Cloud Ngfw Api Security Rule Structure
A security rule within a Cloud NGFW rule stack.
SecurityRule is a JSON Structure definition published by Palo Alto Networks, describing 2 properties. It conforms to the https://json-structure.org/meta/core/v0/# meta-schema.
Properties
Meta-schema: https://json-structure.org/meta/core/v0/#
JSON Structure
{
"$schema": "https://json-structure.org/meta/core/v0/#",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-structure/cloud-ngfw-api-security-rule-structure.json",
"name": "SecurityRule",
"description": "A security rule within a Cloud NGFW rule stack.",
"type": "object",
"properties": {
"Priority": {
"type": "int32",
"description": "Rule evaluation priority (lower numbers evaluated first)."
},
"RuleEntry": {
"type": "object",
"properties": {
"RuleName": {
"type": "string"
},
"Description": {
"type": "string"
},
"Enabled": {
"type": "boolean",
"default": true
},
"Source": {
"type": "object",
"description": "Traffic source matching criteria for a security rule.",
"properties": {
"Cidrs": {
"type": "array",
"description": "Source CIDR blocks (e.g., 10.0.0.0/8).",
"items": {
"type": "string"
}
},
"Countries": {
"type": "array",
"description": "Source country codes (ISO 3166-1 alpha-2).",
"items": {
"type": "string"
}
},
"Feeds": {
"type": "array",
"description": "Threat intelligence feed names.",
"items": {
"type": "string"
}
},
"PrefixLists": {
"type": "array",
"description": "Names of prefix lists defined in the rule stack.",
"items": {
"type": "string"
}
}
}
},
"NegateSource": {
"type": "boolean",
"default": false
},
"Destination": {
"type": "object",
"description": "Traffic destination matching criteria for a security rule.",
"properties": {
"Cidrs": {
"type": "array",
"description": "Destination CIDR blocks.",
"items": {
"type": "string"
}
},
"Countries": {
"type": "array",
"description": "Destination country codes.",
"items": {
"type": "string"
}
},
"Feeds": {
"type": "array",
"items": {
"type": "string"
}
},
"FqdnLists": {
"type": "array",
"description": "Names of FQDN lists defined in the rule stack.",
"items": {
"type": "string"
}
},
"PrefixLists": {
"type": "array",
"items": {
"type": "string"
}
}
}
},
"NegateDestination": {
"type": "boolean",
"default": false
},
"Applications": {
"type": "array",
"description": "Application names to match (use any for all applications).",
"items": {
"type": "string"
}
},
"Category": {
"type": "object",
"properties": {
"URLCategoryNames": {
"type": "array",
"items": {
"type": "string"
}
},
"Feeds": {
"type": "array",
"items": {
"type": "string"
}
}
}
},
"Protocol": {
"type": "string",
"enum": [
"APPLICATION-DEFAULT",
"TCP",
"UDP",
"ICMP",
"ANY"
]
},
"Action": {
"type": "string",
"enum": [
"Allow",
"DenyResetBoth",
"DenyResetServer",
"DenySilent"
]
},
"DecryptionRuleType": {
"type": "string",
"enum": [
"SSLOutboundInspection",
"None"
]
},
"AuditComment": {
"type": "string"
}
}
}
}
}
Work with this as data
Every JSON Structure here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for json structure
4 MCP tools reach this
find_json_structuresBrowse and filter every JSON Structure in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/json-structures/cloud-ngfw-api-security-rule-structure"
curl "https://apis.io/api/v1/json-structures?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.