Firewall class final
Represents a Firewall Rule resource.
Firewall rules allow or deny ingress traffic to, and egress traffic from your instances. For more information, readFirewall rules.
Constructors
-
Firewall({List<
Allowed> allowed = const [], String? creationTimestamp, List<Denied> denied = const [], String? description, List<String> destinationRanges = const [], String? direction, bool? disabled, BigInt? id, String? kind, FirewallLogConfig? logConfig, String? name, String? network, FirewallParams? params, int? priority, String? selfLink, List<String> sourceRanges = const [], List<String> sourceServiceAccounts = const [], List<String> sourceTags = const [], List<String> targetServiceAccounts = const [], List<String> targetTags = const []}) - Firewall.fromJson(Object? j)
-
factory
Properties
-
allowed
→ List<
Allowed> -
The list of ALLOW rules specified by this firewall. Each rule specifies a
protocol and port-range tuple that describes a permitted connection.
final
- creationTimestamp → String?
-
Output only.
Output OnlyCreation timestamp inRFC3339 text format.final -
denied
→ List<
Denied> -
The list of DENY rules specified by this firewall. Each rule specifies a
protocol and port-range tuple that describes a denied connection.
final
- description → String?
-
An optional description of this resource. Provide this field when you
create the resource.
final
-
destinationRanges
→ List<
String> -
If destination ranges are specified, the firewall rule applies only to
traffic that has destination IP address in these ranges. These ranges must
be expressed inCIDR format. Both IPv4 and IPv6 are supported.
final
- direction → String?
-
Direction of traffic to which this firewall applies, either
INGRESSorEGRESS. The default isINGRESS. ForEGRESStraffic, you cannot specify the sourceTags fields. Check the Direction enum for the list of possible values.final - disabled → bool?
-
Denotes whether the firewall rule is disabled. When set to true, the
firewall rule is not enforced and the network behaves as if it did not
exist. If this is unspecified, the firewall rule will be enabled.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- id → BigInt?
-
Output only.
Output OnlyThe unique identifier for the resource. This identifier is defined by the server.final - kind → String?
-
Output only.
Output OnlyType of the resource. Always compute#firewall for firewall rules.final - logConfig → FirewallLogConfig?
-
This field denotes the logging options for a particular firewall rule. If
logging is enabled, logs will be exported to Cloud Logging.
final
- name → String?
-
Name of the resource; provided by the client when the resource is created.
The name must be 1-63 characters long, and comply withRFC1035.
Specifically, the name must be 1-63 characters long and match the regular
expression
[a-z]([-a-z0-9]*[a-z0-9])?. The first character must be a lowercase letter, and all following characters (except for the last character) must be a dash, lowercase letter, or digit. The last character must be a lowercase letter or digit.final - network → String?
-
URL of the network resource for this firewall rule. If not
specified when creating a firewall rule, the default network
is used:
final
- params → FirewallParams?
-
Input only.
Input OnlyAdditional params passed with the request, but not persisted as part of resource payload.final - priority → int?
-
Priority for this rule.
This is an integer between
0and65535, both inclusive. The default value is1000. Relative priorities determine which rule takes effect if multiple rules apply. Lower values indicate higher priority. For example, a rule with priority0has higher precedence than a rule with priority1. DENY rules take precedence over ALLOW rules if they have equal priority. Note that VPC networks have implied rules with a priority of65535. To avoid conflicts with the implied rules, use a priority number less than65535.final - qualifiedName → String
-
The fully qualified name of this message, i.e.,
google.protobuf.Durationorgoogle.rpc.ErrorInfo.finalinherited - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- selfLink → String?
-
Output OnlyServer-defined URL for the resource.final -
sourceRanges
→ List<
String> -
If source ranges are specified, the firewall rule applies only to traffic
that has a source IP address in these ranges. These ranges must be
expressed inCIDR format. One or both of sourceRanges
and sourceTags may be set.
If both fields are set, the rule applies to traffic that has a
source IP address within sourceRanges OR a source IP
from a resource with a matching tag listed in thesourceTags field. The connection does not need to match
both fields for the rule to
apply. Both IPv4 and IPv6 are supported.
final
-
sourceServiceAccounts
→ List<
String> -
If source service accounts are specified, the firewall rules apply only to
traffic originating from an instance with a service account in this list.
Source service accounts cannot be used to control traffic to an instance's
external IP address because service accounts are associated with an
instance, not an IP address.sourceRanges can be set at the same time assourceServiceAccounts.
If both are set, the firewall applies to traffic that
has a source IP address within the sourceRanges OR a source
IP that belongs to an instance with service account listed insourceServiceAccount. The connection does not need to match
both fields for the firewall to apply.sourceServiceAccounts cannot be used at the same time assourceTags or targetTags.
final
-
sourceTags
→ List<
String> -
If source tags are specified, the firewall rule applies only to traffic
with source IPs that match the primary network interfaces of VM instances
that have the tag and are in the same VPC network.
Source tags cannot be used to control traffic to an instance's external IP
address, it only applies to traffic between instances in the same virtual
network. Because tags are associated with instances, not IP addresses.
One or both of sourceRanges and sourceTags may be
set. If both fields are set, the firewall applies to traffic that has a
source IP address within sourceRanges OR a source IP from a
resource with a matching tag listed in the sourceTags
field. The connection does not need to match both fields for the
firewall to apply.
final
-
targetServiceAccounts
→ List<
String> -
A list of service accounts indicating sets of instances located in the
network that may make network connections as specified inallowed[].targetServiceAccounts cannot be used at the same time astargetTags or sourceTags.
If neither targetServiceAccounts nor targetTags
are specified, the firewall rule applies to all instances on the specified
network.
final
-
targetTags
→ List<
String> -
A list of tags that controls which instances the firewall rule
applies to. If targetTags are specified, then the firewall
rule applies only to instances in the VPC network that have one of those
tags. If no targetTags are specified, the firewall rule
applies to all instances on the specified network.
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Object -
toString(
) → String -
A string representation of this object.
override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Constants
- fullyQualifiedName → const String