Hi there! Are you looking for the official Deno documentation? Try docs.deno.com for all your Deno learning needs.

Usage

import * as mod from "https://aws-api.deno.dev/v0.4/services/networkfirewall.ts?docs=full";

§Classes

NetworkFirewall

§Interfaces

ActionDefinition

A custom action to use in stateless rule actions settings. This is used in "CustomAction".

Address

A single IP address specification. This is used in the "MatchAttributes" source and destination specifications.

AssociateFirewallPolicyRequest
AssociateFirewallPolicyResponse
AssociateSubnetsRequest
AssociateSubnetsResponse
Attachment

The configuration and status for a single subnet that you've specified for use by the Network Firewall firewall. This is part of the "FirewallStatus".

CapacityUsageSummary

The capacity usage summary of the resources used by the "ReferenceSets" in a firewall.

CIDRSummary

Summarizes the CIDR blocks used by the IP set references in a firewall. Network Firewall calculates the number of CIDRs by taking an aggregated count of all CIDRs used by the IP sets you are referencing.

CreateFirewallPolicyRequest
CreateFirewallPolicyResponse
CreateFirewallRequest
CreateFirewallResponse
CreateRuleGroupRequest
CreateRuleGroupResponse
CustomAction

An optional, non-standard action to use for stateless packet handling. You can define this in addition to the standard action that you must specify.

DeleteFirewallPolicyRequest
DeleteFirewallPolicyResponse
DeleteFirewallRequest
DeleteFirewallResponse
DeleteResourcePolicyRequest
DeleteRuleGroupRequest
DeleteRuleGroupResponse
DescribeFirewallPolicyRequest
DescribeFirewallPolicyResponse
DescribeFirewallRequest
DescribeFirewallResponse
DescribeLoggingConfigurationRequest
DescribeLoggingConfigurationResponse
DescribeResourcePolicyRequest
DescribeResourcePolicyResponse
DescribeRuleGroupMetadataRequest
DescribeRuleGroupMetadataResponse
DescribeRuleGroupRequest
DescribeRuleGroupResponse
Dimension

The value to use in an Amazon CloudWatch custom metric dimension. This is used in the PublishMetrics "CustomAction". A CloudWatch custom metric dimension is a name/value pair that's part of the identity of a metric.

DisassociateSubnetsRequest
DisassociateSubnetsResponse
EncryptionConfiguration

A complex type that contains optional Amazon Web Services Key Management Service (KMS) encryption settings for your Network Firewall resources. Your data is encrypted by default with an Amazon Web Services owned key that Amazon Web Services owns and manages for you. You can use either the Amazon Web Services owned key, or provide your own customer managed key. To learn more about KMS encryption of your Network Firewall resources, see Encryption at rest with Amazon Web Services Key Managment Service in the Network Firewall Developer Guide.

Firewall

The firewall defines the configuration settings for an Network Firewall firewall. These settings include the firewall policy, the subnets in your VPC to use for the firewall endpoints, and any tags that are attached to the firewall Amazon Web Services resource.

FirewallMetadata

High-level information about a firewall, returned by operations like create and describe. You can use the information provided in the metadata to retrieve and manage a firewall.

FirewallPolicy

The firewall policy defines the behavior of a firewall using a collection of stateless and stateful rule groups and other settings. You can use one firewall policy for multiple firewalls.

FirewallPolicyMetadata

High-level information about a firewall policy, returned by operations like create and describe. You can use the information provided in the metadata to retrieve and manage a firewall policy. You can retrieve all objects for a firewall policy by calling "DescribeFirewallPolicy".

FirewallPolicyResponse

The high-level properties of a firewall policy. This, along with the "FirewallPolicy", define the policy. You can retrieve all objects for a firewall policy by calling "DescribeFirewallPolicy".

FirewallStatus

Detailed information about the current status of a "Firewall". You can retrieve this for a firewall by calling "DescribeFirewall" and providing the firewall name and ARN.

Header

The basic rule criteria for Network Firewall to use to inspect packet headers in stateful traffic flow inspection. Traffic flows that match the criteria are a match for the corresponding "StatefulRule".

IPSet

A list of IP addresses and address ranges, in CIDR notation. This is part of a "RuleVariables".

IPSetMetadata

General information about the IP set.

IPSetReference

Configures one or more IP set references for a Suricata-compatible rule group. This is used in "CreateRuleGroup" or "UpdateRuleGroup". An IP set reference is a rule variable that references a resource that you create and manage in another Amazon Web Services service, such as an Amazon VPC prefix list. Network Firewall IP set references enable you to dynamically update the contents of your rules. When you create, update, or delete the IP set you are referencing in your rule, Network Firewall automatically updates the rule's content with the changes. For more information about IP set references in Network Firewall, see Using IP set references in the Network Firewall Developer Guide.

ListFirewallPoliciesRequest
ListFirewallPoliciesResponse
ListFirewallsRequest
ListFirewallsResponse
ListRuleGroupsRequest
ListRuleGroupsResponse
ListTagsForResourceRequest
ListTagsForResourceResponse
LogDestinationConfig

Defines where Network Firewall sends logs for the firewall for one log type. This is used in "LoggingConfiguration". You can send each type of log to an Amazon S3 bucket, a CloudWatch log group, or a Kinesis Data Firehose delivery stream.

LoggingConfiguration

Defines how Network Firewall performs logging for a "Firewall".

MatchAttributes

Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection. Each match attributes set can include one or more items such as IP address, CIDR range, port number, protocol, and TCP flags.

PerObjectStatus

Provides configuration status for a single policy or rule group that is used for a firewall endpoint. Network Firewall provides each endpoint with the rules that are configured in the firewall policy. Each time you add a subnet or modify the associated firewall policy, Network Firewall synchronizes the rules in the endpoint, so it can properly filter network traffic. This is part of a "SyncState" for a firewall.

PortRange

A single port range specification. This is used for source and destination port ranges in the stateless rule "MatchAttributes", SourcePorts, and DestinationPorts settings.

PortSet

A set of port ranges for use in the rules in a rule group.

PublishMetricAction

Stateless inspection criteria that publishes the specified metrics to Amazon CloudWatch for the matching packet. This setting defines a CloudWatch dimension value to be published.

PutResourcePolicyRequest
ReferenceSets

Contains a set of IP set references.

RuleDefinition

The inspection criteria and action for a single stateless rule. Network Firewall inspects each packet for the specified matching criteria. When a packet matches the criteria, Network Firewall performs the rule's actions on the packet.

RuleGroup

The object that defines the rules in a rule group. This, along with "RuleGroupResponse", define the rule group. You can retrieve all objects for a rule group by calling "DescribeRuleGroup".

RuleGroupMetadata

High-level information about a rule group, returned by "ListRuleGroups". You can use the information provided in the metadata to retrieve and manage a rule group.

RuleGroupResponse

The high-level properties of a rule group. This, along with the "RuleGroup", define the rule group. You can retrieve all objects for a rule group by calling "DescribeRuleGroup".

RuleOption

Additional settings for a stateful rule. This is part of the "StatefulRule" configuration.

RulesSource

The stateless or stateful rules definitions for use in a single rule group. Each rule group requires a single RulesSource. You can use an instance of this for either stateless rules or stateful rules.

RulesSourceList

Stateful inspection criteria for a domain list rule group.

RuleVariables

Settings that are available for use in the rules in the "RuleGroup" where this is defined.

SourceMetadata

High-level information about the managed rule group that your own rule group is copied from. You can use the the metadata to track version updates made to the originating rule group. You can retrieve all objects for a rule group by calling DescribeRuleGroup.

StatefulEngineOptions

Configuration settings for the handling of the stateful rule groups in a firewall policy.

StatefulRule

A single Suricata rules specification, for use in a stateful rule group. Use this option to specify a simple Suricata rule with protocol, source and destination, ports, direction, and rule options. For information about the Suricata Rules format, see Rules Format.

StatefulRuleGroupOverride

The setting that allows the policy owner to change the behavior of the rule group within a policy.

StatefulRuleGroupReference

Identifier for a single stateful rule group, used in a firewall policy to refer to a rule group.

StatefulRuleOptions

Additional options governing how Network Firewall handles the rule group. You can only use these for stateful rule groups.

StatelessRule

A single stateless rule. This is used in "StatelessRulesAndCustomActions".

StatelessRuleGroupReference

Identifier for a single stateless rule group, used in a firewall policy to refer to the rule group.

StatelessRulesAndCustomActions

Stateless inspection criteria. Each stateless rule group uses exactly one of these data types to define its stateless rules.

SubnetMapping

The ID for a subnet that you want to associate with the firewall. This is used with "CreateFirewall" and "AssociateSubnets". Network Firewall creates an instance of the associated firewall in each subnet that you specify, to filter traffic in the subnet's Availability Zone.

SyncState

The status of the firewall endpoint and firewall policy configuration for a single VPC subnet.

Tag

A key:value pair associated with an Amazon Web Services resource. The key:value pair can be anything you define. Typically, the tag key represents a category (such as "environment") and the tag value represents a specific value within that category (such as "test," "development," or "production"). You can add up to 50 tags to each Amazon Web Services resource.

TagResourceRequest
TCPFlagField

TCP flags and masks to inspect packets for, used in stateless rules "MatchAttributes" settings.

UntagResourceRequest
UpdateFirewallDeleteProtectionRequest
UpdateFirewallDeleteProtectionResponse
UpdateFirewallDescriptionRequest
UpdateFirewallDescriptionResponse
UpdateFirewallEncryptionConfigurationRequest
UpdateFirewallEncryptionConfigurationResponse
UpdateFirewallPolicyChangeProtectionRequest
UpdateFirewallPolicyChangeProtectionResponse
UpdateFirewallPolicyRequest
UpdateFirewallPolicyResponse
UpdateLoggingConfigurationRequest
UpdateLoggingConfigurationResponse
UpdateRuleGroupRequest
UpdateRuleGroupResponse
UpdateSubnetChangeProtectionRequest
UpdateSubnetChangeProtectionResponse

§Type Aliases

AttachmentStatus
ConfigurationSyncState
EncryptionType
FirewallStatusValue
GeneratedRulesType
IPAddressType
LogDestinationType
LogType
OverrideAction
PerObjectSyncStatus
ResourceManagedStatus
ResourceManagedType
ResourceStatus
RuleGroupType
RuleOrder
StatefulAction
StatefulRuleDirection
StatefulRuleProtocol
StreamExceptionPolicy
TargetType
TCPFlag