IPS-Specific Configurations Using REST APIs
policy management creating the hc policy request post api/v1/configuration/authentication/endpoint/host checker/policies/policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "policy name" "hc", "regular" { "platforms" { "chromeos" { "dashboard" { "consider for reporting" "true" }, "remediation" { "custom instructions" "", "enable custom instructions" "false", "send reason strings" "true" } }, "windows" { "dashboard" { "consider for reporting" "true" }, "remediation" { "custom instructions" "", "delete files" "false", "enable custom instructions" "false", "files" null, "kill processes" "false", "processes" null, "send reason strings" "true" }, "rule expression" { "custom expression" "", "requirement" "all" }, "rules" { "advancedrule" \[], "firewall rules" { "firewall rule" \[ { "needs monitoring" "false", "product list" null, "product selection option" "specific", "rule name" "rule1", "select specific product" "false", "select specific vendor" "true", "selected product list" { "product info" \[ { "product name" "windows firewall (10 x)", "turn on firewall" "true" }, { "product name" "windows firewall (6 x)", "turn on firewall" "false" } ] }, "turn on firewall all" "false", "vendor list" \[ "microsoft corporation" ] } ] } } } } } } response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } deleting the hc policy request delete api/v1/configuration/authentication/endpoint/host checker/policies/policy/hc http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating auth table mapping policy request post /api/v1/configuration/uac/infranet enforcer/auth table mapping policies/auth table mapping policy host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "nat support" "false", "action" "always provision auth table", "apply" "all roles", "description" "restapi panipv6authtablemapping", "device group support" "false", "infranet enforcer" \[ "restapi panipv6" ], "name" "restapi panipv6authtablemapping", "provision userid" "false", "roles" null, "source device groups" null, "vsys" "" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } creating a resource policy request post api/v1/configuration/uac/infranet enforcer/resource access policies/resource access policy/ http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "action" "allow access", "apply" "all roles", "apply ie options" "all options", "deny message" "", "description" "", "ie options" \[], "infranet enforcer" \[ "(all)" ], "name" "resource policy", "resources" \[ "\<ip address>/24 " ], "roles" null, "vsys" "" } deleting a resource policy request delete api/v1/configuration/uac/infranet enforcer/resource access policies/resource access policy/resource%20policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } creating a resource access policy (pan firewall) request post api/v1/configuration/uac/infranet enforcer/resource access policies/resource access policy/ http/1 1 host x x x x authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "action" "allow access", "apply" "all roles", "apply ie options" "all options", "auto update" "false", "deny message" "", "description" "pan resource", "destination zone" \[ "untrust" ], "device group support" "false", "device groups" null, "device manufacturer" null, "device port" "", "device protocol" null, "device types" null, "enforcer type" "palo alto", "filter type" "none", "ie options" \[], "infranet enforcer" \[ "(all)" ], "name" "pan resource", "pan service" "any", "resources" \[ "x x x x/x" ], "resources excluded" null, "resources v6" \[ "2001\ db8 123 1 /64" ], "roles" null, "source device groups" null, "source zone" \[ "dmz" ], "vsys" "" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } creating a radius attribute policy request post /api/v1/configuration/uac/network access/radius attribute/radius attributes policies/radius attribute policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "apply" "all", "description" "", "location group" \[ "guest" ], "name" "return attribute policy", "network interface" "automatic", "open port" "false", "return attribute flag" "false", "return attributes" { "return attribute" \[] }, "roles" null, "send session timeout by default" "false", "send termination action by default" "false", "vlan" "65", "vlan check" "true" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting a radius attribute policy request delete /api/v1/configuration/uac/network access/radius attribute/radius attributes policies/radius attribute policy/return%20attribute%20policy/http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating snmp policy request post /api/v1/configuration/uac/snmpenforcement/snmppolicies/policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "apply to roles" "selected", "description" "", "location group" "guest wired", "name" "snmp policy", "roles" \[ "guest wired restricted" ], "vlan" "65" } response host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting snmp policy request delete /api/v1/configuration/uac/snmpenforcement/snmppolicies/policy/snmp%20policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating shell policies request post /api/v1/configuration/uac/networkdeviceadministration/policies/policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "apply action" "deny", "apply groups" "all", "apply roles" "all", "commandsets" { "command set" \[] }, "defaultprivilege" "1", "description" "", "groups" null, "maxprivilege" "1", "name" "tacacs policy", "roles" null } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting shell policies request delete /api/v1/configuration/uac/networkdeviceadministration/policies/policy/tacacs%20policy http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } creating admission control policy request post /api/v1/configuration/uac/admissioncontrol/policies/policy/ http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "action" "ignore", "apply" "selected", "count" "1", "event" "utm\ ips", "name" "policy1", "replacementrole" null, "replacementtype" "permanent", "roles" null, "severity" "critical", "templateid" "fortigate text itmpl" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } deleting admission control policy request delete /api/v1/configuration/uac/admissioncontrol/policies/policy/policy1 http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json device management creating the infranet enforcer request post api/v1/configuration/uac/infranet enforcer/connections/infranet enforcer http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "idp for local sessions only" "true", "junos" { "location group" " no 802 1x ", "password encrypted" "3u+ur6n8agabaaaaofsnibru19vdwuslg5lg4cg1qh6cbxdsmy4zw0x85hy=" }, "name" "srx", "serial number" \[ "abcnwpwfs" ], "severity filter" "medium", "use idp" "false" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting the infranet enforcer request delete api/v1/configuration/uac/infranet enforcer/connections/infranet enforcer/srx http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating the infranet enforcer (pan) get api key requesturl https //\<pan ip address>/api/?type=keygen\&user=\<pan username>\&password=\<pan password> response \<response status = 'success'> \<result> \<key>lufrpt10kzvwodyxtlm1bvbtwktdymjlwgtzatfxyzg9wu52qtmxyk1kng1kzg40zuv3wu1gykhim0zxnjjuckjowljonzdoahvzv0rmuhuyuk91b0tnsvzwvzvty3fwsg==\</key> \</result> \</response> create infranet enforcer using above pan apikey request post /api/v1/configuration/uac/infranet enforcer/connections/infranet enforcer/ host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "idp for local sessions only" "false", "name" "restapi panipv6", "pan" { "apikey cleartext" "lufrpt03cvztadvcovbfohhml0tym0jqmgfazmritza9wu52qtmxyk1kng1kzg40zuv3wu1gykhim0zxnjjuckjowljonzdoahvzvnhzd3d3nwqyyjboutzgn3uwv2traq==", "ipaddress" "xx xx xx xx", "use secure ssl" "false" }, "serial number" null, "severity filter" "info", "use idp" "false" } response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } creating snmp device request post /api/v1/configuration/uac/snmpenforcement/clients/client http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "default vlan" "0", "description" "", "enable" "true", "ip address" "\<ip address>", "location group" "none", "model" "ruckus wireless", "name" "ruckus", "read auth password encrypted" "", "read auth protocol" "md5", "read priv password encrypted" "", "read priv protocol" "", "read security level" "auth", "read username" "public", "snmp enforcement" "false", "snmp version" "v2", "ssh passphrase encrypted" "", "ssh port number" "22", "ssh private key encrypted" "", "ssh user name" "", "ssh user password encrypted" "", "sys contact" "https //support ruckuswireless com/contact us", "sys description" "ruckus wireless zd1200", "sys location" "350 west java dr sunnyvale, ca 94089 us", "sys name" "ruckus", "trap auth password encrypted" "", "trap auth protocol" "md5", "trap priv password encrypted" "", "trap priv protocol" "", "trap security level" "auth", "trap username" "public", "use samecredential" "true", "write auth password encrypted" "", "write auth protocol" "md5", "write priv password encrypted" "", "write priv protocol" "", "write security level" "auth", "write username" "public" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting snmp device request delete /api/v1/configuration/uac/snmpenforcement/clients/client/ruckus/http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating device group tacacs+ request post /api/v1/configuration/uac/networkdeviceadministration/groups/group/ http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "admin realm" "admin users", "description" "", "name" "device group" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting device group tacacs+ request delete /api/v1/configuration/uac/networkdeviceadministration/groups/group/device%20group http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json client management creating a radius client request post /api/v1/configuration/uac/network access/radius clients/radius client http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "coa support" "false", "description" "", "disconnect support" "true", "dynamic auth port" "3799", "enable" "true", "gatewayid" "", "ip address" "10 204 88 12", "ip address range" "1", "kek encrypted" "", "key wrap format" "hex", "key wrap support" "false", "location group" "default", "mack encrypted" "", "make model" "ruckus wireless", "name" "ruckus", "ruckus certificate verification" "false", "ruckus password encrypted" "", "shared secret encrypted" "3u+ur6n8agabaaaaofsnibru19vdwuslg5lg4cg1qh6cbxdsmy4zw0x85hy=" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting a radius client request delete /api/v1/configuration/uac/network access/radius clients/radius client/ruckus http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating tacacs+ client request post api/v1/configuration/uac/networkdeviceadministration/clients/client http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "description" "", "devicegroup" "device group", "enable" "true", "ipaddress" "\<ip address>", "ipaddressrange" "1", "name" "tacacs client", "shared secret encrypted" "3u+ur6n8agabaaaaofsnibru19vdwuslg5lg4cg1qh6cbxdsmy4zw0x85hy=" } response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } deleting tacacs+ client request delete /api/v1/configuration/uac/networkdeviceadministration/clients/client/tacacs%20client http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating admission control client request post /api/v1/configuration/uac/admissioncontrol/clients/client http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "description" "", "enable" "true", "ipaddress" "\<ip address>", "name" "fortinet", "templateid" "fortigate text itmpl" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting admission control client request delete /api/v1/configuration/uac/admissioncontrol/clients/client/fortinet http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json response http/1 1 204 no content content length 0 content type application/json getting authentication api key request get \<ips ip address>/api/v1/auth response "api key" "naiq3dnqoh7adtsxjbzruo4b+tilb1vpf5sasdasdfao=" request get \<ips ip address>/api/v1/auth/profiler/auth response "api key" "naiq3dnqoh7adtsxjbzruo4b+tilb1vpf5sasdasdfao=" ips alert based admission control apis checking status of ips server request get \<ips ip address>/api/v1/integration/status response "{\\"message\\" \\"api server is up\\"}" getting session details for endpoint based on ip address request get \<ips ip address>/api/v1/integration/sessions/\<endpoint ip address> response { "data" \[ { "ip" "xx xxx xx xx", "macaddr" "00 56 65 bf 0b cx", "switch ip" "", "switch port" "", "username" "user1" } ] } note this sample response is for juniper sdsn getting session details for endpoint based on mac address request get \<ips ip address>/api/v1/integration/sessions/\<endpoint mac address> response { "data" \[ { "macaddr" "00 56 65 bf 0b cx", "switch ip" "", "switch port" "", } ] } sending alert event to ips request ut /api/v1/ integration/sessions for example sample put request payload for juniper sdsn is {"event name" "block endpoint", "srcip" "10 xxx xx xxx"} note the event names and field to parse the source ip from the event should be defined in the admission control template response http/1 1 204 no content profiler rest apis approving devices request put api/v1/profiler/endpoints/simplified/xx\ xx\ xx\ xx\ xx\ xx http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "status" "approved" } response http/1 1 200 ok content type application/json { "successfully updated ” } updating device attributes request put api/v1/profiler/endpoints/simplified/xx\ xx\ xx\ xx\ xx\ xx http/1 1 host xx xx xx xx authorization basic vu9qstlgtznryvk5d0t2axpbn1dpz0fyzln1s3fmtknnquh0r0zur0xsbz06 content type application/json { "manufacturer" "windows", "os" "windows" } response http/1 1 200 ok content type application/json { "successfully updated ” }
