Firewall

Get the project firewall

GET
/cloud/project/{project_uuid}/firewall/map/

Returns the whole firewall setup of the project in one request: security groups with their rules, IP sets with their members, and the firewall options and rules of every VM. Use it to see which VMs use a security group (a rule with type group has the group's pve_group_name as action) or an IP set (+<pve_ipset_name> in source or dest). A null value means that state is temporarily unavailable.

Authorization

bearerAuth
AuthorizationBearer <token>

API key created in the portal (Settings → API Keys). Send as Authorization: Bearer <key>.

In: header

Path Parameters

project_uuid*string

Project UUID.

Response Body

application/json

curl -X GET "https://example.com/cloud/project/string/firewall/map/"
{  "security_groups": [    {      "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",      "display_name": "string",      "pve_group_name": "string",      "comment": "string",      "rules": [        {          "pos": 0,          "type": "string",          "action": "string",          "proto": "string",          "source": "string",          "dest": "string",          "sport": "string",          "dport": "string",          "comment": "string",          "enable": true        }      ]    }  ],  "ip_sets": [    {      "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f",      "display_name": "string",      "pve_ipset_name": "string",      "comment": "string",      "members": [        {          "cidr": "string",          "comment": "string",          "nomatch": true        }      ]    }  ],  "vms": [    {      "vmid": 0,      "options": {        "enable": true,        "policy_in": "ACCEPT",        "policy_out": "ACCEPT"      },      "rules": [        {          "pos": 0,          "type": "string",          "action": "string",          "proto": "string",          "source": "string",          "dest": "string",          "sport": "string",          "dport": "string",          "comment": "string",          "enable": true        }      ]    }  ]}