All Products
Search
Document Center

Cloud Firewall:DescribeVpcFirewallDetail

Last Updated:Oct 23, 2024

Queries the details about a virtual private cloud (VPC) firewall. The VPC firewall controls traffic between two VPCs that are connected by using an Express Connect circuit.

Operation description

You can call the DescribeVpcFirewallDetail operation to query the details about a VPC firewall. The VPC firewall controls traffic between two VPCs that are connected by using an Express Connect circuit.

Before you call the operation, make sure that you created a VPC firewall by calling the CreateVpcFirewallConfigure operation.

Limits

You can call this operation up to 10 times per second per account. If the number of the calls per second exceeds the limit, throttling is triggered. As a result, your business may be affected. We recommend that you take note of the limit when you call this operation.

Debugging

You can run this interface directly in OpenAPI Explorer, saving you the trouble of calculating signatures. After running successfully, OpenAPI Explorer can automatically generate SDK code samples.

Authorization information

The following table shows the authorization information corresponding to the API. The authorization information can be used in the Action policy element to grant a RAM user or RAM role the permissions to call this API operation. Description:

  • Operation: the value that you can use in the Action element to specify the operation on a resource.
  • Access level: the access level of each operation. The levels are read, write, and list.
  • Resource type: the type of the resource on which you can authorize the RAM user or the RAM role to perform the operation. Take note of the following items:
    • The required resource types are displayed in bold characters.
    • If the permissions cannot be granted at the resource level, All Resources is used in the Resource type column of the operation.
  • Condition Key: the condition key that is defined by the cloud service.
  • Associated operation: other operations that the RAM user or the RAM role must have permissions to perform to complete the operation. To complete the operation, the RAM user or the RAM role must have the permissions to perform the associated operations.
OperationAccess levelResource typeCondition keyAssociated operation
yundun-cloudfirewall:DescribeVpcFirewallDetailget
  • All Resources
    *
    none
none

Request parameters

ParameterTypeRequiredDescriptionExample
LangstringNo

The natural language of the request and response. Valid values:

  • zh: Chinese (default)
  • en: English
zh
VpcFirewallIdstringYes

The instance ID of the VPC firewall.

Note You can call the DescribeVpcFirewallList operation to query the instance IDs of VPC firewalls.
vfw-m5e7dbc4y****
LocalVpcIdstringNo

The ID of the local VPC.

vpc-8vbwbo90rq0anm6t****
PeerVpcIdstringNo

The ID of the peer VPC.

vpc-90rq0anm6t8vbwbo****

Response parameters

ParameterTypeDescriptionExample
object
ConnectTypestring

The connection type of the VPC firewall. The value is fixed as expressconnect, which indicates Express Connect circuits.

expressconnect
VpcFirewallIdstring

The instance ID of the VPC firewall.

vfw-m5e7dbc4y****
RequestIdstring

The ID of the request.

850A84D6-0DE4-4797-A1E8-00090125g4d2
Bandwidthinteger

The bandwidth of the Express Connect circuit. Unit: Mbit/s.

2
VpcFirewallNamestring

The instance name of the VPC firewall.

tf-test
FirewallSwitchStatusstring

The status of the VPC firewall. Valid values:

  • opened: The VPC firewall is enabled.
  • closed: The VPC firewall is disabled.
  • notconfigured: The VPC firewall is not configured.
  • configured: The VPC firewall is configured.
opened
LocalVpcobject

The details about the local VPC.

VpcIdstring

The ID of the local VPC.

vpc-8vbwbo90rq0anm6t****
VpcNamestring

The name of the local VPC.

Vitasoy
RegionNostring

The region ID of the local VPC.

cn-hangzhou
EniPrivateIpAddressstring

The private IP address of the elastic network interface (ENI) for the local VPC.

192.168.XX.XX
RouterInterfaceIdstring

The router interface ID of the local VPC.

vrt-m5eb5me6c3l5sezae****
EniIdstring

The ID of the ENI for the local VPC.

eni-8vbhfosfqv2rff42****
VpcCidrTableListarray<object>

The CIDR blocks of the local VPC.

cidrTableobject
RouteTableIdstring

The ID of the route table for the local VPC.

vtb-1234
RouteEntryListarray<object>

The route entries of the local VPC.

routeEntryobject
NextHopInstanceIdstring

The instance ID of the next hop for the local VPC.

vrt-m5eb5me6c3l5sezae****
DestinationCidrstring

The destination CIDR block of the local VPC.

192.168.XX.XX/24
PeerVpcobject

The details about the peer VPC.

VpcIdstring

The ID of the peer VPC.

vpc-90rq0anm6t8vbwbo****
VpcNamestring

The name of the peer VPC.

zcy_prod
RegionNostring

The region ID of the peer VPC.

cn-hangzhou
EniPrivateIpAddressstring

The private IP address of the ENI for the peer VPC.

192.168.XX.XX
RouterInterfaceIdstring

The router interface ID of the peer VPC.

vrt-m5eb5me6c3l5sezae****
EniIdstring

The ID of the ENI for the peer VPC.

eni-8vbhfosfqv2rff42****
VpcCidrTableListarray<object>

The CIDR blocks of the peer VPC.

cidrTableobject
RouteTableIdstring

The ID of the route table for the peer VPC.

vtb-1256
RouteEntryListarray<object>

The route entries of the peer VPC.

routeEntryobject
NextHopInstanceIdstring

The instance ID of the next hop for the peer VPC.

vrt-m5eb5me6c3l5sezae****
DestinationCidrstring

The destination CIDR block of the peer VPC.

192.168.XX.XX/24
MemberUidstring

The UID of the member that is managed by your Alibaba Cloud account.

258039427902****

Examples

Sample success responses

JSONformat

{
  "ConnectType": "expressconnect",
  "VpcFirewallId": "vfw-m5e7dbc4y****",
  "RequestId": "850A84D6-0DE4-4797-A1E8-00090125g4d2",
  "Bandwidth": 2,
  "VpcFirewallName": "tf-test",
  "FirewallSwitchStatus": "opened",
  "LocalVpc": {
    "VpcId": "vpc-8vbwbo90rq0anm6t****",
    "VpcName": "Vitasoy",
    "RegionNo": "cn-hangzhou",
    "EniPrivateIpAddress": "192.168.XX.XX",
    "RouterInterfaceId": "vrt-m5eb5me6c3l5sezae****",
    "EniId": "eni-8vbhfosfqv2rff42****",
    "VpcCidrTableList": [
      {
        "RouteTableId": "vtb-1234",
        "RouteEntryList": [
          {
            "NextHopInstanceId": "vrt-m5eb5me6c3l5sezae****",
            "DestinationCidr": "192.168.XX.XX/24"
          }
        ]
      }
    ]
  },
  "PeerVpc": {
    "VpcId": "vpc-90rq0anm6t8vbwbo****",
    "VpcName": "zcy_prod",
    "RegionNo": "cn-hangzhou",
    "EniPrivateIpAddress": "192.168.XX.XX",
    "RouterInterfaceId": "vrt-m5eb5me6c3l5sezae****",
    "EniId": "eni-8vbhfosfqv2rff42****",
    "VpcCidrTableList": [
      {
        "RouteTableId": "vtb-1256",
        "RouteEntryList": [
          {
            "NextHopInstanceId": "vrt-m5eb5me6c3l5sezae****",
            "DestinationCidr": "192.168.XX.XX/24"
          }
        ]
      }
    ]
  },
  "MemberUid": "258039427902****"
}

Error codes

HTTP status codeError codeError messageDescription
400ErrorAliUidThe aliuid is invalid.The aliuid is invalid.
400ErrorFirewallNotFoundFirewall not foundThe firewall does not exist.
400ErrorDBSelectErrorA database select error occurred.The error message returned because an internal error has occurred in querying the database.
400ErrorInvalidMemberUidMember uid is invalidThe member is invalid.
400ErrorFirewallStatusfirewall status error.Firewall status error, please try again later.
400ErrorVpcIdParavpc id and firewall id parameter not exist.The firewall VPC parameter is incorrect. Select another one.
400ErrorLocalVpcIdPeerVpcIdErrorlocal vpc id and peer vpc id cannot be empty at the same time.The firewall VPC parameter is incorrect. Select another one.

For a list of error codes, visit the Service error codes.

Change history

Change timeSummary of changesOperation
2024-09-05The Error code has changedView Change Details
2022-12-08API Description Update. The Error code has changed. The response structure of the API has changedView Change Details