourceType: The type of the source address in the access control policy.Valid values: net: source CIDR block group: source address book.


DestPortOptional

public object DestPort { get; set; }
  • Type: object

Property destPort: The destination port in the access control policy.

Valid values: If Proto is set to ICMP, DestPort is automatically left empty. If Proto is set to TCP, UDP, or ANY and DestPortType is set to group, DestPort is empty. If Proto is set to TCP, UDP, or ANY and DestPortType is set to port, the value of DestPort is the destination port number.


DestPortGroupOptional

public object DestPortGroup { get; set; }
  • Type: object

Property destPortGroup: The name of the destination port address book in the access control policy.


DestPortTypeOptional

public object DestPortType { get; set; }
  • Type: object

Property destPortType: The type of the destination port in the access control policy.

Valid values: net: source CIDR block group: source address book


DomainResolveTypeOptional

public object DomainResolveType { get; set; }
  • Type: object

Property domainResolveType: The domain name resolution method of the access control policy.

Valid values: 0: fully qualified domain name (FQDN)-based resolution 1: Domain Name System (DNS)-based dynamic resolution 2: FQDN and DNS-based dynamic resolution


EndTimeOptional

public object EndTime { get; set; }
  • Type: object

Property endTime: The time when the access control policy stops taking effect.

The value is a UNIX timestamp. Unit: seconds. The value must be on the hour or on the half hour, and at least 30 minutes later than the value of StartTime.


IpVersionOptional

public object IpVersion { get; set; }
  • Type: object

Property ipVersion: The IP version supported by the access control policy.

Valid values: 4: IPv4 (default)


ReleaseOptional

public object Release { get; set; }
  • Type: object

Property release: Specifies whether to enable the access control policy.

By default, an access control policy is enabled after it is created. Valid values: true false


RepeatDaysOptional

public object RepeatDays { get; set; }
  • Type: object

Property repeatDays: The days of a week or of a month on which the access control policy takes effect.

If RepeatType is set to Permanent, None, or Daily, RepeatDays is left empty. Example: []. If RepeatType is set to Weekly, RepeatDays must be specified. Example: [0, 6]. If RepeatType is set to Monthly, RepeatDays must be specified. Example: [1, 31].


RepeatEndTimeOptional

public object RepeatEndTime { get; set; }
  • Type: object

Property repeatEndTime: The point in time when the recurrence ends.

Example: 23:30. The value must be on the hour or on the half hour, and at least 30 minutes later than the value of RepeatStartTime.


RepeatStartTimeOptional

public object RepeatStartTime { get; set; }
  • Type: object

Property repeatStartTime: The point in time when the recurrence starts.

Example: 08:00. The value must be on the hour or on the half hour, and at least 30 minutes earlier than the value of RepeatEndTime.


RepeatTypeOptional

public object RepeatType { get; set; }
  • Type: object

Property repeatType: The recurrence type for the access control policy to take effect.

Valid values: Permanent (default): The policy always takes effect. None: The policy takes effect for only once. Daily: The policy takes effect on a daily basis. Weekly: The policy takes effect on a weekly basis. Monthly: The policy takes effect on a monthly basis.


StartTimeOptional

public object StartTime { get; set; }
  • Type: object

Property startTime: The time when the access control policy starts to take effect.

The value is a UNIX timestamp. Unit: seconds. The value must be on the hour or on the half hour, and at least 30 minutes earlier than the value of EndTime.