Help Center/ Cloud Firewall/ CLI Reference/ CLI Command Reference
Updated on 2026-09-01 GMT+08:00

CLI Command Reference

Access Control Rule Management

API Name

Command

Description

Operation

Importing Access Control Rules

hcloud CFW ImportRuleAcl

This API is used to import access control rules.

Go debug

Exporting Access Control Rules

hcloud CFW ExportRuleAcl

This API is used to export access control rules.

Go debug

Downloading the Import Template

hcloud CFW DownloadImportTemplate

This API is used to download the import template.

Go debug

Downloading the Export Result

hcloud CFW DownloadExportResult

This API is used to download the export result.

Go debug

Querying the Export Result

hcloud CFW ShowExportStatus

This API is used to query the export result.

Go debug

Downloading the Imported Rules

hcloud CFW DownloadImportResult

This API is used to download the imported rules.

Go debug

Obtaining the Number of Rule Hits and the Last Hit Time

hcloud CFW ListAclRuleHitStatus

This API is used to obtain the number of rule hits and the last hit time.

Go debug

Obtaining the Number of Rule Hits

hcloud CFW ListAclRuleHitCount

This API is used to obtain the number of rule hits.

Go debug

Deleting the Number of Rule Hits

hcloud CFW DeleteAclRuleHitCount

This API is used to delete the rule hit count.

Go debug

Creating an ACL Rule

hcloud CFW AddAclRule

This API is used to create an ACL rule.

Go debug

Deleting ACL Rules in Batches

hcloud CFW BatchDeleteAclRules

This API is used to delete ACL rules in batches.

Go debug

Updating an ACL Rule

hcloud CFW UpdateAclRule

This API is used to update an ACL rule.

Go debug

Deleting an ACL Rule

hcloud CFW DeleteAclRule

This API is used to delete an ACL rule.

Go debug

Querying a Protection Rule

hcloud CFW ListAclRules

This API is used to query a protection rule.

Go debug

Setting the Priority of an ACL Protection Rule

hcloud CFW UpdateAclRuleOrder

This API is used to set the priority of an ACL protection rule.

Go debug

Updating Rule Actions in Batches

hcloud CFW BatchUpdateAclRuleActions

This API is used to update rule actions in batches.

Go debug

Querying Rule Tags

hcloud CFW ListRuleAclTags

This API is used to query rule tags.

Go debug

Viewing the Region List

hcloud CFW ListRegions

This API is used to view the region list.

Go debug

Checking the ACL Import Status

hcloud CFW ShowImportStatus

This API is used to query the ACL import status.

Go debug

Address Group Management

API Name

Command

Description

Operation

Deleting a Member from an Address Group

hcloud CFW DeleteAddressItem

This API is used to delete a member from an address group.

Go debug

Deleting Address Groups in Batches

hcloud CFW BatchDeleteAddressSets

This API is used to Delete address groups in batches.

Go debug

Querying Address Group Members

hcloud CFW ListAddressItems

This API is used to query members in an address group.

Go debug

Adding an Address Group Member

hcloud CFW AddAddressItem

This API is used to add a member to an address group.

Go debug

Deleting Address Group Members in Batches

hcloud CFW BatchDeleteAddressItems

This API is used to delete address group members in batches.

Go debug

Adding an Address Group

hcloud CFW AddAddressSet

This API is used to add an address group.

Go debug

Querying the Address Group List

hcloud CFW ListAddressSets

This API is used to query the address group list.

Go debug

Querying Address Group Details

hcloud CFW ListAddressSetDetail

This API is used to query address group details.

Go debug

Updating Address Group Information

hcloud CFW UpdateAddressSet

This API is used to update address group information.

Go debug

Deleting an Address Group

hcloud CFW DeleteAddressSet

This API is used to delete an address group.

Go debug

Updating the Object Configuration Description

hcloud CFW UpdateObjectConfigDesc

This API is used to update the object configuration description.

Go debug

Blacklist/Whitelist Management

API Name

Command

Description

Operation

Querying a Blacklist or Whitelist

hcloud CFW ListBlackWhiteLists

This API is used to query a blacklist or whitelist.

Go debug

Adding Blacklist or Whitelist Items in Batches

hcloud CFW BatchCreateBlackWhiteList

This API is used to add blacklist or whitelist items in batches.

Go debug

Creating a Blacklist or Whitelist Rule

hcloud CFW AddBlackWhiteList

This API is used to create a blacklist or whitelist rule.

Go debug

Deleting Blacklist or Whitelist Items in Batches

hcloud CFW BatchDeleteBlackWhiteLists

This API is used to delete blacklist or whitelist items in batches.

Go debug

Updating a Blacklist or Whitelist

hcloud CFW UpdateBlackWhiteList

This API is used to update a blacklist or whitelist.

Go debug

Deleting a Blacklist or Whitelist Rule

hcloud CFW DeleteBlackWhiteList

This API is used to delete a blacklist or whitelist rule.

Go debug

Domain Name Resolution and Domain Name Group Management

API Name

Command

Description

Operation

Querying the DNS Server List

hcloud CFW ListDnsServers

This API is used to query the DNS server list.

Go debug

Updating the DNS Server List

hcloud CFW UpdateDnsServers

This API is used to update the DNS server list.

Go debug

Querying the IP Address for Domain Name Resolution

hcloud CFW ListDomainParseDetail

This API is used to check the validity of a domain name.

Go debug

Querying the Domain Name Group List

hcloud CFW ListDomainSets

This API is used to query the domain name group list.

Go debug

Adding a Domain Name Group

hcloud CFW AddDomainSet

This API is used to add a domain name group.

Go debug

Updating a Domain Name Group

hcloud CFW UpdateDomainSet

This API is used to update a domain name group.

Go debug

Deleting a Domain Name Group

hcloud CFW DeleteDomainSet

This API is used to delete a domain name group.

Go debug

Obtain the list of domain names in a domain name group

hcloud CFW ListDomains

Obtain the list of domain names in a domain name group

Go debug

Adding a Domain Name List

hcloud CFW AddDomains

This API is used to add a domain name list.

Go debug

Deleting a Domain Name List

hcloud CFW DeleteDomains

This API is used to delete a domain name list.

Go debug

Viewing Domain Group Details

hcloud CFW ShowDomainSetDetail

This API is used to view the details about a domain name group.

Go debug

Obtaining the DNS Resolution Result of a Domain Name

hcloud CFW ListDomainParseIp

This API is used to obtain the DNS resolution result of a domain name.

Go debug

Deleting Domain Groups in Batches

hcloud CFW BatchDeleteDomainSet

This API is used to delete domain name groups in batches.

Go debug

Adding a Specified DNS Server

hcloud CFW AddCustomDnsServer

This API is used to add a specified DNS server.

Go debug

Obtaining the Domain Name Resolution Result

hcloud CFW ListDomainResolveIp

This API is used to obtain the domain name resolution result.

Go debug

Firewall Management

API Name

Command

Description

Operation

Querying the Number of Protected VPCs

hcloud CFW ListProtectedVpcs

This API is used to query information about protected VPCs.

Go debug

Obtaining East-West Firewall Information

hcloud CFW ListEastWestFirewall

This API is used to obtain east-west firewall information.

Go debug

Creating an East-West Firewall

hcloud CFW CreateEastWestFirewall

This API is used to create an east-west firewall.

Go debug

Obtaining the Status of a CFW Task

hcloud CFW ListJob

This API is used to obtain the status of a CFW task.

Go debug

Deleting a Firewall

hcloud CFW DeleteFirewall

This API is used to delete a firewall. It takes effect only for pay-per-use firewalls.

Go debug

Creating a Tag

hcloud CFW CreateTag

This API is used to create a tag.

Go debug

Deleting a Tag

hcloud CFW DeleteTag

This API is used to delete a tag.

Go debug

Creating a Firewall

hcloud CFW CreateFirewall

This API is used to create a firewall.

Go debug

Querying Firewall Details

hcloud CFW ListFirewallDetail

This API is used to query firewall instance details.

Go debug

Querying the Firewall List

hcloud CFW ListFirewallList

This API is used to query a firewall list.

Go debug

Changing a Firewall Name

hcloud CFW UpdateFirewallName

This API is used to change a firewall name.

Go debug

Querying Firewall Quota Information

hcloud CFW ShowConfigQuota

This API is used to query firewall quota information.

Go debug

Querying the Protection Status of a North-south Firewall

hcloud CFW ShowSnFirewallProtectionStatus

This API is used to query the protection status of a north-south firewall.

Go debug

IPS Management

API Name

Command

Description

Operation

Querying the Status of the IPS Feature

hcloud CFW ListIpsSwitchStatus

This API is used to query the status of the IPS feature.

Go debug

Changing the IPS Feature Status

hcloud CFW ChangeIpsSwitchStatus

This API is used to enable or disable the feature.

Go debug

Querying a Protection Mode

hcloud CFW ListIpsProtectMode

This API is used to query a protection mode.

Go debug

Changing the Protection Mode

hcloud CFW ChangeIpsProtectMode

This API is used to change the protection mode.

Go debug

Changing the IPS Rule Mode

hcloud CFW ChangeIpsRuleMode

This API is used to change the IPS rule mode.

Go debug

Updating a Frequency IPS Rule

hcloud CFW UpdateAdvancedIpsRule

This API is used to update a frequency IPS rule.

Go debug

Querying Frequency IPS Rule Information

hcloud CFW ListAdvancedIpsRules

This API is used to query frequency IPS rule information.

Go debug

Obtaining the IPS Rule List

hcloud CFW ListIpsRules

This API is used to obtain the IPS rule list.

Go debug

Obtaining the IPS Rule Update Time

hcloud CFW ShowIpsUpdateTime

This API is used to obtain the IPS rule update time.

Go debug

Viewing the Custom IPS Rule List

hcloud CFW ListCustomerIps

This API is used to view the custom IPS rule list.

Go debug

Creating a Custom IPS Rule

hcloud CFW CreateCustomerIps

This API is used to create a custom IPS rule.

Go debug

Deleting Custom IPS Rules in Batches

hcloud CFW BatchDeleteCustomerIps

This API is used to delete custom IPS rules in batches.

Go debug

Updating the Actions of Custom IPS Rules in Batches

hcloud CFW BatchUpdateCustomerIpsAction

This API is used to update the actions of custom IPS rules in batches.

Go debug

Querying Custom IPS Rule Details

hcloud CFW ShowCustomerIpsInfo

Function: Query custom IPS rule details. Feature: Query custom IPS rule details based on the IPS ID entered in the path.

Go debug

Updating a Custom IPS Rule

hcloud CFW UpdateCustomerIps

This API is used to update a custom IPS rule.

Go debug

Log Management

API Name

Command

Description

Operation

Querying Flow Logs

hcloud CFW ListFlowLogs

This API is used to query flow logs.

Go debug

Querying Access Control Logs

hcloud CFW ListAccessControlLogs

This API is used to query access control logs.

Go debug

Querying Attack Logs

hcloud CFW ListAttackLogs

This API is used to query attack logs.

Go debug

Obtaining Log Configurations

hcloud CFW ListLogConfig

This API is used to obtain log configurations.

Go debug

Adding Log Configurations

hcloud CFW AddLogConfig

This API is used to add log configurations.

Go debug

Updating Log Configurations

hcloud CFW UpdateLogConfig

This API is used to update log configurations.

Go debug

Querying Firewall Logs

hcloud CFW ListLogs

This API is used to query firewall logs.

Go debug

Exporting Firewall Logs

hcloud CFW ExportLogs

This API is used to export firewall logs.

Go debug

Service Group Management

API Name

Command

Description

Operation

Creating a Service Group

hcloud CFW AddServiceSet

This API is used to create a service group.

Go debug

Querying Service Group Details

hcloud CFW ListServiceSetDetail

This API is used to query details about a service group.

Go debug

Modifying a Service Group

hcloud CFW UpdateServiceSet

This API is used to update a service group.

Go debug

Deleting a Service Group

hcloud CFW DeleteServiceSet

This API is used to delete a service group.

Go debug

Querying the Service Group Member List

hcloud CFW ListServiceItems

This API is used to query the service group member list.

Go debug

Adding Service Group Members

hcloud CFW AddServiceItems

This API is used to add service group members in batches.

Go debug

Deleting Service Group Members in Batches

hcloud CFW BatchDeleteServiceItems

This API is used to delete service group members in batches.

Go debug

Obtaining the Service Group List

hcloud CFW ListServiceSets

This API is used to obtain the service group list.

Go debug

Deleting a Service Group Member

hcloud CFW DeleteServiceItem

This API is used to delete a service group member.

Go debug

Deleting Service Groups in Batches

hcloud CFW BatchDeleteServiceSets

This API is used to delete service groups in batches.

Go debug

EIP Management

API Name

Command

Description

Operation

Querying the Number of EIPs

hcloud CFW ListEipCount

Query the number of EIPs.

Go debug

Enabling or Disabling EIP Protection

hcloud CFW ChangeEipStatus

This API is used to enable or disable EIP protection. After a customer purchases an EIP, the customer needs to call ListEips to synchronize EIPs asset before enabling EIP protection for the first time. The **sync** field should be set to **1**.

Go debug

Querying the EIP List

hcloud CFW ListEips

This API is used to query the EIP list.

Go debug

Viewing the EIP Alarm Whitelist

hcloud CFW ListAlarmWhitelist

This API is used to query the EIP alarm whitelist.

Go debug

Modifying the Automatic EIP Protection Switch

hcloud CFW SwitchAutoProtectStatus

This API is used to modify the automatic EIP protection switch.

Go debug

Obtaining the Automatic EIP Protection Status

hcloud CFW ShowAutoProtectStatus

This API is used to obtain the automatic EIP protection status.

Go debug

One-click Kill Switch and One-click Restoration

hcloud CFW SwitchFirewallEipProtection

This API is used for one-click kill switch and one-click restoration.

Go debug

Adding an EIP to Alarm Whitelist

hcloud CFW AddEipAlarmWhitelist

This API is used to add an EIP to the alarm whitelist.

Go debug

Packet Capture Management

API Name

Command

Description

Operation

Querying a Packet Capture Task

hcloud CFW ListCaptureTask

This API is used to query a packet capture task.

Go debug

Creating a Packet Capture Task

hcloud CFW CreateCaptureTask

Create a packet capture task. Each task can be executed only once.

Go debug

Deleting Packet Capture Tasks in Batches

hcloud CFW DeleteCaptureTask

This API is used to delete packet capture tasks in batches.

Go debug

Obtaining Packet Capture Task Results

hcloud CFW ListCaptureResult

This API is used to obtain packet capture task results.

Go debug

Canceling a Packet Capture Task

hcloud CFW CancelCaptureTask

This API is used to cancel a packet capture task.

Go debug

Antivirus Management

API Name

Command

Description

Operation

Checking the Antivirus Switch

hcloud CFW ShowAntiVirusSwitch

This API is used to check the antivirus switch.

Go debug

Modifying the Antivirus Switch

hcloud CFW UpdateAntiVirusSwitch

This API is used to modify the antivirus switch.

Go debug

Obtaining Firewall Antivirus Rule Information

hcloud CFW ShowAntiVirusRule

This API is used to obtain information about antivirus rules.

Go debug

Modifying an Antivirus Rule

hcloud CFW UpdateAntiVirusRule

This API is used to modify an antivirus rule.

Go debug

Alarm Configuration Management

API Name

Command

Description

Operation

Obtaining Alarm Configurations

hcloud CFW ShowAlarmConfig

This API is used to obtain alarm configurations.

Go debug

Modifying Alarm Configurations

hcloud CFW UpdateAlarmConfig

This API is used to modify alarm configurations.

Go debug

Tag Management

API Name

Command

Description

Operation

Querying Tag Information

hcloud CFW ListProjectTags

This API is used to query tag information.

Go debug

Querying Resource Tag Information

hcloud CFW ListResourceTags

This API is used to query resource tag information.

Go debug

Saving a Resource Tag

hcloud CFW SaveTags

This API is used to save a resource tag.

Go debug

Traffic Filtering

API Name

Command

Description

Operation

Importing an IP Address Blacklist for Traffic Filtering

hcloud CFW ImportIpBlacklist

This API is used to import an IP address blacklist. The IP address list is saved in the body of the request. The IP address list supports the following formats:

Go debug

Obtain the imported IP address blacklist.

hcloud CFW ListIpBlacklist

Obtain the IP address blacklist imported to the firewall instance. For a standard edition firewall, only one EIP record is displayed. For a professional edition firewall, one or more EIP, NAT, or EIP and NAT records may be displayed, depending on the imported records.

Go debug

Deleting the Imported IP Address Blacklist

hcloud CFW DeleteIpBlacklist

Delete the imported IP address blacklist of the traffic filtering function with a specified effective scope. For the standard edition, only the IP address blacklist whose effective scope is EIP is available. For the professional edition, the IP address blacklist whose effective scope is EIP and NAT is available.

Go debug

Exporting the IP Address Blacklist for Traffic Filtering

hcloud CFW ExportIpBlacklist

Name of the IP address blacklist to be exported. Currently, only two file names are supported: **ip-blacklist-eip.txt** (for EIP) and **ip-blacklist-nat.txt** (for NAT).

Go debug

Re-importing the IP Address Blacklist Used for Traffic Filtering After an Import Failed

hcloud CFW RetryIpBlacklist

After the IP address blacklist used for traffic filtering fails to be imported, this API is used to retry the import.

Go debug

Obtaining the Traffic Filtering Switch Information

hcloud CFW ListIpBlacklistSwitch

Traffic filtering can be enabled or disabled. This API is used to obtain the current switch information.

Go debug

Enabling or Disabling the IP Address Blacklist for Traffic Filtering

hcloud CFW EnableIpBlacklist

Enable or disable the traffic filtering function. Currently, traffic filtering is implemented by importing an IP address blacklist.

Go debug

Inter-VPC Firewall Management

API Name

Command

Description

Operation

Updating the VPC Border Firewall Protection Status

hcloud CFW ChangeEastWestFirewallStatus

This API is used to update the VPC border firewall protection status.

Go debug

Querying the Inspection VPC Used by a VPC Border Firewall

hcloud CFW ShowEwAssociatedVpc

This API is used to query the inspection VPC used by a VPC border firewall.

Go debug

Querying the Enterprise Router Used by a VPC Border Firewall

hcloud CFW ShowEwAssociatedEr

This API is used to query the enterprise router used by a VPC border firewall.

Go debug

Obtaining the CIDR Block Information of a Private Network

hcloud CFW ListPrivateNetworkSegments

This API is used to query the east-west private CIDR block list.

Go debug

Updating the CIDR Blocks of a Private Network

hcloud CFW UpdatePrivateNetworkSegment

This API is used to update the east-west private CIDR block. Main feature:

Go debug

Creating a CIDR Block for a Private Network

hcloud CFW BatchCreatePrivateNetworkSegments

This API is used to add a private CIDR block. After the private CIDR block is added, the traffic of the CIDR block will be diverted to the VPC firewall for protection.

Go debug

Deleting the CIDR Block Information of a Private Network

hcloud CFW BatchDeletePrivateNetworkSegments

Delete the private CIDR block based on the private CIDR block **conf_id** entered by the user.

Go debug

Log Analysis

API Name

Command

Description

Operation

Querying the Traffic Trend

hcloud CFW ShowTrafficTrend

This API is used to query the traffic trends, including north-south, east-west, and EIP traffic trends.

Go debug

Querying Slow Query Log Statistics

hcloud CFW ShowAccessTop

This API is used to obtain the top N statistics in access logs, such as the rules with the most hits.

Go debug

Querying Attack Statistics

hcloud CFW ListAttackStatistic

This API is used to query attack statistics based on firewall attack logs.

Go debug

Querying the Attack Trend

hcloud CFW ShowAttackTrend

This API is used to query the attack trend.

Go debug

Querying the Attack Overview

hcloud CFW ShowAttackTotal

This API is used to query the attack overview.

Go debug

Querying the Number of Logs

hcloud CFW ShowLogsCount

Collect statistics on the number of logs, for example, the number of unsafe IP addresses.

Go debug

Querying Traffic Log Statistics Details

hcloud CFW ShowFlowDetail

This API is used to query traffic log statistics, for example, the access details of a source IP address.

Go debug

Querying Top Traffic Statistics

hcloud CFW ShowFlowTop

This API is used to query top traffic statistics.

Go debug

Querying Traffic Log Statistics

hcloud CFW ListFlowStatistic

This API is used to query traffic log statistics.

Go debug

Querying the Session Trend

hcloud CFW ShowFlowTrend

This API is used to query the session trend.

Go debug

Querying Attack Log Statistics

hcloud CFW ShowAttackDetail

This API is used to query attack log statistics.

Go debug

Querying Top Attack Log Statistics

hcloud CFW ShowAttackTop

This API is used to query top attack log statistics.

Go debug

Querying Access Control Statistics Details

hcloud CFW ShowAccessDetail

This API is used to query details about access control statistics.

Go debug

Multi-Account Management

API Name

Command

Description

Operation

Querying the Account List

hcloud CFW ListAccounts

This API is used to query the account list.

Go debug

Adding Accounts in Batches

hcloud CFW BatchAddAccounts

This API is used to add accounts in batches.

Go debug

Removing Accounts in Batches

hcloud CFW BatchRemoveAccounts

This API is used to remove accounts in batches.

Go debug

Enabling Multi-Account Management

hcloud CFW EnableMultiAccount

This API is used to enable multi-account management.

Go debug

Querying the Organization Account List

hcloud CFW ListOrganizationAccounts

This API is used to query the organization account list.

Go debug

Querying the Organization Structure

hcloud CFW ListOrganizationTree

Query the organization structure.

Go debug

Security Reports

API Name

Command

Description

Operation

Querying the Security Report Template List

hcloud CFW ListReportProfiles

This API is used to query the security report template list.

Go debug

Creating a Report Template

hcloud CFW CreateReportProfile

This API is used to create a report template.

Go debug

Obtaining a Security Report Template

hcloud CFW ShowReportProfile

This API is used to obtain a security report template.

Go debug

Updating a Security Report Template

hcloud CFW UpdateReportProfile

This API is used to update a security report template.

Go debug

Deleting a Security Report Template

hcloud CFW DeleteReportProfile

This API is used to delete a security report template.

Go debug

Querying the Sending History of a Security Report

hcloud CFW ListReportHistory

This API is used to query the sending history of a security report.

Go debug

Query Security Reports

hcloud CFW ShowFirewallReport

This API is used to query security reports.

Go debug