Skip to content

ACLRuleProps

Properties for defining a ACLRule.

See https://www.alibabacloud.com/help/ros/developer-reference/aliyun-sag-aclrule

Initializer

import ros_cdk_sag
ros_cdk_sag.ACLRuleProps(
  acl_id: typing.Union[str, IResolvable],
  dest_cidr: typing.Union[str, IResolvable],
  dest_port_range: typing.Union[str, IResolvable],
  direction: typing.Union[str, IResolvable],
  ip_protocol: typing.Union[str, IResolvable],
  policy: typing.Union[str, IResolvable],
  source_cidr: typing.Union[str, IResolvable],
  source_port_range: typing.Union[str, IResolvable],
  description: typing.Union[str, IResolvable] = None,
  dpi_group_ids: typing.Union[IResolvable, typing.List[typing.Union[str, IResolvable]]] = None,
  dpi_signature_ids: typing.Union[IResolvable, typing.List[typing.Union[str, IResolvable]]] = None,
  name: typing.Union[str, IResolvable] = None,
  priority: typing.Union[typing.Union[int, float], IResolvable] = None,
  type: typing.Union[str, IResolvable] = None
)

Properties

Name Type Description
acl_id typing.Union[str, ros_cdk_core.IResolvable] Property aclId: Access control ID.
dest_cidr typing.Union[str, ros_cdk_core.IResolvable] Property destCidr: Destination address, CIDR format and IP address range in IPv4 format.
dest_port_range typing.Union[str, ros_cdk_core.IResolvable] Property destPortRange: The destination port range.
direction typing.Union[str, ros_cdk_core.IResolvable] Property direction: The direction of traffic to which the ACL rule applies.
ip_protocol typing.Union[str, ros_cdk_core.IResolvable] Property ipProtocol: Protocol, not case sensitive.
policy typing.Union[str, ros_cdk_core.IResolvable] Property policy: Access: accept|drop.
source_cidr typing.Union[str, ros_cdk_core.IResolvable] Property sourceCidr: Source address, CIDR format and IP address range in IPv4 format.
source_port_range typing.Union[str, ros_cdk_core.IResolvable] Property sourcePortRange: The source port range.
description typing.Union[str, ros_cdk_core.IResolvable] Property description: Rule description information, ranging from 1 to 512 characters.
dpi_group_ids typing.Union[ros_cdk_core.IResolvable, typing.List[typing.Union[str, ros_cdk_core.IResolvable]]] Property dpiGroupIds: The ID of the application group.
dpi_signature_ids typing.Union[ros_cdk_core.IResolvable, typing.List[typing.Union[str, ros_cdk_core.IResolvable]]] Property dpiSignatureIds: The ID of the application.
name typing.Union[str, ros_cdk_core.IResolvable] Property name: The name of the ACL rule.
priority typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable] Property priority: The priority of the ACL rule.
type typing.Union[str, ros_cdk_core.IResolvable] Property type: The type of the ACL rule: Valid values: LAN: The ACL rule controls traffic of private IP addresses.

acl_idRequired

acl_id: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property aclId: Access control ID.


dest_cidrRequired

dest_cidr: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property destCidr: Destination address, CIDR format and IP address range in IPv4 format.


dest_port_rangeRequired

dest_port_range: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property destPortRange: The destination port range.

Valid values: -1 and 1 to 65535. Use the format 1/200 or 80/80. A value of -1/-1 means all ports.


directionRequired

direction: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property direction: The direction of traffic to which the ACL rule applies.

Valid values:

  • in: inbound. Traffic from an external network to the local branch where the SAG instance is deployed.
  • out: outbound. Traffic from the local branch where the SAG instance is deployed to an external network.

ip_protocolRequired

ip_protocol: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property ipProtocol: Protocol, not case sensitive.


policyRequired

policy: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property policy: Access: accept|drop.


source_cidrRequired

source_cidr: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property sourceCidr: Source address, CIDR format and IP address range in IPv4 format.


source_port_rangeRequired

source_port_range: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property sourcePortRange: The source port range.

Valid values: -1 and 1 to 65535. Use the format 1/200 or 80/80. A value of -1/-1 means all ports.


descriptionOptional

description: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property description: Rule description information, ranging from 1 to 512 characters.


dpi_group_idsOptional

dpi_group_ids: typing.Union[IResolvable, typing.List[typing.Union[str, IResolvable]]]
  • Type: typing.Union[ros_cdk_core.IResolvable, typing.List[typing.Union[str, ros_cdk_core.IResolvable]]]

Property dpiGroupIds: The ID of the application group.

You can enter at most 100 application group IDs at a time. You can call the ListDpiGroups operation to query application group IDs and information about the applications.


dpi_signature_idsOptional

dpi_signature_ids: typing.Union[IResolvable, typing.List[typing.Union[str, IResolvable]]]
  • Type: typing.Union[ros_cdk_core.IResolvable, typing.List[typing.Union[str, ros_cdk_core.IResolvable]]]

Property dpiSignatureIds: The ID of the application.

You can enter at most 100 application IDs at a time. You can call the ListDpiSignatures operation to query application IDs and information about the applications.


nameOptional

name: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property name: The name of the ACL rule.

The name must be 2 to 100 characters in length, start with a letter, and can contain digits, periods (.), underscores (_), and hyphens (-).


priorityOptional

priority: typing.Union[typing.Union[int, float], IResolvable]
  • Type: typing.Union[typing.Union[int, float], ros_cdk_core.IResolvable]

Property priority: The priority of the ACL rule.

A smaller value indicates a higher priority. If multiple rules have the same priority, the rule that is first delivered to the Smart Access Gateway device takes precedence. Valid values: 1 to 100. Default value: 1.


typeOptional

type: typing.Union[str, IResolvable]
  • Type: typing.Union[str, ros_cdk_core.IResolvable]

Property type: The type of the ACL rule: Valid values: LAN: The ACL rule controls traffic of private IP addresses.

This is the default value. WAN: The ACL rule controls traffic of public IP addresses.