delete_dfw_rule
Preview or permanently delete a single NSX Distributed Firewall rule from its parent security policy, showing the blast radius before any change is applied.
Instructions
[WRITE] Permanently delete one DFW rule from its parent security policy.
Irreversible and immediate: traffic it matched falls through to lower-priority rules or the policy default. Without confirm=True this only previews: it returns blast_radius (the parent policy, the rule's action, sources, destinations, services, scope, direction, disabled flag, blockers, unmeasured) and deletes nothing. Show that to the user and get their decision. Do not set confirm=True on your own because the user asked to delete earlier: they have not seen the blast radius yet. Check recent hits with get_dfw_rule_stats first; prefer update_dfw_rule with disabled=True when you may need the rule back. A rule_id not in the policy is an error, and confirm=True refuses when the rules could not be read. To remove a whole policy use delete_dfw_policy — it refuses while rules remain. Returns {"action": "preview" | "deleted", "blast_radius": ...}, else {"error", "hint", "blast_radius"?}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | Target name from config; default if omitted. | |
| confirm | No | False (default) returns the blast radius and changes nothing. True applies it. | |
| rule_id | Yes | Rule id within that policy, from list_dfw_rules. | |
| policy_id | Yes | Parent policy id, from list_dfw_policies. |