← Cloudflare DDoS Protection / ddos-protection / advanced-ddos-systems / api / tcp-protection
Типичные вызовы API
В следующих разделах приведены примеры запросов для распространённых вызовов API. Список доступных конечных точек API см. в Конечные точки.
Получить статус Advanced TCP Protection
В этом примере получается текущий статус Advanced TCP Protection (включено или отключено).
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/tcp_protection_status \
--header "Authorization: Bearer <API_TOKEN>"{
"result": {
"enabled": false
},
"success": true,
"errors": [],
"messages": []
}Включить Advanced TCP Protection
В этом примере включается Advanced TCP Protection.
curl --request PATCH \
https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/tcp_protection_status \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"enabled": true
}'Получить существующие префиксы
В этом примере получаются все существующие префиксы в Advanced TCP Protection.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/prefixes \
--header "Authorization: Bearer <API_TOKEN>"{
"result": [
{
"prefix": "203.0.113/24",
"comment": "My prefix",
"excluded": false
}
],
"success": true,
"errors": [],
"messages": []
}Добавить префиксы
Этот пример POST добавляет два префикса. Второй префикс исключает часть первого префикса из Advanced TCP Protection.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/prefixes/bulk \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '[
{
"prefix": "192.0.2.0/24",
"comment": "Game ranges",
"excluded": false
},
{
"prefix": "192.0.2.2/26",
"comment": "Range for a specific game",
"excluded": true
}
]'{
"result": [
{
"id": "<PREFIX_1_ID>",
"prefix": "192.0.2.0/24",
"excluded": false,
"comment": "Game ranges",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
{
"id": "<PREFIX_2_ID>",
"prefix": "192.0.2.2/26",
"excluded": true,
"comment": "Range for a specific game",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
}
],
"success": true,
"errors": [],
"messages": []
}Получить все префиксы в allowlist
В этом примере получаются все префиксы из списка разрешений.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/allowlist \
--header "Authorization: Bearer <API_TOKEN>"{
"result": [
{
"id": "<ALLOWLIST_PREFIX_ID>",
"prefix": "192.0.2.127",
"comment": "Single IP address in allowlist",
"enabled": true,
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
}
],
"success": true,
"errors": [],
"messages": []
}Добавить префикс в allowlist
Этот пример POST добавляет префикс в список разрешенных для аккаунта.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/allowlist \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"prefix": "203.0.113.0/26",
"comment": "Partner range",
"enabled": true
}'{
"result": {
"id": "<ALLOWLIST_PREFIX_1_ID>",
"prefix": "203.0.113.0/26",
"comment": "Partner range",
"enabled": true,
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
"success": true,
"errors": [],
"messages": []
}Создание правила для SYN flood
Этот пример POST запрос создает правило SYN flood с региональной областью действия (Западная Европа) в режиме мониторинга.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/syn_protection/rules \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"scope": "region",
"name": "WEUR",
"mode": "monitoring",
"rate_sensitivity": "medium",
"burst_sensitivity": "medium"
}'{
"result": {
"id": "<SYN_FLOOD_RULE_ID>",
"scope": "region",
"name": "WEUR",
"mode": "monitoring",
"rate_sensitivity": "medium",
"burst_sensitivity": "medium",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
"success": true,
"errors": [],
"messages": []
}См. Объекты JSON для получения дополнительной информации о полях в теле JSON.
Создание правила out-of-state TCP
Этот пример POST запрос создает правило out-of-state TCP в режиме мониторинга, с региональной областью действия и низкой чувствительностью к частоте и всплескам.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/tcp_flow_protection/rules \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"scope": "region",
"name": "WEUR",
"mode": "monitoring",
"rate_sensitivity": "low",
"burst_sensitivity": "low"
}'{
"result": {
"id": "<OOS_TCP_RULE_ID>",
"scope": "region",
"name": "WEUR",
"mode": "monitoring",
"rate_sensitivity": "low",
"burst_sensitivity": "low",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
"success": true,
"errors": [],
"messages": []
}См. Объекты JSON для получения дополнительной информации о полях в теле JSON.
Создание фильтра для SYN flood
Этот пример POST запрос создает SYN flood фильтр, переведя защиту от SYN-флуда в режим мониторинга для определённого диапазона IP-адресов назначения.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/syn_protection/filters \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"expression": "ip.dst in { 192.0.2.0/24 }",
"mode": "monitoring"
}'{
"result": {
"id": "<SYN_FLOOD_FILTER_ID>",
"expression": "ip.dst in { 192.0.2.0/24 }",
"mode": "monitoring",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
"success": true,
"errors": [],
"messages": []
}См. Объекты JSON для получения дополнительной информации о полях в теле JSON.
Создание фильтра out-of-state TCP
Этот пример POST запрос создает out-of-state TCP фильтр, отключив защиту от TCP-атак вне состояния соединения для определённого диапазона IP-адресов и портов назначения.
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/magic/advanced_tcp_protection/configs/tcp_flow_protection/filters \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
"expression": "ip.dst in { 203.0.113.0/24 } and tcp.dstport in { 8000..8081 }",
"mode": "disabled"
}'{
"result": {
"id": "<OOS_TCP_FILTER_ID>",
"expression": "ip.dst in { 203.0.113.0/24 } and tcp.dstport in { 8000..8081 }",
"mode": "disabled",
"created_on": "<TIMESTAMP>",
"modified_on": "<TIMESTAMP>"
},
"success": true,
"errors": [],
"messages": []
}См. Объекты JSON для получения дополнительной информации о полях в теле JSON.