Adds an access control policy to a specified VPC firewall policy group.
Operation description
This operation is used to add an access control policy to a specified virtual private cloud (VPC) firewall policy group. Different access control policies are used when a VPC firewall protects traffic between two VPCs connected through Cloud Enterprise Network (CEN) or traffic between two VPCs connected through Express Connect.
QPS limit
The single-user QPS limit for this operation is 10 calls per second. If the number of calls exceeds the limit, throttling is triggered, which may affect your business. Invoke this operation properly.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-cloudfirewall:CreateVpcFirewallControlPolicy |
create |
*VpcFirewallControlPolicy
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
The language of the request and response. Valid values:
|
zh |
| AclAction |
string |
Yes |
The action that Cloud Firewall performs on the traffic in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
accept |
ApplicationName
deprecated
|
string |
No |
The application type supported by the virtual private cloud (VPC) firewall access control policy. Valid values:
|
HTTP |
| Description |
string |
Yes |
The description of the virtual private cloud (VPC) firewall access control policy. |
test |
| DestPort |
string |
No |
The destination port of traffic in the virtual private cloud (VPC) firewall access control policy. Note
Set this parameter when DestPortType is set to |
80 |
| Destination |
string |
Yes |
The destination address of traffic in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
10.2.XX.XX/24 |
| DestinationType |
string |
Yes |
The type of the destination address in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
net |
| VpcFirewallId |
string |
Yes |
The ID of the virtual private cloud (VPC) firewall access control policy group.
Note
You can invoke the DescribeVpcFirewallAclGroupList operation to obtain the ID. |
vfw-a42bbb7b887148c9**** |
| Proto |
string |
Yes |
The security protocol type of traffic in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
TCP |
| Source |
string |
Yes |
The source address in the virtual private cloud (VPC) firewall access control policy.
|
10.2.XX.XX/24 |
| SourceType |
string |
Yes |
The type of the source address in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
net |
| NewOrder |
string |
Yes |
The priority of the virtual private cloud (VPC) firewall access control policy. The priority value starts from 1 and increases by increment. A smaller value indicates a higher priority. |
1 |
| DestPortType |
string |
No |
The type of the destination port of traffic in the virtual private cloud (VPC) firewall access control policy. Valid values:
|
port |
| DestPortGroup |
string |
No |
The name of the destination port address book of traffic in the virtual private cloud (VPC) firewall access control policy. Note
Set this parameter when DestPortType is set to |
my_port_group |
| MemberUid |
string |
No |
The UID of a member account of the current Alibaba Cloud account. |
258039427902**** |
| Release |
string |
No |
Specifies whether to enable the access control policy. The policy is enabled by default after it is created. Valid values:
|
true |
| ApplicationNameList |
array |
No |
The application types supported by the access control policy. |
|
|
string |
No |
The application type supported by the access control policy. Valid values:
Note
The supported application types depend on the value of the protocol type (Proto). If Proto is set to TCP, ApplicationNameList supports all the preceding application types and is expressed in the format of |
[ "ANY" ] |
|
| RepeatType |
string |
No |
The recurrence type of the policy validity period for the access control policy. Valid values:
Valid values:
|
Permanent |
| RepeatDays |
array |
No |
The days of the recurrence for the policy validity period of the access control policy.
Note
If RepeatType is set to Weekly, the values in RepeatDays cannot be repeated.
Note
If RepeatType is set to Monthly, the values in RepeatDays cannot be repeated. |
|
|
integer |
No |
The recurrence day of the policy validity period for the access control policy. Note
If RepeatType is set to Weekly, the valid values are 0 to 6. The week starts on Sunday. If RepeatType is set to Monthly, the valid values are 1 to 31. |
1 |
|
| RepeatStartTime |
string |
No |
The recurrence start time of the policy validity period for the access control policy. Example: 08:00. The value must be on the hour or on the half hour and must be at least 30 minutes earlier than the recurrence end time. Note
If RepeatType is set to Permanent or None, RepeatStartTime is empty. If RepeatType is set to Daily, Weekly, or Monthly, RepeatStartTime must be specified. The format is HH:MM (24-hour clock), such as 08:00. |
08:00 |
| RepeatEndTime |
string |
No |
The recurrence end time of the policy validity period for the access control policy. Example: 23:30. The value must be on the hour or on the half hour and must be at least 30 minutes later than the recurrence start time. Note
If RepeatType is set to Permanent or None, RepeatEndTime is empty. If RepeatType is set to Daily, Weekly, or Monthly, RepeatEndTime must be specified. The format is HH:MM (24-hour clock), such as 08:00. |
23:30 |
| StartTime |
integer |
No |
The start time of the policy validity period for the access control policy. The value is a UNIX timestamp in seconds. The value must be on the hour or on the half hour and must be at least 30 minutes earlier than the end time. Note
If RepeatType is set to Permanent, StartTime is empty. If RepeatType is set to None, Daily, Weekly, or Monthly, StartTime must be specified. |
1694761200 |
| EndTime |
integer |
No |
The end time of the policy validity period for the access control policy. The value is a UNIX timestamp in seconds. The value must be on the hour or on the half hour and must be at least 30 minutes later than the start time. Note
If RepeatType is set to Permanent, EndTime is empty. If RepeatType is set to None, Daily, Weekly, or Monthly, EndTime must be specified. |
1694764800 |
| DomainResolveType |
string |
No |
The domain name resolution method of the access control policy. Valid values:
|
FQDN |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| AclUuid |
string |
The unique ID of the access control policy. |
00281255-d220-4db1-8f4f-c4df221ad84c |
| RequestId |
string |
The request ID. |
CBF1E9B7-D6A0-4E9E-AD3E-2B47E6C2837D |
Examples
Success response
JSON format
{
"AclUuid": "00281255-d220-4db1-8f4f-c4df221ad84c",
"RequestId": "CBF1E9B7-D6A0-4E9E-AD3E-2B47E6C2837D"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | ErrorParametersUid | The aliUid parameter is invalid. | The aliUid parameter is invalid. |
| 400 | ErrorUUIDNew | The UUID is invalid. | The UUID is invalid. |
| 400 | ErrorParametersSource | The source is invalid. | The source is invalid. |
| 400 | ErrorParametersDestination | The Destination parameter is invalid. | The Destination parameter is invalid. |
| 400 | ErrorParametersProto | The protocol is invalid. | The protocol is invalid. |
| 400 | ErrorParametersDestPort | The dst_port is invalid. | The dst_port is invalid. |
| 400 | ErrorParametersAction | The action is invalid. | The action is invalid. |
| 400 | ErrorDBSelect | An error occurred while querying database. | An error occurred while querying database. |
| 400 | ErrorParameters | A parameter error occurred. | A parameter error occurred. |
| 400 | ErrorAddressCountExceed | The maximum number of addresses is exceeded. | The maximum number of address is exceeded. |
| 400 | ErrorParametersNewOrder | The newOrder is invalid. | The newOrder is invalid. |
| 400 | ErrorDBInsert | An error occurred while performing an insert operation in the database. | An error occurred while performing an insert operation in the database. |
| 400 | ErrorDBDelete | An error occurred while deleting the database. | An error occurred while deleting the database. |
| 400 | ErrorRecordLog | An error occurred while updating the operation log. | An error occurred while updating the operation log. |
| 400 | ErrorParameterIpVersion | The IP version is invalid. | The IP version is invalid. |
| 400 | ErrorParametersDirection | The direction is invalid. | The direction is invalid. |
| 400 | ErrorDomainResolve | An error occurred while resolving the domain. | An error occurred while resolving the domain. |
| 400 | ErrorAclExtendedCountExceed | ACL or extended ACL rules are not matched. | The quota for access control policies or extra access control policies is exhausted. |
| 400 | ErrorAclDomainAnyCountExceed | The number of resolved domain names cannot exceed 200. ACL configuration can be continued for HTTP, HTTPS, SMTP, SMTPS, and SSL applications. | The domain name is resolved to more than 200 IP addresses. We recommend that you set Application in your access control policy to HTTPS, HTTPS, SMTP, SMTPS, or SSL. |
| 400 | ErrorMarshalJSON | An error occurred. Try again later. | An error occurred. Try again later. |
| 400 | ErrorParametersFtpNotSupport | domain destination not support ftp. | FTP application is not supported when the policy destination is a domain name |
| 400 | ErrorParametersApplicationName | Specified parameter ApplicationName is not valid. | Specified parameter ApplicationName is not valid. |
| 400 | ErrorParametersApplicationNameList | Specified parameter ApplicationNameList is not valid. | Specified parameter ApplicationNameList is not valid. |
| 400 | ErrorAddressGroupNotExist | The address group does not exist. | The address group does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.