授权信息

访问控制(RAM)是阿里云提供的管理用户身份与资源访问权限的服务。使用 RAM 可以让您避免与其他用户共享阿里云账号密钥,并可按需为用户授予最小权限。RAM 中使用权限策略描述授权的具体内容。

本文为您介绍 云防火墙 为 RAM 权限策略定义的操作(Action)、资源(Resource)和条件(Condition)。 云防火墙 的 RAM 代码(RamCode)为 yundun-cloudfirewall ,支持的授权粒度为 资源级

权限策略通用结构

权限策略支持 JSON 格式,其通用结构如下:

{
  "Version": "1",
  "Statement": [
    {
      "Effect": "<Effect>",
      "Action": "<Action>",
      "Resource": "<Resource>",
      "Condition": {
        "<Condition_operator>": {
          "<Condition_key>": [
            "<Condition_value>"
          ]
        }
      }
    }
  ]
}        

各字段含义如下:

  • Effect:权限策略效果。取值:Allow(允许)、Deny(拒绝)。

  • Action:授予允许或拒绝权限的具体操作。具体信息,请参见操作(Action)

  • Resource:受操作影响的具体对象,您可以使用资源 ARN 来描述指定资源。具体信息,请参见资源(Resource)

  • Condition:指授权生效的条件。可选字段。具体信息,请参见条件(Condition)

    • Condition_operator:条件运算符,不同类型的条件对应不同的条件运算符。具体信息,请参见权限策略基本元素

    • Condition_key:条件关键字。

    • Condition_value:条件关键字对应的值。

操作(Action)

下表是云防火墙定义的操作,这些操作可以在 RAM 权限策略语句的Action元素中使用,用来授予执行该操作的权限。下面对表中的具体项提供说明:

  • 操作:是指具体的权限点。

  • API:是指操作对应的 API 接口。

  • 访问级别:是指每个操作的访问级别,取值为写入(Write)、读取(Read)或列出(List)。

  • 资源类型:是指操作中支持授权的资源类型。具体说明如下:

    • 对于必选的资源类型,用前面加 * 表示。

    • 对于不支持资源级授权的操作,用全部资源表示。

  • 条件关键字:是指云产品自身定义的条件关键字。该列不体现适用于任何操作的通用条件关键字

  • 关联操作:是指成功执行操作所需要的其他权限。操作者必须同时具备关联操作的权限,操作才能成功。

操作

API

访问级别

资源类型

条件关键字

关联操作

yundun-cloudfirewall:DescribeUserBuyVersion DescribeUserBuyVersion get

*全部资源

*

yundun-cloudfirewall:DescribeResourceTypeAutoEnable DescribeResourceTypeAutoEnable none

*全部资源

*

yundun-cloudfirewall:DescribePostpayUserInternetStatus DescribePostpayUserInternetStatus get

*全部资源

*

yundun-cloudfirewall:ModifyDnsFirewallPolicy ModifyDnsFirewallPolicy update

*DnsFirewallPolicy

acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeRiskSecurityGroupDetail DescribeRiskSecurityGroupDetail get

*全部资源

*

yundun-cloudfirewall:ModifyIpsRulesToDefault ModifyIpsRulesToDefault get

*全部资源

*

yundun-cloudfirewall:DescribeAclRuleCount DescribeAclRuleCount get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyHitData DescribeStrategyHitData get

*全部资源

*

yundun-cloudfirewall:ModifySlsDispatchStatus ModifySlsDispatchStatus update

*全部资源

*

yundun-cloudfirewall:DescribeTlsInspectFeature DescribeTlsInspectFeature get

*全部资源

*

yundun-cloudfirewall:DescribeVulnerabilityResourceList DescribeVulnerabilityResourceList get

*全部资源

*

yundun-cloudfirewall:DescribeDownloadTaskType DescribeDownloadTaskType get

*全部资源

*

yundun-cloudfirewall:CreateTlsInspectAssociation CreateTlsInspectAssociation create

*TlsInspectAssociation

acs:cloudfirewall::{#accountId}:tlsinspectassociation/*

yundun-cloudfirewall:DescribeVpcFirewallCenDetail DescribeVpcFirewallCenDetail get

*VpcFirewallCen

acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}

yundun-cloudfirewall:ModifyStrategyGroupCheckRuleStatus ModifyStrategyGroupCheckRuleStatus update

*全部资源

*

yundun-cloudfirewall:UpdateAITrafficAnalysisStatus UpdateAITrafficAnalysisStatus none

*AiTrafficAnalysisStatus

acs:yundun-cloudfirewall::{#accountId}:aitrafficanalysisstatus/*

yundun-cloudfirewall:ResetRuleHitCount ResetRuleHitCount none

*全部资源

*

yundun-cloudfirewall:DescribeApp DescribeApp get

*全部资源

*

yundun-cloudfirewall:CreateNatFirewallControlPolicy CreateNatFirewallControlPolicy create

*NatFirewallControlPolicy

acs:yundun-cloudfirewall::{#accountId}:natfirewallcontrolpolicy/*

yundun-cloudfirewall:CreateBiz CreateBiz create

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallAclGroupList DescribeNatFirewallAclGroupList get

*全部资源

*

yundun-cloudfirewall:AddControlPolicy AddControlPolicy create

*ControlPolicy

acs:cloudfirewall::{#accountId}:controlpolicy/*

yundun-cloudfirewall:ResetVpcFirewallRuleHitCount ResetVpcFirewallRuleHitCount update

*VpcFirewallControlPolicy

acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeNatFirewallList DescribeNatFirewallList get

*NatFirewall

acs:cloudfirewall::{#accountId}:natfirewall/{#ProxyId}

yundun-cloudfirewall:OpenTlsInspectFeature OpenTlsInspectFeature update

*全部资源

*

yundun-cloudfirewall:DescribeAclChecks DescribeAclChecks get

*全部资源

*

yundun-cloudfirewall:DescribeApplicationPortDetail DescribeApplicationPortDetail get

*全部资源

*

yundun-cloudfirewall:DescribePrivateDnsEndpointList DescribePrivateDnsEndpointList get

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:CreateSecurityProxy CreateSecurityProxy get

*全部资源

*

yundun-cloudfirewall:DescribeAssetRiskList DescribeAssetRiskList get

*全部资源

*

yundun-cloudfirewall:DescribeSensitiveSwitch DescribeSensitiveSwitch none

*全部资源

*

yundun-cloudfirewall:DescribeAccessInstanceVSwitchList DescribeAccessInstanceVSwitchList none

*全部资源

*

yundun-cloudfirewall:DescribeDownloadTask DescribeDownloadTask get

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallPolicyPriorUsed DescribeNatFirewallPolicyPriorUsed get

*全部资源

*

yundun-cloudfirewall:DeleteAppGroup DeleteAppGroup delete

*全部资源

*

yundun-cloudfirewall:DeleteTlsInspectScope DeleteTlsInspectScope delete

*TlsInspectScope

acs:cloudfirewall::{#accountId}:tlsinspectscope/{#TlsInspectScopeId}

yundun-cloudfirewall:CreateSrNatFirewall CreateSrNatFirewall create

*全部资源

*

yundun-cloudfirewall:DescribeSrNatFirewallRegion DescribeSrNatFirewallRegion get

*全部资源

*

yundun-cloudfirewall:CreatePrivateDnsEndpoint CreatePrivateDnsEndpoint create

*PrivateDNS

acs:yundun-cloudfirewall::{#accountId}:privatedns/*

yundun-cloudfirewall:AddDomainResolveRealtimeTask AddDomainResolveRealtimeTask create

*全部资源

*

yundun-cloudfirewall:ModifyTrFirewallV2RoutePolicyScope ModifyTrFirewallV2RoutePolicyScope update

*VpcCenTrFirewallPolicy

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}

yundun-cloudfirewall:DescribeNatFirewallQuota DescribeNatFirewallQuota get

*全部资源

*

yundun-cloudfirewall:ModifyCfwInstance ModifyCfwInstance update

*全部资源

*

yundun-cloudfirewall:DescribePostpayTrafficTotal DescribePostpayTrafficTotal get

*全部资源

*

yundun-cloudfirewall:DescribeIPSAttackTypeList DescribeIPSAttackTypeList get

*全部资源

*

yundun-cloudfirewall:DescribeAckClusterConnector DescribeAckClusterConnector get

*全部资源

*

yundun-cloudfirewall:DeleteApp DeleteApp delete

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallPageShowStatus DescribeVpcFirewallPageShowStatus get

*全部资源

*

yundun-cloudfirewall:CreateAclCheck CreateAclCheck create

*全部资源

*

yundun-cloudfirewall:ModifyInstanceMemberAttributes ModifyInstanceMemberAttributes update

*InstanceMember

acs:cloudfirewall::{#accountId}:instancemember/{#MemberUid}

yundun-cloudfirewall:ModifyThreatIntelligenceSwitch ModifyThreatIntelligenceSwitch none

*ThreatIntelligenceSwitch

acs:cloudfirewall::{#accountId}:threatintelligenceswitch/{#CategoryId}

yundun-cloudfirewall:ModifyVpcFirewallSwitchStatus ModifyVpcFirewallSwitchStatus update

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:DeleteVpcFirewallCenManualConfigure DeleteVpcFirewallCenManualConfigure delete

*全部资源

*

yundun-cloudfirewall:UpdatePostpayUserNatStatus UpdatePostpayUserNatStatus get

*全部资源

*

yundun-cloudfirewall:GetTlsInspectTrialCaCertificateTask GetTlsInspectTrialCaCertificateTask get

*全部资源

*

yundun-cloudfirewall:DescribeVpcInstanceList DescribeVpcInstanceList get

*全部资源

*

yundun-cloudfirewall:AddSlrGrant AddSlrGrant none

*全部资源

*

yundun-cloudfirewall:DescribePrepayBillTotal DescribePrepayBillTotal get

*全部资源

*

yundun-cloudfirewall:CreateInstanceSyncTask CreateInstanceSyncTask create

*全部资源

*

yundun-cloudfirewall:DescribeAccessInstanceRegionList DescribeAccessInstanceRegionList none

*全部资源

*

yundun-cloudfirewall:DescribeSdlEventList DescribeSdlEventList none

*全部资源

*

yundun-cloudfirewall:DeleteCaptureTask DeleteCaptureTask delete

*全部资源

*

yundun-cloudfirewall:DescribeVulnDefenseStatus DescribeVulnDefenseStatus get

*全部资源

*

yundun-cloudfirewall:UpdateAckClusterConnector UpdateAckClusterConnector update

*全部资源

*

yundun-cloudfirewall:DescribeIPSRules DescribeIPSRules get

*全部资源

*

yundun-cloudfirewall:ListTlsInspectRules ListTlsInspectRules get

*TlsInspectRule

acs:cloudfirewall::{#accountId}:tlsinspectrule/{#TlsInspectRuleId}

yundun-cloudfirewall:MarkDestination MarkDestination none

*全部资源

*

yundun-cloudfirewall:DescribeAppListWithRelation DescribeAppListWithRelation get

*全部资源

*

yundun-cloudfirewall:DescribeTopologySummaryInfo DescribeTopologySummaryInfo get

*全部资源

*

yundun-cloudfirewall:DescribePrivateDnsDomainNameList DescribePrivateDnsDomainNameList get

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:CreateDnsFirewall CreateDnsFirewall create

*全部资源

*

yundun-cloudfirewall:DescribeUnprotectedVulnTrend DescribeUnprotectedVulnTrend get

*全部资源

*

yundun-cloudfirewall:CreateVpcFirewallControlPolicy CreateVpcFirewallControlPolicy create

*VpcFirewallControlPolicy

acs:cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/*

yundun-cloudfirewall:DescribeOutgoingDomainDetail DescribeOutgoingDomainDetail get

*全部资源

*

yundun-cloudfirewall:DescribeTlsInspectStatistics DescribeTlsInspectStatistics get

*全部资源

*

yundun-cloudfirewall:DescribeAclBackupList DescribeAclBackupList get

*全部资源

*

yundun-cloudfirewall:PutEnableFwSwitch PutEnableFwSwitch update

*全部资源

*

yundun-cloudfirewall:DescribeAppProduceList DescribeAppProduceList get

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallControlPolicy DescribeNatFirewallControlPolicy list

*NatFirewallControlPolicy

acs:cloudfirewall::{#accountId}:natfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:ListTlsInspectCACertificates ListTlsInspectCACertificates list

*TlsInspectCaCertificate

acs:cloudfirewall::{#accountId}:tlsinspectcacertificate/{#CaCertId}

yundun-cloudfirewall:DescribeVpcFirewallDetail DescribeVpcFirewallDetail get

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:DescribeVpcFirewallSessionTop DescribeVpcFirewallSessionTop get

*全部资源

*

yundun-cloudfirewall:DescribePrivateDnsStatistics DescribePrivateDnsStatistics none

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallAssetRegionList DescribeVpcFirewallAssetRegionList none

*全部资源

*

yundun-cloudfirewall:ModifyUserIPSWhitelist ModifyUserIPSWhitelist update

*全部资源

*

yundun-cloudfirewall:CreateVpcFirewallCenConfigure CreateVpcFirewallCenConfigure create

*VpcFirewallCen

acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcen/*

yundun-cloudfirewall:DescribeAppListByEcs DescribeAppListByEcs get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyDiff DescribeStrategyDiff get

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupProduceAppList DescribeAppGroupProduceAppList get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallManualVSwitchList DescribeVpcFirewallManualVSwitchList get

*全部资源

*

yundun-cloudfirewall:DeleteBuyProbation DeleteBuyProbation delete

*全部资源

*

yundun-cloudfirewall:DisableSdlProtectedAsset DisableSdlProtectedAsset update

*全部资源

*

yundun-cloudfirewall:DescribeApplicationPortRatio DescribeApplicationPortRatio get

*全部资源

*

yundun-cloudfirewall:DescribeDnsFirewallPolicy DescribeDnsFirewallPolicy get

*DnsFirewallPolicy

acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/{#AclUuid}

yundun-cloudfirewall:DescribePostpayUserNatStatus DescribePostpayUserNatStatus get

*全部资源

*

yundun-cloudfirewall:DescribeIPSTrend DescribeIPSTrend get

*全部资源

*

yundun-cloudfirewall:DescribeCfwRiskLevelSummary DescribeCfwRiskLevelSummary get

*全部资源

*

yundun-cloudfirewall:DescribeAckClusters DescribeAckClusters get

*全部资源

*

yundun-cloudfirewall:ModifyDefaultIPSConfig ModifyDefaultIPSConfig get

*全部资源

*

yundun-cloudfirewall:DescribeInvadeEcsTrend DescribeInvadeEcsTrend get

*全部资源

*

yundun-cloudfirewall:DescribeInternetOpenDetail DescribeInternetOpenDetail get

*全部资源

*

yundun-cloudfirewall:DescribeTrFirewallsV2List DescribeTrFirewallsV2List get

*VpcCenTrFirewall

acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}

yundun-cloudfirewall:BatchUpdateAppGroupId BatchUpdateAppGroupId update

*全部资源

*

yundun-cloudfirewall:DescribeVpcSnapList DescribeVpcSnapList get

*全部资源

*

yundun-cloudfirewall:DeleteInstanceMembers DeleteInstanceMembers delete

*InstanceMember

acs:cloudfirewall::{#accountId}:instancemember/{#MemberUid}

yundun-cloudfirewall:DescribeGLobalInstance DescribeGLobalInstance get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupRule DescribeStrategyGroupRule get

*全部资源

*

yundun-cloudfirewall:AddAddressBook AddAddressBook create

*AddressBook

acs:yundun-cloudfirewall::{#accountId}:addressbook/*

yundun-cloudfirewall:DescribeEcsInfo DescribeEcsInfo get

*全部资源

*

yundun-cloudfirewall:SetAutoProtectNewAssets SetAutoProtectNewAssets get

*全部资源

*

yundun-cloudfirewall:DescribeTrFirewallV2RoutePolicyList DescribeTrFirewallV2RoutePolicyList get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkTrafficList DescribeNetworkTrafficList get

*全部资源

*

yundun-cloudfirewall:CreateStrategyGroup CreateStrategyGroup get

*全部资源

*

yundun-cloudfirewall:DescribeVfwIPSConfigList DescribeVfwIPSConfigList list

*全部资源

*

yundun-cloudfirewall:DescribeVpcRelationList DescribeVpcRelationList get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkTrafficDataType DescribeNetworkTrafficDataType get

*全部资源

*

yundun-cloudfirewall:DeleteControlPolicyBatch DeleteControlPolicyBatch get

*全部资源

*

yundun-cloudfirewall:DeleteFirewallV2RoutePolicies DeleteFirewallV2RoutePolicies delete

*VpcCenTrFirewallPolicy

acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}

yundun-cloudfirewall:DeleteDnsFirewall DeleteDnsFirewall delete

*全部资源

*

yundun-cloudfirewall:ModifyApp ModifyApp update

*全部资源

*

yundun-cloudfirewall:DescribeAttackApp DescribeAttackApp get

*全部资源

*

yundun-cloudfirewall:DescribeSystemLog DescribeSystemLog get

*全部资源

*

yundun-cloudfirewall:DescribeBizList DescribeBizList get

*全部资源

*

yundun-cloudfirewall:ModifyAddressBook ModifyAddressBook update

*AddressBook

acs:yundun-cloudfirewall::{#accountId}:addressbook/{#GroupUuid}

yundun-cloudfirewall:DescribeNetworkTrafficTrend DescribeNetworkTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallAclGroupList DescribeVpcFirewallAclGroupList get

*全部资源

*

yundun-cloudfirewall:UpdatePostpayUserVpcStatus UpdatePostpayUserVpcStatus update

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallVpcTrafficList DescribeVpcFirewallVpcTrafficList get

*全部资源

*

yundun-cloudfirewall:DescribeProductFeatures DescribeProductFeatures get

*全部资源

*

yundun-cloudfirewall:DeleteVpcFirewallConfigure DeleteVpcFirewallConfigure delete

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:SwitchSecurityProxy SwitchSecurityProxy none

*NatFirewall

acs:cloudfirewall::{#accountId}:natfirewall/{#ProxyId}

yundun-cloudfirewall:DeleteControlPolicy DeleteControlPolicy delete

*ControlPolicy

acs:yundun-cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}

yundun-cloudfirewall:ModifyBiz ModifyBiz update

*全部资源

*

yundun-cloudfirewall:DescribeControlPolicy DescribeControlPolicy get

*ControlPolicyOrder

acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}/controlpolicyorder/{#Direction}

*ControlPolicy

acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeUserIPSWhitelist DescribeUserIPSWhitelist get

*全部资源

*

yundun-cloudfirewall:DescribeAttackType DescribeAttackType get

*全部资源

*

yundun-cloudfirewall:DescribeInternetDropTrafficTrend DescribeInternetDropTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DeleteStrategyGroupRule DeleteStrategyGroupRule get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroups DescribeStrategyGroups get

*全部资源

*

yundun-cloudfirewall:DescribeInvadeEventDetail DescribeInvadeEventDetail get

*全部资源

*

yundun-cloudfirewall:DeleteDnsFirewallPolicy DeleteDnsFirewallPolicy delete

*DnsFirewallPolicy

acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeBizFlowDetail DescribeBizFlowDetail get

*全部资源

*

yundun-cloudfirewall:DescribeAssetStatistic DescribeAssetStatistic get

*全部资源

*

yundun-cloudfirewall:DescribeUserBandwithDetail DescribeUserBandwithDetail get

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallPrecheckDetail DescribeNatFirewallPrecheckDetail get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallDropTrafficTrend DescribeVpcFirewallDropTrafficTrend get

*全部资源

*

yundun-cloudfirewall:AddSurveyInfo AddSurveyInfo create

*全部资源

*

yundun-cloudfirewall:DescribeVpcListLite DescribeVpcListLite get

*全部资源

*

yundun-cloudfirewall:DescribeInvadeEventStatistic DescribeInvadeEventStatistic get

*全部资源

*

yundun-cloudfirewall:ModifyFirstFlowConfig ModifyFirstFlowConfig update

*全部资源

*

yundun-cloudfirewall:DescribeInternetOpenPort DescribeInternetOpenPort get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupCheckRuleResult DescribeStrategyGroupCheckRuleResult get

*全部资源

*

yundun-cloudfirewall:AddPrivateDnsDomainName AddPrivateDnsDomainName create

*PrivateDNS

acs:yundun-cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:UpgradeClassicSlbProtectMode UpgradeClassicSlbProtectMode update

*全部资源

*

yundun-cloudfirewall:DescribePolicyPriorUsed DescribePolicyPriorUsed list

*全部资源

*

yundun-cloudfirewall:DescribeStrategyTemplate DescribeStrategyTemplate get

*全部资源

*

yundun-cloudfirewall:DescribeRecommendedReason DescribeRecommendedReason get

*全部资源

*

yundun-cloudfirewall:DescribeMemberInfo DescribeMemberInfo get

*全部资源

*

yundun-cloudfirewall:DescribeHighRiskVulnList DescribeHighRiskVulnList get

*全部资源

*

yundun-cloudfirewall:DescribeAclCheck DescribeAclCheck get

*全部资源

*

yundun-cloudfirewall:DescribeVirtualPatches DescribeVirtualPatches get

*全部资源

*

yundun-cloudfirewall:DescribeAppInfo DescribeAppInfo get

*全部资源

*

yundun-cloudfirewall:DescribeSignatureLibVersion DescribeSignatureLibVersion get

*全部资源

*

yundun-cloudfirewall:DescribeIPList DescribeIPList get

*全部资源

*

yundun-cloudfirewall:DescribeConsumBizList DescribeConsumBizList get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkConcurrentTrend DescribeNetworkConcurrentTrend get

*全部资源

*

yundun-cloudfirewall:SwitchDnsFirewall SwitchDnsFirewall none

*全部资源

*

yundun-cloudfirewall:DescribeConfiguredDestinationPort DescribeConfiguredDestinationPort get

*全部资源

*

yundun-cloudfirewall:DeletePrivateDnsDomainName DeletePrivateDnsDomainName delete

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:DescribePostpayCreatedAcl DescribePostpayCreatedAcl get

*全部资源

*

yundun-cloudfirewall:DescribeInvadeEventList DescribeInvadeEventList get

*全部资源

*

yundun-cloudfirewall:DescribeRegionInfo DescribeRegionInfo list

*全部资源

*

yundun-cloudfirewall:DescribeSecurityProxy DescribeSecurityProxy get

*全部资源

*

yundun-cloudfirewall:DescribeInternetOpenIp DescribeInternetOpenIp get

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventStatistic DescribeRiskEventStatistic list

*全部资源

*

yundun-cloudfirewall:CreateDownloadTask CreateDownloadTask create

*全部资源

*

yundun-cloudfirewall:DescribeVulnCnt DescribeVulnCnt get

*全部资源

*

yundun-cloudfirewall:DescribeBizDetailList DescribeBizDetailList get

*全部资源

*

yundun-cloudfirewall:ModifyFirewallV2RoutePolicySwitch ModifyFirewallV2RoutePolicySwitch update

*VpcCenTrFirewallPolicy

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}

yundun-cloudfirewall:DescribeInternetTrafficTrend DescribeInternetTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribePolicyAdvancedConfig DescribePolicyAdvancedConfig list

*PolicyAdvancedConfig

acs:yundun-cloudfirewall::{#accountId}:policyadvancedconfig

yundun-cloudfirewall:DescribeVpcFirewallSummaryInfo DescribeVpcFirewallSummaryInfo get

*全部资源

*

yundun-cloudfirewall:DescribeEcsInstanceList DescribeEcsInstanceList get

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventGroup DescribeRiskEventGroup list

*全部资源

*

yundun-cloudfirewall:DescribeTrFirewallPolicyBackUpAssociationList DescribeTrFirewallPolicyBackUpAssociationList get

*VpcCenTrFirewallPolicy

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}

yundun-cloudfirewall:DescribeLogStoreInfo DescribeLogStoreInfo get

*全部资源

*

yundun-cloudfirewall:DescribeAclApps DescribeAclApps get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupPassRules DescribeStrategyGroupPassRules get

*全部资源

*

yundun-cloudfirewall:DescribeInternetTrafficTop DescribeInternetTrafficTop get

*全部资源

*

yundun-cloudfirewall:DescribeSlsAnalyzeOpenStatus DescribeSlsAnalyzeOpenStatus get

*全部资源

*

yundun-cloudfirewall:DescribeBizListWithRelation DescribeBizListWithRelation get

*全部资源

*

yundun-cloudfirewall:DescribeTaskLimitParam DescribeTaskLimitParam get

*全部资源

*

yundun-cloudfirewall:CreateAckClusterConnector CreateAckClusterConnector create

*全部资源

*

yundun-cloudfirewall:DescribeSdlEventStatistic DescribeSdlEventStatistic none

*全部资源

*

yundun-cloudfirewall:CreateAppGroup CreateAppGroup create

*全部资源

*

yundun-cloudfirewall:PutDisableFwSwitch PutDisableFwSwitch update

*全部资源

*

yundun-cloudfirewall:UseAclBackupData UseAclBackupData none

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallTimeTop DescribeNatFirewallTimeTop get

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupDetail DescribeAppGroupDetail get

*全部资源

*

yundun-cloudfirewall:CreateVpcFirewallTask CreateVpcFirewallTask create

*全部资源

*

yundun-cloudfirewall:ModifySecurityMode ModifySecurityMode update

*全部资源

*

yundun-cloudfirewall:DeleteVpcFirewallCenConfigure DeleteVpcFirewallCenConfigure delete

*VpcFirewallCen

acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}

yundun-cloudfirewall:ModifyVpcFirewallConfigure ModifyVpcFirewallConfigure update

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:DescribeGroupFlowDetail DescribeGroupFlowDetail get

*全部资源

*

yundun-cloudfirewall:CreateTlsInspectTrialCaCertificateTask CreateTlsInspectTrialCaCertificateTask create

*全部资源

*

yundun-cloudfirewall:DescribeInvadeEventNameList DescribeInvadeEventNameList get

*全部资源

*

yundun-cloudfirewall:ListTlsInspectScopes ListTlsInspectScopes get

*TlsInspectScope

acs:cloudfirewall::{#accountId}:tlsinspectscope/{#TlsInspectScopeId}

yundun-cloudfirewall:DescribeBizDetail DescribeBizDetail get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallZone DescribeVpcFirewallZone none

*全部资源

*

yundun-cloudfirewall:DeleteAddressBook DeleteAddressBook delete

*AddressBook

acs:cloudfirewall::{#accountId}:addressbook/{#GroupUuid}

yundun-cloudfirewall:ReleaseExpiredInstance ReleaseExpiredInstance get

*全部资源

*

yundun-cloudfirewall:DeletePrivateDnsEndpoint DeletePrivateDnsEndpoint delete

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:DescribeBizProduceAppGroupList DescribeBizProduceAppGroupList get

*全部资源

*

yundun-cloudfirewall:GetTlsInspectCertificateDownloadUrl GetTlsInspectCertificateDownloadUrl get

*TlsInspectCaCertificate

acs:yundun-cloudfirewall::{#accountId}:tlsinspectcacertificate/{#CaCertId}

yundun-cloudfirewall:ModifyUserAlarmConfig ModifyUserAlarmConfig update

*全部资源

*

yundun-cloudfirewall:UpdateDnsFirewall UpdateDnsFirewall update

*全部资源

*

yundun-cloudfirewall:CommitStrategyGroupRules CommitStrategyGroupRules get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallTrafficTop DescribeVpcFirewallTrafficTop get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallTrafficTrend DescribeVpcFirewallTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeIPSAttackAppList DescribeIPSAttackAppList get

*全部资源

*

yundun-cloudfirewall:DescribeAckClusterConnectors DescribeAckClusterConnectors get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallIPSWhitelist DescribeVpcFirewallIPSWhitelist get

*全部资源

*

yundun-cloudfirewall:CreateTrFirewallV2RoutePolicy CreateTrFirewallV2RoutePolicy create

*全部资源

*

yundun-cloudfirewall:DescribeDomainResolve DescribeDomainResolve get

*Domain

acs:yundun-cloudfirewall::{#accountId}:domain/{#Domain}

yundun-cloudfirewall:PutDisableAllFwSwitch PutDisableAllFwSwitch update

*全部资源

*

yundun-cloudfirewall:ModifyPrivateDnsEndpoint ModifyPrivateDnsEndpoint update

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:DescribeAppDetail DescribeAppDetail get

*全部资源

*

yundun-cloudfirewall:DescribeBizTopo DescribeBizTopo get

*全部资源

*

yundun-cloudfirewall:CreateCaptureTask CreateCaptureTask create

*全部资源

*

yundun-cloudfirewall:DeleteDownloadTask DeleteDownloadTask delete

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallPrecheckDetail DescribeVpcFirewallPrecheckDetail get

*全部资源

*

yundun-cloudfirewall:DescribeAppRelaList DescribeAppRelaList get

*全部资源

*

yundun-cloudfirewall:ModifyIpsRules ModifyIpsRules get

*全部资源

*

yundun-cloudfirewall:ModifyControlPolicy ModifyControlPolicy update

*ControlPolicy

acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeVpcFirewallControlPolicy DescribeVpcFirewallControlPolicy get

*VpcFirewallControlPolicy

acs:cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:DescribeRecommendAcls DescribeRecommendAcls get

*全部资源

*

yundun-cloudfirewall:DeleteAckClusterConnector DeleteAckClusterConnector delete

*全部资源

*

yundun-cloudfirewall:ModifyUserSlsLogStorageTime ModifyUserSlsLogStorageTime update

*全部资源

*

yundun-cloudfirewall:DeleteBiz DeleteBiz delete

*全部资源

*

yundun-cloudfirewall:DescribeAssetList DescribeAssetList get

*Asset

acs:cloudfirewall::{#accountId}:asset/{#Type}

yundun-cloudfirewall:DescribeSlrGrant DescribeSlrGrant get

*全部资源

*

yundun-cloudfirewall:DescribeSnatTableEntries DescribeSnatTableEntries get

*全部资源

*

yundun-cloudfirewall:DescribeInternetAccessSource DescribeInternetAccessSource get

*全部资源

*

yundun-cloudfirewall:DescribeNatAclPageStatus DescribeNatAclPageStatus get

*全部资源

*

yundun-cloudfirewall:AddDnsFirewallPolicy AddDnsFirewallPolicy get

*DnsFirewallPolicy

acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/*

yundun-cloudfirewall:DescribeVpcFirewallDefaultIPSConfig DescribeVpcFirewallDefaultIPSConfig get

*VpcFirewallIpsConfig

acs:cloudfirewall::{#accountId}:vpcfirewallipsconfig/{#VpcFirewallId}

yundun-cloudfirewall:DescribeUserGrayConfig DescribeUserGrayConfig get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallList DescribeVpcFirewallList get

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:DescribeAppGroupDetailList DescribeAppGroupDetailList get

*全部资源

*

yundun-cloudfirewall:AddStrategyGroupSyncTask AddStrategyGroupSyncTask get

*全部资源

*

yundun-cloudfirewall:DescribeBizRelaList DescribeBizRelaList get

*全部资源

*

yundun-cloudfirewall:IgnoreInvadeEvent IgnoreInvadeEvent none

*全部资源

*

yundun-cloudfirewall:DescribeUserAssetIPTrafficInfo DescribeUserAssetIPTrafficInfo get

*全部资源

*

yundun-cloudfirewall:DescribeAccessInstanceZoneList DescribeAccessInstanceZoneList none

*全部资源

*

yundun-cloudfirewall:DescribeVpcZone DescribeVpcZone list

*全部资源

*

yundun-cloudfirewall:DescribeInternetOpenStatistic DescribeInternetOpenStatistic get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupSyncStatus DescribeStrategyGroupSyncStatus get

*全部资源

*

yundun-cloudfirewall:DescribeUserIpsVersion DescribeUserIpsVersion get

*全部资源

*

yundun-cloudfirewall:DeletePrivateDnsAllDomainName DeletePrivateDnsAllDomainName delete

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:AddInstanceMembers AddInstanceMembers create

*InstanceMember

acs:yundun-cloudfirewall::{#accountId}:instancemember/*

yundun-cloudfirewall:DescribeVpcFirewallDomainList DescribeVpcFirewallDomainList get

*全部资源

*

yundun-cloudfirewall:ModifyObjectGroupOperation ModifyObjectGroupOperation update

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingDestinationIPDetail DescribeOutgoingDestinationIPDetail get

*全部资源

*

yundun-cloudfirewall:ModifyPolicyAdvancedConfig ModifyPolicyAdvancedConfig update

*PolicyAdvancedConfig

acs:yundun-cloudfirewall::{#accountId}:policyadvancedconfig

yundun-cloudfirewall:DescribeAclWhitelist DescribeAclWhitelist list

*全部资源

*

yundun-cloudfirewall:DescribePrivateDnsEndpointDetail DescribePrivateDnsEndpointDetail get

*PrivateDNS

acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}

yundun-cloudfirewall:ModifyControlPolicyPriority ModifyControlPolicyPriority get

*ControlPolicyOrder

acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}

yundun-cloudfirewall:CommitStrategyGroup CommitStrategyGroup get

*全部资源

*

yundun-cloudfirewall:ModifyNatFirewallControlPolicyPosition ModifyNatFirewallControlPolicyPosition update

*NatFirewallControlPolicy

acs:cloudfirewall::{#accountId}:natfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:CancelIgnoreInvadeEvent CancelIgnoreInvadeEvent none

*全部资源

*

yundun-cloudfirewall:DescribeUserInstanceInfo DescribeUserInstanceInfo get

*全部资源

*

yundun-cloudfirewall:DeleteTrFirewallV2 DeleteTrFirewallV2 delete

*VpcCenTrFirewall

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}

yundun-cloudfirewall:ListTlsInspectInternetAssets ListTlsInspectInternetAssets list

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingDestination DescribeOutgoingDestination get

*全部资源

*

yundun-cloudfirewall:DescribeEcsInstancesByTag DescribeEcsInstancesByTag get

*全部资源

*

yundun-cloudfirewall:DescribeFeatures DescribeFeatures get

*全部资源

*

yundun-cloudfirewall:DescribeUserDnsFirewallRegionVpc DescribeUserDnsFirewallRegionVpc get

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallControlPolicyPosition ModifyVpcFirewallControlPolicyPosition update

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupConsumAppList DescribeAppGroupConsumAppList get

*全部资源

*

yundun-cloudfirewall:DescribeAclCheckQuota DescribeAclCheckQuota get

*全部资源

*

yundun-cloudfirewall:DescribeDnsFirewall DescribeDnsFirewall get

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallControlPolicy ModifyVpcFirewallControlPolicy update

*VpcFirewallControlPolicy

acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeInstanceRiskLevels DescribeInstanceRiskLevels get

*全部资源

*

yundun-cloudfirewall:DeleteStrategyGroup DeleteStrategyGroup get

*全部资源

*

yundun-cloudfirewall:DescribeUserAlarmConfig DescribeUserAlarmConfig get

*全部资源

*

yundun-cloudfirewall:DeleteAclBackupData DeleteAclBackupData delete

*全部资源

*

yundun-cloudfirewall:DeleteIpsPrivateAssoc DeleteIpsPrivateAssoc delete

*全部资源

*

yundun-cloudfirewall:DescribeAppDetailList DescribeAppDetailList get

*全部资源

*

yundun-cloudfirewall:BatchDeleteVpcFirewallControlPolicy BatchDeleteVpcFirewallControlPolicy none

*全部资源

*

yundun-cloudfirewall:DescribePostpayTotalTraffic DescribePostpayTotalTraffic get

*全部资源

*

yundun-cloudfirewall:DescribePostpayBill DescribePostpayBill get

*全部资源

*

yundun-cloudfirewall:DescribeSecurityMode DescribeSecurityMode get

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingStatistic DescribeOutgoingStatistic get

*全部资源

*

yundun-cloudfirewall:DescribeProduceBizList DescribeProduceBizList list

*全部资源

*

yundun-cloudfirewall:DeleteControlPolicyTemplate DeleteControlPolicyTemplate delete

*全部资源

*

yundun-cloudfirewall:DescribeConfiguredDomainNames DescribeConfiguredDomainNames get

*全部资源

*

yundun-cloudfirewall:DeleteVpcFirewallControlPolicy DeleteVpcFirewallControlPolicy delete

*VpcFirewallControlPolicy

acs:cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:GetTlsInspectCaCertificateTrialStatus GetTlsInspectCaCertificateTrialStatus get

*全部资源

*

yundun-cloudfirewall:DescribeFirewallTask DescribeFirewallTask get

*全部资源

*

yundun-cloudfirewall:DescribeAckClusterNamespaces DescribeAckClusterNamespaces get

*全部资源

*

yundun-cloudfirewall:DescribeAITrafficAnalysisStatus DescribeAITrafficAnalysisStatus none

*AiTrafficAnalysisStatus

acs:yundun-cloudfirewall::{#accountId}:aitrafficanalysisstatus/*

yundun-cloudfirewall:DescribeAppGroupConsumList DescribeAppGroupConsumList get

*全部资源

*

yundun-cloudfirewall:ModifySensitiveSwitch ModifySensitiveSwitch none

*全部资源

*

yundun-cloudfirewall:DescribeClearAuthInfo DescribeClearAuthInfo get

*全部资源

*

yundun-cloudfirewall:DescribeTrFirewallsV2RouteList DescribeTrFirewallsV2RouteList get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyTemplateRule DescribeStrategyTemplateRule get

*全部资源

*

yundun-cloudfirewall:DescribePageDocuments DescribePageDocuments get

*全部资源

*

yundun-cloudfirewall:DescribeSdlStatistic DescribeSdlStatistic none

*全部资源

*

yundun-cloudfirewall:DeleteNatFirewallControlPolicy DeleteNatFirewallControlPolicy delete

*NatFirewallControlPolicy

acs:cloudfirewall::{#accountId}:natfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeACLProtectTrend DescribeACLProtectTrend get

*全部资源

*

yundun-cloudfirewall:DescribeInternetServiceNameList DescribeInternetServiceNameList get

*全部资源

*

yundun-cloudfirewall:CreateIpsPrivateAssoc CreateIpsPrivateAssoc create

*全部资源

*

yundun-cloudfirewall:DescribeIspInfo DescribeIspInfo get

*全部资源

*

yundun-cloudfirewall:CreateTlsInspectRule CreateTlsInspectRule create

*TlsInspectRule

acs:yundun-cloudfirewall::{#accountId}:tlsinspectrule/*

yundun-cloudfirewall:DescribeOutgoingTag DescribeOutgoingTag get

*全部资源

*

yundun-cloudfirewall:CreateTrFirewallV2 CreateTrFirewallV2 create

*VpcCenTrFirewall

acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/*

yundun-cloudfirewall:AddStrategyGroupCheckTask AddStrategyGroupCheckTask get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallAccessDetail DescribeVpcFirewallAccessDetail get

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallCenConfigure ModifyVpcFirewallCenConfigure update

*VpcFirewallCen

acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}

yundun-cloudfirewall:DescribeInstanceRdAccounts DescribeInstanceRdAccounts get

*全部资源

*

yundun-cloudfirewall:DeleteNatFirewallControlPolicyBatch DeleteNatFirewallControlPolicyBatch delete

*全部资源

*

yundun-cloudfirewall:BatchCloseVpcFirewallCen BatchCloseVpcFirewallCen delete

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventPayload DescribeRiskEventPayload get

*全部资源

*

yundun-cloudfirewall:DescribeFirewallTrafficTrend DescribeFirewallTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeBizConsumAppGroupList DescribeBizConsumAppGroupList get

*全部资源

*

yundun-cloudfirewall:DeleteTlsInspectRule DeleteTlsInspectRule delete

*TlsInspectRule

acs:cloudfirewall::{#accountId}:tlsinspectrule/{#TlsInspectRuleId}

yundun-cloudfirewall:DescribeInvadeEventPayload DescribeInvadeEventPayload get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkInstanceList DescribeNetworkInstanceList get

*全部资源

*

yundun-cloudfirewall:UpdateTlsInspectScope UpdateTlsInspectScope update

*TlsInspectScope

acs:cloudfirewall::{#accountId}:tlsinspectscope/{#TlsInspectScopeId}

yundun-cloudfirewall:DescribeStrategyGroupStatusDetail DescribeStrategyGroupStatusDetail get

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingDestinationCategory DescribeOutgoingDestinationCategory get

*全部资源

*

yundun-cloudfirewall:DescribeVpcInfo DescribeVpcInfo get

*全部资源

*

yundun-cloudfirewall:BatchCopyVpcFirewallControlPolicy BatchCopyVpcFirewallControlPolicy update

*VpcFirewallControlPolicy

acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/*

yundun-cloudfirewall:CreateSlsLogDispatch CreateSlsLogDispatch create

Instance

acs:yundun-cloudfirewall::{#accountId}:instance/{#InstanceId}

yundun-cloudfirewall:DescribeAclStats DescribeAclStats list

*全部资源

*

yundun-cloudfirewall:UpdateTlsInspectRule UpdateTlsInspectRule update

*TlsInspectRule

acs:cloudfirewall::{#accountId}:tlsinspectrule/{#TlsInspectRuleId}

yundun-cloudfirewall:DescribeOutgoingDomain DescribeOutgoingDomain get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkInstanceRelationList DescribeNetworkInstanceRelationList get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallTrafficTimeTop DescribeVpcFirewallTrafficTimeTop get

*全部资源

*

yundun-cloudfirewall:CreateVpcFirewallPrecheck CreateVpcFirewallPrecheck create

*全部资源

*

yundun-cloudfirewall:DescribeAccessInstanceTask DescribeAccessInstanceTask none

*全部资源

*

yundun-cloudfirewall:DescribeTrFirewallsV2Detail DescribeTrFirewallsV2Detail get

*VpcCenTrFirewall

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}

yundun-cloudfirewall:DescribeFirewallDropTrend DescribeFirewallDropTrend get

*全部资源

*

yundun-cloudfirewall:DescribeFirewallVswitchResources DescribeFirewallVswitchResources get

*全部资源

*

yundun-cloudfirewall:DescribeInternetTimeTop DescribeInternetTimeTop get

*全部资源

*

yundun-cloudfirewall:DescribeRecommendAclStatistics DescribeRecommendAclStatistics get

*全部资源

*

yundun-cloudfirewall:CheckStsGrant CheckStsGrant get

*全部资源

*

yundun-cloudfirewall:DescribeInstanceMembers DescribeInstanceMembers get

*InstanceMember

acs:cloudfirewall::{#accountId}:instancemember/{#MemberUid}

yundun-cloudfirewall:CreateVpcFirewallCenManualConfigure CreateVpcFirewallCenManualConfigure create

*VpcFirewallCen

acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcen/*

yundun-cloudfirewall:DescribeDnatTableEntries DescribeDnatTableEntries get

*全部资源

*

yundun-cloudfirewall:DescribeVpcTrafficRelation DescribeVpcTrafficRelation get

*全部资源

*

yundun-cloudfirewall:DescribeProductNews DescribeProductNews get

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallIPSWhitelist ModifyVpcFirewallIPSWhitelist update

*全部资源

*

yundun-cloudfirewall:DeleteTlsInspectAssociation DeleteTlsInspectAssociation delete

*TlsInspectAssociation

acs:cloudfirewall::{#accountId}:tlsinspectassociation/{#FirewallType}

yundun-cloudfirewall:DescribeInternetOpenDataIntegrity DescribeInternetOpenDataIntegrity get

*全部资源

*

yundun-cloudfirewall:DescribeIpsPrivateAssoc DescribeIpsPrivateAssoc get

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupRelaList DescribeAppGroupRelaList get

*全部资源

*

yundun-cloudfirewall:ModifyNatFirewallControlPolicy ModifyNatFirewallControlPolicy update

*NatFirewallControlPolicy

acs:cloudfirewall::{#accountId}:natfirewallcontrolpolicy/{#AclUuid}

yundun-cloudfirewall:DescribeAssetRegionList DescribeAssetRegionList get

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingRiskDomainAndIpCount DescribeOutgoingRiskDomainAndIpCount get

*全部资源

*

yundun-cloudfirewall:DescribeUserAclLimit DescribeUserAclLimit get

*全部资源

*

yundun-cloudfirewall:DescribeCaptureStatus DescribeCaptureStatus get

*全部资源

*

yundun-cloudfirewall:CreateApp CreateApp create

*全部资源

*

yundun-cloudfirewall:DescribeSlbAcl DescribeSlbAcl get

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallDefaultIPSConfig ModifyVpcFirewallDefaultIPSConfig update

*VpcFirewallIpsConfig

acs:cloudfirewall::{#accountId}:vpcfirewallipsconfig/{#VpcFirewallId}

yundun-cloudfirewall:DescribeTrafficLog DescribeTrafficLog get

*全部资源

*

yundun-cloudfirewall:DescribeVpcRegionList DescribeVpcRegionList get

*全部资源

*

yundun-cloudfirewall:ResetNatFirewallRuleHitCount ResetNatFirewallRuleHitCount update

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallAclEngineMode ModifyVpcFirewallAclEngineMode create

*全部资源

*

yundun-cloudfirewall:ModifyResourceTypeAutoEnable ModifyResourceTypeAutoEnable update

*全部资源

*

yundun-cloudfirewall:DescribeAccessInstanceVpcList DescribeAccessInstanceVpcList none

*全部资源

*

yundun-cloudfirewall:DescribeFirewallDropStatistics DescribeFirewallDropStatistics get

*全部资源

*

yundun-cloudfirewall:AdjustStrategyGroupRules AdjustStrategyGroupRules get

*全部资源

*

yundun-cloudfirewall:AddAclBackupData AddAclBackupData get

*全部资源

*

yundun-cloudfirewall:DescribeEcsInstanceTags DescribeEcsInstanceTags get

*全部资源

*

yundun-cloudfirewall:DescribeCaptureTask DescribeCaptureTask get

*全部资源

*

yundun-cloudfirewall:DeleteSecurityProxy DeleteSecurityProxy get

*NatFirewall

acs:cloudfirewall::{#accountId}:natfirewall/{#ProxyId}

yundun-cloudfirewall:DescribeThreatIntelligenceSwitch DescribeThreatIntelligenceSwitch none

*全部资源

*

yundun-cloudfirewall:ResetDnsRuleHitCount ResetDnsRuleHitCount none

*全部资源

*

yundun-cloudfirewall:DescribeUnprotectedPortTrend DescribeUnprotectedPortTrend get

*全部资源

*

yundun-cloudfirewall:DescribeConfiguredAssetsIP DescribeConfiguredAssetsIP get

*全部资源

*

yundun-cloudfirewall:DescribeOpenIpAccessSrcStat DescribeOpenIpAccessSrcStat get

*全部资源

*

yundun-cloudfirewall:ListTlsInspectAssociations ListTlsInspectAssociations list

*TlsInspectAssociation

acs:cloudfirewall::{#accountId}:tlsinspectassociation/{#PageSize}

yundun-cloudfirewall:AddControlPolicyBatch AddControlPolicyBatch update

*全部资源

*

yundun-cloudfirewall:CheckClassicSlbUpgrade CheckClassicSlbUpgrade get

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingAssetList DescribeOutgoingAssetList get

*全部资源

*

yundun-cloudfirewall:ModifyControlPolicyPosition ModifyControlPolicyPosition update

*全部资源

*

yundun-cloudfirewall:DescribeAddressBook DescribeAddressBook get

*AddressBook

acs:cloudfirewall::{#accountId}:addressbook/{#GroupUuid}

yundun-cloudfirewall:CreateTlsInspectScope CreateTlsInspectScope create

*TlsInspectScope

acs:cloudfirewall::{#accountId}:tlsinspectscope/*

yundun-cloudfirewall:DescribeInternetSlb DescribeInternetSlb get

*全部资源

*

yundun-cloudfirewall:DescribeVulnerabilityProtectedList DescribeVulnerabilityProtectedList get

*全部资源

*

yundun-cloudfirewall:DescribeSdlEventDetail DescribeSdlEventDetail none

*全部资源

*

yundun-cloudfirewall:DescribeAssetTypeList DescribeAssetTypeList list

*全部资源

*

yundun-cloudfirewall:UpdateAclCheckDetailStatus UpdateAclCheckDetailStatus get

*全部资源

*

yundun-cloudfirewall:DescribeConfiguredDestinationIP DescribeConfiguredDestinationIP get

*全部资源

*

yundun-cloudfirewall:DescribeAttackAppCategory DescribeAttackAppCategory none

*全部资源

*

yundun-cloudfirewall:DescribeCommitHistory DescribeCommitHistory get

*全部资源

*

yundun-cloudfirewall:DescribePostpayTrafficDetail DescribePostpayTrafficDetail get

*全部资源

*

yundun-cloudfirewall:ModifyTrFirewallV2Configuration ModifyTrFirewallV2Configuration update

*VpcCenTrFirewall

acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}

yundun-cloudfirewall:DescribeAckClusterPodLabels DescribeAckClusterPodLabels get

*全部资源

*

yundun-cloudfirewall:DescribeCtrlInstanceMemberAccounts DescribeCtrlInstanceMemberAccounts get

*全部资源

*

yundun-cloudfirewall:DescribeVulnAttackTrend DescribeVulnAttackTrend get

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupListWithRelation DescribeAppGroupListWithRelation get

*全部资源

*

yundun-cloudfirewall:DescribeNetworkTrafficTopRatio DescribeNetworkTrafficTopRatio get

*全部资源

*

yundun-cloudfirewall:DescribeInAndOutRecommendAclsCount DescribeInAndOutRecommendAclsCount get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallManualVpcList DescribeVpcFirewallManualVpcList get

*全部资源

*

yundun-cloudfirewall:CreateVpcFirewallConfigure CreateVpcFirewallConfigure create

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/*

yundun-cloudfirewall:DescribeControlPolicyDomainResolve DescribeControlPolicyDomainResolve get

*全部资源

*

yundun-cloudfirewall:UpdatePostpayUserInternetStatus UpdatePostpayUserInternetStatus update

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingDestinationIP DescribeOutgoingDestinationIP get

*全部资源

*

yundun-cloudfirewall:DescribeBatchSlsDispatchStatus DescribeBatchSlsDispatchStatus get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallPortList DescribeVpcFirewallPortList get

*全部资源

*

yundun-cloudfirewall:CreateNatFirewallPreCheck CreateNatFirewallPreCheck create

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupProduceList DescribeAppGroupProduceList get

*全部资源

*

yundun-cloudfirewall:DescribeControlPolicyTemplate DescribeControlPolicyTemplate get

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventTopAttackType DescribeRiskEventTopAttackType list

*全部资源

*

yundun-cloudfirewall:DescribeAppConsumList DescribeAppConsumList get

*全部资源

*

yundun-cloudfirewall:CreateStrategyGroupRule CreateStrategyGroupRule get

*全部资源

*

yundun-cloudfirewall:DescribeAITrafficStat DescribeAITrafficStat none

*全部资源

*

yundun-cloudfirewall:DownloadsCaptureSample DownloadsCaptureSample none

*全部资源

*

yundun-cloudfirewall:DescribeAppGroup DescribeAppGroup get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallCenSummaryList DescribeVpcFirewallCenSummaryList get

*全部资源

*

yundun-cloudfirewall:EnableSdlProtectedAsset EnableSdlProtectedAsset update

*全部资源

*

yundun-cloudfirewall:ClearLogStoreStorage ClearLogStoreStorage none

*全部资源

*

yundun-cloudfirewall:DescribeDnsFirewallResources DescribeDnsFirewallResources get

*全部资源

*

yundun-cloudfirewall:DescribeBasicRules DescribeBasicRules get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallDomainRelationList DescribeVpcFirewallDomainRelationList get

*全部资源

*

yundun-cloudfirewall:DescribeAssetProtectInfo DescribeAssetProtectInfo get

*全部资源

*

yundun-cloudfirewall:DescribeSecurityProxyResources DescribeSecurityProxyResources get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallAssetList DescribeVpcFirewallAssetList get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallPolicyPriorUsed DescribeVpcFirewallPolicyPriorUsed get

*VpcFirewall

acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}

yundun-cloudfirewall:ModifyStrategyGroup ModifyStrategyGroup update

*全部资源

*

yundun-cloudfirewall:DescribeAppGroupList DescribeAppGroupList get

*全部资源

*

yundun-cloudfirewall:DescribeAssetInfo DescribeAssetInfo get

*全部资源

*

yundun-cloudfirewall:DescribeAppFlowDetail DescribeAppFlowDetail get

*全部资源

*

yundun-cloudfirewall:DescribeDefaultIPSConfig DescribeDefaultIPSConfig get

*全部资源

*

yundun-cloudfirewall:CloseTlsInspectFeature CloseTlsInspectFeature update

*全部资源

*

yundun-cloudfirewall:DescribeAllVpcFirewallTrafficTrend DescribeAllVpcFirewallTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallCenList DescribeVpcFirewallCenList get

*VpcFirewallCen

acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}

yundun-cloudfirewall:DescribeVulnDetail DescribeVulnDetail get

*全部资源

*

yundun-cloudfirewall:DescribeCaptureFileAddr DescribeCaptureFileAddr get

*全部资源

*

yundun-cloudfirewall:DescribeFirewallRegion DescribeFirewallRegion get

*全部资源

*

yundun-cloudfirewall:DescribePostpayEnabledProtection DescribePostpayEnabledProtection get

*全部资源

*

yundun-cloudfirewall:DescribePostpayUserVpcStatus DescribePostpayUserVpcStatus get

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallDropTrafficTrend DescribeNatFirewallDropTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeFirewallVSwitch DescribeFirewallVSwitch get

*全部资源

*

yundun-cloudfirewall:ModifyAppGroup ModifyAppGroup update

*全部资源

*

yundun-cloudfirewall:DescribeCreatedNatFirewall DescribeCreatedNatFirewall get

*全部资源

*

yundun-cloudfirewall:PutEnableAllFwSwitch PutEnableAllFwSwitch update

*全部资源

*

yundun-cloudfirewall:DescribeNatFirewallTrafficTrend DescribeNatFirewallTrafficTrend get

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupCheckResult DescribeStrategyGroupCheckResult get

*全部资源

*

yundun-cloudfirewall:DescribeLocationInfo DescribeLocationInfo get

*全部资源

*

yundun-cloudfirewall:DescribeVpcFirewallTrafficAssetList DescribeVpcFirewallTrafficAssetList get

*全部资源

*

yundun-cloudfirewall:UpdateSecurityProxy UpdateSecurityProxy update

*全部资源

*

yundun-cloudfirewall:StartCaptureSample StartCaptureSample none

*全部资源

*

yundun-cloudfirewall:CreateNatFirewallSyncTask CreateNatFirewallSyncTask create

*全部资源

*

yundun-cloudfirewall:ReleasePostInstance ReleasePostInstance delete

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventTopAttackApp DescribeRiskEventTopAttackApp get

*全部资源

*

yundun-cloudfirewall:DescribeRiskEventTopAttackAsset DescribeRiskEventTopAttackAsset get

*全部资源

*

yundun-cloudfirewall:DescribeTransitRouterResourcesList DescribeTransitRouterResourcesList get

*全部资源

*

yundun-cloudfirewall:DestroyProbationInstance DestroyProbationInstance delete

*全部资源

*

yundun-cloudfirewall:DescribeSdlEventSdList DescribeSdlEventSdList none

*全部资源

*

yundun-cloudfirewall:DescribeStrategyGroupCheckRuleDetail DescribeStrategyGroupCheckRuleDetail list

*全部资源

*

yundun-cloudfirewall:ModifyStrategyGroupRule ModifyStrategyGroupRule update

*全部资源

*

yundun-cloudfirewall:OpenBuyProbation OpenBuyProbation none

*全部资源

*

yundun-cloudfirewall:DescribeSystemLogNew DescribeSystemLogNew get

*全部资源

*

yundun-cloudfirewall:DescribeOutgoingRiskTrend DescribeOutgoingRiskTrend get

*全部资源

*

yundun-cloudfirewall:DescribeInternetOpenService DescribeInternetOpenService get

*全部资源

*

yundun-cloudfirewall:DescribePrefixLists DescribePrefixLists list

*全部资源

*

yundun-cloudfirewall:UpdateDefaultFirewall UpdateDefaultFirewall update

*全部资源

*

yundun-cloudfirewall:ModifyVpcFirewallCenSwitchStatus ModifyVpcFirewallCenSwitchStatus update

*VpcFirewallCen

acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}

资源(Resource)

下表是云防火墙定义的资源,这些资源可以在 RAM 权限策略语句的Resource元素中使用,用来授予对该资源执行具体操作的权限。 其中,资源 ARN 是资源在阿里云上的唯一标识。具体说明如下:

  • {#}为变量标识,需要您替换为实际值。例如:{#ramcode}需要您替换为实际的云服务RAM代码。

  • *表示全部。例如:

    • {#resourceType}*时:表示全部资源。

    • {#regionId}*时:表示全部地域。

    • {#accountId}*时:表示全部阿里云账号。

资源类型

资源 ARN

DnsFirewallPolicy
  • acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/{#AclUuid}
  • acs:yundun-cloudfirewall::{#accountId}:dnsfirewallpolicy/*
TlsInspectAssociation
  • acs:cloudfirewall::{#accountId}:tlsinspectassociation/*
  • acs:cloudfirewall::{#accountId}:tlsinspectassociation/{#FirewallType}
  • acs:cloudfirewall::{#accountId}:tlsinspectassociation/{#PageSize}
VpcFirewallCen
  • acs:cloudfirewall::{#accountId}:vpcfirewallcen/{#VpcFirewallId}
  • acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcen/*
AiTrafficAnalysisStatus
  • acs:yundun-cloudfirewall::{#accountId}:aitrafficanalysisstatus/*
NatFirewallControlPolicy
  • acs:yundun-cloudfirewall::{#accountId}:natfirewallcontrolpolicy/*
  • acs:cloudfirewall::{#accountId}:natfirewallcontrolpolicy/{#AclUuid}
ControlPolicy
  • acs:cloudfirewall::{#accountId}:controlpolicy/*
  • acs:yundun-cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}
  • acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}
VpcFirewallControlPolicy
  • acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}
  • acs:cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/*
  • acs:cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/{#AclUuid}
  • acs:yundun-cloudfirewall::{#accountId}:vpcfirewallcontrolpolicy/*
NatFirewall
  • acs:cloudfirewall::{#accountId}:natfirewall/{#ProxyId}
PrivateDNS
  • acs:cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}
  • acs:yundun-cloudfirewall::{#accountId}:privatedns/*
  • acs:yundun-cloudfirewall::{#accountId}:privatedns/{#AccessInstanceId}
TlsInspectScope
  • acs:cloudfirewall::{#accountId}:tlsinspectscope/{#TlsInspectScopeId}
  • acs:cloudfirewall::{#accountId}:tlsinspectscope/*
VpcCenTrFirewallPolicy
  • acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}
  • acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}/{#TrFirewallRoutePolicyId}
InstanceMember
  • acs:cloudfirewall::{#accountId}:instancemember/{#MemberUid}
  • acs:yundun-cloudfirewall::{#accountId}:instancemember/*
ThreatIntelligenceSwitch
  • acs:cloudfirewall::{#accountId}:threatintelligenceswitch/{#CategoryId}
  • acs:cloudfirewall::{#accountId}:threatintelligenceswitch
VpcFirewall
  • acs:cloudfirewall::{#accountId}:vpcfirewall/{#VpcFirewallId}
  • acs:cloudfirewall::{#accountId}:vpcfirewall/*
TlsInspectRule
  • acs:cloudfirewall::{#accountId}:tlsinspectrule/{#TlsInspectRuleId}
  • acs:yundun-cloudfirewall::{#accountId}:tlsinspectrule/*
TlsInspectCaCertificate
  • acs:cloudfirewall::{#accountId}:tlsinspectcacertificate/{#CaCertId}
  • acs:yundun-cloudfirewall::{#accountId}:tlsinspectcacertificate/{#CaCertId}
VpcCenTrFirewall
  • acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}
  • acs:cloudfirewall::{#accountId}:vpccentrfirewall/{#FirewallId}
  • acs:yundun-cloudfirewall::{#accountId}:vpccentrfirewall/*
AddressBook
  • acs:yundun-cloudfirewall::{#accountId}:addressbook/*
  • acs:yundun-cloudfirewall::{#accountId}:addressbook/{#GroupUuid}
  • acs:cloudfirewall::{#accountId}:addressbook/{#GroupUuid}
ControlPolicyOrder
  • acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}/controlpolicyorder/{#Direction}
  • acs:cloudfirewall::{#accountId}:controlpolicy/{#AclUuid}
PolicyAdvancedConfig
  • acs:yundun-cloudfirewall::{#accountId}:policyadvancedconfig
Domain
  • acs:yundun-cloudfirewall::{#accountId}:domain/{#Domain}
Asset
  • acs:cloudfirewall::{#accountId}:asset/{#Type}
VpcFirewallIpsConfig
  • acs:cloudfirewall::{#accountId}:vpcfirewallipsconfig/{#VpcFirewallId}
Instance
  • acs:yundun-cloudfirewall::{#accountId}:instance/{#InstanceId}

条件(Condition)

云防火墙未定义产品级别的条件关键字。如需查看适用于所有云产品的通用条件关键字,请参见通用条件关键字

相关操作

您可以创建自定义权限策略,并将权限策略授予 RAM 用户、RAM 用户组或 RAM 角色。具体操作如下: