Class RuleDefinition
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<RuleDefinition.Builder,RuleDefinition>
The inspection criteria and action for a single stateless rule. Network Firewall inspects each packet for the specified matching criteria. When a packet matches the criteria, Network Firewall performs the rule's actions on the packet.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionactions()The actions to take on a packet that matches one of the stateless rule definition's match attributes.static RuleDefinition.Builderbuilder()final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final booleanFor responses, this returns true if the service returned a value for the Actions property.final inthashCode()final MatchAttributesCriteria for Network Firewall to use to inspect an individual packet in stateless rule inspection.static Class<? extends RuleDefinition.Builder> Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
matchAttributes
Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection. Each match attributes set can include one or more items such as IP address, CIDR range, port number, protocol, and TCP flags.
- Returns:
- Criteria for Network Firewall to use to inspect an individual packet in stateless rule inspection. Each match attributes set can include one or more items such as IP address, CIDR range, port number, protocol, and TCP flags.
-
hasActions
public final boolean hasActions()For responses, this returns true if the service returned a value for the Actions property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
actions
The actions to take on a packet that matches one of the stateless rule definition's match attributes. You must specify a standard action and you can add custom actions.
Network Firewall only forwards a packet for stateful rule inspection if you specify
aws:forward_to_sfefor a rule that the packet matches, or if the packet doesn't match any stateless rule and you specifyaws:forward_to_sfefor theStatelessDefaultActionssetting for the FirewallPolicy.For every rule, you must specify exactly one of the following standard actions.
-
aws:pass - Discontinues all inspection of the packet and permits it to go to its intended destination.
-
aws:drop - Discontinues all inspection of the packet and blocks it from going to its intended destination.
-
aws:forward_to_sfe - Discontinues stateless inspection of the packet and forwards it to the stateful rule engine for inspection.
Additionally, you can specify a custom action. To do this, you define a custom action by name and type, then provide the name you've assigned to the action in this
Actionssetting. For information about the options, see CustomAction.To provide more than one action in this setting, separate the settings with a comma. For example, if you have a custom
PublishMetricsaction that you've namedMyMetricsAction, then you could specify the standard actionaws:passand the custom action with[“aws:pass”, “MyMetricsAction”].Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasActions()method.- Returns:
- The actions to take on a packet that matches one of the stateless rule definition's match attributes. You
must specify a standard action and you can add custom actions.
Network Firewall only forwards a packet for stateful rule inspection if you specify
aws:forward_to_sfefor a rule that the packet matches, or if the packet doesn't match any stateless rule and you specifyaws:forward_to_sfefor theStatelessDefaultActionssetting for the FirewallPolicy.For every rule, you must specify exactly one of the following standard actions.
-
aws:pass - Discontinues all inspection of the packet and permits it to go to its intended destination.
-
aws:drop - Discontinues all inspection of the packet and blocks it from going to its intended destination.
-
aws:forward_to_sfe - Discontinues stateless inspection of the packet and forwards it to the stateful rule engine for inspection.
Additionally, you can specify a custom action. To do this, you define a custom action by name and type, then provide the name you've assigned to the action in this
Actionssetting. For information about the options, see CustomAction.To provide more than one action in this setting, separate the settings with a comma. For example, if you have a custom
PublishMetricsaction that you've namedMyMetricsAction, then you could specify the standard actionaws:passand the custom action with[“aws:pass”, “MyMetricsAction”]. -
-
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<RuleDefinition.Builder,RuleDefinition> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo- Returns:
- The mapping between the field name and its corresponding field.
-