Creates a virtual private cloud (VPC) firewall to protect traffic between network instances in a Cloud Enterprise Network (CEN) instance and a specified VPC.
Operation description
This operation is used to create a virtual private cloud (VPC) firewall for VPC-connected instances in a CEN instance. The virtual private cloud (VPC) firewall protects traffic between network instances (including VPCs, virtual border routers (VBRs), and Cloud Connect Networks (CCNs)) in the CEN instance and a specified VPC. The virtual private cloud (VPC) firewall does not protect traffic between VBRs, between CCNs, or between VBRs and CCNs. Prerequisites: (1) Invoke the Cbn CreateCen operation to create a CEN instance. (2) Create at least two VPCs. (3) Invoke the Cbn AttachCenChildInstance operation to associate the VPCs with the CEN instance. (4) Make sure no conflicting RouteMaps or transit router (TR) routing entries exist in the CEN instance. For more information, see VPC border firewall limits.
Rate limit
The single-user queries per second (QPS) limit for this operation is 10 calls per second. If the number of calls per second exceeds the limit, throttling is triggered. This may affect your business. Manage your calls appropriately.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-cloudfirewall:CreateVpcFirewallCenConfigure |
create |
*VpcFirewallCen
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
The language of the content within the request and response. Valid values:
|
zh |
| VpcFirewallName |
string |
Yes |
The instance name of the virtual private cloud (VPC) firewall. |
vpc-firewall-test |
| NetworkInstanceId |
string |
Yes |
The instance ID of the VPC-connected instance for which you want to create a virtual private cloud (VPC) firewall. Note
Prerequisite: The VPC must have been attached to the CEN instance specified by CenId by invoking the Cbn.AttachCenChildInstance operation. |
vpc-bp10zlifxh6j0232w**** |
| VpcRegion |
string |
Yes |
The region ID of the VPC for which you want to create a virtual private cloud (VPC) firewall. Note
For more information about the regions supported by Cloud Firewall, see Supported regions. |
cn-hangzhou |
| FirewallSwitch |
string |
Yes |
Settings for the virtual private cloud (VPC) firewall status after you create a VPC. Valid values:
|
open |
| CenId |
string |
Yes |
The instance ID of the CEN instance. Note
Prerequisite: The CEN instance must have been created by invoking the Cbn.CreateCen operation. |
cen-x5jayxou71ad73**** |
| MemberUid |
string |
No |
The UID of the member account of the current Alibaba Cloud account. |
258039427902**** |
| VSwitchId |
string |
No |
The ID of the vSwitch to which the Cloud Firewall interface belongs. |
vsw-qzeaol304m*** |
| FirewallVpcCidrBlock |
string |
No |
The CIDR block of the VPC used by the firewall. Specify a CIDR block with a subnet mask of no more than 28 bits. This CIDR block is allocated to the VPC that is required during the create a VPC firewall procedure and is used for automatic creation of a security VPC (Cloud_Firewall_VPC) for traffic redirection. If you leave this parameter empty, the CIDR block 10.0.0.0/8 is automatically allocated by default. Note
This parameter takes effect only when a VPC firewall is created for the first time in the local region of the CEN instance. |
10.0.0.0/8 |
| FirewallVpcZoneId |
string |
No |
The ID of the primary active zone of the firewall. If your business is latency-sensitive, you can set the firewall zone to the same zone as the vSwitch of the business VPC to reduce latency. If you leave this parameter empty, a zone is automatically allocated by default. Note
This parameter takes effect only when you create a VPC firewall for the first time in the local region of the CEN instance. |
cn-hangzhou-a |
| FirewallVSwitchCidrBlock |
string |
No |
The CIDR block of the vSwitch used by the firewall. Specify a CIDR block with a subnet mask of no more than 29 bits that does not conflict with your network planning. This CIDR block is allocated to the vSwitch that is required during the create a VPC firewall procedure and is used for automatic creation of a vSwitch (Cloud_Firewall_VSWITCH) within the security VPC for traffic redirection. The vSwitch CIDR block must be a subnet of the firewall VPC CIDR block. If you leave this parameter empty, the CIDR block 10.219.219.216/29 is automatically allocated by default. Note
This parameter takes effect only when a VPC firewall is created for the first time in the local region of the CEN instance. |
10.219.219.216/29 |
| FirewallVpcStandbyZoneId |
string |
No |
The ID of the secondary active zone of the firewall. The firewall performs an automatic switchover to the secondary zone to continue running only when the primary zone becomes unavailable. If you leave this parameter empty, a secondary zone is automatically allocated by default. Note
This parameter takes effect only when you create a VPC firewall for the first time in the local region of the CEN instance. |
10.219.219.216/29 |
| FirewallVSwitchZoneId |
string |
No |
The zone ID of the vSwitch used by the firewall. |
cn-hangzhou-i |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| VpcFirewallId |
string |
The instance ID of the virtual private cloud (VPC) firewall. |
vfw-m5e7dbc4y**** |
| RequestId |
string |
The request ID. |
850A84D6-0DE4-4797-A1E8-00090125h4j6 |
Examples
Success response
JSON format
{
"VpcFirewallId": "vfw-m5e7dbc4y****",
"RequestId": "850A84D6-0DE4-4797-A1E8-00090125h4j6"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | ErrorAliUid | The aliuid is invalid. | The aliuid is invalid. |
| 400 | ErrorVpcFirewallExist | The firewall has been configured and cannot be created repeatedly. | The firewall is configured and cannot be repeatedly created. |
| 400 | ErrorVpcId | The VPC ID is invalid. | The VPC ID is invalid. |
| 400 | ErrorRegionNoError | The region is invalid. | The region is invalid. |
| 400 | ErrorVpcFirewallNotFound | The specified VPC firewall does not exist. Please select again. | The specified VPC firewall does not exist. Enter another value. |
| 400 | ErrorCenNotFound | The specified CEN instance does not exist. Please verify the CenId and ensure it is in Active state. | |
| 400 | ErrorVpcNotAttachedToCen | The specified VPC is not attached to the given CEN. Attach the VPC to the CEN before creating the VPC firewall. | |
| 400 | ErrorDBSelectError | A database select error occurred. | The error message returned because an internal error has occurred in querying the database. |
| 400 | ErrorDBTxError | A database transaction error occurred. | The error message returned because an internal error has occurred in the database transaction. |
| 400 | ErrorDBUpdateError | A database update error occurred. | |
| 400 | ErrorRecordLog | An error occurred while updating the operation log. | An error occurred while updating the operation log. |
| 400 | ErrorCenVbrNotSupport | 云企业网vbr不支持开防火墙 | |
| 400 | ErrorCenNotSupportCCN | VPC防火墙云企业网CCN实例, 不支持开启VPC防火墙 | |
| 400 | ErrorCenNotSupportMultipleAccounts | The current version of Cloud Firewall does not support multiple accounts when it uses VPC Firewall to protect Cloud Enterprise Network. Upgrade the specifications and try again. | The current edition of Cloud Firewall does not support multiple accounts when it uses VPC Firewall to protect CEN. Upgrade the specifications and try again. |
| 400 | ErrorFirewallStatus | Firewall status error, please try again later. | The status of the firewall is invalid. Try again later. |
| 400 | ErrorFirewallQuotaNotEmpty | quota is not enough, unable to configure VPC firewall, please increase quota first. | |
| 400 | ErrorHubvpcCannotCreate | HUB VPC不允许创建防火墙 | |
| 400 | ErrorCenVpcEcConflict | The VPC of the cloud enterprise network conflicts with the VPC of the high-speed channel, and the firewall cannot be opened. Please select again | Conflicts occur between the VPC of CEN and the VPC of Express Connect. You cannot enable the firewall. Specify another value. |
| 400 | ErrorRegionNoDisable | There are unsupported regions, please reselect | Some regions are not supported. Specify supported regions. |
| 400 | ErrorCenFirewallVpcNumInvalid | 云企业网vpc数量不足, 无法开启VPC边界防火墙 | |
| 400 | ErrorDestCidrError | The target network segment is wrong. Please configure the target network segment correctly. | The specified destination CIDR block is invalid. Enter another value. |
| 400 | ErrorVpcCustomRouteTableWithVswitch | VPC存在自定义路由表且关联了vswitch, 不允许创建VPC防火墙 | |
| 400 | ErrorCenNotSupportTREnterpriseAutoMode | VPC firewall does not support TR Enterprise Edition auto mode protection, please use manual mode protection | VPC firewalls do not support the CEN-TR automatic mode. |
| 400 | ErrorInvalidMemberUid | Member uid is invalid | The member is invalid. |
| 400 | ErrorFirewallName | Firewall name invalid. | Firewall name error, please re-enter. |
| 400 | ErrorFirewallSwitch | The firewall enabling parameter is incorrect. Please select again. | The specified switch of the firewall is invalid. Enter another value. |
| 400 | ErrorNetworkInstanceIdError | Network InstanceId ID is invalid | The ID of the network instance is invalid. |
| 400 | ErrorCenId | CEN ID is error | The ID of the CEN instance is invalid. |
| 400 | ErrorCidrFormat | Cidr ip format error. | CIDR format error, please re-select |
| 400 | ErrorDestCidrEmpty | The target network segment is empty and cannot be created | The destination CIDR block is not specified. The firewall cannot be created. |
| 400 | ErrorOwnerId | owner id invalid. | The account is incorrect, please re-enter. |
| 400 | ErrorCenManualFirewallExist | VPC firewall in manual mode already exists in this CEN network. You are not allowed to create a VPC firewall in automatic mode. | This CEN already has a VPC firewall in manual mode. You cannot create a VPC firewall in automatic mode. |
| 400 | ErrorFirewallExistDeleting | There is a VPC firewall that is being deleted, and it is not allowed to create. | The VPC firewall being deleted is not allowed to be created. |
| 400 | ErrorSameCidrIp | The same network segment cannot be configured repeatedly. Please reselect the network segment. | The CIDR block is already in use. Specify another CIDR block. |
| 400 | ErrorCenRouteMapExist | cen route map is exist. | Creating a VPC perimeter firewall is not allowed RouteMap it already exists. Please contact the cloud firewall after-sales technical support. |
| 400 | ErrorUserCredentials | User credentials failed. | Unauthorized, not accessible, please first authorize firewall permissions. |
| 400 | ErrorDBNoRow | No rows in database. | No data found. |
| 400 | ErrorVpcFirewallVpcNumLimit | The number of vpcs in this region is limited to open the vpc firewall. | The VPC boundary firewall cannot be enabled because of the limited number of VPCs in this region. |
| 400 | ErrorCenExistPublicCidr | cen domain route exist public route. | There is a public network segment in the cloud enterprise network, and the VPC boundary firewall is not supported. |
| 400 | ErrorCenExistTrRoute | Cen VPC route exist tr route. | The VPC in the cloud enterprise network has a route whose next hop is TR, and the VPC boundary firewall is not supported. |
| 400 | ErrorCenTRAssociationCustomRouteTable | CEN-TR association custom route table. | The VPC boundary firewall does not support the custom route table associated with the CEN-TR network instance connection, and the VPC boundary firewall cannot be enabled. |
| 400 | ErrorDBInsertError | A database insert error occurred. | An error occurred while performing an insert operation in the database. |
| 400 | ErrorInvalidMemberUidStatus | invalid member uid status. | The status of the member account is invalid. This operation is not supported. |
| 400 | ErrorBandwidthPenalty | Cloud Firewall bandwidth is being overused. | Cloud Firewall bandwidth is being overused. |
| 400 | ErrorGeneralInstanceSpecFull | Cloud Firewall instance specifications are full. | Cloud Firewall instance specifications are full. |
| 400 | ErrorFirewallVSwitchCidrConflict | Firewall switch network segment conflicts with business network segment. | Firewall switch network segment conflicts with business network segment |
| 400 | ResourceNotFound.Cen | The specified CEN instance does not exist. | |
| 400 | InvalidParameter.VpcNotAttachedToCen | The specified VPC is not attached to the CEN instance. | |
| 400 | ErrorFirewallZoneId | Firewall zone error. | Firewall zone selection error |
| 400 | ErrorSwitchZoneTaskDoing | zone switch task in progress. | Zone modification task in progress |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.