Skip to main content

Extended Access List

Location in GUI: Objects » Object Management » Access List » Extended

Diagram

Classes

objects (fmc.domains)

NameTypeConstraintMandatoryDefault Value
extended_access_listsList[extended_access_lists]No

extended_access_lists (fmc.domains.objects)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.+-]{1,64}$Yes
loggingChoicePER_ACCESS_LIST_ENTRY, DEFAULT, DISABLEDNo
log_levelChoiceALERT, CRIT, DEBUG, EMERG, ERR, INFORMATIONAL, NOTICE, WARNINGNo
log_intervalIntegermin: 1, max: 600No
entriesList[entries]Yes

entries (fmc.domains.objects.extended_access_lists)

NameTypeConstraintMandatoryDefault Value
actionChoiceDENY, PERMITYes
loggingChoicePER_ACCESS_LIST_ENTRY, DEFAULT, DISABLEDYes
destination_network_literalsListStringNo
destination_network_objectsListStringNo
destination_port_literalsList[destination_port_literals]No
destination_port_objectsListStringNo
source_network_literalsListStringNo
source_network_objectsListStringNo
source_sgt_objectsListStringNo
source_port_literalsList[source_port_literals]No
source_port_objectsListStringNo

destination_port_literals (fmc.domains.objects.extended_access_lists.entries)

NameTypeConstraintMandatoryDefault Value
portIntegermin: 1, max: 65535Yes
protocolChoiceTCP, UDPYes

Examples

Prerequisites:

fmc:
domains:
- name: Global
objects:
hosts:
- name: MyHostName1
ip: 10.10.10.10
networks:
- name: MyNetworkName1
prefix: 10.10.10.0/24
ports:
- name: MyPortName1
port: 8080
protocol: TCP
sgts:
- name: MySGTName1
tag: 123

Extended Access List:

fmc:
domains:
- name: Global
objects:
extended_access_lists:
- name: MyExtendedACLName1
entries:
- action: PERMIT
logging: DEFAULT
source_network_literals:
- 13.13.13.13
source_network_objects:
- MyHostName1
source_port_literals:
- protocol: TCP
port: 8080
source_port_objects:
- MyPortName1
source_sgt_objects:
- MySGTName1
destination_network_literals:
- 13.13.13.13
destination_network_objects:
- MyNetworkName1
destination_port_literals:
- protocol: TCP
port: 8080
destination_port_objects:
- HTTPS