Akamai API Security IP/Geo Firewall settings API

Manage which network lists are used in the IP/Geo Firewall settings. If you want to add or remove IP addresses from the network lists, use the Network Lists API.

OpenAPI Specification

akamai-api-security-ip-geo-firewall-settings-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history IP/Geo Firewall settings API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage which network lists are used in the IP/Geo Firewall

    settings.  If you want to add or remove IP addresses from the

    network lists, use the Network Lists API.'
  name: IP/Geo Firewall settings
paths:
  /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/ip-geo-firewall:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    - description: A unique identifier for a security policy.
      example: '{{policyId}}'
      in: path
      name: policyId
      required: true
      schema:
        example: boBF_19288
        type: string
      x-akamai:
        file-path: parameters/policy-id-path.yaml
    x-akamai:
      file-path: paths/policy-ip-geo-firewall.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/ip-geo-firewall
    get:
      description: Lists which network lists are used in the IP/Geo Firewall settings. In Control Center this method is called `mode`. In this API the method is called `blocked`. The response shows blocked and allowed IPs depending on which network lists you include and which version of the mode you choose. If you want to add or remove IP addresses from the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api). Note that subnet controls are a legacy item in Control Center and are not available through this API. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-policy-ip-geo-firewall
      operationId: get-policy-ip-geo-firewall
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                asnControls:
                  allowedIPNetworkLists:
                    networkList:
                    - 9876_ASNTEST
                  blockedIPNetworkLists:
                    networkList:
                    - 567321_TESTASNLIST
                block: blockSpecificIPGeo
                geoControls:
                  blockedIPNetworkLists:
                    networkList:
                    - 72138_TEST1
                ipControls:
                  allowedIPNetworkLists:
                    networkList:
                    - 56921_TEST
                  blockedIPNetworkLists:
                    networkList:
                    - 53712_TESTLIST123
                ukraineGeoControl:
                  action: deny
              schema:
                additionalProperties: false
                description: The GET Response JSON for IP/Geo Firewall.
                properties:
                  asnControls:
                    additionalProperties: false
                    description: The network lists you block or allow by AS number.
                    properties:
                      allowedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                    type: object
                  block:
                    description: The method by which you block or allow requests by IP or geographic location. In Control Center, this is called `mode`. Use `blockSpecificIPGeo` to block any IPs, subnets, geographies, or network lists you specify. Use `blockAllTrafficExceptAllowedIPs` to allow requests from IPs, subnets, geographies or networks lists in your `blockExceptions` that you maintain with the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                    enum:
                    - blockSpecificIPGeo
                    - blockAllTrafficExceptAllowedIPs
                    type: string
                  geoControls:
                    additionalProperties: false
                    description: The network lists you block geographically.
                    properties:
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                    type: object
                  ipControls:
                    additionalProperties: false
                    description: The network lists you block or allow by IP.
                    properties:
                      allowedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                    type: object
                  ukraineGeoControl:
                    additionalProperties: false
                    description: The settings for requests to and from Ukraine.
                    properties:
                      ukraineGeoControl:
                        additionalProperties: false
                        description: Take action on requests from Ukraine.
                        properties:
                          action:
                            description: The action to take on requests from the Donetsk and Luhansk regions of Ukraine — either `alert`, `deny`, or `none`. Because this setting is intended to address fluid situations, Akamai will automatically update the included regions as necessary.
                            enum:
                            - alert
                            - deny
                            - none
                            type: string
                        type: object
                        x-akamai:
                          file-path: schemas/ukraine-geo-control.yaml
                    type: object
                required:
                - block
                type: object
                x-akamai:
                  file-path: schemas/ip-geo-firewall-get-200.yaml
          description: Successfully retrieved the IP/Geo firewall settings.
        '400':
          content:
            application/json:
              example:
                detail: The request could not be understood by the server due to malformed syntax.
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 400
                title: Bad Request
                type: https://problems.luna.akamaiapis.net/appsec/error-types/BAD-REQUEST
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Invalid](https://techdocs.akamai.com/application-security/reference/400). Client error, such as invalid or malformed input.'
          x-akamai:
            file-path: errors/400-client-read-errors.yaml
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource is not found
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 404
                title: Not Found
                type: https://problems.luna.akamaiapis.net/appsec/error-types/NOT-FOUND
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Not found](https://techdocs.akamai.com/application-security/reference/404). The named security policy doesn''t exist, doesn''t carry application layer controls, or no rule with this ID is available for use in this policy.'
          x-akamai:
            file-path: errors/404-client-read-errors.yaml
        '500':
          content:
            application/problem+json:
              example:
                detail: Internal Server Error
                instance: 12ab3c45-789d-01ef-2gh3-ijk4l56m78no
                status: 500
                title: Internal Server Error
                type: internal_server_error
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Internal server error](https://techdocs.akamai.com/application-security/reference/500). Something went wrong on our side. Try again in a few minutes, and contact support if the error persists.'
          x-akamai:
            file-path: errors/500-server-errors.yaml
      summary: Akamai API Security Get IP/Geo Firewall Settings
      tags:
      - IP/Geo Firewall settings
    put:
      description: Update the method and which network lists to use for IP/Geo firewall blocking. In Control Center this method is called `mode`. In this API the method is called `blocked`. Use `blockSpecificIPGeo` to block any IPs, geographies, or network lists you choose with this setting. Use `blockAllTrafficExceptAllowedIPs` to allow specific IPs or geographies that you choose to let through while the rest remain blocked. IPs you want to allow are contained in the `allowedIPNetworkLists`. It's important to verify the IPs you block are the ones you intend to block as it's easy to block wanted traffic by accident. Note that subnet controls are a legacy item in Control Center and are not available through this API. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/put-policy-ip-geo-firewall
      operationId: put-policy-ip-geo-firewall
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      requestBody:
        content:
          application/json:
            example:
              asnControls:
                allowedIPNetworkLists:
                  networkList:
                  - 9876_ASNTEST
                blockedIPNetworkLists:
                  networkList:
                  - 567321_TESTASNLIST
              block: blockSpecificIPGeo
              geoControls:
                blockedIPNetworkLists:
                  networkList:
                  - 72138_TEST1
              ipControls:
                allowedIPNetworkLists:
                  networkList:
                  - 56921_TEST
                blockedIPNetworkLists:
                  networkList:
                  - 53712_TESTLIST123
              ukraineGeoControl:
                action: deny
            schema:
              additionalProperties: false
              description: Describes the mode of the IP/Geo Firewall and the allowed and blocked IP lists.
              properties:
                asnControls:
                  additionalProperties: false
                  description: The network lists you block or allow by AS number.
                  properties:
                    allowedIPNetworkLists:
                      additionalProperties: false
                      description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                      properties:
                        networkList:
                          description: The specific network list you specify to block or allow, depending on the method you choose.
                          items:
                            type: string
                          type: array
                      type: object
                      x-akamai:
                        file-path: schemas/network-lists.yaml
                    blockedIPNetworkLists:
                      additionalProperties: false
                      description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                      properties:
                        networkList:
                          description: The specific network list you specify to block or allow, depending on the method you choose.
                          items:
                            type: string
                          type: array
                      type: object
                      x-akamai:
                        file-path: schemas/network-lists.yaml
                  type: object
                block:
                  description: The method by which you block or allow requests by IP or geographic location. In Control Center, this is called `mode`. Use `blockSpecificIPGeo` to block any IPs, subnets, geographies, or network lists you specify. Use `blockAllTrafficExceptAllowedIPs` to allow requests from IPs, subnets, geographies or networks lists in your `blockExceptions` maintained in [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                  enum:
                  - blockSpecificIPGeo
                  - blockAllTrafficExceptAllowedIPs
                  example: '{{block}}'
                  type: string
                geoControls:
                  additionalProperties: false
                  description: The network lists you block geographically.
                  properties:
                    blockedIPNetworkLists:
                      additionalProperties: false
                      description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                      properties:
                        networkList:
                          description: The specific network list you specify to block or allow, depending on the method you choose.
                          items:
                            type: string
                          type: array
                      type: object
                      x-akamai:
                        file-path: schemas/network-lists.yaml
                  type: object
                ipControls:
                  additionalProperties: false
                  description: The network lists you block or allow by IP.
                  properties:
                    allowedIPNetworkLists:
                      additionalProperties: false
                      description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                      properties:
                        networkList:
                          description: The specific network list you specify to block or allow, depending on the method you choose.
                          items:
                            type: string
                          type: array
                      type: object
                      x-akamai:
                        file-path: schemas/network-lists.yaml
                    blockedIPNetworkLists:
                      additionalProperties: false
                      description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                      properties:
                        networkList:
                          description: The specific network list you specify to block or allow, depending on the method you choose.
                          items:
                            type: string
                          type: array
                      type: object
                      x-akamai:
                        file-path: schemas/network-lists.yaml
                  type: object
                ukraineGeoControl:
                  additionalProperties: false
                  description: The settings for requests to and from Ukraine.
                  properties:
                    ukraineGeoControl:
                      additionalProperties: false
                      description: Take action on requests from Ukraine.
                      properties:
                        action:
                          description: The action to take on requests from the Donetsk and Luhansk regions of Ukraine — either `alert`, `deny`, or `none`. Because this setting is intended to address fluid situations, Akamai will automatically update the included regions as necessary.
                          enum:
                          - alert
                          - deny
                          - none
                          type: string
                      type: object
                      x-akamai:
                        file-path: schemas/ukraine-geo-control.yaml
                  type: object
              required:
              - block
              type: object
              x-akamai:
                file-path: schemas/ip-geo-firewall-put.yaml
        required: true
      responses:
        '200':
          content:
            application/json:
              example:
                asnControls:
                  allowedIPNetworkLists:
                    networkList:
                    - 9876_ASNTEST
                  blockedIPNetworkLists:
                    networkList:
                    - 567321_TESTASNLIST
                block: blockSpecificIPGeo
                geoControls:
                  blockedIPNetworkLists:
                    networkList:
                    - 72138_TEST1
                ipControls:
                  allowedIPNetworkLists:
                    networkList:
                    - 56921_TEST
                  blockedIPNetworkLists:
                    networkList:
                    - 53712_TESTLIST123
                ukraineGeoControl:
                  action: deny
              schema:
                additionalProperties: false
                description: The PUT Response JSON for IP/Geo Firewall.
                properties:
                  asnControls:
                    additionalProperties: false
                    description: The network lists you block or allow by AS number. ASN network lists are a distinct network list type.
                    properties:
                      allowedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                    type: object
                  block:
                    description: The method by which you block or allow requests by IP or geographic location. In Control Center, this is called `mode`. Use `blockSpecificIPGeo` to block any IPs, subnets, geographies, or network lists you specify. Use `blockAllTrafficExceptAllowedIPs` to allow requests from IPs, subnets, geographies or networks lists in your `blockExceptions` maintained in [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                    enum:
                    - blockSpecificIPGeo
                    - blockAllTrafficExceptAllowedIPs
                    type: string
                  geoControls:
                    additionalProperties: false
                    description: The network lists you block geographically. Geo network lists are a distinct network list type compared to IP network lists. Use [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api) to manage the network lists.
                    properties:
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                    type: object
                  ipControls:
                    additionalProperties: false
                    description: The network lists you block or allow by IP. IP network lists are a distinct network list type.
                    properties:
                      allowedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: object
                        x-akamai:
                          file-path: schemas/network-lists.yaml
                      blockedIPNetworkLists:
                        additionalProperties: false
                        description: The list of networks. To edit the network lists, use the [Network Lists API](https://techdocs.akamai.com/network-lists/reference/api).
                        properties:
                          networkList:
                            description: The specific network list you specify to block or allow, depending on the method you choose.
                            items:
                              type: string
                            type: array
                        type: o

# --- truncated at 32 KB (43 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-ip-geo-firewall-settings-api-openapi.yml