All Products
Search
Document Center

Cloud Firewall:DescribeVpcFirewallCenDetail

Last Updated:Mar 19, 2024

Queries the details about a virtual private cloud (VPC) firewall. The VPC firewall protects access traffic between a VPC and a network instance that is attached to a Cloud Enterprise Network (CEN) instance.

Operation description

You can call the DescribeVpcFirewallCenDetail operation to query the details about a VPC firewall. The VPC firewall protects access traffic between a specified VPC and a network instance that is attached to a CEN instance. The network instance can be a VPC, a virtual border router (VBR), or a Cloud Connect Network (CCN) instance.

Limits

You can call this operation up to 10 times per second per account. If the number of calls per second exceeds the limit, throttling is triggered. As a result, your business may be affected. We recommend that you take note of the limit when you call this operation.

Debugging

OpenAPI Explorer automatically calculates the signature value. For your convenience, we recommend that you call this operation in OpenAPI Explorer.

Authorization information

The following table shows the authorization information corresponding to the API. The authorization information can be used in the Action policy element to grant a RAM user or RAM role the permissions to call this API operation. Description:

  • Operation: the value that you can use in the Action element to specify the operation on a resource.
  • Access level: the access level of each operation. The levels are read, write, and list.
  • Resource type: the type of the resource on which you can authorize the RAM user or the RAM role to perform the operation. Take note of the following items:
    • The required resource types are displayed in bold characters.
    • If the permissions cannot be granted at the resource level, All Resources is used in the Resource type column of the operation.
  • Condition Key: the condition key that is defined by the cloud service.
  • Associated operation: other operations that the RAM user or the RAM role must have permissions to perform to complete the operation. To complete the operation, the RAM user or the RAM role must have the permissions to perform the associated operations.
OperationAccess levelResource typeCondition keyAssociated operation
yundun-cloudfirewall:DescribeVpcFirewallCenDetailRead
  • All Resources
    *
    none
none

Request parameters

ParameterTypeRequiredDescriptionExample
LangstringNo

The language of the content within the request and response. Valid values:

  • zh: Chinese (default)
  • en: English
zh
VpcFirewallIdstringYes

The instance ID of the VPC firewall.

Note You can call the DescribeVpcFirewallCenList operation to query the instance IDs of VPC firewalls.
vfw-m5e7dbc4y****
NetworkInstanceIdstringNo

The ID of the VPC for which the VPC firewall is created.

vpc-2zefk9fbn8j7v585g****

Response parameters

ParameterTypeDescriptionExample
object
ConnectTypestring

The connection type of the VPC firewall. The value is fixed as cen, which indicates CEN instances.

cen
VpcFirewallNamestring

The instance name of the VPC firewall.

Test firewall
VpcFirewallIdstring

The instance ID of the VPC firewall.

vfw-m5e7dbc4y****
FirewallSwitchStatusstring

The status of the VPC firewall. Valid values:

  • opened: enabled
  • closed: disabled
  • notconfigured: not configured
opened
RequestIdstring

The ID of the request.

850A84D6-0DE4-4797-A1E8-00090125g4d2
LocalVpcobject

The details about the VPC.

VpcIdstring

The ID of the VPC.

vpc-8vbwbo90rq0anm6t****
TransitRouterTypestring

The edition of the CEN transit router. Valid values:

  • Basic: Basic Edition
  • Enterprise: Enterprise Edition
Basic
RouteModestring

The routing mode. Valid values:

  • auto: automatic mode
  • manual: manual mode
auto
NetworkInstanceIdstring

The ID of the VPC for which the VPC firewall is created.

vpc-2zefk9fbn8j7v585g****
RegionNostring

The ID of the region in which the VPC resides.

cn-hangzhou
ManualVSwitchIdstring

The ID of the specified vSwitch when the routing mode is manual.

vsw-zeq4o875u****
OwnerIdstring

The UID of the Alibaba Cloud account to which the VPC belongs.

158039427902****
NetworkInstanceTypestring

The type of the network instance. The value is fixed as VPC.

VPC
VpcNamestring

The name of the VPC.

Test instance
SupportManualModestring

Indicates whether the manual routing mode is supported. Valid values:

  • 1: yes
  • 0: no
0
TransitRouterIdstring

The instance ID of the CEN transit router.

tr-2zetwxskej633l3u1****
AttachmentIdstring

The ID of the connection between two network instances.

tr-attach-sxig7bye51fid5****
NetworkInstanceNamestring

The name of the network instance.

Test VPC
AttachmentNamestring

The name of the connection between two network instances.

Local test
VpcCidrTableListobject []

An array that consists of the CIDR blocks of the VPC.

RouteTableIdstring

The route table ID of the VPC.

vtb-1234
RouteEntryListobject []

The route entries for the VPC.

NextHopInstanceIdstring

The instance ID of the next hop for the VPC.

vrt-m5eb5me6c3l5sezae****
DestinationCidrstring

The destination CIDR block of the VPC.

192.168.XX.XX/24
EniListobject []

The Elastic Network Interfaces (ENIs).

EniIdstring

The ID of the ENI that belongs to the VPC.

eni-8vbhfosfqv2rff42****
EniPrivateIpAddressstring

The private IP address of the ENI that belongs to the VPC.

192.168.XX.XX
EniVSwitchIdstring

The ID of the vSwitch to which the ENI is connected.

vsw-wz9viido7j436b0n1****
DefendCidrListarray

An array consisting of the CIDR blocks that are protected by the VPC firewall.

string

The CIDR block that is protected by the VPC firewall.

10.0.XX.XX/24
FirewallVpcobject

The VPC that is automatically created for the firewall.

VpcIdstring

The VPC ID.

vpc-bp1245k5oagy2bp74****
VpcCidrstring

The CIDR block of the VPC.

10.0.0.0/8
VswitchIdstring

The vSwitch ID.

vsw-bp1sqg9wms9wxcs1****
VswitchCidrstring

The CIDR block of the vSwitch.

10.0.0.1/24
ZoneIdstring

The zone ID.

cn-hangzhou-i
AllowConfigurationinteger

Indicates whether you can specify a CIDR block when you create a VPC firewall for a Basic Edition transit router of a CEN instance. Valid values:

  • 1: yes
  • 0: no
0

Examples

Sample success responses

JSONformat

{
  "ConnectType": "cen",
  "VpcFirewallName": "Test firewall\n",
  "VpcFirewallId": "vfw-m5e7dbc4y****",
  "FirewallSwitchStatus": "opened",
  "RequestId": "850A84D6-0DE4-4797-A1E8-00090125g4d2",
  "LocalVpc": {
    "VpcId": "vpc-8vbwbo90rq0anm6t****",
    "TransitRouterType": "Basic",
    "RouteMode": "auto",
    "NetworkInstanceId": "vpc-2zefk9fbn8j7v585g****",
    "RegionNo": "cn-hangzhou",
    "ManualVSwitchId": "vsw-zeq4o875u****",
    "OwnerId": "158039427902****",
    "NetworkInstanceType": "VPC",
    "VpcName": "Test instance\n",
    "SupportManualMode": "0",
    "TransitRouterId": "tr-2zetwxskej633l3u1****",
    "AttachmentId": "tr-attach-sxig7bye51fid5****",
    "NetworkInstanceName": "Test VPC\n",
    "AttachmentName": "Local test\n",
    "VpcCidrTableList": [
      {
        "RouteTableId": "vtb-1234",
        "RouteEntryList": [
          {
            "NextHopInstanceId": "vrt-m5eb5me6c3l5sezae****",
            "DestinationCidr": "192.168.XX.XX/24"
          }
        ]
      }
    ],
    "EniList": [
      {
        "EniId": "eni-8vbhfosfqv2rff42****",
        "EniPrivateIpAddress": "192.168.XX.XX",
        "EniVSwitchId": "vsw-wz9viido7j436b0n1****"
      }
    ],
    "DefendCidrList": [
      "10.0.XX.XX/24"
    ]
  },
  "FirewallVpc": {
    "VpcId": "vpc-bp1245k5oagy2bp74****",
    "VpcCidr": "10.0.0.0/8",
    "VswitchId": "vsw-bp1sqg9wms9wxcs1****",
    "VswitchCidr": "10.0.0.1/24",
    "ZoneId": "cn-hangzhou-i",
    "AllowConfiguration": 0
  }
}

Error codes

HTTP status codeError codeError messageDescription
400ErrorAliUidThe aliuid is invalid.The aliuid is invalid.
400ErrorDBSelectErrorA database select error occurred.The error message returned because an internal error has occurred in querying the database.
400ErrorVpcFirewallIdThe VPC firewall ID is invalid.The VPC firewall ID is invalid.
400ErrorVpcFirewallExistThe firewall has been configured and cannot be created repeatedly.The firewall is configured and cannot be repeatedly created.
400ErrorUnmarshalJSONAn error occurred while parsing JSON.An error occurred while decoding JSON.
400ErrorDBTxErrorA database transaction error occurred.The error message returned because an internal error has occurred in the database transaction.
400ErrorVpcOpenApivpc open api failedFailed to call the VPC API.

For a list of error codes, visit the Service error codes.

Change history

Change timeSummary of changesOperation
2023-06-13The Error code has changed. The response structure of the API has changedsee changesets
Change itemChange content
Error CodesThe Error code has changed.
    delete Error Codes: 400
Output ParametersThe response structure of the API has changed.