sophos_firewall
On-premise firewall by Sophos enables you to manage your firewall, respond to threats, and monitor what’s happening on your network.
Network Security · Sophos XG Firewall
Details
| ID | sophos_firewall |
|---|---|
| Provider | Thoma Bravo |
| Category | Network Security |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM EDR Cortex Cloud Cloud Runtime Security |
README
On-Premise firewall by Sophos enables you to manage your firewall, respond to threats, and monitor what’s
happening on your network.
Configure Sophos Firewall in Cortex
| Parameter | Description | Required |
|---|---|---|
| server_url | Server URL | True |
| credentials | User Credentials | True |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
sophos-firewall-rule-list
Lists all firewall rules. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-rule-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicy.Name | String | Name of the rule. |
| SophosFirewall.SecurityPolicy.Description | String | Description of the rule. |
| SophosFirewall.SecurityPolicy.Status | String | Status of the rule. |
| SophosFirewall.SecurityPolicy.PolicyType | String | Policy type of the rule. |
| SophosFirewall.SecurityPolicy.IPFamily | String | IP family of the security policy. Either IPv4 or IPv6. |
| SophosFirewall.SecurityPolicy.AttachIdentity | String | Rule attach identity status. |
| SophosFirewall.SecurityPolicy.Action | String | Current rule action. |
| SophosFirewall.SecurityPolicy.LogTraffic | Number | Rule traffic logging code. |
Command Example
!sophos-firewall-rule-list start=0 end=6
Context Example
{
"SophosFirewall": {
"SecurityPolicy": [
{
"After": {
"Name": "[example] Traffic to DMZ"
},
"ApplyNAT": "CustomNatPolicy",
"Description": "This rule was added automatically by SFOS MTA. However you could edit this policy based on network requirement.",
"DestSecurityHeartbeat": "Disable",
"IPFamily": "IPv4",
"IntrusionPrevention": "None",
"IsDeleted": false,
"LogTraffic": "Disable",
"MatchIdentity": "Disable",
"MinimumDestinationHBPermitted": "No Restriction",
"MinimumSourceHBPermitted": "No Restriction",
"Name": "Auto added firewall policy for MTA",
"OutboundAddress": "MASQ",
"OverrideGatewayDefaultNATPolicy": "Disable",
"PolicyType": "PublicNonHTTPPolicy",
"Position": "After",
"PublicNonHTTPBasedPolicy": {
"ScanIMAP": "Disable",
"ScanIMAPS": "Disable",
"ScanPOP3": "Disable",
"ScanPOP3S": "Disable",
"ScanSMTP": "Enable",
"ScanSMTPS": "Enable"
},
"SourceSecurityHeartbeat": "Disable",
"Status": "Enable",
"TrafficShappingPolicy": "None"
},
{
"Action": "Drop",
"After": {
"Name": "[example] Traffic to WAN"
},
"Description": "A disabled Firewall rule with the destination zone as DMZ. Such rules would be added to Traffic to DMZ group on the first match basis if user selects automatic grouping option.",
"DestinationZones": {
"Zone": "DMZ"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Enable",
"MatchIdentity": "Enable",
"Name": "[example] Traffic to DMZ",
"PolicyType": "User",
"Position": "After",
"Schedule": "All The Time",
"ShowCaptivePortal": "Enable",
"Status": "Disable"
},
{
"Action": "Drop",
"After": {
"Name": "after"
},
"Description": "A disabled Firewall rule with the destination zone as WAN. Such rules would be added to Traffic to WAN group on the first match basis if user selects automatic grouping option.",
"DestinationZones": {
"Zone": "WAN"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Enable",
"MatchIdentity": "Disable",
"Name": "[example] Traffic to WAN",
"PolicyType": "Network",
"Position": "After",
"Schedule": "All The Time",
"Status": "Disable"
},
{
"Action": "Drop",
"After": {
"Name": "Auto added firewall policy for MTA"
},
"Description": null,
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Disable",
"MatchIdentity": "Disable",
"Name": "[example] Traffic to Internal Zones",
"PolicyType": "Network",
"Position": "After",
"Schedule": "All The Time",
"Status": "Enable"
},
{
"Action": "Drop",
"Description": null,
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Disable",
"MatchIdentity": "Disable",
"Name": "Blocked IPs",
"PolicyType": "Network",
"Position": "Top",
"Schedule": "All The Time",
"SourceNetworks": {
"Network": "Blocked by Playbook"
},
"Status": "Enable"
},
{
"Action": "Drop",
"After": {
"Name": "before"
},
"Description": null,
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Disable",
"MatchIdentity": "Disable",
"Name": "after",
"PolicyType": "Network",
"Position": "After",
"Schedule": "All The Time",
"Status": "Enable"
}
]
}
}
Human Readable Output
Showing 0 to 6 SecurityPolicy objects out of 8
Name Description Status PolicyType IPFamily Action LogTraffic Auto added firewall policy for MTA This rule was added automatically by SFOS MTA. However you could edit this policy based on network requirement. Enable PublicNonHTTPPolicy IPv4 Disable [example] Traffic to DMZ A disabled Firewall rule with the destination zone as DMZ. Such rules would be added to Traffic to DMZ group on the first match basis if user selects automatic grouping option. Disable User IPv4 Drop Enable [example] Traffic to WAN A disabled Firewall rule with the destination zone as WAN. Such rules would be added to Traffic to WAN group on the first match basis if user selects automatic grouping option. Disable Network IPv4 Drop Enable [example] Traffic to Internal Zones Enable Network IPv4 Drop Disable Blocked IPs Enable Network IPv4 Drop Disable after Enable Network IPv4 Drop Disable
sophos-firewall-rule-get
Gets a single firewall rule by name.
Base Command
sophos-firewall-rule-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the rule to get. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicy.Name | String | Name of the rule. |
| SophosFirewall.SecurityPolicy.Description | String | Description of the rule. |
| SophosFirewall.SecurityPolicy.Status | String | Status of the rule. |
| SophosFirewall.SecurityPolicy.PolicyType | String | Policy type of the rule. |
| SophosFirewall.SecurityPolicy.IPFamily | String | IP family of the security policy. Either IPv4 or IPv6. |
| SophosFirewall.SecurityPolicy.AttachIdentity | String | Rule attach identity status. |
| SophosFirewall.SecurityPolicy.Action | String | Current rule action. |
| SophosFirewall.SecurityPolicy.LogTraffic | Number | Rule traffic logging code. |
Command Example
!sophos-firewall-rule-get name=user_rule
Context Example
{
"SophosFirewall": {
"SecurityPolicy": {
"Action": "Drop",
"After": {
"Name": "1"
},
"Description": null,
"DestinationZones": {
"Zone": "LAN"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Enable",
"MatchIdentity": "Disable",
"Name": "user_rule",
"PolicyType": "Network",
"Position": "After",
"Schedule": "All The Time",
"SourceZones": {
"Zone": "LAN"
},
"Status": "Enable"
}
}
}
Human Readable Output
SecurityPolicy Object details
Name Status PolicyType IPFamily Action LogTraffic user_rule Enable Network IPv4 Drop Enable
sophos-firewall-rule-add
Adds a new firewall rule.
Base Command
sophos-firewall-rule-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the new rule. | Required |
| description | Description of the new rule. | Optional |
| status | Whether the rule is enabled. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. Default is “IPv4”. | Optional |
| position | Whether the rule should be at the “top” or “bottom” of the list, or “before” or\ \ “after” a specific rule? IMPORTANT: If “before” or “after” is selected, provide the\ \ position_policy_name parameter. | Required |
| position_policy_name | The name of the policy that the rule should be created before or after. REQUIRED: When the position is “before” or “after”. | Optional |
| policy_type | Type of the new rule (policy). Possible values: “User” and “Network”. | Required |
| source_zones | Source zones to add to the rule. Possible values: “Any”, “LAN”. “WAN”, “VPN”, “DMZ”, “WiFi”. | Optional |
| source_networks | Source networks to add to the rule. | Optional |
| destination_zones | Destination zones to add to the rule. Possible values: “Any”, “LAN”. “WAN”, “VPN”, “DMZ”, “WiFi”. | Optional |
| destination_networks | Destination networks to add to the rule. | Optional |
| services | Destination services to add to the rule. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available from the web console. | Optional |
| log_traffic | Whether to enable traffic logging for the policy. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| match_identity | Whether to check if the specified user/user group from the\ \ selected zone is allowed to access the selected service. Possible values: “Enable” and “Disable”. Default is “Disable”. IMPORTANT: When enabling match_identity, the members argument is required. | Optional |
| show_captive_portal | Whether to accept traffic from unknown users. Captive portal page\ \ is displayed to the user where the user can login to access the Internet.\ \ Possible values: “Enable” and “Disable”. Default is “Disable”. IMPORTANT: MatchIdentity must be Enabled. PARAMETER OF: UserPolicy. | Optional |
| members | An existing user(s) or group(s) to add to the rule. REQUIRED when match_identity is enabled. | Optional |
| action | Action for the rule traffic. Possible values: “Accept”, “Reject”, and “Drop”. Default is “Drop”. | Optional |
| dscp_marking | The DSCP marking level to classify the flow of packets based on the Traffic Shaping policy. | Optional |
| primary_gateway | The primary gateway. Applicable only in case of multiple gateways. | Optional |
| backup_gateway | The backup gateway. Applicable only in case of multiple gateways. | Optional |
| application_control | The Application Filter policy for the rule. Default is “Allow All”. | Optional |
| application_based_qos_policy | Whether to limit the bandwidth for the applications categorized\ \ under the Application category. This tag is only applicable when\ \ an application_control is selected. Possible values: “Apply” and “Revoke”. Default is “Revoke”. | Optional |
| web_filter | The Web Filter policy for the rule. Default is “Allow All”. | Optional |
| web_category_base_qos_policy | Whether to limit the bandwidth for the URLs categorized under the Web\ \ category. This tag is only applicable when any web_filter is defined.” Possible values: “Apply” and “Revoke”. Default is “Revoke”. | Optional |
| traffic_shaping_policy | The Traffic Shaping policy for the rule. Default is “None”. | Optional |
| scan_http | Whether to enable virus and spam scanning for HTTP protocol. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| scan_https | Whether to enable virus and spam scanning for HTTPS protocol. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| sandstorm | Whether to enable sandstorm analysis. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| block_quick_quic | Whether to enable Google websites to use HTTP/s instead of QUICK QUIC. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| scan_ftp | Whether to enable scanning of FTP traffic. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| data_accounting | Whether to exclude a user’s network traffic from data accounting. This option is available only if the parameter “Match rule-based on user identity” is enabled. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| rewrite_source_address | Whether to enable the NAT policy. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
| web_filter_internet_scheme | Whether to enable the internet scheme to apply the user-based Web Filter policy for the rule. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| application_control_internet_scheme | Whether to enable the internet scheme to apply user-based Application Filter Policy for the rule. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| override_gateway_default_nat_policy | Whether to override the gateway of the default NAT policy. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| source_security_heartbeat | Whether to enable the source security heartbeat. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| destination_security_heartbeat | Whether to enable the destination security heartbeat. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| outbound_address | The NAT policy to be applied. Default is “MASQ”. | Optional |
| minimum_source_hb_permitted | The minimum source health status permitted. Default is “No Restriction”. | Optional |
| minimum_destination_hb_permitted | The minimum destination health status permitted. Default is “No Restriction”. | Optional |
| intrusion_prevention | The IPS policy for the rule. Default is “generalpolicy”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicy.Name | String | Name of the rule. |
| SophosFirewall.SecurityPolicy.Description | String | Description of the rule. |
| SophosFirewall.SecurityPolicy.Status | String | Status of the rule. |
| SophosFirewall.SecurityPolicy.PolicyType | String | Policy type of the rule. |
| SophosFirewall.SecurityPolicy.IPFamily | String | IP family of the security policy. Either IPv4 or IPv6. |
| SophosFirewall.SecurityPolicy.AttachIdentity | String | Rule attach identity status. |
| SophosFirewall.SecurityPolicy.Action | String | Current rule action. |
| SophosFirewall.SecurityPolicy.LogTraffic | Number | Rule traffic logging code. |
Command Example
!sophos-firewall-rule-add name=user_rule action=Accept ip_family=IPv4 log_traffic=Disable policy_type=User position=bottom match_identity=Enable show_captive_portal=Enable destination_zones=LAN members="Guest Group"
Context Example
{
"SophosFirewall": {
"SecurityPolicy": {
"Action": "Accept",
"After": {
"Name": "1"
},
"ApplicationBaseQoSPolicy": "Revoke",
"ApplicationControl": "Allow All",
"ApplicationControlInternetScheme": "Disable",
"BackupGateway": null,
"BlockQuickQuic": "Disable",
"DSCPMarking": null,
"DataAccounting": "Disable",
"Description": null,
"DestSecurityHeartbeat": "Disable",
"DestinationZones": {
"Zone": "LAN"
},
"IPFamily": "IPv4",
"Identity": {
"Member": "Guest Group"
},
"IntrusionPrevention": "generalpolicy",
"IsDeleted": false,
"LogTraffic": "Disable",
"MatchIdentity": "Enable",
"MinimumDestinationHBPermitted": "No Restriction",
"MinimumSourceHBPermitted": "No Restriction",
"Name": "user_rule",
"OutboundAddress": "MASQ",
"OverrideGatewayDefaultNATPolicy": "Disable",
"PolicyType": "User",
"Position": "After",
"PrimaryGateway": null,
"RewriteSourceAddress": "Enable",
"Sandstorm": "Disable",
"ScanFTP": "Disable",
"ScanHTTP": "Disable",
"ScanHTTPS": "Disable",
"Schedule": "All The Time",
"ShowCaptivePortal": "Enable",
"SourceSecurityHeartbeat": "Disable",
"Status": "Enable",
"TrafficShappingPolicy": "None",
"WebCategoryBaseQoSPolicy": "Revoke",
"WebFilter": "Allow All",
"WebFilterInternetScheme": "Disable"
}
}
}
Human Readable Output
SecurityPolicy Object details
Name Status PolicyType IPFamily Action LogTraffic user_rule Enable User IPv4 Accept Disable
sophos-firewall-rule-update
Updates an existing firewall rule.
Base Command
sophos-firewall-rule-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the new rule. | Required |
| description | Description of the new rule. | Optional |
| status | Whether the rule is enabled. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. Default is “IPv4”. | Optional |
| position | Whether the rule should be at the “top” or “bottom” of the list, or “before” or\ \ “after” a specific rule? IMPORTANT: If “before” or “after” is selected, provide the\ \ position_policy_name parameter. | Optional |
| position_policy_name | The name of the policy that the rule should be created before or after. REQUIRED: When the position is “before” or “after”. | Optional |
| policy_type | Type of the new rule (policy). Possible values: “User” and “Network”. | Optional |
| source_zones | Source zones to add to the rule. Possible values: “Any”, “LAN”. “WAN”, “VPN”, “DMZ”, “WiFi”. | Optional |
| source_networks | Source networks to add to the rule. | Optional |
| destination_zones | Destination zones to add to the rule. Possible values: “Any”, “LAN”. “WAN”, “VPN”, “DMZ”, “WiFi”. | Optional |
| destination_networks | Destination networks to add to the rule. | Optional |
| services | Destination services to add to the rule. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available in the web console. | Optional |
| log_traffic | Whether to enable traffic logging for the policy. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| match_identity | Whether to check if the specified user/user group from the\ \ selected zone is allowed to access the selected service. Possible values: “Enable” and “Disable”. Default is “Disable”. IMPORTANT: When enabling match_identity, the members argument is required. | Optional |
| show_captive_portal | Whether to accept traffic from unknown users. Captive portal page\ \ is displayed to the user where the user can login to access the Internet.\ \ Possible values: “Enable” and “Disable”. Default is “Disable”. IMPORTANT: MatchIdentity must be Enabled. PARAMETER OF: UserPolicy. | Optional |
| members | An existing user(s) or group(s) to add to the rule. REQUIRED when match_identity is enabled. | Optional |
| action | Action for the rule traffic. Possible values: “Accept”, “Reject”, and “Drop”. Default is “Drop”. | Optional |
| dscp_marking | The DSCP marking level to classify the flow of packets based on the Traffic Shaping policy. | Optional |
| primary_gateway | The primary gateway. Applicable only in case of multiple gateways. | Optional |
| backup_gateway | The backup gateway. Applicable only in case of multiple gateways. | Optional |
| application_control | The Application Filter policy for the rule. Default is “Allow All”. | Optional |
| application_based_qos_policy | Whether to limit the bandwidth for the applications categorized\ \ under the Application category. This tag is only applicable when\ \ an application_control is selected. Possible values: “Apply” and “Revoke”. Default is “Revoke”. | Optional |
| web_filter | The Web Filter policy for the rule. Default is “Allow All”. | Optional |
| web_category_base_qos_policy | Whether to limit the bandwidth for the URLs categorized under the Web\ \ category. This tag is only applicable when any web_filter is defined.” Possible values: “Apply” and “Revoke”. Default is “Revoke”. | Optional |
| traffic_shaping_policy | The Traffic Shaping policy for the rule. Default is “None”. | Optional |
| scan_http | Whether to enable virus and spam scanning for HTTP protocol. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| scan_https | Whether to enable virus and spam scanning for HTTPS protocol. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| sandstorm | Whether to enable sandstorm analysis. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| block_quick_quic | Whether to enable Google websites to use HTTP/s instead of QUICK QUIC. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| scan_ftp | Whether to enable scanning of FTP traffic. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| data_accounting | Whether to exclude a user’s network traffic from data accounting. This option is available only if the parameter “Match rule-based on user identity” is enabled. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| rewrite_source_address | Whether to enable the NAT policy. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
| web_filter_internet_scheme | Whether to enable the internet scheme to apply the user-based Web Filter policy for the rule. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| application_control_internet_scheme | Whether to enable the internet scheme to apply user-based Application Filter Policy for the rule. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| override_gateway_default_nat_policy | Whether to override the gateway of the default NAT policy. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| source_security_heartbeat | Whether to enable the source security heartbeat. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| destination_security_heartbeat | Whether to enable the destination security heartbeat. Possible values: “Enable” and “Disable”. Default is “Disable”. | Optional |
| outbound_address | The NAT policy to be applied. Default is “MASQ”. | Optional |
| minimum_source_hb_permitted | The minimum source health status permitted. Default is “No Restriction”. | Optional |
| minimum_destination_hb_permitted | The minimum destination health status permitted. Default is “No Restriction”. | Optional |
| intrusion_prevention | The IPS policy for the rule. Default is “generalpolicy”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicy.Name | String | Name of the rule. |
| SophosFirewall.SecurityPolicy.Description | String | Description of the rule. |
| SophosFirewall.SecurityPolicy.Status | String | Status of the rule. |
| SophosFirewall.SecurityPolicy.PolicyType | String | Policy type of the rule. |
| SophosFirewall.SecurityPolicy.IPFamily | String | IP family of the security policy. Either IPv4 or IPv6. |
| SophosFirewall.SecurityPolicy.AttachIdentity | String | Rule attach identity status. |
| SophosFirewall.SecurityPolicy.Action | String | Current rule action. |
| SophosFirewall.SecurityPolicy.LogTraffic | Number | Rule traffic logging code. |
Command Example
!sophos-firewall-rule-update name=user_rule log_traffic=Enable source_zones=LAN
Context Example
{
"SophosFirewall": {
"SecurityPolicy": {
"Action": "Drop",
"After": {
"Name": "1"
},
"Description": null,
"DestinationZones": {
"Zone": "LAN"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"LogTraffic": "Enable",
"MatchIdentity": "Disable",
"Name": "user_rule",
"PolicyType": "Network",
"Position": "After",
"Schedule": "All The Time",
"SourceZones": {
"Zone": "LAN"
},
"Status": "Enable"
}
}
}
Human Readable Output
SecurityPolicy Object details
Name Status PolicyType IPFamily Action LogTraffic user_rule Enable Network IPv4 Drop Enable
sophos-firewall-rule-delete
Deletes an existing firewall rule.
Base Command
sophos-firewall-rule-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the rule. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicy.Name | String | Name of the rule. |
| SophosFirewall.SecurityPolicy.IsDeleted | Bool | Whether the rule is deleted. |
Command Example
!sophos-firewall-rule-delete name=user_rule
Context Example
{
"SophosFirewall": {
"SecurityPolicy": {
"IsDeleted": true,
"Name": "user_rule"
}
}
}
Human Readable Output
Deleting SecurityPolicy Objects Results
Name IsDeleted user_rule true
sophos-firewall-rule-group-list
Lists all firewall rule groups. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-rule-group-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicyGroup.Name | String | Name of the group. |
| SophosFirewall.SecurityPolicyGroup.Description | String | Description of the group. |
| SophosFirewall.SecurityPolicyGroup.SecurityPolicyList.SecurityPolicy | String | Rules contained inside the group. |
| SophosFirewall.SecurityPolicyGroup.SourceZones.Zone | String | Source zone in the group. |
| SophosFirewall.SecurityPolicyGroup.DestinationZones.Zone | String | Destination zone in the group. |
| SophosFirewall.SecurityPolicyGroup.PolicyType | Number | Type of the rules in the group. |
Command Example
!sophos-firewall-rule-group-list start=0 end=6
Context Example
{
"SophosFirewall": {
"SecurityPolicyGroup": [
{
"Description": "Inbound traffic to DMZ. Firewall rules with the destination zone as DMZ would be added to this group on the first match basis if user selects automatic grouping option. This is the default group.",
"DestinationZones": {
"Zone": "DMZ"
},
"IsDeleted": false,
"Name": "Traffic to DMZ",
"Policytype": "Any",
"SecurityPolicyList": {
"SecurityPolicy": "[example] Traffic to DMZ"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "hi",
"Policytype": "Any"
},
{
"Description": null,
"IsDeleted": false,
"Name": "forunitest",
"Policytype": "Any"
},
{
"Description": "Outbound traffic to WAN. Firewall rules with the destination zone as WAN would be added to this group on the first match basis if user selects automatic grouping option. This is the default group.",
"DestinationZones": {
"Zone": "WAN"
},
"IsDeleted": false,
"Name": "Traffic to WAN",
"Policytype": "Any",
"SecurityPolicyList": {
"SecurityPolicy": "[example] Traffic to WAN"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "unitest",
"Policytype": "Any"
},
{
"Description": "For testing only",
"IsDeleted": false,
"Name": "unitest2",
"Policytype": "Any"
}
]
}
}
Human Readable Output
Showing 0 to 6 SecurityPolicyGroup objects out of 8
Name Description SecurityPolicyList DestinationZones Traffic to DMZ Inbound traffic to DMZ. Firewall rules with the destination zone as DMZ would be added to this group on the first match basis if user selects automatic grouping option. This is the default group. SecurityPolicy: [example] Traffic to DMZ Zone: DMZ hi forunitest Traffic to WAN Outbound traffic to WAN. Firewall rules with the destination zone as WAN would be added to this group on the first match basis if user selects automatic grouping option. This is the default group. SecurityPolicy: [example] Traffic to WAN Zone: WAN unitest unitest2 For testing only
sophos-firewall-rule-group-get
Gets a single firewall rule group by name.
Base Command
sophos-firewall-rule-group-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the firewall rule group. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicyGroup.Name | String | Name of the group. |
| SophosFirewall.SecurityPolicyGroup.Description | String | Description of the group. |
| SophosFirewall.SecurityPolicyGroup.SecurityPolicyList.SecurityPolicy | String | Rules contained inside the group. |
| SophosFirewall.SecurityPolicyGroup.SourceZones.Zone | String | Source zone in the group. |
| SophosFirewall.SecurityPolicyGroup.DestinationZones.Zone | String | Destination zone in the group. |
| SophosFirewall.SecurityPolicyGroup.PolicyType | Number | Type of the rules in the group. |
Command Example
!sophos-firewall-rule-group-get name=rulegroup
Context Example
{
"SophosFirewall": {
"SecurityPolicyGroup": {
"Description": "rulegroup for user/network rules",
"IsDeleted": false,
"Name": "rulegroup",
"Policytype": "User/network rule",
"SecurityPolicyList": {
"SecurityPolicy": [
"network_rule",
"user_rule"
]
}
}
}
}
Human Readable Output
SecurityPolicyGroup Object details
Name Description SecurityPolicyList rulegroup rulegroup for user/network rules SecurityPolicy: network_rule,
user_rule
sophos-firewall-rule-group-add
Adds a new firewall rule group.
Base Command
sophos-firewall-rule-group-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the rule group. | Required |
| description | Description of the rule group. | Optional |
| policy_type | Type of the rules (policies) inside the group. Possible values: “Any”, “User/network rule”, “User rule”, “Business application rule”. | Optional |
| rules | Rules contained in the group. | Optional |
| source_zones | Source zones contained in the group. Possible values: “Any”, “LAN”, “WAN”, “VPN”, “DMZ”, “WiFi. | Optional |
| destination_zones | Destination zones contained in the group. Possible values: “Any”, “LAN”, “WAN”, “VPN”, “DMZ”, “WiFi. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicyGroup.Name | String | Name of the group. |
| SophosFirewall.SecurityPolicyGroup.Description | String | Description of the group. |
| SophosFirewall.SecurityPolicyGroup.SecurityPolicyList.SecurityPolicy | String | Rules contained in the group. |
| SophosFirewall.SecurityPolicyGroup.SourceZones.Zone | String | Source zone in the group. |
| SophosFirewall.SecurityPolicyGroup.DestinationZones.Zone | String | Destination zone in the group. |
| SophosFirewall.SecurityPolicyGroup.PolicyType | Number | Type of the rules in the group. |
Command Example
!sophos-firewall-rule-group-add name=rulegroup policy_type="User/network rule" rules=user_rule,network_rule
Context Example
{
"SophosFirewall": {
"SecurityPolicyGroup": {
"Description": null,
"IsDeleted": false,
"Name": "rulegroup",
"Policytype": "User/network rule",
"SecurityPolicyList": {
"SecurityPolicy": [
"user_rule",
"network_rule"
]
}
}
}
}
Human Readable Output
SecurityPolicyGroup Object details
Name SecurityPolicyList rulegroup SecurityPolicy: user_rule,
network_rule
sophos-firewall-rule-group-update
Updates an existing firewall rule group.
Base Command
sophos-firewall-rule-group-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the rule group. | Required |
| description | Description of the rule group. | Optional |
| policy_type | Type of the rules (policies) inside the group. Possible values: “Any”, “User/network rule”, “User rule”, “Business application rule”. | Optional |
| rules | Rules contained in the group. | Optional |
| source_zones | Source zones contained in the group. Possible values: “Any”, “LAN”, “WAN”, “VPN”, “DMZ”, “WiFi. | Optional |
| destination_zones | Destination zones contained in the group. Possible values: “Any”, “LAN”, “WAN”, “VPN”, “DMZ”, “WiFi. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicyGroup.Name | String | Name of the group. |
| SophosFirewall.SecurityPolicyGroup.Description | String | Description of the group. |
| SophosFirewall.SecurityPolicyGroup.SecurityPolicyList.SecurityPolicy | String | Rules contained in the group. |
| SophosFirewall.SecurityPolicyGroup.SourceZones.Zone | String | Source zone in the group. |
| SophosFirewall.SecurityPolicyGroup.DestinationZones.Zone | String | Destination zone in the group. |
| SophosFirewall.SecurityPolicyGroup.PolicyType | Number | Type of the rules in the group. |
Command Example
!sophos-firewall-rule-group-update name=rulegroup description="rulegroup for user/network rules"
Context Example
{
"SophosFirewall": {
"SecurityPolicyGroup": {
"Description": "rulegroup for user/network rules",
"IsDeleted": false,
"Name": "rulegroup",
"Policytype": "User/network rule",
"SecurityPolicyList": {
"SecurityPolicy": [
"network_rule",
"user_rule"
]
}
}
}
}
Human Readable Output
SecurityPolicyGroup Object details
Name Description SecurityPolicyList rulegroup rulegroup for user/network rules SecurityPolicy: network_rule,
user_rule
sophos-firewall-rule-group-delete
Deletes an existing firewall group.
Base Command
sophos-firewall-rule-group-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.SecurityPolicyGroup.Name | String | Name of the group. |
| SophosFirewall.SecurityPolicyGroup.IsDeleted | Bool | Whether the group is deleted. |
Command Example
!sophos-firewall-rule-group-delete name=rulegroup
Context Example
{
"SophosFirewall": {
"SecurityPolicyGroup": {
"IsDeleted": true,
"Name": "rulegroup"
}
}
}
Human Readable Output
Deleting SecurityPolicyGroup Objects Results
Name IsDeleted rulegroup true
sophos-firewall-url-group-list
Lists all URL groups. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-url-group-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterURLGroup.Name | String | Name of the URL group. |
| SophosFirewall.WebFilterURLGroup.Description | String | Description of the URL group. |
| SophosFirewall.WebFilterURLGroup.URLlist.URL | String | URL in the group. |
Command Example
!sophos-firewall-url-group-list start=0 end=6
Context Example
{
"SophosFirewall": {
"WebFilterURLGroup": [
{
"Description": "1desc",
"IsDeleted": false,
"Name": "1",
"URLlist": {
"URL": [
"www.x.com",
"www.y.com"
]
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "2",
"URLlist": {
"URL": "www.z.com"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "google",
"URLlist": {
"URL": "www.google.com"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "urlgroup1",
"URLlist": {
"URL": "www.blockthisurl.com"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "forunitest",
"URLlist": {
"URL": "badwebsite.com"
}
},
{
"Description": null,
"IsDeleted": false,
"Name": "forunitest2",
"URLlist": {
"URL": "badwebsite2.com"
}
}
]
}
}
Human Readable Output
Showing 0 to 6 WebFilterURLGroup objects out of 12
Name Description URLlist 1 1desc URL: www.x.com,
www.y.com2 URL: www.z.com URL: www.google.com urlgroup1 URL: www.blockthisurl.com forunitest URL: badwebsite.com forunitest2 URL: badwebsite2.com
sophos-firewall-url-group-get
Gets a single URL group by name.
Base Command
sophos-firewall-url-group-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterURLGroup.Name | String | Name of the URL group. |
| SophosFirewall.WebFilterURLGroup.Description | String | Description of the URL group. |
| SophosFirewall.WebFilterURLGroup.URLlist.URL | String | URL contained in the group. |
Command Example
!sophos-firewall-url-group-get name=urlgroup
Context Example
{
"SophosFirewall": {
"WebFilterURLGroup": {
"Description": null,
"IsDeleted": false,
"Name": "urlgroup",
"URLlist": {
"URL": [
"www.example.com",
"www.another-example.com"
]
}
}
}
}
Human Readable Output
WebFilterURLGroup Object details
Name URLlist urlgroup URL: www.example.com,
www.another-example.com
sophos-firewall-url-group-add
Adds a new URL group.
Base Command
sophos-firewall-url-group-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group. | Required |
| description | Description of the group. | Optional |
| urls | URLs to add to the group. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterURLGroup.Name | String | Name of the URL group. |
| SophosFirewall.WebFilterURLGroup.Description | String | Description of the URL group. |
| SophosFirewall.WebFilterURLGroup.URLlist.URL | String | URL contained in the group. |
Command Example
!sophos-firewall-url-group-add name=urlgroup urls=www.example.com
Context Example
{
"SophosFirewall": {
"WebFilterURLGroup": {
"Description": null,
"IsDeleted": false,
"Name": "urlgroup",
"URLlist": {
"URL": [
"www.example.com"
]
}
}
}
}
sophos-firewall-url-group-update
Updates an existing URL group.
Base Command
sophos-firewall-url-group-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group. | Required |
| description | Description of the group. | Optional |
| urls | URLs to add to the group. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterURLGroup.Name | String | Name of the URL group. |
| SophosFirewall.WebFilterURLGroup.Description | String | Description of the URL group. |
| SophosFirewall.WebFilterURLGroup.URLlist.URL | String | URL contained in the group. |
Command Example
!sophos-firewall-url-group-update name=urlgroup urls=www.another-example.com
Context Example
{
"SophosFirewall": {
"WebFilterURLGroup": {
"Description": null,
"IsDeleted": false,
"Name": "urlgroup",
"URLlist": {
"URL": [
"www.example.com",
"www.another-example.com"
]
}
}
}
}
Human Readable Output
WebFilterURLGroup Object details
Name URLlist urlgroup URL: www.example.com,
www.another-example.com
sophos-firewall-url-group-delete
Deletes an existing URL group or groups.
Base Command
sophos-firewall-url-group-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group(s). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterURLGroup.Name | String | Name of the URL group. |
| SophosFirewall.WebFilterURLGroup.IsDeleted | Bool | Whether the URL group is deleted. |
Command Example
!sophos-firewall-url-group-delete name=urlgroup
Context Example
{
"SophosFirewall": {
"WebFilterURLGroup": {
"IsDeleted": true,
"Name": "urlgroup"
}
}
}
Human Readable Output
Deleting WebFilterURLGroup Objects Results
Name IsDeleted urlgroup true
sophos-firewall-ip-host-list
Lists all IP hosts. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-ip-host-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHost.Name | String | Name of the IP host. |
| SophosFirewall.IPHost.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
| SophosFirewall.IPHost.HostType | String | Type of the host. |
Command Example
!sophos-firewall-ip-host-list start=0 end=6
Context Example
{
"SophosFirewall": {
"IPHost": [
{
"HostType": "System Host",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "##ALL_RW"
},
{
"HostType": "System Host",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "##ALL_IPSEC_RW"
},
{
"HostType": "System Host",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "##ALL_SSLVPN_RW"
},
{
"HostType": "System Host",
"IPFamily": "IPv6",
"IsDeleted": false,
"Name": "##ALL_RW6"
},
{
"HostType": "System Host",
"IPFamily": "IPv6",
"IsDeleted": false,
"Name": "##ALL_SSLVPN_RW6"
},
{
"HostType": "System Host",
"IPFamily": "IPv6",
"IsDeleted": false,
"Name": "##ALL_IPSEC_RW6"
}
]
}
}
Human Readable Output
Showing 0 to 6 IPHost objects out of 13
Name IPFamily HostType ##ALL_RW IPv4 System Host ##ALL_IPSEC_RW IPv4 System Host ##ALL_SSLVPN_RW IPv4 System Host ##ALL_RW6 IPv6 System Host ##ALL_SSLVPN_RW6 IPv6 System Host ##ALL_IPSEC_RW6 IPv6 System Host
sophos-firewall-ip-host-get
Gets a single IP host by name.
Base Command
sophos-firewall-ip-host-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHost.Name | String | Name of the IP host. |
| SophosFirewall.IPHost.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
| SophosFirewall.IPHost.HostType | String | Type of the host. |
Command Example
!sophos-firewall-ip-host-get name=iphost
Context Example
{
"SophosFirewall": {
"IPHost": {
"HostType": "IP",
"IPAddress": "2.2.2.2",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphost"
}
}
}
Human Readable Output
IPHost Object details
Name IPFamily HostType iphost IPv4 IP
sophos-firewall-ip-host-add
Adds a new IP host.
Base Command
sophos-firewall-ip-host-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host. | Required |
| host_type | Type of the host. Possible values: “IP”, “Network”, “IPRange”, “IPList”. | Required |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. Default is “IPv4”. | Optional |
| ip_address | IP address if IP or network was the chosen type. | Optional |
| subnet_mask | Subnet mask if network was the chosen type. | Optional |
| start_ip | Start of the IP range if IPRange was chosen. | Optional |
| end_ip | End of the IP range if IPRange was chosen. | Optional |
| ip_addresses | List of IP addresses if IPList was chosen. | Optional |
| host_group | Select the host group to which the host belongs. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHost.Name | String | Name of the IP host. |
| SophosFirewall.IPHost.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
| SophosFirewall.IPHost.HostType | String | Type of the host. |
Command Example
!sophos-firewall-ip-host-add name=iphost host_type=IP ip_address=1.1.1.1
Context Example
{
"SophosFirewall": {
"IPHost": {
"HostType": "IP",
"IPAddress": "1.1.1.1",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphost"
}
}
}
Human Readable Output
IPHost Object details
Name IPFamily HostType iphost IPv4 IP
sophos-firewall-ip-host-update
Updates an existing IP host.
Base Command
sophos-firewall-ip-host-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host. | Required |
| host_type | Type of the host. Possible values: “IP”, “Network”, “IPRange”, “IPList”. | Optional |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. Default is “IPv4”. | Optional |
| ip_address | IP address if IP or network was the chosen type. | Optional |
| subnet_mask | Subnet mask if network was the chosen type. | Optional |
| start_ip | Start of the IP range if IPRange was chosen. | Optional |
| end_ip | End of the IP range if IPRange was chosen. | Optional |
| ip_addresses | List of IP addresses if IPList was chosen. | Optional |
| host_group | Select the host group to which the host belongs. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHost.Name | String | Name of the IP host. |
| SophosFirewall.IPHost.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
| SophosFirewall.IPHost.HostType | String | Type of the host. |
Command Example
!sophos-firewall-ip-host-update name=iphost ip_address=2.2.2.2
Context Example
{
"SophosFirewall": {
"IPHost": {
"HostType": "IP",
"IPAddress": "2.2.2.2",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphost"
}
}
}
Human Readable Output
IPHost Object details
Name IPFamily HostType iphost IPv4 IP
sophos-firewall-ip-host-delete
Deletes an existing IP host.
Base Command
sophos-firewall-ip-host-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the host. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHost.Name | String | Name of the IP host. |
| SophosFirewall.IPHost.IsDeleted | Bool | Whether the IP host is deleted. |
Command Example
!sophos-firewall-ip-host-delete name=iphost
Context Example
{
"SophosFirewall": {
"IPHost": {
"IsDeleted": true,
"Name": "iphost"
}
}
}
Human Readable Output
Deleting IPHost Objects Results
Name IsDeleted iphost true
sophos-firewall-ip-host-group-list
Lists all IP host groups. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-ip-host-group-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHostGroup.Name | String | Name of the IP host group. |
| SophosFirewall.IPHostGroup.description | String | Description of the IP host group. |
| SophosFirewall.IPHostGroup.HostList.Host | String | Host contained in the host group. |
| SophosFirewall.IPHostGroup.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
Command Example
!sophos-firewall-ip-host-group-list start=0 end=6
Context Example
{
"SophosFirewall": {
"IPHostGroup": [
{
"Description": null,
"HostList": {
"Host": [
"1.2.3.4",
"8.8.8.8"
]
},
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "Blocked by Playbook"
},
{
"Description": "FOR TESTING",
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "unitest2"
},
{
"Description": null,
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "Noam-Test"
}
]
}
}
Human Readable Output
Showing 0 to 3 IPHostGroup objects out of 3
Name Description IPFamily HostList Blocked by Playbook IPv4 Host: 1.2.3.4,
8.8.8.8unitest2 FOR TESTING IPv4 Noam-Test IPv4
sophos-firewall-ip-host-group-get
Gets a single IP host group by name.
Base Command
sophos-firewall-ip-host-group-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host group. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHostGroup.Name | String | Name of the IP host group. |
| SophosFirewall.IPHostGroup.description | String | Description of the IP host group. |
| SophosFirewall.IPHostGroup.HostList.Host | String | Host contained inside the host group. |
| SophosFirewall.IPHostGroup.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
Command Example
!sophos-firewall-ip-host-group-get name=iphostgroup
Context Example
{
"SophosFirewall": {
"IPHostGroup": {
"Description": null,
"HostList": {
"Host": "iphost"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphostgroup"
}
}
}
Human Readable Output
IPHostGroup Object details
Name IPFamily HostList iphostgroup IPv4 Host: iphost
sophos-firewall-ip-host-group-add
Adds a new IP host group.
Base Command
sophos-firewall-ip-host-group-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host group. | Required |
| description | Description of the IP host group. | Optional |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. | Optional |
| hosts | IP hosts contained in the group. Must be hosts already existing in the system. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHostGroup.Name | String | Name of the IP host group. |
| SophosFirewall.IPHostGroup.description | String | Description of the IP host group. |
| SophosFirewall.IPHostGroup.HostList.Host | String | Host contained in the host group. |
| SophosFirewall.IPHostGroup.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
Command Example
!sophos-firewall-ip-host-group-add name=iphostgroup
Context Example
{
"SophosFirewall": {
"IPHostGroup": {
"Description": null,
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphostgroup"
}
}
}
Human Readable Output
IPHostGroup Object details
Name IPFamily iphostgroup IPv4
sophos-firewall-ip-host-group-update
Updates an existing IP host group.
Base Command
sophos-firewall-ip-host-group-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the IP host group. | Required |
| description | Description of the IP host group. | Optional |
| ip_family | The IP family. Possible values: “IPv4” and “IPv6”. | Optional |
| hosts | IP hosts contained in the group. Must be hosts already existing in the system. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHostGroup.Name | String | Name of the IP host group. |
| SophosFirewall.IPHostGroup.description | String | Description of the IP host group. |
| SophosFirewall.IPHostGroup.HostList.Host | String | Host contained inside the host group. |
| SophosFirewall.IPHostGroup.IPFamily | String | IP family of the host group. Either IPv4 or IPv6. |
Command Example
!sophos-firewall-ip-host-group-update name=iphostgroup hosts=iphost
Context Example
{
"SophosFirewall": {
"IPHostGroup": {
"Description": null,
"HostList": {
"Host": "iphost"
},
"IPFamily": "IPv4",
"IsDeleted": false,
"Name": "iphostgroup"
}
}
}
Human Readable Output
IPHostGroup Object details
Name IPFamily HostList iphostgroup IPv4 Host: iphost
sophos-firewall-ip-host-group-delete
Deletes an existing IP host group.
Base Command
sophos-firewall-ip-host-group-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the group. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.IPHostGroup.Name | String | Name of the IP host group. |
| SophosFirewall.IPHostGroup.IsDeleted | Bool | Whether the IP host group is deleted. |
Command Example
!sophos-firewall-ip-host-group-delete name=iphostgroup
Context Example
{
"SophosFirewall": {
"IPHostGroup": {
"IsDeleted": true,
"Name": "iphostgroup"
}
}
}
Human Readable Output
Deleting IPHostGroup Objects Results
Name IsDeleted iphostgroup true
sophos-firewall-services-list
Lists all firewall services. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-services-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.Services.Name | String | Name of the firewall service. |
| SophosFirewall.Services.Type | String | Type of the firewall service. |
| SophosFirewall.Services.ServiceDetails.ServiceDetail | String | Details about the service. |
Command Example
!sophos-firewall-services-list start=0 end=6
Context Example
{
"SophosFirewall": {
"Services": [
{
"IsDeleted": false,
"Name": "AH",
"ServiceDetails": {
"ServiceDetail": {
"ProtocolName": "AH"
}
},
"Type": "IP"
},
{
"IsDeleted": false,
"Name": "AOL",
"ServiceDetails": {
"ServiceDetail": {
"DestinationPort": "5190:5194",
"Protocol": "TCP",
"SourcePort": "1:65535"
}
},
"Type": "TCPorUDP"
},
{
"IsDeleted": false,
"Name": "BGP",
"ServiceDetails": {
"ServiceDetail": {
"DestinationPort": "179",
"Protocol": "TCP",
"SourcePort": "1:65535"
}
},
"Type": "TCPorUDP"
},
{
"IsDeleted": false,
"Name": "DHCP",
"ServiceDetails": {
"ServiceDetail": {
"DestinationPort": "67:68",
"Protocol": "UDP",
"SourcePort": "67:68"
}
},
"Type": "TCPorUDP"
},
{
"IsDeleted": false,
"Name": "DNS",
"ServiceDetails": {
"ServiceDetail": [
{
"DestinationPort": "53",
"Protocol": "TCP",
"SourcePort": "1:65535"
},
{
"DestinationPort": "53",
"Protocol": "UDP",
"SourcePort": "1:65535"
}
]
},
"Type": "TCPorUDP"
},
{
"IsDeleted": false,
"Name": "ESP",
"ServiceDetails": {
"ServiceDetail": {
"ProtocolName": "ESP"
}
},
"Type": "IP"
}
]
}
}
Human Readable Output
Showing 0 to 6 Services objects out of 63
Name Type ServiceDetails AH IP ServiceDetail: {“ProtocolName”: “AH”} AOL TCPorUDP ServiceDetail: {“SourcePort”: “1:65535”, “DestinationPort”: “5190:5194”, “Protocol”: “TCP”} BGP TCPorUDP ServiceDetail: {“SourcePort”: “1:65535”, “DestinationPort”: “179”, “Protocol”: “TCP”} DHCP TCPorUDP ServiceDetail: {“SourcePort”: “67:68”, “DestinationPort”: “67:68”, “Protocol”: “UDP”} DNS TCPorUDP ServiceDetail: {‘SourcePort’: ‘1:65535’, ‘DestinationPort’: ‘53’, ‘Protocol’: ‘TCP’},
{‘SourcePort’: ‘1:65535’, ‘DestinationPort’: ‘53’, ‘Protocol’: ‘UDP’}ESP IP ServiceDetail: {“ProtocolName”: “ESP”}
sophos-firewall-services-get
Gets a single service by name.
Base Command
sophos-firewall-services-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the firewall service. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.Services.Name | String | Name of the firewall service. |
| SophosFirewall.Services.Type | String | Type of the firewall service. |
| SophosFirewall.Services.ServiceDetails.ServiceDetail | String | Details about the service. |
Command Example
!sophos-firewall-services-get name=service
Context Example
{
"SophosFirewall": {
"Services": {
"IsDeleted": false,
"Name": "service",
"ServiceDetails": {
"ServiceDetail": [
{
"ProtocolName": "Compaq-Peer"
},
{
"ProtocolName": "AH"
}
]
},
"Type": "IP"
}
}
}
Human Readable Output
Services Object details
Name Type ServiceDetails service IP ServiceDetail: {‘ProtocolName’: ‘Compaq-Peer’},
{‘ProtocolName’: ‘AH’}
sophos-firewall-services-add
Adds a new firewall service.
Base Command
sophos-firewall-services-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the firewall service. | Required |
| service_type | Type of service. Possible values: “TCPorUDP”, “IP”, “ICMP”, “ICMPv6”. | Required |
| protocol | The protocol for the service if service_type is TCPorUDP. Possible values: “TCP” and “UDP”. | Optional |
| source_port | Source port if service_type is TCPorUDP. | Optional |
| destination_port | Destination port if service_type is TCPorUDP. | Optional |
| protocol_name | Protocol name if service_type is IP. | Optional |
| icmp_type | ICMP type if service_type is ICMP. | Optional |
| icmp_code | ICMP code if service_type is ICMP. | Optional |
| icmp_v6_type | ICMPv6 type if service_type is ICMPv6. | Optional |
| icmp_v6_code | ICMPv6 code if service_type is ICMPv6. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.Services.Name | String | Name of the firewall service. |
| SophosFirewall.Services.Type | String | Type of the firewall service. |
| SophosFirewall.Services.ServiceDetails.ServiceDetail | String | Details about the service. |
Command Example
!sophos-firewall-services-add name=service service_type=IP protocol_name="Compaq-Peer"
Context Example
{
"SophosFirewall": {
"Services": {
"IsDeleted": false,
"Name": "service",
"ServiceDetails": {
"ServiceDetail": {
"ProtocolName": "Compaq-Peer"
}
},
"Type": "IP"
}
}
}
Human Readable Output
Services Object details
Name Type ServiceDetails service IP ServiceDetail: {“ProtocolName”: “Compaq-Peer”}
sophos-firewall-services-update
Updates an existing firewall service.
Base Command
sophos-firewall-services-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the firewall service. | Required |
| service_type | Type of service. Possible values: “TCPorUDP”, “IP”, “ICMP”, “ICMPv6”. | Optional |
| protocol | The protocol for the service if service_type is TCPorUDP. Possible values: “TCP” and “UDP”. | Optional |
| source_port | Source port if service_type is TCPorUDP. | Optional |
| destination_port | Destination port if service_type is TCPorUDP. | Optional |
| protocol_name | Protocol name if service_type is IP. | Optional |
| icmp_type | ICMP type if service_type is ICMP. | Optional |
| icmp_code | ICMP code if service_type is ICMP. | Optional |
| icmp_v6_type | ICMPv6 type if service_type is ICMPv6. | Optional |
| icmp_v6_code | ICMPv6 code if service_type is ICMPv6. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.Services.Name | String | Name of the firewall service. |
| SophosFirewall.Services.Type | String | Type of the firewall service. |
| SophosFirewall.Services.ServiceDetails.ServiceDetail | String | Details about the service. |
Command Example
!sophos-firewall-services-update name=service service_type=IP protocol_name=AH
Context Example
{
"SophosFirewall": {
"Services": {
"IsDeleted": false,
"Name": "service",
"ServiceDetails": {
"ServiceDetail": [
{
"ProtocolName": "Compaq-Peer"
},
{
"ProtocolName": "AH"
}
]
},
"Type": "IP"
}
}
}
Human Readable Output
Services Object details
Name Type ServiceDetails service IP ServiceDetail: {‘ProtocolName’: ‘Compaq-Peer’},
{‘ProtocolName’: ‘AH’}
sophos-firewall-services-delete
Deletes an existing firewall service.
Base Command
sophos-firewall-services-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the service. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.Services.Name | String | Name of the firewall service. |
| SophosFirewall.Services.IsDeleted | Bool | Whether the firewall service is deleted. |
Command Example
!sophos-firewall-services-delete name=service
Context Example
{
"SophosFirewall": {
"Services": {
"IsDeleted": true,
"Name": "service"
}
}
}
Human Readable Output
Deleting Services Objects Results
Name IsDeleted service true
sophos-firewall-user-list
Lists all users. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-user-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.User.Name | String | Name of the user. |
| SophosFirewall.User.Username | String | Username of the user. |
| SophosFirewall.User.Description | String | Description of the user. |
| SophosFirewall.User.EmailList.EmailID | String | Email of the user. |
| SophosFirewall.User.Group | String | Group of the user. |
| SophosFirewall.User.UserType | String | User type of the user. |
| SophosFirewall.User.Status | String | Status of the user. |
Command Example
!sophos-firewall-user-list start=0 end=6
Context Example
{
"SophosFirewall": {
"User": [
{
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": null,
"EmailList": {
"EmailID": "test@test.com"
},
"Group": "Open Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "Disable",
"Name": "user_new",
"PPTP": "Disable",
"Password": {
"#text": "0488F379742662C337D2FB1BDD1F08D9",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "Disable",
"SSLVPNPolicy": "sg",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "user new"
},
{
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": "new desc",
"EmailList": {
"EmailID": "test@test.com"
},
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "sg",
"PPTP": "Disable",
"Password": {
"#text": "ECA5ABF3D68822A1C3C9193F8AAE1522",
"@passwordform": "encrypt"
},
"Profile": "Administrator",
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "0",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "sg1"
},
{
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": "1",
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "1",
"PPTP": "Disable",
"Password": {
"#text": "A8DFE8F6454F585D404E04435416C95E",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "0",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "1"
},
{
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": null,
"EmailList": {
"EmailID": "test@test.test"
},
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "unitest2",
"PPTP": "Disable",
"Password": {
"#text": "F5A7EFCF49F10328D7198A1968618B38",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "Disable",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "unitestuser"
},
{
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": null,
"EmailList": {
"EmailID": "test@test.test"
},
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "unitest3",
"PPTP": "Disable",
"Password": {
"#text": "F5A7EFCF49F10328D7198A1968618B38",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "Disable",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "unitestuser2"
}
]
}
}
Human Readable Output
Showing 0 to 6 User objects out of 8
Username Name Description EmailList Group UserType Status user new user_new EmailID: test@test.com Open Group User Active sg sg This is sg desc EmailID: test@test.com Guest Group Administrator Active 1 1 1 Guest Group User Active sg1 sg new desc Guest Group User Active unitestuser unitest2 EmailID: test@test.test Guest Group User Active unitestuser2 unitest3 EmailID: test@test.test Guest Group User Active
sophos-firewall-user-get
Gets a single user by name.
Base Command
sophos-firewall-user-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the user. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.User.Name | String | Name of the user. |
| SophosFirewall.User.Username | String | Username of the user. |
| SophosFirewall.User.Description | String | Description of the user. |
| SophosFirewall.User.EmailList.EmailID | String | Email of the user. |
| SophosFirewall.User.Group | String | Group of the user. |
| SophosFirewall.User.UserType | String | User type of the user. |
| SophosFirewall.User.Status | String | Status of the user. |
Command Example
!sophos-firewall-user-get name=user
Context Example
{
"SophosFirewall": {
"User": {
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": "Description for the user",
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "user",
"PPTP": "Disable",
"Password": {
"#text": "A8DFE8F6454F585D404E04435416C95E",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "0",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "user"
}
}
}
Human Readable Output
User Object details
Username Name Description Group UserType Status user user Description for the user Guest Group User Active
sophos-firewall-user-add
Adds a new user.
Base Command
sophos-firewall-user-add
Input
| Argument Name | Description | Required |
|---|---|---|
| username | Username of the user. | Required |
| name | Name of the user. | Required |
| description | Description of the user. | Optional |
| Email of the user. | Required | |
| group | Group of the user. Default is “Guest Group”. | Optional |
| password | The password of the user. | Required |
| user_type | The type of the user. Possible values: “Administrator” and “User”. Default is “User”. | Optional |
| profile | Profile of the administrator if user_type is Administrator. Possible values: “Administrator”, “Crypto Admin”, “Security Admin”, “Audit Admin”, “HAProfile”. IMPORTANT: You can add more types in the web console. | Optional |
| surfing_quota_policy | The Surfing Quota policy. Default is “Unlimited Internet Access”. | Optional |
| access_time_policy | The Access Time policy. Default is “Allowed all the time”. | Optional |
| ssl_vpn_policy | The SSL VPN policy. Default is “No Policy Applied”. | Optional |
| clientless_policy | The clientless policy. Default is “No Policy Applied”. | Optional |
| data_transfer_policy | The Data Transfer policy. Default is: “100 MB Total Data Transfer policy”. | Optional |
| simultaneous_logins_global | Whether to enable simultaneous logins global. Possible values: “Enable” and “Disable”. Default is “Eanble”. | Optional |
| schedule_for_appliance_access | The schedule for appliance access. Default is “All The Time”. IMPORTANT: This option\ \ is available only for Administrators. | Optional |
| qos_policy | The QoS policy. Default is “High Guarantee User”. | Optional |
| login_restriction | The login restriction option. Possible values: “AnyNode” and “UserGroupNode”. Default is “UserGroupNode”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.User.Name | String | Name of the user. |
| SophosFirewall.User.Username | String | Username of the user. |
| SophosFirewall.User.Description | String | Description of the user. |
| SophosFirewall.User.EmailList.EmailID | String | Email of the user. |
| SophosFirewall.User.Group | String | Group of the user. |
| SophosFirewall.User.UserType | String | User type of the user. |
| SophosFirewall.User.Status | String | Status of the user. |
Command Example
!sophos-firewall-user-add name=user username=user password=1234 email=user@mail.com
Context Example
{
"SophosFirewall": {
"User": {
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": null,
"EmailList": {
"EmailID": "user@mail.com"
},
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "user",
"PPTP": "Disable",
"Password": {
"#text": "A8DFE8F6454F585D404E04435416C95E",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "Disable",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "user"
}
}
}
Human Readable Output
User Object details
Username Name EmailList Group UserType Status user user EmailID: user@mail.com Guest Group User Active
sophos-firewall-user-update
Updates a user.
Base Command
sophos-firewall-user-update
Input
| Argument Name | Description | Required |
|---|---|---|
| username | Username of the user. | Required |
| name | Name of the user. | Required |
| description | Description of the user. | Optional |
| Email of the user. | Optional | |
| group | Group of the user. Default is “Guest Group”. | Optional |
| password | The password of the user. | Optional |
| user_type | The type of the user. Possible values: “Administrator” and “User”. Default is “User”. | Optional |
| profile | Profile of the administrator if user_type is Administrator. Possible values: “Administrator”, “Crypto Admin”, “Security Admin”, “Audit Admin”, “HAProfile”. IMPORTANT: You can add more types in the web console. | Optional |
| surfing_quota_policy | The Surfing Quota policy. Default is “Unlimited Internet Access”. | Optional |
| access_time_policy | The Access Time policy. Default is “Allowed all the time”. | Optional |
| ssl_vpn_policy | The SSL VPN policy. Default is “No Policy Applied”. | Optional |
| clientless_policy | The clientless policy. Default is “No Policy Applied”. | Optional |
| data_transfer_policy | The Data Transfer policy. Default is: “100 MB Total Data Transfer policy”. | Optional |
| simultaneous_logins_global | Whether to enable simultaneous logins global. Possible values: “Enable” and “Disable”. Default is “Eanble”. | Optional |
| schedule_for_appliance_access | The schedule for appliance access. Default is “All The Time”.IMPORTANT: This option\ \ is available only for Administrators. | Optional |
| qos_policy | The QoS policy. Default is “High Guarantee User”. | Optional |
| login_restriction | The login restriction option. Possible values: “AnyNode” and “UserGroupNode”. Default is “UserGroupNode”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.User.Name | String | Name of the user. |
| SophosFirewall.User.Username | String | Username of the user. |
| SophosFirewall.User.Description | String | Description of the user. |
| SophosFirewall.User.EmailList.EmailID | String | Email of the user. |
| SophosFirewall.User.Group | String | Group of the user. |
| SophosFirewall.User.UserType | String | User type of the user. |
| SophosFirewall.User.Status | String | Status of the user. |
Command Example
!sophos-firewall-user-update name=user username=user description="Description for the user"
Context Example
{
"SophosFirewall": {
"User": {
"AccessTimePolicy": "Allowed all the time",
"CISCO": "Disable",
"ClientlessPolicy": "No Policy Applied",
"DataTransferPolicy": "100 MB Total Data Transfer policy",
"Description": "Description for the user",
"Group": "Guest Group",
"IsDeleted": false,
"IsEncryptCert": "Disable",
"L2TP": "Disable",
"LoginRestriction": "UserGroupNode",
"LoginRestrictionForAppliance": null,
"MACBinding": "0",
"Name": "user",
"PPTP": "Disable",
"Password": {
"#text": "A8DFE8F6454F585D404E04435416C95E",
"@passwordform": "encrypt"
},
"QoSPolicy": "High Guarantee User",
"QuarantineDigest": "0",
"SSLVPNPolicy": "No Policy Applied",
"ScheduleForApplianceAccess": "All The Time",
"SimultaneousLoginsGlobal": "Enable",
"Status": "Active",
"SurfingQuotaPolicy": "Unlimited Internet Access",
"UserType": "User",
"Username": "user"
}
}
}
Human Readable Output
User Object details
Username Name Description Group UserType Status user user Description for the user Guest Group User Active
sophos-firewall-user-delete
Deletes an existing user.
Base Command
sophos-firewall-user-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the user. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.User.Name | String | Name of the user. |
| SophosFirewall.User.IsDeleted | Bool | Whether the user is deleted. |
Command Example
!sophos-firewall-user-delete name=user
Context Example
{
"SophosFirewall": {
"User": {
"IsDeleted": true,
"Name": "user"
}
}
}
Human Readable Output
Deleting User Objects Results
Name IsDeleted user true
sophos-firewall-app-policy-list
Lists all app policies. IMPORTANT: Listing starst at 0 (not 1)!
Base Command
sophos-firewall-app-policy-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterPolicy.Name | String | Name of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.Description | String | Description of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.MicroAppSupport | String | Whether the policy support microapps. |
| SophosFirewall.ApplicationFilterPolicy.DefaultAction | String | Default action the policy executes. |
| SophosFirewall.ApplicationFilterPolicy.RuleList.Rule | String | Details of the rule. |
Command Example
!sophos-firewall-app-policy-list start=0 end=6
Context Example
{
"SophosFirewall": {
"ApplicationFilterPolicy": [
{
"DefaultAction": "Allow",
"Description": "Allow All Policy.",
"IsDeleted": false,
"MicroAppSupport": "True",
"Name": "Allow All"
},
{
"DefaultAction": "Allow",
"Description": "Drops traffic from applications that tunnels other apps, proxy and tunnel apps, and from apps that can bypass firewall policy. These applications allow users to anonymously browse Internet by connecting to servers on the Internet via encrypted SSL tunnels. This, in turn, enables users to bypass network security measures.",
"IsDeleted": false,
"MicroAppSupport": "True",
"Name": "Block filter avoidance apps",
"RuleList": {
"Rule": [
{
"Action": "Deny",
"ApplicationList": {
"Application": [
"test"
]
},
"CategoryList": {
"Category": "Proxy and Tunnel"
},
"Schedule": "All The Time",
"SelectAllRule": "Enable",
"SmartFilter": null
},
{
"Action": "Deny",
"ApplicationList": {
"Application": [
"test"
]
},
"CharacteristicsList": {
"Characteristics": "Can bypass firewall policy"
},
"Schedule": "All The Time",
"SelectAllRule": "Enable",
"SmartFilter": null
},
{
"Action": "Deny",
"ApplicationList": {
"Application": [
"test"
]
},
"CharacteristicsList": {
"Characteristics": "Tunnels other apps"
},
"Schedule": "All The Time",
"SelectAllRule": "Enable",
"SmartFilter": null
}
]
}
}
]
}
}
Human Readable Output
Showing 0 to 6 ApplicationFilterPolicy objects out of 12
Name Description MicroAppSupport DefaultAction RuleList Allow All Allow All Policy. True Allow Block filter avoidance apps Drops traffic from applications that tunnels other apps, proxy and tunnel apps, and from apps that can bypass firewall policy. These applications allow users to anonymously browse Internet by connecting to servers on the Internet via encrypted SSL tunnels. This, in turn, enables users to bypass network security measures. True Allow Rule: {‘SelectAllRule’: ‘Enable’, ‘CategoryList’: {‘Category’: ‘Proxy and Tunnel’}, ‘SmartFilter’: None, ‘ApplicationList’: {‘Application’: ‘test’}, ‘Action’: ‘Deny’, ‘Schedule’: ‘All The Time’} Block generally unwanted apps Drops generally unwanted applications traffic. This includes file transfer apps, proxy & tunnel apps, risk prone apps, peer to peer networking (P2P) apps and apps that causes loss of productivity. True Allow Rule: {‘SelectAllRule’: ‘Enable’, ‘CategoryList’: {‘Category’: ‘P2P’}, ‘SmartFilter’: None, ‘ApplicationList’: {‘Application’: [‘test’]}, ‘Action’: ‘Deny’, ‘Schedule’: ‘All The Time’} Block high risk (Risk Level 4 and 5) apps Drops traffic that are classified under high risk apps (Risk Level- 4 and 5). True Allow Rule: {‘SelectAllRule’: ‘Enable’, ‘RiskList’: {‘Risk’: ‘High’}, ‘SmartFilter’: None, ‘ApplicationList’: {‘Application’: [‘test’]}, ‘Action’: ‘Deny’, ‘Schedule’: ‘All The Time’} Block peer to peer (P2P) networking apps Drops traffic from applications that are categorized as P2P apps. P2P could be a mechanism for distributing Bots, Spywares, Adware, Trojans, Rootkits, Worms and other types of malwares. It is generally advised to have P2P application blocked in your network. True Allow Rule: {“SelectAllRule”: “Enable”, “CategoryList”: {“Category”: “P2P”}, “SmartFilter”: null, “ApplicationList”: {“Application”: [“test”]}, “Action”: “Deny”, “Schedule”: “All The Time”} Block very high risk (Risk Level 5) apps Drops traffic that are classified under very high risk apps (Risk Level- 5). True Allow Rule: {“SelectAllRule”: “Enable”, “RiskList”: {“Risk”: “Very High”}, “SmartFilter”: null, “ApplicationList”: {“Application”: [“test]}, “Action”: “Deny”, “Schedule”: “All The Time”}
sophos-firewall-app-policy-get
Gets a single app policy by name.
Base Command
sophos-firewall-app-policy-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterPolicy.Name | String | Name of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.Description | String | Description of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.MicroAppSupport | String | Does the policy support microapps. |
| SophosFirewall.ApplicationFilterPolicy.DefaultAction | String | Default action the policy executes. |
| SophosFirewall.ApplicationFilterPolicy.RuleList.Rule | String | Details of the rule. |
Command Example
!sophos-firewall-app-policy-get name=apppolicy
Context Example
{
"SophosFirewall": {
"ApplicationFilterPolicy": {
"DefaultAction": "Allow",
"Description": "Description for app policy object",
"IsDeleted": false,
"MicroAppSupport": "True",
"Name": "apppolicy"
}
}
}
Human Readable Output
ApplicationFilterPolicy Object details
Name Description MicroAppSupport DefaultAction apppolicy Description for app policy object True Allow
sophos-firewall-app-policy-add
Adds a new app policy.
Base Command
sophos-firewall-app-policy-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
| description | Description of the policy. | Optional |
| micro_app_support | Whether microapp support is enabled. Possible values: “true” and “false”. | Optional |
| default_action | Default action for the policy. Possible values: “Allow” and “Deny”. | Optional |
| select_all | Whether to enable the select all rule. Possible values: “Enable” and “Disable”. | Optional |
| categories | Categories to add to the rule. | Optional |
| risks | Risks to add to the rule. | Optional |
| applications | Applications to add to the rule. | Optional |
| characteristics | Characteristics to add to the rule. | Optional |
| technologies | Technologies to add to the rule. | Optional |
| classifications | Classifications to add to the rule. | Optional |
| action | Action for the rule. Possible values: “Allow” and “Deny”. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available in the web console. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterPolicy.Name | String | Name of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.Description | String | Description of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.MicroAppSupport | String | Whether the policy supports microapps. |
| SophosFirewall.ApplicationFilterPolicy.DefaultAction | String | Default action the policy executes. |
| SophosFirewall.ApplicationFilterPolicy.RuleList.Rule | String | Details of the rule. |
Command Example
!sophos-firewall-app-policy-add name=apppolicy
Context Example
{
"SophosFirewall": {
"ApplicationFilterPolicy": {
"DefaultAction": "Allow",
"Description": null,
"IsDeleted": false,
"MicroAppSupport": "True",
"Name": "apppolicy"
}
}
}
Human Readable Output
ApplicationFilterPolicy Object details
Name MicroAppSupport DefaultAction apppolicy True Allow
sophos-firewall-app-policy-update
Updates an existing app policy.
Base Command
sophos-firewall-app-policy-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
| description | Description of the policy. | Optional |
| micro_app_support | Whether microapp support is enabled. Possible values: “true” and “false”. | Optional |
| default_action | Default action for the policy. Possible values: “Allow” and “Deny”. | Optional |
| select_all | Whether to enable the select all rule. Possible values: “Enable” and “Disable”. | Optional |
| categories | Categories to add to the rule. | Optional |
| risks | Risks to add to the rule. | Optional |
| applications | Applications to add to the rule. | Optional |
| characteristics | Characteristics to add to the rule. | Optional |
| technologies | Technologies to add to the rule. | Optional |
| classifications | Classifications to add to the rule. | Optional |
| action | Action for the rule. Possible values: “Allow” and “Deny”. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available in the web console. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterPolicy.Name | String | Name of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.Description | String | Description of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.MicroAppSupport | String | Whether the policy supports microapps. |
| SophosFirewall.ApplicationFilterPolicy.DefaultAction | String | Default action the policy executes. |
| SophosFirewall.ApplicationFilterPolicy.RuleList.Rule | String | Details of the rule. |
Command Example
!sophos-firewall-app-policy-update name=apppolicy description="Description for app policy object"
Context Example
{
"SophosFirewall": {
"ApplicationFilterPolicy": {
"DefaultAction": "Allow",
"Description": "Description for app policy object",
"IsDeleted": false,
"MicroAppSupport": "True",
"Name": "apppolicy"
}
}
}
Human Readable Output
ApplicationFilterPolicy Object details
Name Description MicroAppSupport DefaultAction apppolicy Description for app policy object True Allow
sophos-firewall-app-policy-delete
Deletes an existing app policy.
Base Command
sophos-firewall-app-policy-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterPolicy.Name | String | Name of the firewall app policy. |
| SophosFirewall.ApplicationFilterPolicy.IsDeleted | Bool | Whether the firewall app policy is deleted. |
Command Example
!sophos-firewall-app-policy-delete name=apppolicy
Context Example
{
"SophosFirewall": {
"ApplicationFilterPolicy": {
"IsDeleted": true,
"Name": "apppolicy"
}
}
}
Human Readable Output
Deleting ApplicationFilterPolicy Objects Results
Name IsDeleted apppolicy true
sophos-firewall-app-category-list
Lists all app filter categories. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-app-category-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterCategory.Name | String | Name of the app category. |
| SophosFirewall.ApplicationFilterCategory.Description | String | Description of the app category. |
| SophosFirewall.ApplicationFilterCategory.QoSPolicy | String | QoS policy of the category. |
| SophosFirewall.ApplicationFilterCategory.BandwidthUsageType | String | Bandwidth usage type of the category. |
Command Example
!sophos-firewall-app-category-list start=0 end=6
Context Example
{
"SophosFirewall": {
"ApplicationFilterCategory": [
{
"BandwidthUsageType": null,
"Description": "Conferencing",
"IsDeleted": false,
"Name": "Conferencing",
"QoSPolicy": "None"
},
{
"BandwidthUsageType": null,
"Description": "Desktop Mail",
"IsDeleted": false,
"Name": "Desktop Mail",
"QoSPolicy": "None"
},
{
"BandwidthUsageType": null,
"Description": "Database Applications",
"IsDeleted": false,
"Name": "Download Applications",
"QoSPolicy": "None"
},
{
"BandwidthUsageType": null,
"Description": "E-commerce",
"IsDeleted": false,
"Name": "E-commerce",
"QoSPolicy": "None"
},
{
"BandwidthUsageType": null,
"Description": "File Transfer",
"IsDeleted": false,
"Name": "File Transfer",
"QoSPolicy": "None"
},
{
"BandwidthUsageType": "Individual",
"Description": "Gaming Sites and Applications",
"IsDeleted": false,
"Name": "Gaming",
"QoSPolicy": "policy"
}
]
}
}
Human Readable Output
Showing 0 to 6 ApplicationFilterCategory objects out of 25
Name Description QoSPolicy BandwidthUsageType Conferencing Conferencing None Desktop Mail Desktop Mail None Download Applications Database Applications None E-commerce E-commerce None File Transfer File Transfer None Gaming Gaming Sites and Applications policy Individual
sophos-firewall-app-category-get
Gets a single app filter category by name.
Base Command
sophos-firewall-app-category-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the app category. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterCategory.Name | String | Name of the app category. |
| SophosFirewall.ApplicationFilterCategory.Description | String | Description of the app category. |
| SophosFirewall.ApplicationFilterCategory.QoSPolicy | String | QoS policy of the category. |
| SophosFirewall.ApplicationFilterCategory.BandwidthUsageType | String | Bandwidth usage type of the category. |
Command Example
!sophos-firewall-app-category-get name=Gaming
Context Example
{
"SophosFirewall": {
"ApplicationFilterCategory": {
"BandwidthUsageType": "Individual",
"Description": "Gaming Sites and Applications",
"IsDeleted": false,
"Name": "Gaming",
"QoSPolicy": "policy"
}
}
}
Human Readable Output
ApplicationFilterCategory Object details
Name Description QoSPolicy BandwidthUsageType Gaming Gaming Sites and Applications policy Individual
sophos-firewall-app-category-update
Updates an existing app filter category.
Base Command
sophos-firewall-app-category-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the app category. | Required |
| description | The description of the category. | Optional |
| qos_policy | QoS policy of the category. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.ApplicationFilterCategory.Name | String | Name of the app category. |
| SophosFirewall.ApplicationFilterCategory.Description | String | Description of the app category. |
| SophosFirewall.ApplicationFilterCategory.QoSPolicy | String | QoS policy of the category. |
| SophosFirewall.ApplicationFilterCategory.BandwidthUsageType | String | Bandwidth usage type of the category. |
Command Example
!sophos-firewall-app-category-update name=Gaming qos_policy=policy
Context Example
{
"SophosFirewall": {
"ApplicationFilterCategory": {
"BandwidthUsageType": "Individual",
"Description": "Gaming Sites and Applications",
"IsDeleted": false,
"Name": "Gaming",
"QoSPolicy": "policy"
}
}
}
Human Readable Output
ApplicationFilterCategory Object details
Name Description QoSPolicy BandwidthUsageType Gaming Gaming Sites and Applications policy Individual
sophos-firewall-web-filter-list
Lists all web filter policies. IMPORTANT: Listing starts at 0 (not 1)!
Base Command
sophos-firewall-web-filter-list
Input
| Argument Name | Description | Required |
|---|---|---|
| start | The start index for the rules to list, e.g: 5. Default is “0”. | Optional |
| end | The end index for the rules to list, e.g: 20. Default is “50”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterPolicy.Name | String | Name of the policy. |
| SophosFirewall.WebFilterPolicy.DefaultAction | String | Default action for the web filter policy. |
| SophosFirewall.WebFilterPolicy.Description | String | Description of the rule. |
| SophosFirewall.WebFilterPolicy.EnableReporting | String | Whether the policy reports events. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestriction | Number | Maximum file size that can be downloaded. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestrictionEnabled | String | Whether the file size restriction is active. |
| SophosFirewall.WebFilterPolicy.RuleList.Rule | String | Rule list information. |
Command Example
!sophos-firewall-web-filter-list start=0 end=6
Context Example
{
"SophosFirewall": {
"WebFilterPolicy": [
{
"DefaultAction": "Allow",
"Description": "Deny access to web mail and online chat sites",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "No Web Mail or Chat",
"RuleList": {
"Rule": [
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Web E-Mail",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Online Chat",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
]
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
},
{
"DefaultAction": "Allow",
"Description": "Deny access to web mail sites",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "No Web Mail",
"RuleList": {
"Rule": {
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Web E-Mail",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
},
{
"DefaultAction": "Allow",
"Description": "Deny access to online chat sites",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "No Online Chat",
"RuleList": {
"Rule": {
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Online Chat",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
},
{
"DefaultAction": "Allow",
"Description": "Restrict users from uploading content to any site",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "No web uploads",
"RuleList": {
"Rule": {
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "HTTPUpload",
"type": "DynamicCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
},
{
"DefaultAction": "Allow",
"Description": "Deny access to categories most commonly unwanted in professional environments",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "Default Workplace Policy",
"RuleList": {
"Rule": [
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Weapons",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Extreme",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Phishing & Fraud",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Militancy & Extremist",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Gambling",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Criminal Activity",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Pro-Suicide & Self-Harm",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Intellectual Piracy",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Marijuana",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Controlled substances",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Legal highs",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Hunting & Fishing",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Anonymizers",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Sexually Explicit",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Nudity",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
]
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
},
{
"DefaultAction": "Allow",
"Description": "Deny access to sexually explicit sites",
"DownloadFileSizeRestriction": "0",
"DownloadFileSizeRestrictionEnabled": "0",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "0",
"GoogAppDomainList": null,
"GoogAppDomainListEnabled": "0",
"IsDeleted": false,
"Name": "No Explicit Content",
"RuleList": {
"Rule": {
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Sexually Explicit",
"type": "WebCategory"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Deny",
"HTTPSAction": "Deny",
"PolicyRuleEnabled": "1",
"Schedule": "All The Time"
}
},
"YoutubeFilterEnabled": "0",
"YoutubeFilterIsStrict": "0"
}
]
}
}
Human Readable Output
Showing 0 to 6 WebFilterPolicy objects out of 12
Name Description DefaultAction EnableReporting DownloadFileSizeRestrictionEnabled DownloadFileSizeRestriction RuleList No Web Mail or Chat Deny access to web mail and online chat sites Allow Enable 0 0 Rule: {‘CategoryList’: {‘Category’: {‘ID’: ‘Web E-Mail’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Online Chat’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’}No Web Mail Deny access to web mail sites Allow Enable 0 0 Rule: {“CategoryList”: {“Category”: {“ID”: “Web E-Mail”, “type”: “WebCategory”}}, “HTTPAction”: “Deny”, “HTTPSAction”: “Deny”, “FollowHTTPAction”: “1”, “ExceptionList”: {“FileTypeCategory”: null}, “Schedule”: “All The Time”, “PolicyRuleEnabled”: “1”, “CCLRuleEnabled”: “0”} No Online Chat Deny access to online chat sites Allow Enable 0 0 Rule: {“CategoryList”: {“Category”: {“ID”: “Online Chat”, “type”: “WebCategory”}}, “HTTPAction”: “Deny”, “HTTPSAction”: “Deny”, “FollowHTTPAction”: “1”, “ExceptionList”: {“FileTypeCategory”: null}, “Schedule”: “All The Time”, “PolicyRuleEnabled”: “1”, “CCLRuleEnabled”: “0”} No web uploads Restrict users from uploading content to any site Allow Enable 0 0 Rule: {“CategoryList”: {“Category”: {“ID”: “HTTPUpload”, “type”: “DynamicCategory”}}, “HTTPAction”: “Deny”, “HTTPSAction”: “Deny”, “FollowHTTPAction”: “1”, “ExceptionList”: {“FileTypeCategory”: null}, “Schedule”: “All The Time”, “PolicyRuleEnabled”: “1”, “CCLRuleEnabled”: “0”} Default Workplace Policy Deny access to categories most commonly unwanted in professional environments Allow Enable 0 0 Rule: {‘CategoryList’: {‘Category’: {‘ID’: ‘Weapons’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Extreme’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Phishing & Fraud’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Militancy & Extremist’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Gambling’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Criminal Activity’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Pro-Suicide & Self-Harm’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Intellectual Piracy’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Marijuana’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Controlled substances’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Legal highs’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Hunting & Fishing’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Anonymizers’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Sexually Explicit’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘Nudity’, ‘type’: ‘WebCategory’}}, ‘HTTPAction’: ‘Deny’, ‘HTTPSAction’: ‘Deny’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All The Time’, ‘PolicyRuleEnabled’: ‘1’, ‘CCLRuleEnabled’: ‘0’}No Explicit Content Deny access to sexually explicit sites Allow Enable 0 0 Rule: {“CategoryList”: {“Category”: {“ID”: “Sexually Explicit”, “type”: “WebCategory”}}, “HTTPAction”: “Deny”, “HTTPSAction”: “Deny”, “FollowHTTPAction”: “1”, “ExceptionList”: {“FileTypeCategory”: null}, “Schedule”: “All The Time”, “PolicyRuleEnabled”: “1”, “CCLRuleEnabled”: “0”}
sophos-firewall-web-filter-get
Gets a single web filter policy by name.
Base Command
sophos-firewall-web-filter-get
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterPolicy.Name | String | Name of the policy. |
| SophosFirewall.WebFilterPolicy.DefaultAction | String | Default action for the web filter policy. |
| SophosFirewall.WebFilterPolicy.Description | String | Description of the rule. |
| SophosFirewall.WebFilterPolicy.EnableReporting | String | Whether the policy reports events. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestriction | Number | Maximum file size that can be downloaded. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestrictionEnabled | String | Whether the file size restriction is active. |
| SophosFirewall.WebFilterPolicy.RuleList.Rule | String | Rule list information. |
Command Example
!sophos-firewall-web-filter-get name=webfilter
Context Example
{
"SophosFirewall": {
"WebFilterPolicy": {
"DefaultAction": "Allow",
"Description": "Description for web filter",
"DownloadFileSizeRestriction": "300",
"DownloadFileSizeRestrictionEnabled": "1",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "1",
"GoogAppDomainList": "gmail.com",
"GoogAppDomainListEnabled": "1",
"IsDeleted": false,
"Name": "webfilter",
"RuleList": {
"Rule": [
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Blocked URLs for Default Policy",
"type": "URLGroup"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Allow",
"HTTPSAction": "Allow",
"PolicyRuleEnabled": "0",
"Schedule": "All Time on Sunday"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "1",
"type": "URLGroup"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "0",
"HTTPAction": "Allow",
"HTTPSAction": "Allow",
"PolicyRuleEnabled": "0",
"Schedule": "All Time on Sunday"
}
]
},
"YoutubeFilterEnabled": "1",
"YoutubeFilterIsStrict": "0"
}
}
}
Human Readable Output
WebFilterPolicy Object details
Name Description DefaultAction EnableReporting DownloadFileSizeRestrictionEnabled DownloadFileSizeRestriction RuleList webfilter Description for web filter Allow Enable 1 300 Rule: {‘CategoryList’: {‘Category’: {‘ID’: ‘Blocked URLs for Default Policy’, ‘type’: ‘URLGroup’}}, ‘HTTPAction’: ‘Allow’, ‘HTTPSAction’: ‘Allow’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All Time on Sunday’, ‘PolicyRuleEnabled’: ‘0’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘1’, ‘type’: ‘URLGroup’}}, ‘HTTPAction’: ‘Allow’, ‘HTTPSAction’: ‘Allow’, ‘FollowHTTPAction’: ‘0’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All Time on Sunday’, ‘PolicyRuleEnabled’: ‘0’, ‘CCLRuleEnabled’: ‘0’}
sophos-firewall-web-filter-add
Adds a new web filter policy.
Base Command
sophos-firewall-web-filter-add
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy | Required |
| description | Description of the policy. | Optional |
| default_action | Default action for the policy. Possible values: “Allow” and “Deny”. | Required |
| download_file_size_restriction_enabled | Whether the max download file size is enabled. Possible values: “0” and “1”. | Optional |
| download_file_size_restriction | Maximum file size to enable downloading in MB. | Optional |
| goog_app_domain_list_enabled | Enable to specify domains allowed to access google service. Possible values: “0” and “1”. | Optional |
| goog_app_domain_list | The domains allowed to access google service. | Optional |
| youtube_filter_enabled | Whether to enable YouTube Restricted Mode to restrict the content that is accessible. Possible values: “0” and “1”. | Optional |
| youtube_filter_is_strict | Whether to adjust the policy used for YouTube Restricted Mode. Possible values: “0” and “1”. | Optional |
| enforce_safe_search | Enable to block websites containing pornography and explicit sexual content from appearing in the search results of Google, Yahoo, Bing search results. Possible values: “0” and “1”. | Optional |
| enforce_image_licensing | Whether to further limit inappropriate content by enforcing search engine filters for Creative Commons licensed images. Possible values: “0” and “1”. | Optional |
| url_group_names | Comma-separted list of URL groups to block, allow, warn, or log. | Optional |
| http_action | The HTTP action. Possible values: “Deny”, “Allow”, “Warn”, and “Log”. | Optional |
| https_action | The HTTPs action. Possible values: “Deny”, “Allow”, “Warn”, and “Log”. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available in the web console. | Optional |
| policy_rule_enabled | Whether to enable the policy rule. Possible values: “1” and “0”. | Optional |
| user_names | A comma-separated list of users who this rule will apply to. | Optional |
| ccl_names | A comma-separated list of CCL names. REQUIRED: When ccl_rule_enabled is ON. | Optional |
| ccl_rule_enabled | Whether to enable the CCL rule. Possible values: “0” and “1”. IMPORTANT: If enabled, ccl_name is required. | Optional |
| follow_http_action | Whether to enable the HTTP action. Possible values: “0” and “1”. | Optional |
| enable_reporting | Whether to enable reporting of the policy. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterPolicy.Name | String | Name of the policy. |
| SophosFirewall.WebFilterPolicy.DefaultAction | String | Default action for the web filter policy. |
| SophosFirewall.WebFilterPolicy.Description | String | Description of the rule. |
| SophosFirewall.WebFilterPolicy.EnableReporting | String | Whether the policy reports events. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestriction | Number | Maximum file size that can be downloaded. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestrictionEnabled | String | Whether the file size restriction is active. |
| SophosFirewall.WebFilterPolicy.RuleList.Rule | String | Rule list information. |
Command Example
!sophos-firewall-web-filter-add name=webfilter default_action=Allow enable_reporting=Enable download_file_size_restriction=300 download_file_size_restriction_enabled=1 enforce_image_licensing=1 enforce_safe_search=1 goog_app_domain_list=gmail.com goog_app_domain_list_enabled=1 http_action=Allow https_action=Allow schedule="All Time on Sunday" youtube_filter_enabled=1 youtube_filter_is_strict=1 ccl_rule_enabled=0 follow_http_action=1 policy_rule_enabled=0 url_group_names="Blocked URLs for Default Policy"
Context Example
{
"SophosFirewall": {
"WebFilterPolicy": {
"DefaultAction": "Allow",
"Description": null,
"DownloadFileSizeRestriction": "300",
"DownloadFileSizeRestrictionEnabled": "1",
"EnableReporting": "Enable",
"EnforceImageLicensing": "1",
"EnforceSafeSearch": "1",
"GoogAppDomainList": "gmail.com",
"GoogAppDomainListEnabled": "1",
"IsDeleted": false,
"Name": "webfilter",
"RuleList": {
"Rule": {
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Blocked URLs for Default Policy",
"type": "URLGroup"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Allow",
"HTTPSAction": "Allow",
"PolicyRuleEnabled": "0",
"Schedule": "All Time on Sunday"
}
},
"YoutubeFilterEnabled": "1",
"YoutubeFilterIsStrict": "1"
}
}
}
Human Readable Output
WebFilterPolicy Object details
Name DefaultAction EnableReporting DownloadFileSizeRestrictionEnabled DownloadFileSizeRestriction RuleList webfilter Allow Enable 1 300 Rule: {“CategoryList”: {“Category”: {“ID”: “Blocked URLs for Default Policy”, “type”: “URLGroup”}}, “HTTPAction”: “Allow”, “HTTPSAction”: “Allow”, “FollowHTTPAction”: “1”, “ExceptionList”: {“FileTypeCategory”: null}, “Schedule”: “All Time on Sunday”, “PolicyRuleEnabled”: “0”, “CCLRuleEnabled”: “0”}
sophos-firewall-web-filter-update
Updates an existing web filter policy.
Base Command
sophos-firewall-web-filter-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
| description | Description of the policy. | Optional |
| default_action | Default action for the policy. Possible values: “Allow” and “Deny”. | Required |
| download_file_size_restriction_enabled | Whether the maximum download file size is enabled. Possible values: “0” and “1”. | Optional |
| download_file_size_restriction | The maximum file size to enable downloading in MB. | Optional |
| goog_app_domain_list_enabled | Whether to enable specifying domains allowed to access the Google service. Possible values: “0” and “1”. | Optional |
| goog_app_domain_list | Comma-separated list of domains allowed to access google service. | Optional |
| youtube_filter_enabled | Whether to enable YouTube Restricted Mode to restrict the content that is accessible. Possible values: “0” and “1”. | Optional |
| youtube_filter_is_strict | Whether to adjust the policy used for YouTube Restricted Mode. Possible values: “0” and “1”. | Optional |
| enforce_safe_search | Whether to enable blocking websites containing pornography and explicit sexual content from appearing in the search results of Google, Yahoo, and Bing search results. Possible values: “0” and “1”. | Optional |
| enforce_image_licensing | Whether to further limit inappropriate content by enforcing search engine filters for Creative Commons licensed images. Possible values: “0” and “1”. | Optional |
| url_group_names | Comma-separated list of URL groups to block, allow, warn, or log. | Optional |
| http_action | The HTTP action. Possible values: “Deny”, “Allow”, “Warn”, and “Log”. | Optional |
| https_action | The HTTPs action. Possible values: “Deny”, “Allow”, “Warn”, and “Log”. | Optional |
| schedule | The schedule for the rule. Possible values: “All the time”, “Work hours (5 Day week)”, “Work hours (6 Day week)”, “All Time on Weekdays”, “All Time on Weekends”, “All Time on Sunday”, “All Days 10:00 to 19:00”. IMPORTANT: Creating a new schedule is available in the web console. | Optional |
| policy_rule_enabled | Whether to enable the policy rule. Possible values: “1” and “0”. | Optional |
| user_names | A comma-separated list of users who this rule will apply to. | Optional |
| ccl_names | A comma-separated list of CCL names. REQUIRED: when ccl_rule_enabled is ON | Optional |
| ccl_rule_enabled | Whether to enable the CCL rule. Possible values: “0” and “1”. IMPORTANT: If enabled, ccl_name is required. | Optional |
| follow_http_action | Whether to enable the HTTP action. Possible values: “0” and “1”. | Optional |
| enable_reporting | Whether to enable reporting of the policy. Possible values: “Enable” and “Disable”. Default is “Enable”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterPolicy.Name | String | Name of the policy. |
| SophosFirewall.WebFilterPolicy.DefaultAction | String | Default action for the web filter policy. |
| SophosFirewall.WebFilterPolicy.Description | String | Description of the rule. |
| SophosFirewall.WebFilterPolicy.EnableReporting | String | Whether the policy reports events. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestriction | Number | Maximum file size that can be downloaded. |
| SophosFirewall.WebFilterPolicy.DownloadFileSizeRestrictionEnabled | String | Whether the file size restriction is active. |
| SophosFirewall.WebFilterPolicy.RuleList.Rule | String | Rule list information. |
Command Example
!sophos-firewall-web-filter-update name=webfilter default_action=Allow enable_reporting=Enable download_file_size_restriction=300 download_file_size_restriction_enabled=1 enforce_image_licensing=0 enforce_safe_search=1 goog_app_domain_list=gmail.com goog_app_domain_list_enabled=1 http_action=Allow https_action=Allow schedule="All Time on Sunday" youtube_filter_enabled=1 youtube_filter_is_strict=0 ccl_rule_enabled=0 follow_http_action=0 policy_rule_enabled=0 url_group_names=1 description="Description for web filter"
Context Example
{
"SophosFirewall": {
"WebFilterPolicy": {
"DefaultAction": "Allow",
"Description": "Description for web filter",
"DownloadFileSizeRestriction": "300",
"DownloadFileSizeRestrictionEnabled": "1",
"EnableReporting": "Enable",
"EnforceImageLicensing": "0",
"EnforceSafeSearch": "1",
"GoogAppDomainList": "gmail.com",
"GoogAppDomainListEnabled": "1",
"IsDeleted": false,
"Name": "webfilter",
"RuleList": {
"Rule": [
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "Blocked URLs for Default Policy",
"type": "URLGroup"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "1",
"HTTPAction": "Allow",
"HTTPSAction": "Allow",
"PolicyRuleEnabled": "0",
"Schedule": "All Time on Sunday"
},
{
"CCLRuleEnabled": "0",
"CategoryList": {
"Category": {
"ID": "1",
"type": "URLGroup"
}
},
"ExceptionList": {
"FileTypeCategory": null
},
"FollowHTTPAction": "0",
"HTTPAction": "Allow",
"HTTPSAction": "Allow",
"PolicyRuleEnabled": "0",
"Schedule": "All Time on Sunday"
}
]
},
"YoutubeFilterEnabled": "1",
"YoutubeFilterIsStrict": "0"
}
}
}
Human Readable Output
WebFilterPolicy Object details
Name Description DefaultAction EnableReporting DownloadFileSizeRestrictionEnabled DownloadFileSizeRestriction RuleList webfilter Description for web filter Allow Enable 1 300 Rule: {‘CategoryList’: {‘Category’: {‘ID’: ‘Blocked URLs for Default Policy’, ‘type’: ‘URLGroup’}}, ‘HTTPAction’: ‘Allow’, ‘HTTPSAction’: ‘Allow’, ‘FollowHTTPAction’: ‘1’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All Time on Sunday’, ‘PolicyRuleEnabled’: ‘0’, ‘CCLRuleEnabled’: ‘0’},
{‘CategoryList’: {‘Category’: {‘ID’: ‘1’, ‘type’: ‘URLGroup’}}, ‘HTTPAction’: ‘Allow’, ‘HTTPSAction’: ‘Allow’, ‘FollowHTTPAction’: ‘0’, ‘ExceptionList’: {‘FileTypeCategory’: None}, ‘Schedule’: ‘All Time on Sunday’, ‘PolicyRuleEnabled’: ‘0’, ‘CCLRuleEnabled’: ‘0’}
sophos-firewall-web-filter-delete
Deletes an existing web filter policy.
Base Command
sophos-firewall-web-filter-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SophosFirewall.WebFilterPolicy.Name | String | Name of the policy. |
| SophosFirewall.WebFilterPolicy.IsDeleted | Bool | Whether the policy is deleted. |
Command Example
!sophos-firewall-web-filter-delete name=webfilter
Context Example
{
"SophosFirewall": {
"WebFilterPolicy": {
"IsDeleted": true,
"Name": "webfilter"
}
}
}
Human Readable Output
Deleting WebFilterPolicy Objects Results
Name IsDeleted webfilter true
Configuration parameters
server_url— Server URL (required)credentials— User Credentials (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (48)
-
sophos-firewall-app-category-getGets a single app filter category by name.
-
sophos-firewall-app-category-listLists all app filter categories. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-app-category-updateUpdates an existing app filter category.
-
sophos-firewall-app-policy-addAdds a new app policy.
-
sophos-firewall-app-policy-deleteDeletes an existing app policy.
-
sophos-firewall-app-policy-getGets a single app policy by name.
-
sophos-firewall-app-policy-listLists all app policies. IMPORTANT: The list starst at 0 (not 1)!
-
sophos-firewall-app-policy-updateUpdates an existing app policy.
-
sophos-firewall-ip-host-addAdds a new IP host.
-
sophos-firewall-ip-host-deleteDeletes an existing IP host.
-
sophos-firewall-ip-host-getGets a single IP host by name.
-
sophos-firewall-ip-host-group-addAdds a new IP host group.
-
sophos-firewall-ip-host-group-deleteDeletes an existing IP host group.
-
sophos-firewall-ip-host-group-getGets a single IP host group by name.
-
sophos-firewall-ip-host-group-listLists all IP host groups. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-ip-host-group-updateUpdates an existing IP host group.
-
sophos-firewall-ip-host-listLists all IP hosts. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-ip-host-updateUpdates an existing IP host.
-
sophos-firewall-rule-addAdds a new firewall rule.
-
sophos-firewall-rule-deleteDeletes an existing firewall rule.
-
sophos-firewall-rule-getGets a single firewall rule by name.
-
sophos-firewall-rule-group-addAdds a new firewall rule group.
-
sophos-firewall-rule-group-deleteDeletes an existing firewall group.
-
sophos-firewall-rule-group-getGets a single firewall rule group by name.
-
sophos-firewall-rule-group-listLists all firewall rule groups. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-rule-group-updateUpdates an existing firewall rule group.
-
sophos-firewall-rule-listLists all firewall rules. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-rule-updateUpdates an existing firewall rule.
-
sophos-firewall-services-addAdds a new firewall service.
-
sophos-firewall-services-deleteDeletes an existing firewall service.
-
sophos-firewall-services-getGets a single service by name.
-
sophos-firewall-services-listLists all firewall services. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-services-updateUpdates an existing firewall service.
-
sophos-firewall-url-group-addAdds new URLs to the group.
-
sophos-firewall-url-group-deleteDeletes an existing URL group or groups.
-
sophos-firewall-url-group-getGets a single URL group by name.
-
sophos-firewall-url-group-listLists all URL groups. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-url-group-updateUpdates an existing URL group.
-
sophos-firewall-user-addAdds a new user.
-
sophos-firewall-user-deleteDeletes an existing user.
-
sophos-firewall-user-getGets a single user by name.
-
sophos-firewall-user-listLists all users. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-user-updateUpdates a user.
-
sophos-firewall-web-filter-addAdds a new web filter policy.
-
sophos-firewall-web-filter-deleteDeletes an existing web filter policy.
-
sophos-firewall-web-filter-getGets a single web filter policy by name.
-
sophos-firewall-web-filter-listLists all web filter policies. IMPORTANT: The list starts at 0 (not 1)!
-
sophos-firewall-web-filter-updateUpdates an existing web filter policy.
from collections.abc import Callable import demistomock as demisto import urllib3 from CommonServerPython import * from CommonServerUserPython import * # Disable insecure warnings urllib3.disable_warnings() DATE_FORMAT = "%Y-%m-%dT%H:%M:%SZ" API_VERSION = "1702.1" RULE = { "endpoint_tag": "SecurityPolicy", "table_headers": ["Name", "Description", "Status", "PolicyType", "IPFamily", "AttachIdentity", "Action", "LogTraffic"], } RULE_GROUP = { "endpoint_tag": "SecurityPolicyGroup", "table_headers": ["Name", "Description", "SecurityPolicyList", "SourceZones", "DestinationZones", "PolicyType"], } URL_GROUP = {"endpoint_tag": "WebFilterURLGroup", "table_headers": ["Name", "Description", "URLlist"]} IP_HOST = {"endpoint_tag": "IPHost", "table_headers": ["Name", "IPFamily", "HostType"]} IP_HOST_GROUP = {"endpoint_tag": "IPHostGroup", "table_headers": ["Name", "Description", "IPFamily", "HostList"]} SERVICE = {"endpoint_tag": "Services", "table_headers": ["Name", "Type", "ServiceDetails"]} APP_POLICY = { "endpoint_tag": "ApplicationFilterPolicy", "table_headers": ["Name", "Description", "MicroAppSupport", "DefaultAction", "RuleList"], } APP_CATEGORY = { "endpoint_tag": "ApplicationFilterCategory", "table_headers": ["Name", "Description", "QoSPolicy", "ApplicationSettings", "BandwidthUsageType"], } WEB_FILTER = { "endpoint_tag": "WebFilterPolicy", "table_headers": [ "Name", "Description", "DefaultAction", "EnableReporting", "DownloadFileSizeRestrictionEnabled", "DownloadFileSizeRestriction", "RuleList", ], } USER = {"endpoint_tag": "User", "table_headers": ["Username", "Name", "Description", "EmailList", "Group", "UserType", "Status"]} class Client(BaseClient): """Sophos XG Firewall Client""" def __init__(self, base_url: str, auth: tuple, verify: bool, proxy: bool): super().__init__(base_url=base_url, auth=auth, verify=verify, proxy=proxy) def request(self, data: tuple, request_method: str, xml_method: str, operation: str = None) -> requests.Response: response = self._http_request( method=request_method, url_suffix="/webconsole/APIController", params=self.request_builder(self._auth, xml_method, data, operation), # type: ignore resp_type="Response", ) return response def get_request(self, data: tuple) -> requests.Response: return self.request(data, "GET", "get") def set_request(self, data: tuple, operation: str) -> requests.Response: return self.request(data, "POST", "set", operation) def delete_request(self, data: tuple) -> requests.Response: return self.request(data, "POST", "remove") def get_item_by_name(self, endpoint_tag: str, name: str) -> requests.Response: data = (endpoint_tag, self.request_one_item_builder(name)) return self.request(data, "GET", "get") def validate(self, data: tuple = (None, None)) -> requests.Response: return self.request(data, "GET", "get") @staticmethod def request_builder(auth: tuple, method: str, data: tuple, operation: str) -> dict: """The builder of the basic xml request Args: auth (tuple): authentication tuple -> (username, password) method (str): Get/Set/Remove data (tuple): request body operation (str): operation for Get method -> add/update Returns: dict: returned built dictionary """ request_data = { "Request": { "@APIVersion": API_VERSION, "Login": {"Username": auth[0], "Password": auth[1]}, f"{method.title()}": {"@operation": operation if operation else "", data[0]: data[1]}, } } return {"reqxml": json2xml(json.dumps(request_data))} @staticmethod def request_one_item_builder(name: str) -> dict: """Build a single filter request Args: name (str): The name of the object to find with the filter Returns: dict: returned built dictionary """ request_data = {"Filter": {"key": {"@name": "Name", "@criteria": "=", "#text": name}}} return request_data def sophos_firewall_rule_list_command(client: Client, start: int, end: int) -> CommandResults: """List all the firewall rules. Limited by start and end Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **RULE) # type: ignore def sophos_firewall_rule_get_command(client: Client, name: str) -> CommandResults: """Retrieve firewall rule by name. Args: client (Client): Sophos XG Firewall Client name (str): Name of the rule to get Returns: CommandResults: Command results object """ return generic_get(client, name, **RULE) # type: ignore def sophos_firewall_rule_add_command(client: Client, params: dict) -> CommandResults: """Add firewall rule Args: client (Client): Sophos XG Firewall Client params (dict): Params for the creation of the firewall rule Returns: CommandResults: Command results object """ return generic_save_and_get( client, RULE["endpoint_tag"], # type: ignore params, rule_builder, RULE["table_headers"], # type: ignore ) def sophos_firewall_rule_update_command(client: Client, params: dict) -> CommandResults: """Update an existing firewall rule Args: client (Client): Sophos XG Firewall Client params (dict): Params for updating the firewall rule Returns: CommandResults: Command results object """ return generic_save_and_get( client, RULE["endpoint_tag"], # type: ignore params, rule_builder, # type: ignore RULE["table_headers"], # type: ignore True, ) def sophos_firewall_rule_delete_command(client: Client, name: str) -> CommandResults: """Delete firewall rule Args: client (Client): Sophos XG Firewall Client name (str): Name of the rule to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, RULE["endpoint_tag"]) # type: ignore def sophos_firewall_rule_group_list_command(client: Client, start: int, end: int) -> CommandResults: """List firewall rule groups with limitation Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **RULE_GROUP) # type: ignore def sophos_firewall_rule_group_get_command(client: Client, name: str) -> CommandResults: """Retrieve firewall rule group by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the rule group to get_request Returns: CommandResults: Command results object """ return generic_get(client, name, **RULE_GROUP) # type: ignore def sophos_firewall_rule_group_add_command(client: Client, params: dict) -> CommandResults: """Add rule group Args: client (Client): Sophos XG Firewall Client params (dict): params for the creation of the rule group Returns: CommandResults: Command results object """ return generic_save_and_get( client, RULE_GROUP["endpoint_tag"], # type: ignore params, rule_group_builder, # type: ignore RULE_GROUP["table_headers"], # type: ignore ) def sophos_firewall_rule_group_update_command(client: Client, params: dict) -> CommandResults: """Update firewall rule Args: client (Client): Sophos XG Firewall Client params (dict): Params for updating the rule group Returns: CommandResults: Command results object """ return generic_save_and_get( client, RULE_GROUP["endpoint_tag"], # type: ignore params, rule_group_builder, # type: ignore RULE_GROUP["table_headers"], # type: ignore True, ) def sophos_firewall_rule_group_delete_command(client: Client, name: str) -> CommandResults: """Delete a rule group by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the rule group to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, RULE_GROUP["endpoint_tag"]) # type: ignore def sophos_firewall_url_group_list_command(client: Client, start: int, end: int) -> CommandResults: """List a URL group with limitations Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **URL_GROUP) # type: ignore def sophos_firewall_url_group_get_command(client: Client, name: str) -> CommandResults: """Retrieve URL group by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the URL group to get Returns: CommandResults: Command results object """ return generic_get(client, name, **URL_GROUP) # type: ignore def sophos_firewall_url_group_add_command(client: Client, params: dict) -> CommandResults: """Add URL group Args: client (Client): Sophos XG Firewall Client params (dict): params for the creation of the URL group Returns: CommandResults: Command results object """ return generic_save_and_get( client, URL_GROUP["endpoint_tag"], # type: ignore params, url_group_builder, # type: ignore URL_GROUP["table_headers"], # type: ignore ) def sophos_firewall_url_group_update_command(client: Client, params: dict) -> CommandResults: """Update a URL group Args: client (Client): Sophos XG Firewall Client params (dict): params for the update Returns: CommandResults: Command results object """ return generic_save_and_get( client, URL_GROUP["endpoint_tag"], # type: ignore params, url_group_builder, # type: ignore URL_GROUP["table_headers"], # type: ignore True, ) # type: ignore def sophos_firewall_url_group_delete_command(client: Client, name: str) -> CommandResults: """Delete a URL group by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the rule to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, URL_GROUP["endpoint_tag"]) # type: ignore def sophos_firewall_ip_host_list_command(client: Client, start: int, end: int) -> CommandResults: """List IP host objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **IP_HOST) # type: ignore def sophos_firewall_ip_host_get_command(client: Client, name: str) -> CommandResults: """Retrieve IP host by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the IP host to get Returns: CommandResults: Command results object """ return generic_get(client, name, **IP_HOST) # type: ignore def sophos_firewall_ip_host_add_command(client: Client, params: dict) -> CommandResults: """Add IP host Args: client (Client): Sophos XG Firewall Client params (dict): params for the creation of the IP host Returns: CommandResults: Command results object """ return generic_save_and_get( client, IP_HOST["endpoint_tag"], # type: ignore params, ip_host_builder, # type: ignore IP_HOST["table_headers"], # type: ignore ) # type: ignore def sophos_firewall_ip_host_update_command(client: Client, params: dict) -> CommandResults: """Update IP host Args: client (Client): Sophos XG Firewall Client params (dict): params for the updating of the IP host Returns: CommandResults: Command results object """ return generic_save_and_get( client, IP_HOST["endpoint_tag"], # type: ignore params, ip_host_builder, # type: ignore IP_HOST["table_headers"], # type: ignore True, ) def sophos_firewall_ip_host_delete_command(client: Client, name: str) -> CommandResults: """Delete IP host by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, IP_HOST["endpoint_tag"]) # type: ignore def sophos_firewall_ip_host_group_list_command(client: Client, start: int, end: int) -> CommandResults: """List IP host group objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **IP_HOST_GROUP) # type: ignore def sophos_firewall_ip_host_group_get_command(client: Client, name: str) -> CommandResults: """Retrieve an IP host group object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **IP_HOST_GROUP) # type: ignore def sophos_firewall_ip_host_group_add_command(client: Client, params: dict) -> CommandResults: """Add IP host group Args: client (Client): Sophos XG Firewall Client params (dict): params to create the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, IP_HOST_GROUP["endpoint_tag"], # type: ignore params, ip_host_group_builder, # type: ignore IP_HOST_GROUP["table_headers"], # type: ignore ) def sophos_firewall_ip_host_group_update_command(client: Client, params: dict) -> CommandResults: """Update an existing IP host group object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, IP_HOST_GROUP["endpoint_tag"], # type: ignore params, ip_host_group_builder, # type: ignore IP_HOST_GROUP["table_headers"], # type: ignore True, ) def sophos_firewall_ip_host_group_delete_command(client: Client, name: str) -> CommandResults: """Delete object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, IP_HOST_GROUP["endpoint_tag"]) # type: ignore def sophos_firewall_services_list_command(client: Client, start: int, end: int) -> CommandResults: """List services Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **SERVICE) # type: ignore def sophos_firewall_services_get_command(client: Client, name: str) -> CommandResults: """Retrieve an service object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **SERVICE) # type: ignore def sophos_firewall_services_add_command(client: Client, params: dict) -> CommandResults: """Add service object Args: client (Client): Sophos XG Firewall Client params (dict): params to create the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, SERVICE["endpoint_tag"], # type: ignore params, service_builder, # type: ignore SERVICE["table_headers"], # type: ignore ) def sophos_firewall_services_update_command(client: Client, params: dict) -> CommandResults: """Update an existing object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, SERVICE["endpoint_tag"], # type: ignore params, service_builder, # type: ignore SERVICE["table_headers"], # type: ignore True, ) # type: ignore def sophos_firewall_services_delete_command(client: Client, name: str) -> CommandResults: """Delete object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, SERVICE["endpoint_tag"]) # type: ignore def sophos_firewall_app_policy_list_command(client: Client, start: int, end: int) -> CommandResults: """List app policy objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **APP_POLICY) # type: ignore def sophos_firewall_app_policy_get_command(client: Client, name: str) -> CommandResults: """Retrieve an app policy object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **APP_POLICY) # type: ignore def sophos_firewall_app_policy_add_command(client: Client, params: dict) -> CommandResults: """Add app policy object Args: client (Client): Sophos XG Firewall Client params (dict): params to create the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, APP_POLICY["endpoint_tag"], # type: ignore params, app_policy_builder, # type: ignore APP_POLICY["table_headers"], # type: ignore ) def sophos_firewall_app_policy_update_command(client: Client, params: dict) -> CommandResults: """Update an existing object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, APP_POLICY["endpoint_tag"], # type: ignore params, app_policy_builder, # type: ignore APP_POLICY["table_headers"], # type: ignore True, ) # type: ignore def sophos_firewall_app_policy_delete_command(client: Client, name: str) -> CommandResults: """Delete object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, APP_POLICY["endpoint_tag"]) # type: ignore def sophos_firewall_app_category_list_command(client: Client, start: int, end: int) -> CommandResults: """List app category objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **APP_CATEGORY) # type: ignore def sophos_firewall_app_category_get_command(client: Client, name: str) -> CommandResults: """Retrieve an app category object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **APP_CATEGORY) # type: ignore def sophos_firewall_app_category_update_command(client: Client, params: dict) -> CommandResults: """Update an existing object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, APP_CATEGORY["endpoint_tag"], # type: ignore params, app_category_builder, # type: ignore APP_CATEGORY["table_headers"], # type: ignore ) # type: ignore def sophos_firewall_web_filter_list_command(client: Client, start: int, end: int) -> CommandResults: """List web filter objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **WEB_FILTER) # type: ignore def sophos_firewall_web_filter_get_command(client: Client, name: str) -> CommandResults: """Retrieve an web filter object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **WEB_FILTER) # type: ignore def sophos_firewall_web_filter_add_command(client: Client, params: dict) -> CommandResults: """Add web filter object Args: client (Client): Sophos XG Firewall Client params (dict): params to create the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, WEB_FILTER["endpoint_tag"], # type: ignore params, web_filter_builder, # type: ignore WEB_FILTER["table_headers"], # type: ignore ) # type: ignore def sophos_firewall_web_filter_update_command(client: Client, params: dict) -> CommandResults: """Update an existing object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, WEB_FILTER["endpoint_tag"], # type: ignore params, web_filter_builder, # type: ignore WEB_FILTER["table_headers"], # type: ignore True, ) # type: ignore def sophos_firewall_web_filter_delete_command(client: Client, name: str) -> CommandResults: """Delete object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, WEB_FILTER["endpoint_tag"]) # type: ignore def sophos_firewall_user_list_command(client: Client, start: int, end: int) -> CommandResults: """Retrieve a list of users Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects Returns: CommandResults: Command results object """ return generic_list(client, start, end, **USER) # type: ignore def sophos_firewall_user_get_command(client: Client, name: str) -> CommandResults: """Retrieve an user object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to get Returns: CommandResults: Command results object """ return generic_get(client, name, **USER) # type: ignore def sophos_firewall_user_add_command(client: Client, params: dict) -> CommandResults: """Add user object Args: client (Client): Sophos XG Firewall Client params (dict): params to create the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, USER["endpoint_tag"], # type: ignore params, user_builder, # type: ignore USER["table_headers"], # type: ignore ) # type: ignore def sophos_firewall_user_update_command(client: Client, params: dict) -> CommandResults: """Update an existing object Args: client (Client): Sophos XG Firewall Client params (dict): params to update the object with Returns: CommandResults: Command results object """ return generic_save_and_get( client, USER["endpoint_tag"], # type: ignore params, user_builder, # type: ignore USER["table_headers"], # type: ignore True, ) # type: ignore def sophos_firewall_user_delete_command(client: Client, name: str) -> CommandResults: """Delete object by name Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete Returns: CommandResults: Command results object """ return generic_delete(client, name, USER["endpoint_tag"]) # type: ignore def test_module(client): """ Returning 'ok' indicates that the integration works like it is supposed to. Args: client: Sophos XG Firewall client Returns: 'ok' if test passed, anything else will fail the test. """ try: result = client.validate() json_result = json.loads(xml2json(result.text)) status_message = retrieve_dict_item_recursively(json_result, "status") message = "" if status_message and "Successful" in status_message: # type: ignore message = "ok" elif status_message and "Authentication Failure" in status_message: # type: ignore message = "Please check your credentials" status_code = dict_safe_get(json_result, ["Response", "Status", "@code"], 0) if status_code and int(status_code) >= 500: status_message = retrieve_dict_item_recursively(json_result, "#text") if status_message and "enable the API Configuration" in status_message: # type: ignore message = "Please enable API configuration from the webconsole (in Backup & firmware)" else: message = status_message return message except DemistoException as error: return error.message def generic_delete(client: Client, name: str, endpoint_tag: str) -> CommandResults: """A generic deleting object function Args: client (Client): Sophos XG Firewall Client name (str): Name of the object to delete endpoint_tag (str): Tag of the object to delete Returns: CommandResults: Command results object """ response = client.delete_request((endpoint_tag, {"Name": name})) response = json.loads(xml2json(response.text)) check_error_on_response(response) # type: ignore delete_status = retrieve_dict_item_recursively(response, "#text") old_context = demisto.dt(demisto.context(), f"SophosFirewall.{endpoint_tag}(val.Name == '{name}')") if old_context and isinstance(old_context, list): old_context = old_context[0] outputs = {"Name": name, "IsDeleted": False} # check if there is a previous data about an object that has been deleted before, # and if not, update the IsDeleted field by the message that returns from the API if delete_status: if old_context and old_context.get("IsDeleted"): is_deleted = old_context["IsDeleted"] else: is_deleted = "successfully" in delete_status # type: ignore outputs["IsDeleted"] = is_deleted readable_output = tableToMarkdown(f"Deleting {endpoint_tag} Objects Results", outputs, ["Name", "IsDeleted"]) return CommandResults( outputs_prefix=f"SophosFirewall.{endpoint_tag}", outputs_key_field="Name", outputs=outputs, raw_response=response, readable_output=readable_output, ) def merge_for_update(client: Client, name: str, data: dict, keys_for_update: dict, endpoint_tag: str) -> dict: """This function used when update is needed. The steps for updating the object is as the following: 1. Retrieve the object from the API 2. Add the specified params in keys_for_update to the new object 3. return the object with the previous and the new data merged. Args: client (Client): Sophos XG Firewall Client name (str): Name of the object we want to get data from data (dict): the new object data keys_for_update (dict): keys for update endpoint_tag (str): The endpoint_tag of the object we want to get data from Returns: dict: returned built dictionary """ previous_object = client.get_item_by_name(endpoint_tag, name) previous_object = json.loads(xml2json(previous_object.text)) check_error_on_response(previous_object) # type: ignore previous_object = retrieve_dict_item_recursively(previous_object, endpoint_tag) # find the related field by keys_for_update and adding it to data for key in keys_for_update: info = dict_safe_get(previous_object, keys_for_update[key], []) if isinstance(info, str): data[key].append(info) else: data[key].extend(info) # if the previous info is list we extent the current # remove duplications for item in data: data[item] = list(set(data[item])) # if there is nothing, makes sure its None so it'll get removed in the end for item in data: data[item] = None if not data[item] else data[item] return data def prepare_builder_params( client: Client, keys: dict, is_for_update: bool, name: str, endpoint_tag: str, locals_copy: dict ) -> dict: """prepare the list of objects for the builder - get the params for locals(), split it into list, and return the params after the merge with the new object was done (if the is_for_update flag is True) Args: client (Client): Sophos XG Firewall Client keys (dict): field to update is_for_update (bool): True if this is an update request name (str): name of the object we want to update if is_for_update is True endpoint_tag (str): The endpoint_tag of the object we want to get data from locals_copy (dict): the locals() object copy in order to extract the params Returns: dict: returned built dictionary """ params = {} # creates a dict with the variables names from keys, and add the current data that insides # the locals() in the function that called this function. for key in keys: params[key] = locals_copy.get(key) # making the params a list params = {key: argToList(item) for key, item in params.items()} # update the params with the previous information of the object if the desired action is update if is_for_update: params = merge_for_update(client, name, params, keys, endpoint_tag) return params def update_dict_from_params_using_path(keys_to_update: dict, params: dict, data: dict) -> dict: """Update a dictionary using a path given in a list [nest1, nest2] and update it. For example: some_dict[nest1][nest2] = some_value Args: keys_to_update (dict): The keys names with the path to update it into params (dict): params with the data of the keys name data (dict): data of the object to update Returns: dict: returned built dictionary """ for key in keys_to_update: path = keys_to_update[key] # check that there is at least 2 fields for adding the data if len(path) >= 2: data[f"{path[0]}"] = {f"{path[1]}": params.get(key)} return data def rule_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, policy_type: str = None, position: str = None, description: str = None, status: str = None, ip_family: str = None, position_policy_name: str = None, source_zones: str = None, source_networks: str = None, # pylint: disable=unused-argument destination_zones: str = None, destination_networks: str = None, # pylint: disable=unused-argument services: str = None, members: str = None, # pylint: disable=unused-argument log_traffic: str = None, match_identity: str = None, show_captive_portal: str = None, schedule: str = None, action: str = None, dscp_marking: str = None, application_control: str = None, application_based_qos_policy: str = None, web_filter: str = None, web_category_base_qos_policy: str = None, intrusion_prevention: str = None, traffic_shapping_policy: str = None, apply_nat: str = None, override_gateway_default_nat_policy: str = None, scan_http: str = None, scan_https: str = None, sandstorm: str = None, block_quick_quic: str = None, scan_ftp: str = None, source_security_heartbeat: str = None, minimum_source_hb_permitted: str = None, destination_security_heartbeat: str = None, rewrite_source_address: str = None, minimum_destination_hb_permitted: str = None, data_accounting: str = None, application_control_internet_scheme: str = None, web_filter_internet_scheme: str = None, outbound_address: str = None, backup_gateway: str = None, primary_gateway: str = None, ) -> dict: """The builder of the rule object - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the rule should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to create/update policy_type (str, optional): Policy Type information of the rule position (str, optional): Position information of the rule description (str, optional): Description information of the rule status (str, optional): Status information of the rule ip_family (str, optional): Ip Family information of the rule position_policy_name (str, optional): Position Policy Name information of the rule source_zones (str, optional): Source Zones information of the rule source_networks (str, optional): Source Networks information of the rule destination_zones (str, optional): Destination Zones information of the rule destination_networks (str, optional): Destination Networks information of the rule services (str, optional): Services information of the rule schedule (str, optional): Schedule information of the rule log_traffic (str, optional): Log Traffic information of the rule match_identity (str, optional): Match Identity information of the rule show_captive_portal (str, optional): Show Captive Portal information of the rule members (str, optional): Members information of the rule action (str, optional): Action information of the rule dscp_marking (str, optional): Dscp Marking information of the rule application_control (str, optional): Application Control information of the rule application_based_qos_policy (str, optional): Application Based Qos Policy information of the rule web_filter (str, optional): Web Filter information of the rule web_category_base_qos_policy (str, optional): Web Category Base Qos Policy information of the rule intrusion_prevention (str, optional): Intrusion Prevention information of the rule traffic_shapping_policy (str, optional): Traffic Shapping Policy information of the rule apply_nat (str, optional): Apply Nat information of the rule override_gateway_default_nat_policy (str, optional): Override Gateway Default Nat Policy information of the rule scan_http (str, optional): Scan Http information of the rule scan_https (str, optional): Scan Https information of the rule sandstorm (str, optional): Sandstorm information of the rule block_quick_quic (str, optional): Block Quick Quic information of the rule scan_ftp (str, optional): Scan Ftp information of the rule source_security_heartbeat (str, optional): Source Security Heartbeat information of the rule minimum_source_hb_permitted (str, optional): Minimum Source Hb Permitted information of the rule destination_security_heartbeat (str, optional): Destination Security Heartbeat information of the rule rewrite_source_address (str, optional): Rewrite Source Address information of the rule minimum_destination_hb_permitted (str, optional): Minimum Destination Hb Permitted information of the rule data_accounting (str, optional): Data Accounting information of the rule application_control_internet_scheme (str, optional): Application Control Internet Scheme information of the rule web_filter_internet_scheme (str, optional): Web Filter Internet Scheme information of the rule outbound_address (str, optional): Outbound Address information of the rule backup_gateway (str, optional): Backup Gateway information of the rule primary_gateway (str, optional): Primary Gateway information of the rule Raises: Exception: if there is an error with getting the previous rule Returns: dict: returned built dictionary """ keys_for_update = { "members": ["Identity", "Member"], "source_zones": ["SourceZones", "Zone"], "source_networks": ["SourceNetworks", "Network"], "destination_zones": ["DestinationZones", "Zone"], "destination_networks": ["DestinationNetworks", "Network"], "services": ["Services", "Service"], } params = prepare_builder_params(client, keys_for_update, is_for_update, name, endpoint_tag, locals()) if is_for_update: response = client.get_item_by_name(endpoint_tag, name) response = json.loads(xml2json(response.text)) check_error_on_response(response) # type: ignore policy_type = retrieve_dict_item_recursively(response, "PolicyType") json_data = { "Name": name, "Description": description, "Status": status, "IPFamily": ip_family, "PolicyType": policy_type, "Position": position, "Schedule": schedule, "MatchIdentity": match_identity, "ShowCaptivePortal": show_captive_portal, "Action": action, "DSCPMarking": dscp_marking, "LogTraffic": log_traffic, "ApplyNAT": apply_nat, "ScanHTTP": scan_http, "ScanHTTPS": scan_https, "Sandstorm": sandstorm, "BlockQuickQuic": block_quick_quic, "ScanFTP": scan_ftp, "DataAccounting": data_accounting, "PrimaryGateway": primary_gateway, "RewriteSourceAddress": rewrite_source_address, "ApplicationControl": application_control, "ApplicationControlInternetScheme": application_control_internet_scheme, "ApplicationBaseQoSPolicy": application_based_qos_policy, "WebFilter": web_filter, "WebFilterInternetScheme": web_filter_internet_scheme, "WebCategoryBaseQoSPolicy": web_category_base_qos_policy, "IntrusionPrevention": intrusion_prevention, "TrafficShappingPolicy": traffic_shapping_policy, "OverrideGatewayDefaultNATPolicy": override_gateway_default_nat_policy, "SourceSecurityHeartbeat": source_security_heartbeat, "MinimumSourceHBPermitted": minimum_source_hb_permitted, "DestSecurityHeartbeat": destination_security_heartbeat, "MinimumDestinationHBPermitted": minimum_destination_hb_permitted, "OutboundAddress": outbound_address, "BackupGateway": backup_gateway, } if (position == "after" or position == "before") and not position_policy_name: raise Exception("please provide position_policy_name") if position == "after": json_data["After"] = {"Name": position_policy_name} # type: ignore elif position == "before": json_data["Before"] = {"Name": position_policy_name} # type: ignore json_data = update_dict_from_params_using_path(keys_for_update, params, json_data) return remove_empty_elements(json_data) def rule_group_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, destination_zones: str = None, source_zones: str = None, rules: str = None, # pylint: disable=unused-argument policy_type: str = None, description: str = None, ) -> dict: """Rule group object builder. Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update description (str, optional): Description information of the rule group policy_type (str, optional): Policy Type information of the rule group rules (str, optional): Rules information of the rule group source_zones (str, optional): Source Zones information of the rule group destination_zones (str, optional): Destination Zones information of the rule group Returns: dict: returned built dictionary """ keys_for_update = { "rules": ["SecurityPolicyList", "SecurityPolicy"], "source_zones": ["SourceZones", "Zone"], "destination_zones": ["DestinationZones", "Zone"], } params = prepare_builder_params(client, keys_for_update, is_for_update, name, endpoint_tag, locals()) json_data = {"Name": name, "Description": description, "PolicyType": policy_type} json_data = update_dict_from_params_using_path(keys_for_update, params, json_data) return remove_empty_elements(json_data) def ip_host_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, host_type: str = None, ip_address: str = None, start_ip: str = None, end_ip: str = None, ip_addresses: str = None, subnet_mask: str = None, ip_family: str = None, host_group: str = None, ) -> dict: # pylint: disable=unused-argument """Builder for the IP host object - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update host_type (str, optional): Host Type information of the IP host ip_address (str, optional): Ip Address information of the IP host start_ip (str, optional): Start Ip information of the IP host end_ip (str, optional): End Ip information of the IP host ip_addresses (str, optional): Ip Addresses information of the IP host subnet_mask (str, optional): Subnet Mask information of the IP host ip_family (str, optional): Ip Family information of the IP host host_group (str, optional): Host Group information of the IP host Raises: Exception: Missing IP address Exception: Missing IP address and subnet mask Exception: Missing start IP and end IP Exception: Missing IP addresses Returns: dict: returned built dictionary """ keys_for_update = { "host_group": ["HostGroupList", "HostGroup"], } params = prepare_builder_params(client, keys_for_update, is_for_update, name, endpoint_tag, locals()) if is_for_update: response = client.get_item_by_name(endpoint_tag, name) response = json.loads(xml2json(response.text)) check_error_on_response(response) # type: ignore host_type = retrieve_dict_item_recursively(response, "HostType") json_data = { "Name": name, "IPFamily": ip_family, "HostType": host_type, } if host_type == "IP": if not ip_address: raise Exception("Please provide an IP address") json_data["IPAddress"] = ip_address elif host_type == "Network": if not (ip_address and subnet_mask): raise Exception("Please provide an IP address and subnet mask") json_data["IPAddress"] = ip_address json_data["Subnet"] = subnet_mask elif host_type == "IPRange": if not (start_ip and end_ip): raise Exception("Please provide start IP and end ip") json_data["StartIPAddress"] = start_ip json_data["EndIPAddress"] = end_ip else: # host_type == 'IPList' if not ip_addresses: raise Exception("Please provide an ip_addresses") json_data["ListOfIPAddresses"] = ip_addresses json_data = update_dict_from_params_using_path(keys_for_update, params, json_data) return remove_empty_elements(json_data) def url_group_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, description: str = None, urls: str = None ) -> dict: # pylint: disable=unused-argument """Builder for the URL group object - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update description (str, optional): Description information of the URL group urls (str, optional): URLs information of the URL group Returns: dict: returned built dictionary """ keys_for_update = { "urls": ["URLlist", "URL"], } params = prepare_builder_params(client, keys_for_update, is_for_update, name, endpoint_tag, locals()) json_data = { "Name": name, "Description": description, } json_data = update_dict_from_params_using_path(keys_for_update, params, json_data) return remove_empty_elements(json_data) def ip_host_group_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, description: str = None, ip_family: str = None, hosts: str = None, ) -> dict: # pylint: disable=unused-argument """Builder for the IP host group - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update description (str, optional): Description information of the IP host group ip_family (str, optional): Ip Family information of the IP host group hosts (str, optional): Hosts information of the IP host group Returns: dict: returned built dictionary """ keys_for_update = { "hosts": ["HostList", "Host"], } params = prepare_builder_params(client, keys_for_update, is_for_update, name, endpoint_tag, locals()) json_data = { "Name": name, "IPFamily": ip_family, "Description": description, } json_data = update_dict_from_params_using_path(keys_for_update, params, json_data) return remove_empty_elements(json_data) def service_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, service_type: str, protocol: str = None, source_port: int = None, destination_port: int = None, protocol_name: str = None, icmp_type: str = None, icmp_code: str = None, icmp_v6_type: str = None, icmp_v6_code: str = None, ) -> dict: """Builder for the service object - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update service_type (str, optional): Service Type information of the service protocol (str, optional): Protocol information of the service source_port (str, optional): Source Port information of the service destination_port (str, optional): Destination Port information of the service protocol_name (str, optional): Protocol Name information of the service icmp_type (str, optional): ICMP Type information of the service icmp_code (str, optional): ICMP Code information of the service icmp_v6_type (str, optional): ICMP V6 Type information of the service icmp_v6_code (str, optional): ICMP V6 Code information of the service Raises: Exception: Missing protocol, source port and destination port Exception: Missing protocol name Exception: Missing icmp_type and icmp_code Exception: Missing icmp_v6_type and icmp_v6_code Returns: dict: returned dictionary """ previous_service_details = [] # type: ignore # if the object need to be updated, merge between old and new information will happen if is_for_update: previous_object = client.get_item_by_name(endpoint_tag, name) previous_object = json.loads(xml2json(previous_object.text)) check_error_on_response(previous_object) # type: ignore service_type = retrieve_dict_item_recursively(previous_object, "Type") previous_service_details = retrieve_dict_item_recursively(previous_object, "ServiceDetail") if not previous_service_details: previous_service_details = [] elif not isinstance(previous_service_details, list): previous_service_details = [previous_service_details] json_data = { "Name": name, "Type": service_type, } if service_type == "TCPorUDP": if not (protocol and source_port and destination_port): raise Exception("Please provide protocol, source_port and destination_port") service_details = {"Protocol": protocol, "SourcePort": source_port, "DestinationPort": destination_port} elif service_type == "IP": if not protocol_name: raise Exception("Please provide protocol_name") service_details = {"ProtocolName": protocol_name} elif service_type == "ICMP": if not (icmp_type and icmp_code): raise Exception("Please provide icmp_type and icmp_code") service_details = {"ICMPType": icmp_type, "ICMPCode": icmp_code} else: # type == 'ICMPv6' if not (icmp_v6_type and icmp_v6_code): raise Exception("Please provide icmp_v6_type and icmp_v6_code") service_details = {"ICMPv6Type": icmp_v6_type, "ICMPv6Code": icmp_v6_code} previous_service_details.append(service_details) json_data.update( { "ServiceDetails": { # type: ignore "ServiceDetail": previous_service_details } } ) return remove_empty_elements(json_data) def web_filter_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, default_action: str = None, description: str = None, download_file_size_restriction_enabled: str = None, download_file_size_restriction: int = None, enable_reporting: str = None, goog_app_domain_list_enabled: str = None, goog_app_domain_list: str = None, youtube_filter_enabled: str = None, youtube_filter_is_strict: str = None, enforce_safe_search: str = None, enforce_image_licensing: str = None, url_group_names: str = None, http_action: str = None, https_action: str = None, schedule: str = None, policy_rule_enabled: str = None, user_names: str = None, ccl_names: str = None, ccl_rule_enabled: str = None, follow_http_action: str = None, ) -> dict: """Builder for web filter object Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update default_action (str, optional): Default Action information of the web filter description (str, optional): Description information of the web filter download_file_size_restriction_enabled (str, optional): Download File Size Restriction Enabled information of the web filter download_file_size_restriction (str, optional): Download File Size Restriction information of the web filter enable_reporting (str, optional): Enable Reporting information of the web filter goog_app_domain_list_enabled (str, optional): Goog App Domain List Enabled information of the web filter goog_app_domain_list (str, optional): Goog App Domain List information of the web filter youtube_filter_enabled (str, optional): Youtube Filter Enabled information of the web filter youtube_filter_is_strict (str, optional): Youtube Filter Is Strict information of the web filter enforce_safe_search (str, optional): Enforce Safe Search information of the web filter enforce_image_licensing (str, optional): Enforce Image Licensing information of the web filter url_group_names (str, optional): Url Group Names information of the web filter http_action (str, optional): Http Action information of the web filter https_action (str, optional): Https Action information of the web filter schedule (str, optional): Schedule information of the web filter policy_rule_enabled (str, optional): Policy Rule Enabled information of the web filter user_names (str, optional): User Names information of the web filter ccl_names (str, optional): Ccl Names information of the web filter ccl_rule_enabled (str, optional): Ccl Rule Enabled information of the web filter follow_http_action (str, optional): Follow Http Action information of the web filter Returns: dict: returned built dictionary """ previous_rules_details = [] # type: ignore # if the object need to be updated, merge between old and new information will happen if is_for_update: previous_object = client.get_item_by_name(endpoint_tag, name) previous_object = json.loads(xml2json(previous_object.text)) check_error_on_response(previous_object) # type: ignore previous_rules_details = retrieve_dict_item_recursively(previous_object, "Rule") if not previous_rules_details: previous_rules_details = [] elif not isinstance(previous_rules_details, list): previous_rules_details = [previous_rules_details] json_data = { "Name": name, "Description": description, "DefaultAction": default_action, "EnableReporting": enable_reporting, "DownloadFileSizeRestriction": download_file_size_restriction, "DownloadFileSizeRestrictionEnabled": download_file_size_restriction_enabled, "GoogAppDomainListEnabled": goog_app_domain_list_enabled, "GoogAppDomainList": argToList(goog_app_domain_list), "YoutubeFilterEnabled": youtube_filter_enabled, "YoutubeFilterIsStrict": youtube_filter_is_strict, "EnforceSafeSearch": enforce_safe_search, "EnforceImageLicensing": enforce_image_licensing, } categories = [{"ID": name, "type": "URLGroup"} for name in argToList(url_group_names)] rule_details = { "PolicyRuleEnabled": policy_rule_enabled, "CCLRuleEnabled": ccl_rule_enabled, "FollowHTTPAction": follow_http_action, "CategoryList": {"Category": categories}, "HTTPAction": http_action, "HTTPSAction": https_action, "Schedule": schedule, "UserList": {"User": argToList(user_names)}, "CCLList": {"CCL": argToList(ccl_names)}, } previous_rules_details.append(rule_details) json_data.update( { "RuleList": { # type: ignore "Rule": previous_rules_details } } ) return remove_empty_elements(json_data) def app_category_builder(name: str, description: str = None, qos_policy: str = None) -> dict: """Builder for app category object Args: name (str): The name of the object we want to add/update description (str, optional): Description information of the app category qos_policy (str, optional): Qos Policy information of the app category Returns: dict: returned built dictionary """ json_data = { "Name": name, "Description": description, "QoSPolicy": qos_policy, } return remove_empty_elements(json_data) def app_policy_builder( client: Client, is_for_update: bool, endpoint_tag: str, name: str, description: str = None, micro_app_support: str = None, default_action: str = None, select_all: str = None, categories: str = None, risks: str = None, applications: str = None, characteristics: str = None, technologies: str = None, classifications: str = None, action: str = None, schedule: str = None, ) -> dict: """Builder for the app policy object - build the body of the request Args: client (Client): Sophos XG Firewall Client is_for_update (bool): True if the object should be updated endpoint_tag (str): The endpoint_tag of the object we want to get data from name (str): The name of the object we want to add/update description (str, optional): Description information of the app policy micro_app_support (str, optional): Micro App Support information of the app policy default_action (str, optional): Default Action information of the app policy select_all (str, optional): Select All information of the app policy categories (str, optional): Categories information of the app policy risks (str, optional): Risks information of the app policy applications (str, optional): Applications information of the app policy characteristics (str, optional): Characteristics information of the app policy technologies (str, optional): Technologies information of the app policy classifications (str, optional): Classifications information of the app policy action (str, optional): Action information of the app policy schedule (str, optional): Schedule information of the app policy Returns: dict: returned built dictionary """ previous_rules_details = [] # type: ignore # if the object need to be updated, merge between old and new information will happen if is_for_update: previous_object = client.get_item_by_name(endpoint_tag, name) previous_object = json.loads(xml2json(previous_object.text)) check_error_on_response(previous_object) # type: ignore previous_rules_details = retrieve_dict_item_recursively(previous_object, "Rule") if not previous_rules_details: previous_rules_details = [] elif not isinstance(previous_rules_details, list): previous_rules_details = [previous_rules_details] json_data = { "Name": name, "Description": description, "MicroAppSupport": micro_app_support, "DefaultAction": default_action, } rule_details = { "SelectAllRule": select_all, "CategoryList": {"Category": argToList(categories)}, "RiskList": {"Risk": argToList(risks)}, "CharacteristicsList": {"Characteristics": argToList(characteristics)}, "TechnologyList": {"Technology": argToList(technologies)}, "ClassificationList": {"Classification": argToList(classifications)}, "ApplicationList": {"Application": argToList(applications)}, "Action": action, "Schedule": schedule, } previous_rules_details.append(rule_details) json_data.update( { "RuleList": { # type: ignore "Rule": previous_rules_details } } ) return remove_empty_elements(json_data) def user_builder( name: str, username: str, email: str = None, password: str = None, description: str = None, group: str = None, user_type: str = None, profile: str = None, surfing_quota_policy: str = None, access_time_policy: str = None, ssl_vpn_policy: str = None, clientless_policy: str = None, data_transfer_policy: str = None, simultaneous_logins_global: str = None, schedule_for_appliance_access: str = None, qos_policy: str = None, login_restriction: str = None, ) -> dict: """Builder for the user object - build the body of the request Args: name (str): The name of the object we want to add/update username (str, optional): Username information of the user email (str, optional): Email information of the user password (str, optional): Password information of the user description (str, optional): Description information of the user group (str, optional): Group information of the user user_type (str, optional): User Type information of the user profile (str, optional): Profile information of the user surfing_quota_policy (str, optional): Surfing Quota Policy information of the user access_time_policy (str, optional): Access Time Policy information of the user ssl_vpn_policy (str, optional): Ssl Vpn Policy information of the user clientless_policy (str, optional): Clientless Policy information of the user data_transfer_policy (str, optional): Data Transfer Policy information of the user simultaneous_logins_global (str, optional): Simultaneous Logins Global information of the user schedule_for_appliance_access (str, optional): Schedule For Appliance Access information of the user qos_policy (str, optional): Qos Policy information of the user login_restriction (str, optional): Login Restriction information of the user Raises: Exception: if Administrator type was selected and profile was not provided Returns: dict: returned built dictionary """ if user_type == "Administrator" and not profile: raise Exception("Administrator type was selected. Please provide profile.") json_data = { "Username": username, "Name": name, "Password": password, "UserType": user_type, "Profile": profile, "EmailList": {"EmailID": email}, "Group": group, "Description": description, "SurfingQuotaPolicy": surfing_quota_policy, "AccessTimePolicy": access_time_policy, "SSLVPNPolicy": ssl_vpn_policy, "ClientlessPolicy": clientless_policy, "DataTransferPolicy": data_transfer_policy, "SimultaneousLoginsGlobal": simultaneous_logins_global, "ScheduleForApplianceAccess": schedule_for_appliance_access, "QoSPolicy": qos_policy, "LoginRestriction": login_restriction, } return remove_empty_elements(json_data) def check_error_on_response(response: dict) -> None: """Check if there is an error on the response Args: response (dict): the object to check the error on Raises: Exception: if there if an error in the response Exception: if there are no records on list or get """ response_message = retrieve_dict_item_recursively(response, "#text") response_code = retrieve_dict_item_recursively(response, "@code") response_status = retrieve_dict_item_recursively(response, "Status") if response_message and "successful" not in response_message and response_code and int(response_code) > 299: # type: ignore raise Exception(f"{response_message} (error code: {response_code})") if response_status and "No. of records Zero." in response_status: # type: ignore raise Exception(response_status) def generic_save_and_get( client: Client, endpoint_tag: str, params: dict, builder: Callable, table_headers: list, to_update: bool = False ) -> CommandResults: """Generic function for add/update Args: to_update (bool): True if the object should be updated client (Client): Sophos XG Firewall Client params (dict): params for the builder builder (Callable): the builder to build the object endpoint_tag (str): The endpoint_tag of the object table_headers (list): table_headers for readable outputs Returns: CommandResults: Command results object """ funcs_without_extra_args = [user_builder, app_category_builder] if builder in funcs_without_extra_args: data = builder(**params) else: data = builder(client, to_update, endpoint_tag, **params) operation = "update" if to_update else "add" response = client.set_request((endpoint_tag, data), operation) response = json.loads(xml2json(response.text)) check_error_on_response(response) # type: ignore return generic_get(client, params.get("name"), endpoint_tag, table_headers) # type: ignore def generic_get(client: Client, name: str, endpoint_tag: str, table_headers: list) -> CommandResults: """Generic get, returns an object based on the endpoint tag and the name Args: client (Client): Sophos XG Firewall Client name (str): The name of the object to get endpoint_tag (str): The endpoint tag of the object table_headers (list): table headers for readable outputs Returns: CommandResults: Command results object """ response = client.get_item_by_name(endpoint_tag, name) response = json.loads(xml2json(response.text)) check_error_on_response(response) # type: ignore outputs = retrieve_dict_item_recursively(response, endpoint_tag) if outputs: outputs.pop("@transactionid") # type: ignore outputs["IsDeleted"] = False # type: ignore table_title = f"{endpoint_tag} Object details" readable_output = tableToMarkdown(table_title, outputs, table_headers, removeNull=True) return CommandResults( outputs_prefix=f"SophosFirewall.{endpoint_tag}", outputs_key_field="Name", raw_response=outputs, outputs=outputs, readable_output=readable_output, ) def generic_list(client: Client, start: int, end: int, endpoint_tag: str, table_headers: str) -> CommandResults: """Generic function for listing objects Args: client (Client): Sophos XG Firewall Client start (int): low limit of returned objects, starts with 0 end (int): high limit of returned objects endpoint_tag (str): The endpoint tag of the objects table_headers (list): table headers for readable outputs Returns: CommandResults: Command results object """ response = client.get_request((endpoint_tag, None)) response = json.loads(xml2json(response.text)) outputs = dict_safe_get(response, ["Response", endpoint_tag]) check_error_on_response(response) # type: ignore outputs = outputs if isinstance(outputs, list) else [outputs] for output in outputs: output.pop("@transactionid") output["IsDeleted"] = False start, end = int(start), int(end) len_outputs = len(outputs) if end > len_outputs: end = len_outputs outputs = outputs[start:end] table_title = f"Showing {start} to {end} {endpoint_tag} objects out of {len_outputs}" readable_output = tableToMarkdown(table_title, outputs, table_headers, removeNull=True) return CommandResults( outputs_prefix=f"SophosFirewall.{endpoint_tag}", outputs_key_field="Name", raw_response=outputs, outputs=outputs, readable_output=readable_output, ) def retrieve_dict_item_recursively(obj, key) -> any: # type: ignore """Find items in given dictionary by the key Args: obj (dict): the dict to search in key (str): the key to search for Returns: The item if found """ if key in obj: return obj[key] for _, value in obj.items(): if isinstance(value, dict): item = retrieve_dict_item_recursively(value, key) if item: return item return None def main(): """ PARSE AND VALIDATE INTEGRATION PARAMS """ params = demisto.params() command = demisto.command() args = demisto.args() username = params.get("credentials").get("identifier") password = params.get("credentials").get("password") server_url = params.get("server_url") verify_certificate = not params.get("insecure", False) proxy = params.get("proxy", False) demisto.debug(f"Command being called is {command}") try: client = Client(base_url=server_url, verify=verify_certificate, auth=(username, password), proxy=proxy) if command == "test-module": # This is the call made when pressing the integration Test button. return_results(test_module(client)) elif command == "sophos-firewall-rule-list": return_results(sophos_firewall_rule_list_command(client, **args)) elif command == "sophos-firewall-rule-get": return_results(sophos_firewall_rule_get_command(client, **args)) elif command == "sophos-firewall-rule-add": return_results(sophos_firewall_rule_add_command(client, args)) elif command == "sophos-firewall-rule-update": return_results(sophos_firewall_rule_update_command(client, args)) elif command == "sophos-firewall-rule-delete": return_results(sophos_firewall_rule_delete_command(client, **args)) elif command == "sophos-firewall-rule-group-list": return_results(sophos_firewall_rule_group_list_command(client, **args)) elif command == "sophos-firewall-rule-group-get": return_results(sophos_firewall_rule_group_get_command(client, **args)) elif command == "sophos-firewall-rule-group-add": return_results(sophos_firewall_rule_group_add_command(client, args)) elif command == "sophos-firewall-rule-group-update": return_results(sophos_firewall_rule_group_update_command(client, args)) elif command == "sophos-firewall-rule-group-delete": return_results(sophos_firewall_rule_group_delete_command(client, **args)) elif command == "sophos-firewall-url-group-list": return_results(sophos_firewall_url_group_list_command(client, **args)) elif command == "sophos-firewall-url-group-get": return_results(sophos_firewall_url_group_get_command(client, **args)) elif command == "sophos-firewall-url-group-add": return_results(sophos_firewall_url_group_add_command(client, args)) elif command == "sophos-firewall-url-group-update": return_results(sophos_firewall_url_group_update_command(client, args)) elif command == "sophos-firewall-url-group-delete": return_results(sophos_firewall_url_group_delete_command(client, **args)) elif command == "sophos-firewall-ip-host-list": return_results(sophos_firewall_ip_host_list_command(client, **args)) elif command == "sophos-firewall-ip-host-get": return_results(sophos_firewall_ip_host_get_command(client, **args)) elif command == "sophos-firewall-ip-host-add": return_results(sophos_firewall_ip_host_add_command(client, args)) elif command == "sophos-firewall-ip-host-update": return_results(sophos_firewall_ip_host_update_command(client, args)) elif command == "sophos-firewall-ip-host-delete": return_results(sophos_firewall_ip_host_delete_command(client, **args)) elif command == "sophos-firewall-ip-host-group-list": return_results(sophos_firewall_ip_host_group_list_command(client, **args)) elif command == "sophos-firewall-ip-host-group-get": return_results(sophos_firewall_ip_host_group_get_command(client, **args)) elif command == "sophos-firewall-ip-host-group-add": return_results(sophos_firewall_ip_host_group_add_command(client, args)) elif command == "sophos-firewall-ip-host-group-update": return_results(sophos_firewall_ip_host_group_update_command(client, args)) elif command == "sophos-firewall-ip-host-group-delete": return_results(sophos_firewall_ip_host_group_delete_command(client, **args)) elif command == "sophos-firewall-services-list": return_results(sophos_firewall_services_list_command(client, **args)) elif command == "sophos-firewall-services-get": return_results(sophos_firewall_services_get_command(client, **args)) elif command == "sophos-firewall-services-add": return_results(sophos_firewall_services_add_command(client, args)) elif command == "sophos-firewall-services-update": return_results(sophos_firewall_services_update_command(client, args)) elif command == "sophos-firewall-services-delete": return_results(sophos_firewall_services_delete_command(client, **args)) elif command == "sophos-firewall-app-policy-list": return_results(sophos_firewall_app_policy_list_command(client, **args)) elif command == "sophos-firewall-app-policy-get": return_results(sophos_firewall_app_policy_get_command(client, **args)) elif command == "sophos-firewall-app-policy-add": return_results(sophos_firewall_app_policy_add_command(client, args)) elif command == "sophos-firewall-app-policy-update": return_results(sophos_firewall_app_policy_update_command(client, args)) elif command == "sophos-firewall-app-policy-delete": return_results(sophos_firewall_app_policy_delete_command(client, **args)) elif command == "sophos-firewall-app-category-list": return_results(sophos_firewall_app_category_list_command(client, **args)) elif command == "sophos-firewall-app-category-get": return_results(sophos_firewall_app_category_get_command(client, **args)) elif command == "sophos-firewall-app-category-update": return_results(sophos_firewall_app_category_update_command(client, args)) elif command == "sophos-firewall-web-filter-list": return_results(sophos_firewall_web_filter_list_command(client, **args)) elif command == "sophos-firewall-web-filter-get": return_results(sophos_firewall_web_filter_get_command(client, **args)) elif command == "sophos-firewall-web-filter-add": return_results(sophos_firewall_web_filter_add_command(client, args)) elif command == "sophos-firewall-web-filter-update": return_results(sophos_firewall_web_filter_update_command(client, args)) elif command == "sophos-firewall-web-filter-delete": return_results(sophos_firewall_web_filter_delete_command(client, **args)) elif command == "sophos-firewall-user-list": return_results(sophos_firewall_user_list_command(client, **args)) elif command == "sophos-firewall-user-get": return_results(sophos_firewall_user_get_command(client, **args)) elif command == "sophos-firewall-user-add": return_results(sophos_firewall_user_add_command(client, args)) elif command == "sophos-firewall-user-update": return_results(sophos_firewall_user_update_command(client, args)) elif command == "sophos-firewall-user-delete": return_results(sophos_firewall_user_delete_command(client, **args)) # Log exceptions except Exception as error: message = f"Failed to execute {command} command. Error: {error!s}" return_error(message) if __name__ in ("__main__", "__builtin__", "builtins"): main()