Package-level declarations

Types

Link copied to clipboard
sealed class AccountRoleStatus
Link copied to clipboard

Configures the accounts within the administrator's Organizations organization that the specified Firewall Manager administrator can apply policies to.

Link copied to clipboard

Describes a remediation action target.

Link copied to clipboard

Contains high level information about the Firewall Manager administrator account.

Link copied to clipboard

Defines the resources that the Firewall Manager administrator can manage. For more information about administrative scope, see Managing Firewall Manager administrators in the Firewall Manager Developer Guide.

Link copied to clipboard
class App

An individual Firewall Manager application.

Link copied to clipboard

An Firewall Manager applications list.

Link copied to clipboard

Details of the Firewall Manager applications list.

Link copied to clipboard

Violation detail for an EC2 instance resource.

Link copied to clipboard

Violation detail for network interfaces associated with an EC2 instance.

Link copied to clipboard

Violation detail for the rule violation in a security group when compared to the primary security group of the Firewall Manager policy.

Link copied to clipboard

Details of the resource that is not protected by the policy.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class DestinationType
Link copied to clipboard

A resource in the organization that's available to be associated with a Firewall Manager resource set.

Link copied to clipboard

A DNS Firewall rule group that Firewall Manager tried to associate with a VPC is already associated with the VPC and can't be associated again.

Link copied to clipboard

The VPC that Firewall Manager was applying a DNS Fireall policy to reached the limit for associated DNS Firewall rule groups. Firewall Manager tried to associate another rule group with the VPC and failed due to the limit.

Link copied to clipboard

A rule group that Firewall Manager tried to associate with a VPC has the same priority as a rule group that's already associated.

Link copied to clipboard

The action of associating an EC2 resource, such as a subnet or internet gateway, with a route table.

Link copied to clipboard

An action that copies the EC2 route table for use in remediation.

Link copied to clipboard

Information about the CreateRoute action in Amazon EC2.

Link copied to clipboard

Information about the CreateRouteTable action in Amazon EC2.

Link copied to clipboard

Information about the DeleteRoute action in Amazon EC2.

Link copied to clipboard

Information about the ReplaceRoute action in Amazon EC2.

Link copied to clipboard

Information about the ReplaceRouteTableAssociation action in Amazon EC2.

Link copied to clipboard

Describes the compliance status for the account. An account is considered noncompliant if it includes resources that are not protected by the specified policy or that don't comply with the policy.

Link copied to clipboard

Information about the expected route in the route table.

Link copied to clipboard

Details of a resource that failed when trying to update it's association to a resource set.

Link copied to clipboard
sealed class FailedItemReason
Link copied to clipboard
Link copied to clipboard

Contains details about the firewall subnet that violates the policy scope.

The violation details for a firewall subnet's VPC endpoint that's deleted or missing.

Link copied to clipboard

Base class for all service related exceptions thrown by the Fms client

Contains information about the actions that you can take to remediate scope violations caused by your policy's FirewallCreationConfig. FirewallCreationConfig is an optional configuration that you can use to choose which Availability Zones Firewall Manager creates Network Firewall endpoints in.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

The operation failed because of a system problem, even though the request was valid. Retry your request.

Link copied to clipboard

The parameters of the request were invalid.

Link copied to clipboard

The operation failed because there was nothing to do or the operation wasn't possible. For example, you might have submitted an AssociateAdminAccount request for an account ID that was already set as the Firewall Manager administrator. Or you might have tried to access a Region that's disabled by default, and that you need to enable for the Firewall Manager administrator account and for Organizations before you can access it.

Link copied to clipboard

The value of the Type parameter is invalid.

Link copied to clipboard

The operation exceeds a resource limit, for example, the maximum number of policy objects that you can create for an Amazon Web Services account. For more information, see Firewall Manager Limits in the WAF Developer Guide.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Violation detail for an internet gateway route with an inactive state in the customer subnet route table or Network Firewall subnet route table.

Violation detail for the subnet for which internet traffic that hasn't been inspected.

Violation detail for the improperly configured subnet route. It's possible there is a missing route table route, or a configuration that causes traffic to cross an Availability Zone boundary.

Violation detail for an expected route missing in Network Firewall.

Violation detail for Network Firewall for a subnet that's not associated to the expected Firewall Manager managed route table.

Link copied to clipboard

Violation detail for Network Firewall for a subnet that doesn't have a Firewall Manager managed firewall in its VPC.

Link copied to clipboard

Violation detail for Network Firewall for an Availability Zone that's missing the expected Firewall Manager managed subnet.

Link copied to clipboard
Link copied to clipboard

Configures the firewall policy deployment model of Network Firewall. For information about Network Firewall deployment models, see Network Firewall example architectures with routing in the Network Firewall Developer Guide.

Link copied to clipboard

The definition of the Network Firewall firewall policy.

Link copied to clipboard

Violation detail for Network Firewall for a firewall policy that has a different NetworkFirewallPolicyDescription than is required by the Firewall Manager policy.

Link copied to clipboard

The setting that allows the policy owner to change the behavior of the rule group within a policy.

Violation detail for an unexpected route that's present in a route table.

Violation detail for an unexpected gateway route that’s present in a route table.

Link copied to clipboard

Defines the Organizations organizational units (OUs) that the specified Firewall Manager administrator can apply policies to. For more information about OUs in Organizations, see Managing organizational units (OUs) in the Organizations User Guide.

Link copied to clipboard
sealed class OrganizationStatus
Link copied to clipboard

The reference rule that partially matches the ViolationTarget rule and violation reason.

Link copied to clipboard
class Policy

An Firewall Manager policy.

Link copied to clipboard

Describes the noncompliant resources in a member account for a specific Firewall Manager policy. A maximum of 100 entries are displayed. If more than 100 resources are noncompliant, EvaluationLimitExceeded is set to True.

Link copied to clipboard

Indicates whether the account is compliant with the specified policy. An account is considered noncompliant if it includes resources that are not protected by the policy, for WAF and Shield Advanced policies, or that are noncompliant with the policy, for security group policies.

Link copied to clipboard
Link copied to clipboard

Contains the Network Firewall firewall policy options to configure the policy's deployment model and third-party firewall policy settings.

Link copied to clipboard

Details of the Firewall Manager policy.

Link copied to clipboard

Defines the policy types that the specified Firewall Manager administrator can manage.

Link copied to clipboard

A list of remediation actions.

Link copied to clipboard

A list of possible remediation action lists. Each individual possible remediation action is a list of individual remediation actions.

Link copied to clipboard

An Firewall Manager protocols list.

Link copied to clipboard

Details of the Firewall Manager protocols list.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Defines the Amazon Web Services Regions that the specified Firewall Manager administrator can manage.

Link copied to clipboard

Information about an individual action you can take to remediate a violation.

Link copied to clipboard
Link copied to clipboard

An ordered list of actions you can take to remediate a violation.

Link copied to clipboard
class Resource

Details of a resource that is associated to an Firewall Manager resource set.

Link copied to clipboard

The specified resource was not found.

Link copied to clipboard

A set of resources to include in a policy.

Link copied to clipboard
sealed class ResourceSetStatus
Link copied to clipboard

Summarizes the resource sets used in a policy.

Link copied to clipboard

The resource tags that Firewall Manager uses to determine if a particular resource should be included or excluded from the Firewall Manager policy. Tags enable you to categorize your Amazon Web Services resources in different ways, for example, by purpose, owner, or environment. Each tag consists of a key and an optional value. Firewall Manager combines the tags with "AND" so that, if you add more than one tag to a policy scope, a resource must have all the specified tags to be included or excluded. For more information, see Working with Tag Editor.

Link copied to clipboard

Violation detail based on resource type.

Link copied to clipboard
class Route

Describes a route in a route table.

Link copied to clipboard

Contains details about the route endpoint that violates the policy scope.

Link copied to clipboard
sealed class RuleOrder
Link copied to clipboard

Remediation option for the rule specified in the ViolationTarget.

Link copied to clipboard

Describes a set of permissions for a security group rule.

Link copied to clipboard

Details about the security service that is being used to protect the resources.

Link copied to clipboard
sealed class SecurityServiceType
Link copied to clipboard

Configuration settings for the handling of the stateful rule groups in a Network Firewall firewall policy.

Link copied to clipboard

Network Firewall stateful rule group, used in a NetworkFirewallPolicyDescription.

Link copied to clipboard

Network Firewall stateless rule group, used in a NetworkFirewallPolicyDescription.

Link copied to clipboard
class Tag

A collection of key:value pairs associated with an Amazon Web Services resource. The key:value pair can be anything you define. Typically, the tag key represents a category (such as "environment") and the tag value represents a specific value within that category (such as "test," "development," or "production"). You can add up to 50 tags to each Amazon Web Services resource.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class TargetType
Link copied to clipboard
sealed class ThirdPartyFirewall
Link copied to clipboard

Configures the third-party firewall's firewall policy.

The violation details for a third-party firewall that's not associated with an Firewall Manager managed route table.

The violation details about a third-party firewall's subnet that doesn't have a Firewall Manager managed firewall in its VPC.

Link copied to clipboard

The violation details for a third-party firewall for an Availability Zone that's missing the Firewall Manager managed subnet.

Link copied to clipboard

Configures the deployment model for the third-party firewall.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Violations for a resource based on the specified Firewall Manager policy and Amazon Web Services account.

Link copied to clipboard
sealed class ViolationReason