addedInput schema / properties / rules / items / properties / egress_services
Added value: +{
+ "description": "Consumer-side process qualifier: services carrying windows_egress_services, which restrict WHICH PROCESS on the consumer may use this rule. Separate from ingress_services (the provider-side port) — the PCE refuses a Windows egress service in ingress_services. Use both together for 'this binary, to that port'.",
+ "items": {
+ "oneOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "port": {
+ "type": "integer"
+ },
+ "proto": {
+ "description": "tcp, udp, icmp or a protocol number"
+ },
+ "to_port": {
+ "type": "integer"
+ }
+ },
+ "required": [
+ "port"
+ ]
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "href": {
+ "type": "string"
+ }
+ },
+ "required": [
+ "href"
+ ]
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "service": {
+ "type": "string"
+ }
+ },
+ "required": [
+ "service"
+ ]
+ }
+ ],
+ "type": "object"
+ },
+ "type": "array"
+}
addedInput schema / properties / rules / items / properties / ingress_services / description
Added value: +"Services this rule covers. Each entry is EITHER an inline port ({'port': 443, 'proto': 'tcp'}), OR a service object by href ({'href': '/orgs/1/sec_policy/draft/services/42'}), OR a service by exact name ({'service': 'All Services'}). Mixing those keys in one entry is an error. For 'any service' use {'service': 'All Services'} — an empty list is rejected by the PCE and {'port': 0} does not mean all ports."
addedInput schema / properties / rules / items / properties / ingress_services / items / oneOf
Added value: +[
+ {
+ "additionalProperties": false,
+ "properties": {
+ "port": {
+ "type": "integer"
+ },
+ "proto": {
+ "description": "tcp, udp, icmp or a protocol number"
+ },
+ "to_port": {
+ "type": "integer"
+ }
+ },
+ "required": [
+ "port"
+ ]
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "href": {
+ "type": "string"
+ }
+ },
+ "required": [
+ "href"
+ ]
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "service": {
+ "type": "string"
+ }
+ },
+ "required": [
+ "service"
+ ]
+ }
+]
removedInput schema / properties / rules / items / properties / ingress_services / items / properties
Removed value: -{
- "port": {
- "type": "integer"
- },
- "proto": {
- "type": "string"
- }
-}
removedInput schema / properties / rules / items / properties / ingress_services / items / required
Removed value: -[
- "port",
- "proto"
-]
addedInput schema / properties / rules / items / properties / rule_type
Added value: +{
+ "default": "allow",
+ "description": "Type of rule: 'allow' (default), 'deny' to block specific traffic, or 'override_deny' to block traffic overriding ALL allow rules (emergency use only — highest priority deny)",
+ "enum": [
+ "allow",
+ "deny",
+ "override_deny"
+ ],
+ "type": "string"
+}