Class FirewallPolicyRuleMatcher (1.31.0)

FirewallPolicyRuleMatcher(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Represents a match condition that incoming traffic is evaluated against. Exactly one field must be specified.

.. _oneof: https://proto-plus-python.readthedocs.io/en/stable/fields.html#oneofs-mutually-exclusive-fields

Attributes

Name Description
dest_address_groups MutableSequence[str]
Address groups which should be matched against the traffic destination. Maximum number of destination address groups is 10.
dest_fqdns MutableSequence[str]
Fully Qualified Domain Name (FQDN) which should be matched against traffic destination. Maximum number of destination fqdn allowed is 100.
dest_ip_ranges MutableSequence[str]
CIDR IP address range. Maximum number of destination CIDR IP ranges allowed is 5000.
dest_network_type str
Network type of the traffic destination. Allowed values are: - UNSPECIFIED - INTERNET - NON_INTERNET Check the DestNetworkType enum for the list of possible values. This field is a member of oneof_ _dest_network_type.
dest_region_codes MutableSequence[str]
Region codes whose IP addresses will be used to match for destination of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of dest region codes allowed is 5000.
dest_threat_intelligences MutableSequence[str]
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic destination.
layer4_configs MutableSequence[google.cloud.compute_v1.types.FirewallPolicyRuleMatcherLayer4Config]
Pairs of IP protocols and ports that the rule should match.
src_address_groups MutableSequence[str]
Address groups which should be matched against the traffic source. Maximum number of source address groups is 10.
src_fqdns MutableSequence[str]
Fully Qualified Domain Name (FQDN) which should be matched against traffic source. Maximum number of source fqdn allowed is 100.
src_ip_ranges MutableSequence[str]
CIDR IP address range. Maximum number of source CIDR IP ranges allowed is 5000.
src_network_type str
Network type of the traffic source. Allowed values are: - UNSPECIFIED - INTERNET - INTRA_VPC - NON_INTERNET - VPC_NETWORKS Check the SrcNetworkType enum for the list of possible values. This field is a member of oneof_ _src_network_type.
src_networks MutableSequence[str]
Networks of the traffic source. It can be either a full or partial url.
src_region_codes MutableSequence[str]
Region codes whose IP addresses will be used to match for source of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of source region codes allowed is 5000.
src_secure_tags MutableSequence[google.cloud.compute_v1.types.FirewallPolicyRuleSecureTag]
List of secure tag values, which should be matched at the source of the traffic. For INGRESS rule, if all the srcSecureTag are INEFFECTIVE, and there is no srcIpRange, this rule will be ignored. Maximum number of source tag values allowed is 256.
src_threat_intelligences MutableSequence[str]
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic source.

Classes

DestNetworkType

DestNetworkType(value)

Network type of the traffic destination. Allowed values are: - UNSPECIFIED - INTERNET - NON_INTERNET Additional supported values which may be not listed in the enum directly due to technical reasons: INTERNET INTRA_VPC NON_INTERNET UNSPECIFIED VPC_NETWORKS

SrcNetworkType

SrcNetworkType(value)

Network type of the traffic source. Allowed values are: - UNSPECIFIED - INTERNET - INTRA_VPC - NON_INTERNET - VPC_NETWORKS Additional supported values which may be not listed in the enum directly due to technical reasons: INTERNET INTRA_VPC NON_INTERNET UNSPECIFIED VPC_NETWORKS