Firewall

Attach a firewall ruleset to a server interface

Since 7.1.0
POST/servers/{serverId}/firewall/{interfaceRef}/rulesets

Copy a ruleset's rules onto the interface, keeping the rules already there. Does not enable the firewall. apply: true pushes the rules to the running server.

Request

Authorization
Provide your bearer token in the Authorization header when making requests to protected resources.
Example: Authorization: Bearer ********************
Path Params#
serverIdinteger#required

A valid server ID as shown in VirtFusion.

Example: 1
interfaceRefstring#required

Which interface: primary, secondary, or the interface's tag, the ten-digit identifier shown as tag in GET /servers/{serverId}/interfaces (it is also the interface's device name on the hypervisor).

Example: primary
Body Paramsapplication/json#

The ruleset, plus apply.

object
rulesetIdinteger#required
applyboolean#
Example
{
    "rulesetId": 7
}

Request Code Samples

curl --location --request POST 'https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "rulesetId": 7
}'
wget --quiet --output-document=- \
  --method=POST \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "rulesetId": 7
}' \
  'https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets'
http POST 'https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "rulesetId": 7
}'
const response = await fetch("https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets", {
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "rulesetId": 7
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "post",
    url: "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "rulesetId": 7
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "rulesetId": 7
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/servers/1/firewall/primary/rulesets",
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "rulesetId": 7,
}

response = requests.request("POST", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "rulesetId": 7,
})

conn.request("POST", "/api/v1/servers/1/firewall/primary/rulesets", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_POSTFIELDS => json_encode([
        'rulesetId' => 7,
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('POST', 'https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'rulesetId' => 7,
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets"
    payload := strings.NewReader(`{
    "rulesetId": 7
}`)
    req, _ := http.NewRequest("POST", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("POST", HttpRequest.BodyPublishers.ofString("{\"rulesetId\":7}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"rulesetId\":7}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")
            .method("POST", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("POST"), "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"rulesetId\":7}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"rulesetId\":7}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")!)
request.httpMethod = "POST"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"rulesetId\":7}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "rulesetId": 7
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "rulesetId": 7
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "rulesetId": 7
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets")
        .method("POST", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('POST', Uri.parse('https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "rulesetId": 7
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "POST");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"rulesetId\":7}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "rulesetId": 7
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/servers/1/firewall/primary/rulesets" -Method POST -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
POST /api/v1/servers/1/firewall/primary/rulesets HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 22

{
    "rulesetId": 7
}

Responses

200

The interface's rules after the attach.

#
application/json
object
dataarray[FirewallRule]#
FirewallRule fields
idinteger#
protocolstring#
Allowed values:tcpudpicmpallsctp
directionstring#

Which way the traffic is heading from the server's point of view.

Allowed values:bothinout
actionstring#
Allowed values:allowdeny
ipTypeinteger#
Allowed values:46
priorityinteger#

Higher is evaluated first.

Range: 500 to 1000
sourcePortstring#nullable

A port or a range start-end; null for any. Always null for ICMP and all.

destinationPortstring#nullable
sourceAddressstring#nullable

address/cidr; null for any. IPv6 is returned uncompressed.

destinationAddressstring#nullable
enabledboolean#
addedarray[FirewallRule]#
FirewallRule fields
idinteger#
protocolstring#
Allowed values:tcpudpicmpallsctp
directionstring#

Which way the traffic is heading from the server's point of view.

Allowed values:bothinout
actionstring#
Allowed values:allowdeny
ipTypeinteger#
Allowed values:46
priorityinteger#

Higher is evaluated first.

Range: 500 to 1000
sourcePortstring#nullable

A port or a range start-end; null for any. Always null for ICMP and all.

destinationPortstring#nullable
sourceAddressstring#nullable

address/cidr; null for any. IPv6 is returned uncompressed.

destinationAddressstring#nullable
enabledboolean#
skippedarray[FirewallRule]#

Rules of the ruleset the interface already had.

FirewallRule fields
idinteger#
protocolstring#
Allowed values:tcpudpicmpallsctp
directionstring#

Which way the traffic is heading from the server's point of view.

Allowed values:bothinout
actionstring#
Allowed values:allowdeny
ipTypeinteger#
Allowed values:46
priorityinteger#

Higher is evaluated first.

Range: 500 to 1000
sourcePortstring#nullable

A port or a range start-end; null for any. Always null for ICMP and all.

destinationPortstring#nullable
sourceAddressstring#nullable

address/cidr; null for any. IPv6 is returned uncompressed.

destinationAddressstring#nullable
enabledboolean#
appliedboolean#nullable

Only when apply was sent: true applied, false the hypervisor did not apply it, null the outcome is unknown (timeout or lost answer). null when apply was not sent. The saved change stands whatever the value.

errorsarray[string]#

Present when apply was sent and did not succeed.

Example
{
    "data": [
        {
            "id": 42,
            "protocol": "tcp",
            "direction": "in",
            "action": "allow",
            "ipType": 4,
            "priority": 600,
            "sourcePort": null,
            "destinationPort": "80",
            "sourceAddress": null,
            "destinationAddress": null,
            "enabled": true
        },
        {
            "id": 44,
            "protocol": "tcp",
            "direction": "in",
            "action": "allow",
            "ipType": 4,
            "priority": 600,
            "sourcePort": null,
            "destinationPort": "443",
            "sourceAddress": null,
            "destinationAddress": null,
            "enabled": true
        }
    ],
    "added": [
        {
            "id": 44,
            "protocol": "tcp",
            "direction": "in",
            "action": "allow",
            "ipType": 4,
            "priority": 600,
            "sourcePort": null,
            "destinationPort": "443",
            "sourceAddress": null,
            "destinationAddress": null,
            "enabled": true
        }
    ],
    "skipped": [
        {
            "id": 42,
            "protocol": "tcp",
            "direction": "in",
            "action": "allow",
            "ipType": 4,
            "priority": 600,
            "sourcePort": null,
            "destinationPort": "80",
            "sourceAddress": null,
            "destinationAddress": null,
            "enabled": true
        }
    ],
    "applied": null
}
401

The bearer token is missing, invalid, or expired. The response has no body.

#
No response body.
404

The server, the interface or the ruleset was not found.

#
application/json
msgstring#
Example
{
    "msg": "ruleset not found"
}
422

The ruleset is disabled, or rulesetId is missing, not an integer, or not the only field.

#
application/json
errorsobject#
Example
{
    "errors": {
        "rulesetId": [
            "ruleset is disabled"
        ]
    }
}
429

Too many requests. Either the token's requests per minute are used up (see the `X-RateL…

#
application/json

Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.

object
errorsarray[string]#
retry_after_secondsinteger#

Seconds to wait before retrying. Present on the failed-authentication limit only.

Response headers
Retry-Afterinteger

Seconds to wait before retrying.

X-RateLimit-Limitinteger

The token's requests per minute (token limit only).

X-RateLimit-Remaininginteger

Requests left in the current minute (token limit only).

X-RateLimit-Resetinteger

Unix timestamp at which the minute resets (token limit only).

Examples
{
    "errors": [
        "Too Many Requests"
    ]
}
{
    "errors": [
        "Too many authentication attempts. Try again later."
    ],
    "retry_after_seconds": 42
}