@Stability(value=Stable)
public static interface CfnRuleGroup.RuleDefinitionProperty
extends software.amazon.jsii.JsiiSerializable
AWS Network Firewall inspects each packet for the specified matching criteria. When a packet matches the criteria, Network Firewall performs the rule's actions on the packet.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.services.networkfirewall.*;
RuleDefinitionProperty ruleDefinitionProperty = RuleDefinitionProperty.builder()
.actions(List.of("actions"))
.matchAttributes(MatchAttributesProperty.builder()
.destinationPorts(List.of(PortRangeProperty.builder()
.fromPort(123)
.toPort(123)
.build()))
.destinations(List.of(AddressProperty.builder()
.addressDefinition("addressDefinition")
.build()))
.protocols(List.of(123))
.sourcePorts(List.of(PortRangeProperty.builder()
.fromPort(123)
.toPort(123)
.build()))
.sources(List.of(AddressProperty.builder()
.addressDefinition("addressDefinition")
.build()))
.tcpFlags(List.of(TCPFlagFieldProperty.builder()
.flags(List.of("flags"))
// the properties below are optional
.masks(List.of("masks"))
.build()))
.build())
.build();
| Modifier and Type | Interface and Description |
|---|---|
static class |
CfnRuleGroup.RuleDefinitionProperty.Builder
A builder for
CfnRuleGroup.RuleDefinitionProperty |
static class |
CfnRuleGroup.RuleDefinitionProperty.Jsii$Proxy
An implementation for
CfnRuleGroup.RuleDefinitionProperty |
| Modifier and Type | Method and Description |
|---|---|
static CfnRuleGroup.RuleDefinitionProperty.Builder |
builder() |
List<String> |
getActions()
The actions to take on a packet that matches one of the stateless rule definition's match attributes.
|
Object |
getMatchAttributes()
Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection.
|
@Stability(value=Stable) @NotNull List<String> getActions()
You must specify a standard action and you can add custom actions.
Network Firewall only forwards a packet for stateful rule inspection if you specify
aws:forward_to_sfefor a rule that the packet matches, or if the packet doesn't match any stateless rule and you specifyaws:forward_to_sfefor theStatelessDefaultActionssetting for theFirewallPolicy.
For every rule, you must specify exactly one of the following standard actions.
Additionally, you can specify a custom action. To do this, you define a custom action by name and type, then provide the name you've assigned to the action in this Actions setting.
To provide more than one action in this setting, separate the settings with a comma. For example, if you have a publish metrics custom action that you've named MyMetricsAction , then you could specify the standard action aws:pass combined with the custom action using [“aws:pass”, “MyMetricsAction”] .
@Stability(value=Stable) @NotNull Object getMatchAttributes()
Each match attributes set can include one or more items such as IP address, CIDR range, port number, protocol, and TCP flags.
@Stability(value=Stable) static CfnRuleGroup.RuleDefinitionProperty.Builder builder()
Copyright © 2022. All rights reserved.