@Generated(value="software.amazon.awssdk:codegen") public final class RuleDefinition extends Object implements SdkPojo, Serializable, ToCopyableBuilder<RuleDefinition.Builder,RuleDefinition>
The inspection criteria and action for a single stateless rule. Network Firewall inspects each packet for the specified matching criteria. When a packet matches the criteria, Network Firewall performs the rule's actions on the packet.
| Modifier and Type | Class and Description |
|---|---|
static interface |
RuleDefinition.Builder |
| Modifier and Type | Method and Description |
|---|---|
List<String> |
actions()
The actions to take on a packet that matches one of the stateless rule definition's match attributes.
|
static RuleDefinition.Builder |
builder() |
boolean |
equals(Object obj) |
boolean |
equalsBySdkFields(Object obj) |
<T> Optional<T> |
getValueForField(String fieldName,
Class<T> clazz) |
boolean |
hasActions()
For responses, this returns true if the service returned a value for the Actions property.
|
int |
hashCode() |
MatchAttributes |
matchAttributes()
Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection.
|
List<SdkField<?>> |
sdkFields() |
static Class<? extends RuleDefinition.Builder> |
serializableBuilderClass() |
RuleDefinition.Builder |
toBuilder() |
String |
toString()
Returns a string representation of this object.
|
clone, finalize, getClass, notify, notifyAll, wait, wait, waitcopypublic final MatchAttributes matchAttributes()
Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection. Each match attributes set can include one or more items such as IP address, CIDR range, port number, protocol, and TCP flags.
public final boolean hasActions()
isEmpty() method on the property). This is
useful because the SDK will never return a null collection or map, but you may need to differentiate between the
service returning nothing (or null) and the service returning an empty collection or map. For requests, this
returns true if a value for the property was specified in the request builder, and false if a value was not
specified.public final List<String> actions()
The actions to take on a packet that matches one of the stateless rule definition's match attributes. You must specify a standard action and you can add custom actions.
Network Firewall only forwards a packet for stateful rule inspection if you specify
aws:forward_to_sfe for a rule that the packet matches, or if the packet doesn't match any stateless
rule and you specify aws:forward_to_sfe for the StatelessDefaultActions setting for the
FirewallPolicy.
For every rule, you must specify exactly one of the following standard actions.
aws:pass - Discontinues all inspection of the packet and permits it to go to its intended destination.
aws:drop - Discontinues all inspection of the packet and blocks it from going to its intended destination.
aws:forward_to_sfe - Discontinues stateless inspection of the packet and forwards it to the stateful rule engine for inspection.
Additionally, you can specify a custom action. To do this, you define a custom action by name and type, then
provide the name you've assigned to the action in this Actions setting. For information about the
options, see CustomAction.
To provide more than one action in this setting, separate the settings with a comma. For example, if you have a
custom PublishMetrics action that you've named MyMetricsAction, then you could specify
the standard action aws:pass and the custom action with [“aws:pass”, “MyMetricsAction”]
.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that
you can differentiate between null and empty), you can use the hasActions() method.
Network Firewall only forwards a packet for stateful rule inspection if you specify
aws:forward_to_sfe for a rule that the packet matches, or if the packet doesn't match any
stateless rule and you specify aws:forward_to_sfe for the
StatelessDefaultActions setting for the FirewallPolicy.
For every rule, you must specify exactly one of the following standard actions.
aws:pass - Discontinues all inspection of the packet and permits it to go to its intended destination.
aws:drop - Discontinues all inspection of the packet and blocks it from going to its intended destination.
aws:forward_to_sfe - Discontinues stateless inspection of the packet and forwards it to the stateful rule engine for inspection.
Additionally, you can specify a custom action. To do this, you define a custom action by name and type,
then provide the name you've assigned to the action in this Actions setting. For information
about the options, see CustomAction.
To provide more than one action in this setting, separate the settings with a comma. For example, if you
have a custom PublishMetrics action that you've named MyMetricsAction, then you
could specify the standard action aws:pass and the custom action with
[“aws:pass”, “MyMetricsAction”].
public RuleDefinition.Builder toBuilder()
toBuilder in interface ToCopyableBuilder<RuleDefinition.Builder,RuleDefinition>public static RuleDefinition.Builder builder()
public static Class<? extends RuleDefinition.Builder> serializableBuilderClass()
public final boolean equalsBySdkFields(Object obj)
equalsBySdkFields in interface SdkPojopublic final String toString()
Copyright © 2023. All rights reserved.