All Products
Search
Document Center

Cloud Firewall:DescribeVpcFirewallDetail

Last Updated:Mar 19, 2024

Queries the details about a virtual private cloud (VPC) firewall. The VPC firewall controls traffic between two VPCs that are connected by using an Express Connect circuit.

Operation description

You can call the DescribeVpcFirewallDetail operation to query the details about a VPC firewall. The VPC firewall controls traffic between two VPCs that are connected by using an Express Connect circuit.

Before you call the operation, make sure that you created a VPC firewall by calling the CreateVpcFirewallConfigure operation.

Limits

You can call this operation up to 10 times per second per account. If the number of the calls per second exceeds the limit, throttling is triggered. As a result, your business may be affected. We recommend that you take note of the limit when you call this operation.

Debugging

OpenAPI Explorer automatically calculates the signature value. For your convenience, we recommend that you call this operation in OpenAPI Explorer.

Authorization information

The following table shows the authorization information corresponding to the API. The authorization information can be used in the Action policy element to grant a RAM user or RAM role the permissions to call this API operation. Description:

  • Operation: the value that you can use in the Action element to specify the operation on a resource.
  • Access level: the access level of each operation. The levels are read, write, and list.
  • Resource type: the type of the resource on which you can authorize the RAM user or the RAM role to perform the operation. Take note of the following items:
    • The required resource types are displayed in bold characters.
    • If the permissions cannot be granted at the resource level, All Resources is used in the Resource type column of the operation.
  • Condition Key: the condition key that is defined by the cloud service.
  • Associated operation: other operations that the RAM user or the RAM role must have permissions to perform to complete the operation. To complete the operation, the RAM user or the RAM role must have the permissions to perform the associated operations.
OperationAccess levelResource typeCondition keyAssociated operation
yundun-cloudfirewall:DescribeVpcFirewallDetailRead
  • All Resources
    *
    none
none

Request parameters

ParameterTypeRequiredDescriptionExample
LangstringNo

The natural language of the request and response. Valid values:

  • zh: Chinese (default)
  • en: English
zh
VpcFirewallIdstringYes

The instance ID of the VPC firewall.

Note You can call the DescribeVpcFirewallList operation to query the instance IDs of VPC firewalls.
vfw-m5e7dbc4y****
LocalVpcIdstringNo

The ID of the local VPC.

vpc-8vbwbo90rq0anm6t****
PeerVpcIdstringNo

The ID of the peer VPC.

vpc-90rq0anm6t8vbwbo****

Response parameters

ParameterTypeDescriptionExample
object
ConnectTypestring

The connection type of the VPC firewall. The value is fixed as expressconnect, which indicates Express Connect circuits.

expressconnect
VpcFirewallIdstring

The instance ID of the VPC firewall.

vfw-m5e7dbc4y****
RequestIdstring

The ID of the request.

850A84D6-0DE4-4797-A1E8-00090125g4d2
Bandwidthinteger

The bandwidth of the Express Connect circuit. Unit: Mbit/s.

2
VpcFirewallNamestring

The instance name of the VPC firewall.

tf-test
FirewallSwitchStatusstring

The status of the VPC firewall. Valid values:

  • opened: The VPC firewall is enabled.
  • closed: The VPC firewall is disabled.
  • notconfigured: The VPC firewall is not configured.
  • configured: The VPC firewall is configured.
opened
LocalVpcobject

The details about the local VPC.

VpcIdstring

The ID of the local VPC.

vpc-8vbwbo90rq0anm6t****
VpcNamestring

The name of the local VPC.

Vitasoy
RegionNostring

The region ID of the local VPC.

cn-hangzhou
EniPrivateIpAddressstring

The private IP address of the elastic network interface (ENI) for the local VPC.

192.168.XX.XX
RouterInterfaceIdstring

The router interface ID of the local VPC.

vrt-m5eb5me6c3l5sezae****
EniIdstring

The ID of the ENI for the local VPC.

eni-8vbhfosfqv2rff42****
VpcCidrTableListobject []

The CIDR blocks of the local VPC.

RouteTableIdstring

The ID of the route table for the local VPC.

vtb-1234
RouteEntryListobject []

The route entries of the local VPC.

NextHopInstanceIdstring

The instance ID of the next hop for the local VPC.

vrt-m5eb5me6c3l5sezae****
DestinationCidrstring

The destination CIDR block of the local VPC.

192.168.XX.XX/24
PeerVpcobject

The details about the peer VPC.

VpcIdstring

The ID of the peer VPC.

vpc-90rq0anm6t8vbwbo****
VpcNamestring

The name of the peer VPC.

zcy_prod
RegionNostring

The region ID of the peer VPC.

cn-hangzhou
EniPrivateIpAddressstring

The private IP address of the ENI for the peer VPC.

192.168.XX.XX
RouterInterfaceIdstring

The router interface ID of the peer VPC.

vrt-m5eb5me6c3l5sezae****
EniIdstring

The ID of the ENI for the peer VPC.

eni-8vbhfosfqv2rff42****
VpcCidrTableListobject []

The CIDR blocks of the peer VPC.

RouteTableIdstring

The ID of the route table for the peer VPC.

vtb-1256
RouteEntryListobject []

The route entries of the peer VPC.

NextHopInstanceIdstring

The instance ID of the next hop for the peer VPC.

vrt-m5eb5me6c3l5sezae****
DestinationCidrstring

The destination CIDR block of the peer VPC.

192.168.XX.XX/24
MemberUidstring

The UID of the member that is managed by your Alibaba Cloud account.

258039427902****

Examples

Sample success responses

JSONformat

{
  "ConnectType": "expressconnect",
  "VpcFirewallId": "vfw-m5e7dbc4y****",
  "RequestId": "850A84D6-0DE4-4797-A1E8-00090125g4d2",
  "Bandwidth": 2,
  "VpcFirewallName": "tf-test",
  "FirewallSwitchStatus": "opened",
  "LocalVpc": {
    "VpcId": "vpc-8vbwbo90rq0anm6t****",
    "VpcName": "Vitasoy",
    "RegionNo": "cn-hangzhou",
    "EniPrivateIpAddress": "192.168.XX.XX",
    "RouterInterfaceId": "vrt-m5eb5me6c3l5sezae****",
    "EniId": "eni-8vbhfosfqv2rff42****",
    "VpcCidrTableList": [
      {
        "RouteTableId": "vtb-1234",
        "RouteEntryList": [
          {
            "NextHopInstanceId": "vrt-m5eb5me6c3l5sezae****",
            "DestinationCidr": "192.168.XX.XX/24"
          }
        ]
      }
    ]
  },
  "PeerVpc": {
    "VpcId": "vpc-90rq0anm6t8vbwbo****",
    "VpcName": "zcy_prod",
    "RegionNo": "cn-hangzhou",
    "EniPrivateIpAddress": "192.168.XX.XX",
    "RouterInterfaceId": "vrt-m5eb5me6c3l5sezae****",
    "EniId": "eni-8vbhfosfqv2rff42****",
    "VpcCidrTableList": [
      {
        "RouteTableId": "vtb-1256",
        "RouteEntryList": [
          {
            "NextHopInstanceId": "vrt-m5eb5me6c3l5sezae****",
            "DestinationCidr": "192.168.XX.XX/24"
          }
        ]
      }
    ]
  },
  "MemberUid": "258039427902****"
}

Error codes

HTTP status codeError codeError messageDescription
400ErrorAliUidThe aliuid is invalid.The aliuid is invalid.
400ErrorFirewallNotFoundFirewall not foundThe firewall does not exist.

For a list of error codes, visit the Service error codes.

Change history

Change timeSummary of changesOperation
2022-12-08API Description Update. The Error code has changed. The response structure of the API has changedsee changesets
Change itemChange content
API DescriptionAPI Description Update.
Error CodesThe Error code has changed.
    delete Error Codes: 400
Output ParametersThe response structure of the API has changed.