Adds traffic classification rules to a traffic marking policy by calling the AddTrafficMatchRuleToTrafficMarkingPolicy operation.
Operation description
AddTrafficMatchRuleToTrafficMarkingPolicy is an asynchronous operation. After you send a request, the system returns a RequestId but the traffic classification rule is not yet created. The creation task continues to run in the background. You can call the ListTrafficMarkingPolicies operation to query the status of the traffic classification rule.
If the traffic classification rule is in the Creating state, the rule is being created. In this state, you can only query the rule and cannot perform other operations on it.
If the traffic classification rule is in the Active state, the rule is created.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cen:AddTrafficMatchRuleToTrafficMarkingPolicy |
create |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The client token can contain only ASCII characters. Note
If you do not specify this parameter, the system automatically uses the RequestId as the ClientToken. The RequestId may be different for each API request. |
123e4567-e89b-12d3-a456-426**** |
| DryRun |
boolean |
No |
Specifies whether to perform a dry run. Valid values:
|
false |
| TrafficMarkingPolicyId |
string |
Yes |
The ID of the traffic marking policy. |
tm-u9nxup5kww5po8**** |
| TrafficMatchRules |
array<object> |
No |
The list of traffic classification rules. You can add up to 50 traffic classification rules at a time. |
|
|
object |
No |
The information about the traffic classification rule. |
||
| MatchDscp |
integer |
No |
The Differentiated Services Code Point (DSCP) value of the traffic packet. Valid values: 0 to 63. The traffic classification rule matches traffic that contains the specified DSCP value. If you do not specify this parameter, the traffic classification rule matches traffic with any DSCP value. Note
The DSCP value refers to the DSCP value that the traffic packet already carries before it enters the inter-region connection. |
5 |
| DstCidr |
string |
No |
The destination CIDR block of the traffic packet. The traffic classification rule matches traffic whose destination IP address falls within the destination CIDR block. If you do not specify this parameter, the traffic classification rule matches traffic with any destination IP address. |
10.10.10.0/24 |
| TrafficMatchRuleDescription |
string |
No |
The description of the traffic classification rule. The description can be empty or 1 to 256 characters in length and cannot start with http:// or https://. |
desctest |
| Protocol |
string |
No |
The protocol type of the traffic packet. The traffic classification rule supports matching traffic of multiple protocol types, such as HTTP, HTTPS, TCP, UDP, SSH, and Telnet. For more protocol types, log on to the Cloud Enterprise Network (CEN) console. |
HTTP |
| DstPortRange |
array |
No |
The destination port of the traffic packet. Valid values: -1 and 1 to 65535. The traffic classification rule matches traffic whose destination port falls within the destination port range. If you do not specify this parameter, the traffic classification rule matches traffic with any destination port. You can specify up to 2 port numbers for this parameter. The input format is described as follows:
|
|
|
integer |
No |
The destination port of the traffic packet. Valid values: -1 and 1 to 65535. The traffic classification rule matches traffic whose destination port falls within the destination port range. If you do not specify this parameter, the traffic classification rule matches traffic with any destination port. You can specify up to two port numbers for this parameter. The input format is described as follows:
|
80 |
|
| SrcCidr |
string |
No |
The source CIDR block of the traffic packet. The traffic classification rule matches traffic whose source IP address falls within the source CIDR block. If you do not specify this parameter, the traffic classification rule matches traffic with any source IP address. |
192.168.10.0/24 |
| AddressFamily |
string |
No |
The address type. Valid values: IPv4, IPv6, or empty. |
IPv4 |
| SrcPortRange |
array |
No |
The source port of the traffic packet. Valid values: -1 and 1 to 65535. The traffic classification rule matches traffic whose source port falls within the source port range. If you do not specify this parameter, the traffic classification rule matches traffic with any source port. You can specify up to two port numbers for this parameter. The input format is described as follows:
|
|
|
integer |
No |
The source port of the traffic packet. Valid values: -1 and 1 to 65535. The traffic classification rule matches traffic whose source port falls within the source port range. If you do not specify this parameter, the traffic classification rule matches traffic with any source port. You can specify up to two port numbers for this parameter. The input format is described as follows:
|
200 |
|
| TrafficMatchRuleName |
string |
No |
The name of the traffic classification rule. The name can be empty or 1 to 128 characters in length and cannot start with http:// or https://. |
nametest |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
0876E54E-3E36-5C31-89F0-9EE8A9266F9A |
Examples
Success response
JSON format
{
"RequestId": "0876E54E-3E36-5C31-89F0-9EE8A9266F9A"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidTrafficMarkingPolicyId.NotFound | Operation is failed because traffic marking policy id is not found. | The error message returned because the specified traffic marking policy ID (TrafficMarkingPolicyId) does not exist. |
| 400 | IllegalParam.SrcCidr | The specified SrcCidr is invalid. | The error message returned because the specified source CIDR block is invalid. |
| 400 | IncorrectStatus.TrafficMarkingPolicy | The status of TrafficMarkingPolicy is incorrect. | The error message returned because the status of the traffic marking policy does not support this operation. Try again later. |
| 400 | IllegalParam.DstCidr | The specified DstCidr is invalid. | The error message returned because the specified destination CIDR block (DstCidr) is invalid. |
| 400 | IllegalParam.Protocol | The specified Protocol is invalid. | The error message returned because the specified protocol is invalid. |
| 400 | Duplicated.TrafficMatchRules | The parameter AddTrafficMatchRules are duplicated. | The specified flow classification rules are duplicated. |
| 400 | InstanceExist.TrafficMatchRules | The instance already exists. | The error message returned because the specified traffic match rules (TrafficMatchRules) already exist. |
| 400 | MissingParam.TrafficMatchRules | The parameter TrafficMatchRules is empty. | The specified flow classification rule is empty. |
| 400 | IllegalParam.SrcPortRange | The specified SrcPortRange is illegal. | The source port is invalid. |
| 400 | IllegalParam.DstPortRange | The specified DstPortRange is illegal. | The specified DstPortRange is illegal. |
| 400 | AttrMismatching.CidrAddressFamily | Attribute SrcCidr or DstCidr of TrafficMarkRule does not match AddressFamily. | Attribute SrcCidr or DstCidr of TrafficMarkRule does not match AddressFamily. |
| 400 | IllegalParam.AddressFamily | AddressFamily is illegal. | The AddressFamily value of the request parameter is invalid. Valid values are IPv4 or IPv6. |
| 400 | AttrMismatching.SrcCidrDstCidr | Attribute SrcCidr of TrafficMarkRule does not match DstCidr. | Attribute SrcCidr of TrafficMarkRule does not match DstCidr. |
| 400 | AttrMismatching.CidrProtocol | Attribute SrcCidr or DstCidr of TrafficMarkRule does not match Protocol. | Attribute SrcCidr or DstCidr of TrafficMarkRule does not match Protocol. |
| 400 | InvalidTransitRouterMode.NeedUpgrade | TransitRouter need to upgrade. | The error message returned because the specified transit router mode is not supported. |
| 400 | OperationUnsupported.SrcPortRange | Current TR version does not support setting source port range. | Current TR version does not support setting source port range |
| 400 | OperationUnsupported.DstPortRange | Current TR version does not support setting destination port range. | Current TR version does not support setting destination port range. |
| 400 | OperationUnsupported.IPv6Cidr | The traffic marking policy for current TR type does not support IPv6 CIDR. | The flow classification rules in the flow marking policy of the basic version forwarding router do not support IPv6 network segments. |
| 400 | InvalidParameter | Invalid parameter. | The error message returned because the parameter is set to an invalid value. |
| 400 | Unauthorized | The AccessKeyId is unauthorized. | The error message returned because you do not have the permissions to perform this operation. |
| 400 | MissingParam.TrafficMarkingPolicyId | The parameter TrafficMarkingPolicyId is mandatory. | |
| 400 | InvalidParameter.TrafficMarkingPolicyId | The specified parameter TrafficMarkingPolicyId is invalid. | The parameter TrafficMarkingPolicyId entered is illegal. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.