CLI Command Reference
Access Control Rule Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Importing Access Control Rules | hcloud CFW ImportRuleAcl | This API is used to import access control rules. | |
| Exporting Access Control Rules | hcloud CFW ExportRuleAcl | This API is used to export access control rules. | |
| Downloading the Import Template | hcloud CFW DownloadImportTemplate | This API is used to download the import template. | |
| Downloading the Export Result | hcloud CFW DownloadExportResult | This API is used to download the export result. | |
| Querying the Export Result | hcloud CFW ShowExportStatus | This API is used to query the export result. | |
| Downloading the Imported Rules | hcloud CFW DownloadImportResult | This API is used to download the imported rules. | |
| Obtaining the Number of Rule Hits and the Last Hit Time | hcloud CFW ListAclRuleHitStatus | This API is used to obtain the number of rule hits and the last hit time. | |
| Obtaining the Number of Rule Hits | hcloud CFW ListAclRuleHitCount | This API is used to obtain the number of rule hits. | |
| Deleting the Number of Rule Hits | hcloud CFW DeleteAclRuleHitCount | This API is used to delete the rule hit count. | |
| Creating an ACL Rule | hcloud CFW AddAclRule | This API is used to create an ACL rule. | |
| Deleting ACL Rules in Batches | hcloud CFW BatchDeleteAclRules | This API is used to delete ACL rules in batches. | |
| Updating an ACL Rule | hcloud CFW UpdateAclRule | This API is used to update an ACL rule. | |
| Deleting an ACL Rule | hcloud CFW DeleteAclRule | This API is used to delete an ACL rule. | |
| Querying a Protection Rule | hcloud CFW ListAclRules | This API is used to query a protection rule. | |
| Setting the Priority of an ACL Protection Rule | hcloud CFW UpdateAclRuleOrder | This API is used to set the priority of an ACL protection rule. | |
| Updating Rule Actions in Batches | hcloud CFW BatchUpdateAclRuleActions | This API is used to update rule actions in batches. | |
| Querying Rule Tags | hcloud CFW ListRuleAclTags | This API is used to query rule tags. | |
| Viewing the Region List | hcloud CFW ListRegions | This API is used to view the region list. | |
| Checking the ACL Import Status | hcloud CFW ShowImportStatus | This API is used to query the ACL import status. |
Address Group Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Deleting a Member from an Address Group | hcloud CFW DeleteAddressItem | This API is used to delete a member from an address group. | |
| Deleting Address Groups in Batches | hcloud CFW BatchDeleteAddressSets | This API is used to Delete address groups in batches. | |
| Querying Address Group Members | hcloud CFW ListAddressItems | This API is used to query members in an address group. | |
| Adding an Address Group Member | hcloud CFW AddAddressItem | This API is used to add a member to an address group. | |
| Deleting Address Group Members in Batches | hcloud CFW BatchDeleteAddressItems | This API is used to delete address group members in batches. | |
| Adding an Address Group | hcloud CFW AddAddressSet | This API is used to add an address group. | |
| Querying the Address Group List | hcloud CFW ListAddressSets | This API is used to query the address group list. | |
| Querying Address Group Details | hcloud CFW ListAddressSetDetail | This API is used to query address group details. | |
| Updating Address Group Information | hcloud CFW UpdateAddressSet | This API is used to update address group information. | |
| Deleting an Address Group | hcloud CFW DeleteAddressSet | This API is used to delete an address group. | |
| Updating the Object Configuration Description | hcloud CFW UpdateObjectConfigDesc | This API is used to update the object configuration description. |
Blacklist/Whitelist Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying a Blacklist or Whitelist | hcloud CFW ListBlackWhiteLists | This API is used to query a blacklist or whitelist. | |
| Adding Blacklist or Whitelist Items in Batches | hcloud CFW BatchCreateBlackWhiteList | This API is used to add blacklist or whitelist items in batches. | |
| Creating a Blacklist or Whitelist Rule | hcloud CFW AddBlackWhiteList | This API is used to create a blacklist or whitelist rule. | |
| Deleting Blacklist or Whitelist Items in Batches | hcloud CFW BatchDeleteBlackWhiteLists | This API is used to delete blacklist or whitelist items in batches. | |
| Updating a Blacklist or Whitelist | hcloud CFW UpdateBlackWhiteList | This API is used to update a blacklist or whitelist. | |
| Deleting a Blacklist or Whitelist Rule | hcloud CFW DeleteBlackWhiteList | This API is used to delete a blacklist or whitelist rule. |
Domain Name Resolution and Domain Name Group Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the DNS Server List | hcloud CFW ListDnsServers | This API is used to query the DNS server list. | |
| Updating the DNS Server List | hcloud CFW UpdateDnsServers | This API is used to update the DNS server list. | |
| Querying the IP Address for Domain Name Resolution | hcloud CFW ListDomainParseDetail | This API is used to check the validity of a domain name. | |
| Querying the Domain Name Group List | hcloud CFW ListDomainSets | This API is used to query the domain name group list. | |
| Adding a Domain Name Group | hcloud CFW AddDomainSet | This API is used to add a domain name group. | |
| Updating a Domain Name Group | hcloud CFW UpdateDomainSet | This API is used to update a domain name group. | |
| Deleting a Domain Name Group | hcloud CFW DeleteDomainSet | This API is used to delete a domain name group. | |
| Obtain the list of domain names in a domain name group | hcloud CFW ListDomains | Obtain the list of domain names in a domain name group | |
| Adding a Domain Name List | hcloud CFW AddDomains | This API is used to add a domain name list. | |
| Deleting a Domain Name List | hcloud CFW DeleteDomains | This API is used to delete a domain name list. | |
| Viewing Domain Group Details | hcloud CFW ShowDomainSetDetail | This API is used to view the details about a domain name group. | |
| Obtaining the DNS Resolution Result of a Domain Name | hcloud CFW ListDomainParseIp | This API is used to obtain the DNS resolution result of a domain name. | |
| Deleting Domain Groups in Batches | hcloud CFW BatchDeleteDomainSet | This API is used to delete domain name groups in batches. | |
| Adding a Specified DNS Server | hcloud CFW AddCustomDnsServer | This API is used to add a specified DNS server. | |
| Obtaining the Domain Name Resolution Result | hcloud CFW ListDomainResolveIp | This API is used to obtain the domain name resolution result. |
Firewall Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Number of Protected VPCs | hcloud CFW ListProtectedVpcs | This API is used to query information about protected VPCs. | |
| Obtaining East-West Firewall Information | hcloud CFW ListEastWestFirewall | This API is used to obtain east-west firewall information. | |
| Creating an East-West Firewall | hcloud CFW CreateEastWestFirewall | This API is used to create an east-west firewall. | |
| Obtaining the Status of a CFW Task | hcloud CFW ListJob | This API is used to obtain the status of a CFW task. | |
| Deleting a Firewall | hcloud CFW DeleteFirewall | This API is used to delete a firewall. It takes effect only for pay-per-use firewalls. | |
| Creating a Tag | hcloud CFW CreateTag | This API is used to create a tag. | |
| Deleting a Tag | hcloud CFW DeleteTag | This API is used to delete a tag. | |
| Creating a Firewall | hcloud CFW CreateFirewall | This API is used to create a firewall. | |
| Querying Firewall Details | hcloud CFW ListFirewallDetail | This API is used to query firewall instance details. | |
| Querying the Firewall List | hcloud CFW ListFirewallList | This API is used to query a firewall list. | |
| Changing a Firewall Name | hcloud CFW UpdateFirewallName | This API is used to change a firewall name. | |
| Querying Firewall Quota Information | hcloud CFW ShowConfigQuota | This API is used to query firewall quota information. | |
| Querying the Protection Status of a North-south Firewall | hcloud CFW ShowSnFirewallProtectionStatus | This API is used to query the protection status of a north-south firewall. |
IPS Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Status of the IPS Feature | hcloud CFW ListIpsSwitchStatus | This API is used to query the status of the IPS feature. | |
| Changing the IPS Feature Status | hcloud CFW ChangeIpsSwitchStatus | This API is used to enable or disable the feature. | |
| Querying a Protection Mode | hcloud CFW ListIpsProtectMode | This API is used to query a protection mode. | |
| Changing the Protection Mode | hcloud CFW ChangeIpsProtectMode | This API is used to change the protection mode. | |
| Changing the IPS Rule Mode | hcloud CFW ChangeIpsRuleMode | This API is used to change the IPS rule mode. | |
| Updating a Frequency IPS Rule | hcloud CFW UpdateAdvancedIpsRule | This API is used to update a frequency IPS rule. | |
| Querying Frequency IPS Rule Information | hcloud CFW ListAdvancedIpsRules | This API is used to query frequency IPS rule information. | |
| Obtaining the IPS Rule List | hcloud CFW ListIpsRules | This API is used to obtain the IPS rule list. | |
| Obtaining the IPS Rule Update Time | hcloud CFW ShowIpsUpdateTime | This API is used to obtain the IPS rule update time. | |
| Viewing the Custom IPS Rule List | hcloud CFW ListCustomerIps | This API is used to view the custom IPS rule list. | |
| Creating a Custom IPS Rule | hcloud CFW CreateCustomerIps | This API is used to create a custom IPS rule. | |
| Deleting Custom IPS Rules in Batches | hcloud CFW BatchDeleteCustomerIps | This API is used to delete custom IPS rules in batches. | |
| Updating the Actions of Custom IPS Rules in Batches | hcloud CFW BatchUpdateCustomerIpsAction | This API is used to update the actions of custom IPS rules in batches. | |
| Querying Custom IPS Rule Details | hcloud CFW ShowCustomerIpsInfo | Function: Query custom IPS rule details. Feature: Query custom IPS rule details based on the IPS ID entered in the path. | |
| Updating a Custom IPS Rule | hcloud CFW UpdateCustomerIps | This API is used to update a custom IPS rule. |
Log Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying Flow Logs | hcloud CFW ListFlowLogs | This API is used to query flow logs. | |
| Querying Access Control Logs | hcloud CFW ListAccessControlLogs | This API is used to query access control logs. | |
| Querying Attack Logs | hcloud CFW ListAttackLogs | This API is used to query attack logs. | |
| Obtaining Log Configurations | hcloud CFW ListLogConfig | This API is used to obtain log configurations. | |
| Adding Log Configurations | hcloud CFW AddLogConfig | This API is used to add log configurations. | |
| Updating Log Configurations | hcloud CFW UpdateLogConfig | This API is used to update log configurations. | |
| Querying Firewall Logs | hcloud CFW ListLogs | This API is used to query firewall logs. | |
| Exporting Firewall Logs | hcloud CFW ExportLogs | This API is used to export firewall logs. |
Service Group Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Creating a Service Group | hcloud CFW AddServiceSet | This API is used to create a service group. | |
| Querying Service Group Details | hcloud CFW ListServiceSetDetail | This API is used to query details about a service group. | |
| Modifying a Service Group | hcloud CFW UpdateServiceSet | This API is used to update a service group. | |
| Deleting a Service Group | hcloud CFW DeleteServiceSet | This API is used to delete a service group. | |
| Querying the Service Group Member List | hcloud CFW ListServiceItems | This API is used to query the service group member list. | |
| Adding Service Group Members | hcloud CFW AddServiceItems | This API is used to add service group members in batches. | |
| Deleting Service Group Members in Batches | hcloud CFW BatchDeleteServiceItems | This API is used to delete service group members in batches. | |
| Obtaining the Service Group List | hcloud CFW ListServiceSets | This API is used to obtain the service group list. | |
| Deleting a Service Group Member | hcloud CFW DeleteServiceItem | This API is used to delete a service group member. | |
| Deleting Service Groups in Batches | hcloud CFW BatchDeleteServiceSets | This API is used to delete service groups in batches. |
EIP Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Number of EIPs | hcloud CFW ListEipCount | Query the number of EIPs. | |
| Enabling or Disabling EIP Protection | hcloud CFW ChangeEipStatus | This API is used to enable or disable EIP protection. After a customer purchases an EIP, the customer needs to call ListEips to synchronize EIPs asset before enabling EIP protection for the first time. The **sync** field should be set to **1**. | |
| Querying the EIP List | hcloud CFW ListEips | This API is used to query the EIP list. | |
| Viewing the EIP Alarm Whitelist | hcloud CFW ListAlarmWhitelist | This API is used to query the EIP alarm whitelist. | |
| Modifying the Automatic EIP Protection Switch | hcloud CFW SwitchAutoProtectStatus | This API is used to modify the automatic EIP protection switch. | |
| Obtaining the Automatic EIP Protection Status | hcloud CFW ShowAutoProtectStatus | This API is used to obtain the automatic EIP protection status. | |
| One-click Kill Switch and One-click Restoration | hcloud CFW SwitchFirewallEipProtection | This API is used for one-click kill switch and one-click restoration. | |
| Adding an EIP to Alarm Whitelist | hcloud CFW AddEipAlarmWhitelist | This API is used to add an EIP to the alarm whitelist. |
Packet Capture Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying a Packet Capture Task | hcloud CFW ListCaptureTask | This API is used to query a packet capture task. | |
| Creating a Packet Capture Task | hcloud CFW CreateCaptureTask | Create a packet capture task. Each task can be executed only once. | |
| Deleting Packet Capture Tasks in Batches | hcloud CFW DeleteCaptureTask | This API is used to delete packet capture tasks in batches. | |
| Obtaining Packet Capture Task Results | hcloud CFW ListCaptureResult | This API is used to obtain packet capture task results. | |
| Canceling a Packet Capture Task | hcloud CFW CancelCaptureTask | This API is used to cancel a packet capture task. |
Antivirus Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Checking the Antivirus Switch | hcloud CFW ShowAntiVirusSwitch | This API is used to check the antivirus switch. | |
| Modifying the Antivirus Switch | hcloud CFW UpdateAntiVirusSwitch | This API is used to modify the antivirus switch. | |
| Obtaining Firewall Antivirus Rule Information | hcloud CFW ShowAntiVirusRule | This API is used to obtain information about antivirus rules. | |
| Modifying an Antivirus Rule | hcloud CFW UpdateAntiVirusRule | This API is used to modify an antivirus rule. |
Alarm Configuration Management
Tag Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying Tag Information | hcloud CFW ListProjectTags | This API is used to query tag information. | |
| Querying Resource Tag Information | hcloud CFW ListResourceTags | This API is used to query resource tag information. | |
| Saving a Resource Tag | hcloud CFW SaveTags | This API is used to save a resource tag. |
Traffic Filtering
| API Name | Command | Description | Operation |
|---|---|---|---|
| Importing an IP Address Blacklist for Traffic Filtering | hcloud CFW ImportIpBlacklist | This API is used to import an IP address blacklist. The IP address list is saved in the body of the request. The IP address list supports the following formats: | |
| Obtain the imported IP address blacklist. | hcloud CFW ListIpBlacklist | Obtain the IP address blacklist imported to the firewall instance. For a standard edition firewall, only one EIP record is displayed. For a professional edition firewall, one or more EIP, NAT, or EIP and NAT records may be displayed, depending on the imported records. | |
| Deleting the Imported IP Address Blacklist | hcloud CFW DeleteIpBlacklist | Delete the imported IP address blacklist of the traffic filtering function with a specified effective scope. For the standard edition, only the IP address blacklist whose effective scope is EIP is available. For the professional edition, the IP address blacklist whose effective scope is EIP and NAT is available. | |
| Exporting the IP Address Blacklist for Traffic Filtering | hcloud CFW ExportIpBlacklist | Name of the IP address blacklist to be exported. Currently, only two file names are supported: **ip-blacklist-eip.txt** (for EIP) and **ip-blacklist-nat.txt** (for NAT). | |
| Re-importing the IP Address Blacklist Used for Traffic Filtering After an Import Failed | hcloud CFW RetryIpBlacklist | After the IP address blacklist used for traffic filtering fails to be imported, this API is used to retry the import. | |
| Obtaining the Traffic Filtering Switch Information | hcloud CFW ListIpBlacklistSwitch | Traffic filtering can be enabled or disabled. This API is used to obtain the current switch information. | |
| Enabling or Disabling the IP Address Blacklist for Traffic Filtering | hcloud CFW EnableIpBlacklist | Enable or disable the traffic filtering function. Currently, traffic filtering is implemented by importing an IP address blacklist. |
Inter-VPC Firewall Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Updating the VPC Border Firewall Protection Status | hcloud CFW ChangeEastWestFirewallStatus | This API is used to update the VPC border firewall protection status. | |
| Querying the Inspection VPC Used by a VPC Border Firewall | hcloud CFW ShowEwAssociatedVpc | This API is used to query the inspection VPC used by a VPC border firewall. | |
| Querying the Enterprise Router Used by a VPC Border Firewall | hcloud CFW ShowEwAssociatedEr | This API is used to query the enterprise router used by a VPC border firewall. | |
| Obtaining the CIDR Block Information of a Private Network | hcloud CFW ListPrivateNetworkSegments | This API is used to query the east-west private CIDR block list. | |
| Updating the CIDR Blocks of a Private Network | hcloud CFW UpdatePrivateNetworkSegment | This API is used to update the east-west private CIDR block. Main feature: | |
| Creating a CIDR Block for a Private Network | hcloud CFW BatchCreatePrivateNetworkSegments | This API is used to add a private CIDR block. After the private CIDR block is added, the traffic of the CIDR block will be diverted to the VPC firewall for protection. | |
| Deleting the CIDR Block Information of a Private Network | hcloud CFW BatchDeletePrivateNetworkSegments | Delete the private CIDR block based on the private CIDR block **conf_id** entered by the user. |
Log Analysis
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Traffic Trend | hcloud CFW ShowTrafficTrend | This API is used to query the traffic trends, including north-south, east-west, and EIP traffic trends. | |
| Querying Slow Query Log Statistics | hcloud CFW ShowAccessTop | This API is used to obtain the top N statistics in access logs, such as the rules with the most hits. | |
| Querying Attack Statistics | hcloud CFW ListAttackStatistic | This API is used to query attack statistics based on firewall attack logs. | |
| Querying the Attack Trend | hcloud CFW ShowAttackTrend | This API is used to query the attack trend. | |
| Querying the Attack Overview | hcloud CFW ShowAttackTotal | This API is used to query the attack overview. | |
| Querying the Number of Logs | hcloud CFW ShowLogsCount | Collect statistics on the number of logs, for example, the number of unsafe IP addresses. | |
| Querying Traffic Log Statistics Details | hcloud CFW ShowFlowDetail | This API is used to query traffic log statistics, for example, the access details of a source IP address. | |
| Querying Top Traffic Statistics | hcloud CFW ShowFlowTop | This API is used to query top traffic statistics. | |
| Querying Traffic Log Statistics | hcloud CFW ListFlowStatistic | This API is used to query traffic log statistics. | |
| Querying the Session Trend | hcloud CFW ShowFlowTrend | This API is used to query the session trend. | |
| Querying Attack Log Statistics | hcloud CFW ShowAttackDetail | This API is used to query attack log statistics. | |
| Querying Top Attack Log Statistics | hcloud CFW ShowAttackTop | This API is used to query top attack log statistics. | |
| Querying Access Control Statistics Details | hcloud CFW ShowAccessDetail | This API is used to query details about access control statistics. |
Multi-Account Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Account List | hcloud CFW ListAccounts | This API is used to query the account list. | |
| Adding Accounts in Batches | hcloud CFW BatchAddAccounts | This API is used to add accounts in batches. | |
| Removing Accounts in Batches | hcloud CFW BatchRemoveAccounts | This API is used to remove accounts in batches. | |
| Enabling Multi-Account Management | hcloud CFW EnableMultiAccount | This API is used to enable multi-account management. | |
| Querying the Organization Account List | hcloud CFW ListOrganizationAccounts | This API is used to query the organization account list. | |
| Querying the Organization Structure | hcloud CFW ListOrganizationTree | Query the organization structure. |
Security Reports
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Security Report Template List | hcloud CFW ListReportProfiles | This API is used to query the security report template list. | |
| Creating a Report Template | hcloud CFW CreateReportProfile | This API is used to create a report template. | |
| Obtaining a Security Report Template | hcloud CFW ShowReportProfile | This API is used to obtain a security report template. | |
| Updating a Security Report Template | hcloud CFW UpdateReportProfile | This API is used to update a security report template. | |
| Deleting a Security Report Template | hcloud CFW DeleteReportProfile | This API is used to delete a security report template. | |
| Querying the Sending History of a Security Report | hcloud CFW ListReportHistory | This API is used to query the sending history of a security report. | |
| Query Security Reports | hcloud CFW ShowFirewallReport | This API is used to query security reports. |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot