openapi: 3.1.0 info: contact: email: tmunzer@juniper.net name: Thomas Munzer description: '> Version: **2604.1.1** > > Date: **May 13, 2026**
NOTE:
Some important API changes will be introduced. Please make sure to read the announcements
--- ## Additional Documentation * [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html) * [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html) * [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/) ## Helpful Resources * [API Sandbox and Exercises](https://api-class.mist.com/) * [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace) * [Python Script Examples](https://github.com/tmunzer/mist_library) * [API Demo Apps](https://apps.mist-lab.fr/) * [Juniper Blog](https://blogs.juniper.net/) ## Mist Web Browser Extension: * Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh) * Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/) ---' license: name: MIT url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE title: Mist Admins Sites Setting API version: 2604.1.1 x-logo: altText: Juniper-MistAI backgroundColor: '#FFFFFF' url: https://www.mist.com/wp-content/uploads/logo.png servers: - description: Mist Global 01 url: https://api.mist.com - description: Mist Global 02 url: https://api.gc1.mist.com - description: Mist Global 03 url: https://api.ac2.mist.com - description: Mist Global 04 url: https://api.gc2.mist.com - description: Mist Global 05 url: https://api.gc4.mist.com - description: Mist EMEA 01 url: https://api.eu.mist.com - description: Mist EMEA 02 url: https://api.gc3.mist.com - description: Mist EMEA 03 url: https://api.ac6.mist.com - description: Mist EMEA 04 url: https://api.gc6.mist.com - description: Mist APAC 01 url: https://api.ac5.mist.com - description: Mist APAC 02 url: https://api.gc5.mist.com - description: Mist APAC 03 url: https://api.gc7.mist.com security: - apiToken: [] - basicAuth: [] - basicAuth: [] csrfToken: [] tags: - description: 'Site settings refer to the configuration and management of of site within a Mist Organization. These settings include access point settings, firmware upgrade schedules, and various features such as location services, occupancy analytics, and engagement analytics.' name: Sites Setting paths: /api/v1/sites/{site_id}/setting: parameters: - $ref: '#/components/parameters/site_id' get: description: Get the Site Settings operationId: getSiteSetting responses: '200': $ref: '#/components/responses/SiteSettings' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: getSiteSetting tags: - Sites Setting put: description: Update Site Settings operationId: updateSiteSettings requestBody: content: application/json: examples: Example: value: additional_config_cmds: - set snmp community public analytic: enabled: false ap_matching: enabled: true rules: - match_model: string name: string port_config: eth1,eth2: disabled: true dynamic_vlan: default_vlan_id: 999 enabled: true port_vlan_id: 1 vlan_id: 9 vlan_ids: 1, 10, 50 ap_port_config: model_specific: AP32: eth1,eth2: port_vlan_id: 1 vlan_ids: 1, 10, 50 auto_upgrade: custom_versions: AP21: stable AP41: 0.1.5135 AP61: 0.1.7215 day_of_week: sun enabled: false time_of_day: '12:00' version: beta config_auto_revert: false device_updown_threshold: 0 dns_servers: - string dns_suffix: - string engagement: dwell_tag_names: bounce: Bounce engaged: Engaged passerby: Passer By stationed: Stationed dwell_tags: bounce: null engaged: 300-14400 passerby: null stationed: 14400-43200 hours: fri: 09:00-17:00 mon: 09:00-17:00 sat: 09:00-12:00 sun: 09:00-12:00 thu: 09:00-17:00 tue: 09:00-17:00 wed: 09:00-17:00 max_dwell: 43200 min_dwell: 0 evpn_options: auto_loopback_subnet: 100.101.0.0/16 auto_router_id_subnet: 100.100.0.0/24 core_as_border: false overlay: as: 65000 per_vlan_vga_v4_mac: false routed_at: edge underlay: as_base: 65001 routed_id_prefix: /24 subnet: 10.255.240.0/20 gateway_additional_config_cmds: - set snmp community public gateway_mgmt: admin_sshkeys: - string app_probing: apps: - string custom_apps: - app_type: string hostnames: - string name: string protocol: http enabled: true app_usage: true auto_signature_update: day_of_week: any enable: true time_of_day: string config_revert_timer: 10 probe_hosts: - string root_password: string security_log_source_address: 192.168.1.1 security_log_source_interface: string led: brightness: 255 enabled: true mxedge_mgmt: mist_password: MIST_PASSWORD root_password: ROOT_PASSWORD networks: property1: gateway: string subnet: string vlan_id: 10 property2: gateway: string subnet: string vlan_id: 10 ntp_servers: - string occupancy: assets_enabled: false clients_enabled: true min_duration: 3000 sdkclients_enabled: false unconnected_clients_enabled: false ospf_areas: property1: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default property2: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default persist_config_on_device: false port_mirroring: property1: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_network: analyze output_port_id: ge-0/0/5 property2: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_network: analyze output_port_id: ge-0/0/5 port_usages: dynamic: mode: dynamic reset_default_when: link_down rules: - equals: string equals_any: - string expression: string src: lldp_chassis_id usage: string property1: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_auth: dot1x port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string property2: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string proxy: url: http://proxy.internal:8080/* rogue: enabled: false honeypot_enabled: false min_duration: 10 min_rssi: -80 whitelisted_bssids: - NeighborSSID whitelisted_ssids: - cc:8e:6f:d4:bf:16 - cc-8e-6f-d4-bf-16 - cc-73-* - cc:82:* simple_alert: arp_failure: client_count: 10 duration: 20 incident_count: 10 dhcp_failure: client_count: 10 duration: 10 incident_count: 20 dns_failure: client_count: 20 duration: 10 incident_count: 30 skyatp: enabled: true send_ip_mac_mapping: true srx_app: enabled: false ssh_keys: - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host ssr: conductor_hosts: - '"1.1.1.1", "2.2.2.2"' disable_stats: true status_portal: enabled: false hostnames: - my.misty.com vars: RADIUS_IP1: 172.31.2.5 RADIUS_SECRET: 11s64632d vna: enabled: false wan_vna: enabled: false wids: repeated_auth_failures: duration: 60 threshold: 0 wifi: cisco_enabled: true disable_11k: false disable_radios_when_power_constrained: false enable_arp_spoof_check: false enable_shared_radio_scanning: true enabled: true locate_connected: true locate_unconnected: false mesh_allow_dfs: false mesh_enable_crm: false mesh_enabled: false mesh_psk: string mesh_ssid: string proxy_arp: default wired_vna: enabled: false zone_occupancy_alert: email_notifiers: - foo@juniper.net - bar@juniper.net enabled: false threshold: 5 schema: $ref: '#/components/schemas/site_setting' description: Request Body responses: '200': $ref: '#/components/responses/SiteSettings' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: updateSiteSettings tags: - Sites Setting /api/v1/sites/{site_id}/setting/blacklist: parameters: - $ref: '#/components/parameters/site_id' delete: description: Delete Site Blacklist Station Clients operationId: deleteSiteWirelessClientsBlocklist responses: '200': $ref: '#/components/responses/OK' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: deleteSiteWirelessClientsBlocklist tags: - Sites Setting post: description: 'This endpoint is to provide list of client macs for annotation blacklist. Retrieve the current clients list `blacklist_url` under Site:Setting' operationId: createSiteWirelessClientsBlocklist requestBody: content: application/json: examples: Example: value: macs: - 18-65-90-de-f4-c6 - 84-89-ad-5d-69-0d schema: $ref: '#/components/schemas/mac_addresses' description: Request Body responses: '200': $ref: '#/components/responses/MacsArray' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: createSiteWirelessClientsBlocklist tags: - Sites Setting /api/v1/sites/{site_id}/setting/derived: parameters: - $ref: '#/components/parameters/site_id' get: description: Get the Derived Site Settings, generated by merging the Org level templates (network templates, gateway templates) and the Site level configuration. If the same parameter is defined in both scopes, the Site level one is used. In addition, the Zoom and Teams accounts are also merged into the derived settings. operationId: getSiteSettingDerived responses: '200': $ref: '#/components/responses/SiteSettingsDerived' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: getSiteSettingDerived tags: - Sites Setting /api/v1/sites/{site_id}/setting/watched_station: parameters: - $ref: '#/components/parameters/site_id' delete: description: Delete Site Watched Station Clients operationId: deleteSiteWatchedStations responses: '200': $ref: '#/components/responses/OK' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: deleteSiteWatchedStations tags: - Sites Setting post: description: 'This endpoint is to provide list of client macs for annotation as watched station. Retrieve the current clients list from `watched_station_url` under Site:Setting' operationId: createSiteWatchedStations requestBody: content: application/json: examples: Example: value: macs: - 18-65-90-de-f4-c6 - 84-89-ad-5d-69-0d schema: $ref: '#/components/schemas/mac_addresses' description: Request Body responses: '200': $ref: '#/components/responses/MacsArray' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: createSiteWatchedStations tags: - Sites Setting /api/v1/sites/{site_id}/setting/whitelist: parameters: - $ref: '#/components/parameters/site_id' delete: description: Delete Site Whitelist Station Clients operationId: deleteSiteWirelessClientsAllowlist responses: '200': $ref: '#/components/responses/OK' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: deleteSiteWirelessClientsAllowlist tags: - Sites Setting post: description: 'This endpoint is to provide list of client macs for annotation as whitelist. Retrieve the current clients list from `whitelist_url` under Site:Setting' operationId: createSiteWirelessClientsAllowlist requestBody: content: application/json: schema: $ref: '#/components/schemas/mac_addresses' description: Request Body responses: '200': $ref: '#/components/responses/MacsArray' '400': $ref: '#/components/responses/HTTP400' '401': $ref: '#/components/responses/HTTP401' '403': $ref: '#/components/responses/HTTP403' '404': $ref: '#/components/responses/HTTP404' '429': $ref: '#/components/responses/HTTP429' summary: createSiteWirelessClientsAllowlist tags: - Sites Setting components: schemas: switch_auto_upgrade_custom_versions: additionalProperties: type: string description: Custom version to be used. The Property Key is the switch hardware and the property value is the firmware version examples: - QFX5120-32C: 23.4R2-S2.1 QFX5130-32CD: 23.4R2-S2.3 type: object protect_re_custom_protocol: default: any description: 'enum: `any`, `icmp`, `tcp`, `udp`' enum: - any - icmp - tcp - udp type: string service_policy_ewf_rule_profile: default: strict description: 'enum: `critical`, `standard`, `strict`' enum: - critical - standard - strict type: string strings: items: type: string type: array uniqueItems: true mxcluster_rad_auth_server_keywrap_format: default: ascii description: 'if used for Mist APs. enum: `ascii`, `hex`' enum: - ascii - hex type: - string - 'null' site_setting_paloalto_networks: additionalProperties: false properties: gateways: $ref: '#/components/schemas/site_setting_paloalto_networks_gateways' send_mist_nac_user_info: default: false type: boolean type: object network_internal_access: additionalProperties: false properties: enabled: type: boolean type: object app_probing_apps: description: APp-keys from [List Applications](/#operations/listApplications) examples: - - facebook items: type: string type: array juniper_srx_auto_upgrade_custom_versions: additionalProperties: description: Firmware version to deploy on the specified SRX hardware examples: - 23.4R2-S2.1 type: string description: Property key is the SRX Hardware model (e.g. "SRX4600") type: object app_probing_custom_app: additionalProperties: false properties: address: description: Required if `protocol`==`icmp` examples: - 192.168.1.1 type: string app_type: type: string hostnames: $ref: '#/components/schemas/app_probing_custom_app_hostname' key: type: string name: examples: - pos_app type: string network: examples: - lan type: string packetSize: description: If `protocol`==`icmp` maximum: 65400 minimum: 0 type: integer protocol: $ref: '#/components/schemas/app_probing_custom_app_protocol' url: description: If `protocol`==`http` examples: - www.abc.com type: string vrf: examples: - lan type: string type: object tunnel_config_node_remote_ids: description: Only if `provider`==`jse-ipsec` or `provider`==`custom-ipsec` items: type: string type: array service_policy_secintel_profile: default: default description: 'enum: `default`, `standard`, `strict`' enum: - default - standard - strict type: string network_internet_access: additionalProperties: false description: Whether this network has direct internet access properties: create_simple_service_policy: default: false type: boolean destination_nat: $ref: '#/components/schemas/network_internet_access_destination_nat' enabled: type: boolean restricted: default: false description: By default, all access is allowed, to only allow certain traffic, make `restricted`=`true` and define service_policies type: boolean static_nat: $ref: '#/components/schemas/network_internet_access_static_nat' type: object gw_routing_policy_term: additionalProperties: false properties: actions: $ref: '#/components/schemas/gw_routing_policy_term_action' matching: $ref: '#/components/schemas/gw_routing_policy_term_matching' type: object switch_bgp_config_networks: description: List of network names for BGP configuration. When a network is specified, a BGP group will be added to the VRF that network is part of. items: type: string type: array gateway_extra_route6: additionalProperties: false properties: via: format: ipv6 type: string type: object mxcluster_radsec: additionalProperties: false description: MxEdge RadSec Configuration properties: acct_servers: $ref: '#/components/schemas/mxcluster_radsec_acct_servers' auth_servers: $ref: '#/components/schemas/mxcluster_radsec_auth_servers' enabled: description: Whether to enable service on Mist Edge i.e. RADIUS proxy over TLS type: boolean match_ssid: description: Whether to match ssid in request message to select from a subset of RADIUS servers type: boolean nas_ip_source: $ref: '#/components/schemas/mxcluster_radsec_nas_ip_source' proxy_hosts: $ref: '#/components/schemas/mxcluster_radsec_proxy_hosts' server_selection: $ref: '#/components/schemas/mxcluster_radsec_server_selection' src_ip_source: $ref: '#/components/schemas/mxcluster_radsec_src_ip_source' type: object vrrp_group_auth_type: default: md5 description: 'enum: `md5`, `simple`' enum: - md5 - simple examples: - md5 type: string tunnel_config: additionalProperties: false properties: auto_provision: $ref: '#/components/schemas/tunnel_config_auto_provision' ike_lifetime: description: Only if `provider`==`custom-ipsec` type: integer ike_mode: $ref: '#/components/schemas/tunnel_config_ike_mode' ike_proposals: $ref: '#/components/schemas/tunnel_config_ike_proposals' ipsec_lifetime: description: If `provider`==`custom-ipsec` type: integer ipsec_proposals: $ref: '#/components/schemas/tunnel_config_ipsec_proposals' local_id: description: Required if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec` type: string local_subnets: $ref: '#/components/schemas/tunnel_config_local_subnets' mode: $ref: '#/components/schemas/tunnel_config_tunnel_mode' networks: $ref: '#/components/schemas/tunnel_config_networks' primary: $ref: '#/components/schemas/tunnel_config_node' probe: $ref: '#/components/schemas/tunnel_config_probe' protocol: $ref: '#/components/schemas/tunnel_config_protocol' provider: $ref: '#/components/schemas/tunnel_config_provider' psk: description: Required if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec` type: string remote_subnets: $ref: '#/components/schemas/tunnel_config_remote_subnets' secondary: $ref: '#/components/schemas/tunnel_config_node' version: $ref: '#/components/schemas/tunnel_config_version' type: object site_rogue: additionalProperties: false description: Rogue site settings properties: allowed_vlan_ids: $ref: '#/components/schemas/vlan_ids' enabled: default: false description: Whether rogue detection is enabled type: boolean honeypot_enabled: default: false description: Whether honeypot detection is enabled type: boolean min_duration: default: 10 description: Minimum duration for a bssid to be considered neighbor examples: - 10 maximum: 59 type: integer min_rogue_duration: default: 10 description: Minimum duration for a bssid to be considered rogue examples: - 10 maximum: 59 type: integer min_rogue_rssi: default: -80 description: Minimum RSSI for an AP to be considered rogue examples: - -80 minimum: -85 type: integer min_rssi: default: -80 description: Minimum RSSI for an AP to be considered neighbor (ignoring APs that’s far away) examples: - -80 minimum: -85 type: integer whitelisted_bssids: $ref: '#/components/schemas/site_rogue_whitelisted_bssids' whitelisted_ssids: $ref: '#/components/schemas/site_rogue_whitelisted_ssids' type: object vars_annotation: additionalProperties: false description: Annotation for a single var, helping identify its purpose and enabling auto-complete/enumeration in UI properties: note: description: User-provided note to describe what this var was created for type: string type: default: generic description: 'Used to identify where to enumerate / auto-complete the field from. Default is `generic` (plain string, no special handling). enum: `generic`, `mxtunnel_id`' type: string type: object switch_bgp_config_hold_time: description: Hold time is three times the interval at which keepalive messages are sent. It indicates to the peer the length of time that it should consider the sender valid. Must be 0 or a number in the range 3-65535. oneOf: - $ref: '#/components/schemas/switch_bgp_config_hold_time_zero' - $ref: '#/components/schemas/switch_bgp_config_hold_time_integer' sw_routing_policy_term_matching: additionalProperties: false description: zero or more criteria/filter can be specified to match the term, all criteria have to be met properties: as_path: $ref: '#/components/schemas/routing_policy_term_matching_as_path' community: $ref: '#/components/schemas/routing_policy_term_matching_community' prefix: $ref: '#/components/schemas/routing_policy_term_matching_prefix' protocol: $ref: '#/components/schemas/sw_routing_policy_term_matching_protocol' type: object app_probing_custom_app_protocol: default: http description: 'enum: `http`, `icmp`' enum: - http - icmp type: string tunnel_config_tunnel_mode: default: active-standby description: 'Required if `provider`==`zscaler-gre`, `provider`==`jse-ipsec`. enum: `active-active`, `active-standby`' enum: - active-active - active-standby type: string gw_routing_policy_terms: description: zero or more criteria/filter can be specified to match the term, all criteria have to be met items: $ref: '#/components/schemas/gw_routing_policy_term' type: array uniqueItems: true gateway_port_dsl_type: default: vdsl description: 'if `wan_type`==`dsl`. enum: `adsl`, `vdsl`' enum: - adsl - vdsl type: string switch_auto_upgrade_container: additionalProperties: false properties: auto_upgrade: $ref: '#/components/schemas/switch_auto_upgrade' type: object acl_policy_src_tags: description: "ACL Policy Source Tags:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to" items: examples: - macs type: string type: array site_setting_srx_app: additionalProperties: false properties: enabled: default: false type: boolean type: object site_mxtunnel_additional_mxtunnel: additionalProperties: false properties: clusters: $ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel_clusters' hello_interval: default: 60 description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by hello_retries examples: - 60 maximum: 300 minimum: 1 type: integer hello_retries: default: 7 examples: - 3 maximum: 30 minimum: 2 type: integer protocol: $ref: '#/components/schemas/site_mxtunnel_protocol' vlan_ids: $ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel_vlan_ids' type: object sle_thresholds: additionalProperties: false properties: capacity: default: 20 description: Capacity, in % maximum: 50 minimum: 5 type: integer coverage: default: -72 description: Coverage, in dBm maximum: -60 minimum: -90 type: integer throughput: default: 10 description: Throughput, in Mbps maximum: 100 minimum: 1 type: integer time-to-connect: default: 4 description: Time to connect, in seconds maximum: 10 minimum: 2 type: integer type: object snmpv3_config_target_address: items: $ref: '#/components/schemas/snmpv3_config_target_address_item' type: array acl_tags: additionalProperties: $ref: '#/components/schemas/acl_tag' description: ACL Tags to identify traffic source or destination. Key name is the tag name type: object site_setting_config_push_policy: additionalProperties: false description: Mist also uses some heuristic rules to prevent destructive configs from being pushed properties: no_push: default: false description: Stop any new config from being pushed to the device type: boolean push_window: $ref: '#/components/schemas/push_policy_push_window' type: object tacacs_default_role: default: none description: 'enum: `admin`, `helpdesk`, `none`, `read`' enum: - admin - helpdesk - none - read type: string switch_port_usage_mac_auth_protocol: default: eap-md5 description: 'Only if `mode`!=`dynamic` and `enable_mac_auth` ==`true`. This type is ignored if mist_nac is enabled. enum: `eap-md5`, `eap-peap`, `pap`' enum: - eap-md5 - eap-peap - pap type: string mxcluster_radsec_src_ip_source: default: any description: 'Specify IP address to connect to auth_servers and acct_servers. enum: `any`, `oob`, `oob6`, `tunnel`, `tunnel6`' enum: - any - oob - oob6 - tunnel - tunnel6 type: string gateway_port_config_ip_config: additionalProperties: false description: Junos IP Config properties: dns: $ref: '#/components/schemas/gateway_ip_config_dns_servers' dns_suffix: $ref: '#/components/schemas/gateway_ip_config_dns_suffix' gateway: description: Except for out-of_band interface (vme/em0/fxp0). Interface Default Gateway IP Address (i.e. "192.168.1.1") or a Variable (i.e. "{{myvar}}") examples: - 192.168.1.1 type: string gateway6: description: Except for out-of_band interface (vme/em0/fxp0). Interface Default Gateway IPv6 Address (i.e. "2001:db8::1") or a Variable (i.e. "{{myvar}}") examples: - 2001:db8::1 type: string ip: description: Interface IP Address (i.e. "192.168.1.8") or a Variable (i.e. "{{myvar}}") examples: - 192.168.1.8 format: ipv4 type: string ip6: description: Interface IPv6 Address (i.e. "2001:db8::123") or a Variable (i.e. "{{myvar}}") examples: - 2001:db8::123 format: ipv6 type: string netmask: description: Used only if `subnet` is not specified in `networks`. Interface Netmask (i.e. "/24") or a Variable (i.e. "{{myvar}}") examples: - /24 type: string netmask6: description: Used only if `subnet` is not specified in `networks`. Interface IPv6 Netmask (i.e. "/64") or a Variable (i.e. "{{myvar}}") examples: - /64 type: string network: description: Optional, the network to be used for mgmt type: string poser_password: description: If `type`==`pppoe` type: string pppoe_auth: $ref: '#/components/schemas/gateway_wan_ppoe_auth' pppoe_username: description: If `type`==`pppoe` type: string type: $ref: '#/components/schemas/gateway_wan_type' type6: $ref: '#/components/schemas/gateway_wan_type6' type: object gateway_wan_probe_override: additionalProperties: false description: Only if `usage`==`wan` properties: ip6s: $ref: '#/components/schemas/strings' ips: $ref: '#/components/schemas/strings' probe_profile: $ref: '#/components/schemas/gateway_wan_probe_override_probe_profile' type: object snmp_vacm_access_item_prefix_list_item_level: description: 'enum: `authentication`, `none`, `privacy`' enum: - authentication - none - privacy type: string radsec_servers: description: List of RadSec Servers. Only if not Mist Edge. items: $ref: '#/components/schemas/radsec_server' type: array uniqueItems: true app_probing_custom_app_hostname: description: If `protocol`==`http` examples: - - https://www.abc.com items: type: string type: array extra_route: additionalProperties: false properties: discard: default: false description: This takes precedence type: boolean metric: examples: - null maximum: 2147483647 minimum: 0 type: - integer - 'null' next_qualified: additionalProperties: $ref: '#/components/schemas/extra_route_next_qualified_properties' examples: - 10.3.1.1: metric: null preference: 40 type: object no_resolve: default: false type: boolean preference: examples: - 30 maximum: 2147483647 minimum: 0 type: - integer - 'null' via: $ref: '#/components/schemas/next_hop_via' type: object gateway_port_lte_auth: default: none description: 'if `wan_type`==`lte`. enum: `chap`, `none`, `pap`' enum: - chap - none - pap type: string gw_routing_policy_term_action_add_community: items: examples: - '3900190' type: string type: array snmp_usm_user: additionalProperties: false properties: authentication_password: description: Not required if `authentication_type`==`authentication-none`. Include alphabetic, numeric, and special characters, but it cannot include control characters. minLength: 7 type: string authentication_type: $ref: '#/components/schemas/snmp_usm_user_authentication_type' encryption_password: description: Not required if `encryption_type`==`privacy-none`. Include alphabetic, numeric, and special characters, but it cannot include control characters minLength: 8 type: string encryption_type: $ref: '#/components/schemas/snmp_usm_user_encryption_type' name: type: string type: object routing_policy_term_matching_as_path: items: $ref: '#/components/schemas/bgp_as' type: array switch_matching_rule_ip_config: additionalProperties: false description: In-Band Management interface configuration properties: network: description: VLAN Name for the management interface type: string type: $ref: '#/components/schemas/ip_type' type: object tunnel_provider_options: additionalProperties: false properties: jse: $ref: '#/components/schemas/tunnel_provider_options_jse' prisma: $ref: '#/components/schemas/tunnel_provider_options_prisma' zscaler: $ref: '#/components/schemas/tunnel_provider_options_zscaler' type: object radius_acct_server: additionalProperties: false properties: host: description: IP/ hostname of RADIUS server examples: - 1.2.3.4 type: string keywrap_enabled: type: boolean keywrap_format: $ref: '#/components/schemas/radius_keywrap_format' keywrap_kek: examples: - '1122334455' type: string keywrap_mack: examples: - '1122334455' type: string port: $ref: '#/components/schemas/radius_acct_port' secret: description: Secret of RADIUS server examples: - testing123 format: password type: string required: - host - secret type: object gateway_mgmt_probe_hostsv6: examples: - - 2001:4860:4860::8888 format: ipv6 items: type: string type: array network_internet_access_static_nat: additionalProperties: $ref: '#/components/schemas/network_internet_access_static_nat_property' description: Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}") type: object idp_profile: properties: base_profile: $ref: '#/components/schemas/idp_profile_base_profile' created_time: $ref: '#/components/schemas/created_time' id: $ref: '#/components/schemas/id' modified_time: $ref: '#/components/schemas/modified_time' name: examples: - relaxed type: string org_id: $ref: '#/components/schemas/org_id' overwrites: $ref: '#/components/schemas/idp_profile_overwrites' type: object remote_syslog: additionalProperties: false properties: archive: $ref: '#/components/schemas/remote_syslog_archive' cacerts: $ref: '#/components/schemas/remote_syslog_cacerts' console: $ref: '#/components/schemas/remote_syslog_console' enabled: default: false type: boolean files: $ref: '#/components/schemas/remote_syslog_files' network: description: If source_address is configured, will use the vlan firstly otherwise use source_ip examples: - default type: string send_to_all_servers: default: false type: boolean servers: $ref: '#/components/schemas/remote_syslog_servers' time_format: $ref: '#/components/schemas/remote_syslog_time_format' users: $ref: '#/components/schemas/remote_syslog_users' type: object switch_port_usage_dynamic_rule_equals_any: description: Use `equals_any` to match any item in a list items: type: string type: array gateway_wan_ppoe_auth: default: none description: 'if `type`==`pppoe`. enum: `chap`, `none`, `pap`' enum: - chap - none - pap type: string snmp_config_trap_group_targets: items: examples: - 172.29.158.19 type: string type: array site_mxtunnel_additional_mxtunnel_clusters: description: For AP, how to connect to tunterm or RadSec Proxy items: $ref: '#/components/schemas/site_mxtunnel_cluster' type: array network_source_nat: additionalProperties: false description: If `routed`==`false` (usually at Spoke), but some hosts needs to be reachable from Hub properties: external_ip: examples: - 172.16.0.8/30 type: string type: object network_tenant_addresses: items: description: The user/tenant IP Address (i.e. "192.168.70.30"), an Subnet (i.e. "192.168.70.0/24") or a Variable (i.e. "{{myvar}}") examples: - 192.168.70.30 type: string type: array snmpv3_config_target_param: additionalProperties: false properties: message_processing_model: $ref: '#/components/schemas/snmpv3_config_target_param_mess_process_model' name: type: string notify_filter: description: Refer to profile-name in notify_filter type: string security_level: $ref: '#/components/schemas/snmpv3_config_target_param_security_level' security_model: $ref: '#/components/schemas/snmpv3_config_target_param_security_model' security_name: description: Refer to security_name in usm examples: - m01620 type: string type: object mxcluster_radsec_auth_server_ssids: description: List of ssids that will use this server if match_ssid is true and match is found items: type: string type: array simple_alert: additionalProperties: false description: Set of heuristic rules will be enabled when marvis subscription is not available. It triggers when, in a Z minute window, there are more than Y distinct client encountering over X failures properties: arp_failure: $ref: '#/components/schemas/simple_alert_arp_failure' dhcp_failure: $ref: '#/components/schemas/simple_alert_dhcp_failure' dns_failure: $ref: '#/components/schemas/simple_alert_dns_failure' type: object gateway_template_type: default: standalone description: 'enum: `spoke`, `standalone`' enum: - spoke - standalone examples: - standalone type: string gateway_ip_config_property_second_ips: description: Optional list of secondary IPs in CIDR format examples: - - 192.168.50.1/24 - 192.168.60.1/26 items: type: string type: array app_probing: additionalProperties: false properties: apps: $ref: '#/components/schemas/app_probing_apps' custom_apps: $ref: '#/components/schemas/app_probing_custom_apps' enabled: type: boolean type: object junos_port_config: additionalProperties: false description: Switch port config properties: ae_disable_lacp: description: To disable LACP support for the AE interface type: boolean ae_idx: description: Users could force to use the designated AE name type: integer ae_lacp_force_up: default: false description: 'If `aggregated`==`true`, sets the state of the interface as UP when the peer has limited LACP capability. Use case: When a device connected to this AE port is ZTPing for the first time, it will not have LACP configured on the other end. **Note:** Turning this on will enable force-up on one of the interfaces in the bundle only' type: boolean ae_lacp_slow: description: To use slow timeout type: boolean aggregated: default: false type: boolean critical: default: false description: To generate port up/down alarm type: boolean description: type: string disable_autoneg: default: false description: If `speed` and `duplex` are specified, whether to disable autonegotiation type: boolean duplex: $ref: '#/components/schemas/junos_port_config_duplex' dynamic_usage: description: Enable dynamic usage for this port. Set to `dynamic` to enable. type: - string - 'null' esilag: type: boolean mtu: default: 1514 description: Media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation type: integer networks: description: List of network names. Required if `usage`==`inet` items: type: string type: array no_local_overwrite: default: true description: Prevent helpdesk to override the port config type: boolean poe_disabled: default: false type: boolean port_network: description: Required if `usage`==`vlan_tunnel`. Q-in-Q tunneling using All-in-one bundling. This also enables standard L2PT for interfaces that are not encapsulation tunnel interfaces and uses MAC rewrite operation. [View more information](https://www.juniper.net/documentation/us/en/software/junos/multicast-l2/topics/topic-map/q-in-q.html#id-understanding-qinq-tunneling-and-vlan-translation) type: string speed: $ref: '#/components/schemas/junos_port_config_speed' usage: description: Port usage name. For Q-in-Q, use `vlan_tunnel`. If EVPN is used, use `evpn_uplink`or `evpn_downlink` type: string required: - usage type: object tunnel_config_ike_mode: default: main description: 'Only if `provider`==`custom-ipsec`. enum: `aggressive`, `main`' enum: - aggressive - main type: string gateway_template: description: Gateway Template is applied to a site for gateway(s) in a site. properties: additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' bgp_config: additionalProperties: $ref: '#/components/schemas/bgp_config' type: object created_time: $ref: '#/components/schemas/created_time' dhcpd_config: $ref: '#/components/schemas/dhcpd_config' dnsOverride: default: false type: boolean dns_servers: $ref: '#/components/schemas/dns_servers' dns_suffix: $ref: '#/components/schemas/dns_suffix' extra_routes: $ref: '#/components/schemas/gateway_extra_routes' extra_routes6: $ref: '#/components/schemas/gateway_extra_routes6' gateway_matching: $ref: '#/components/schemas/gateway_matching' gateway_mgmt: $ref: '#/components/schemas/gateway_mgmt' id: $ref: '#/components/schemas/id' idp_profiles: $ref: '#/components/schemas/gateway_idp_profiles' ip_configs: $ref: '#/components/schemas/gateway_ip_configs' modified_time: $ref: '#/components/schemas/modified_time' name: examples: - gw_template type: string networks: $ref: '#/components/schemas/networks' ntpOverride: default: false type: boolean ntp_servers: $ref: '#/components/schemas/ntp_servers' oob_ip_config: $ref: '#/components/schemas/gateway_oob_ip_config' org_id: $ref: '#/components/schemas/org_id' path_preferences: additionalProperties: $ref: '#/components/schemas/gateway_path_preferences' description: Property key is the path name type: object port_config: additionalProperties: $ref: '#/components/schemas/gateway_port_config' description: Property key is the Port Name (i.e. "ge-0/0/0"), the Ports Range (i.e. "ge-0/0/0-10"), the List of Ports (i.e. "ge-0/0/0,ge-1/0/0", only allowed for Aggregated or Redundant interfaces) or a Variable (i.e. "{{myvar}}"). type: object router_id: description: Auto assigned if not set examples: - 10.2.1.10 type: string routing_policies: $ref: '#/components/schemas/gw_routing_policies' service_policies: $ref: '#/components/schemas/service_policies' tunnel_configs: additionalProperties: $ref: '#/components/schemas/tunnel_config' description: Property key is the tunnel name type: object tunnel_provider_options: $ref: '#/components/schemas/tunnel_provider_options' type: $ref: '#/components/schemas/gateway_template_type' url_filtering_deny_msg: default: Access to this URL Category has been blocked description: When a service policy denies a app_category, what message to show in user's browser examples: - Access to this URL Category has been blocked type: string vrf_config: $ref: '#/components/schemas/vrf_config' vrf_instances: $ref: '#/components/schemas/gateway_vrf_instances' required: - name type: object tunnel_config_auto_provision_lat_lng: additionalProperties: false description: API override for POP selection properties: lat: examples: - 37.295833 format: double type: number lng: examples: - -122.032946 format: double type: number required: - lat - lng type: object sw_routing_policy_term: additionalProperties: false properties: actions: $ref: '#/components/schemas/sw_routing_policy_term_action' matching: $ref: '#/components/schemas/sw_routing_policy_term_matching' name: type: string required: - name type: object snmpv3_config: additionalProperties: false properties: notify: $ref: '#/components/schemas/snmpv3_config_notify' notify_filter: $ref: '#/components/schemas/snmpv3_config_notify_filter' target_address: $ref: '#/components/schemas/snmpv3_config_target_address' target_parameters: $ref: '#/components/schemas/snmpv3_config_target_params' usm: $ref: '#/components/schemas/snmp_usms' vacm: $ref: '#/components/schemas/snmp_vacm' type: object site_setting_vna: additionalProperties: false properties: enabled: default: false description: Enable Virtual Network Assistant (using SUB-VNA license). This applied to AP / Switch / Gateway type: boolean type: object dhcpd_config_type6: default: none description: 'enum: `local` (DHCP Server), `none`, `relay` (DHCP Relay)' enum: - local - none - relay type: string ap_radio_band24: additionalProperties: false description: Radio Band AP settings properties: allow_rrm_disable: default: false type: boolean ant_gain: default: 0 maximum: 10 minimum: 0 type: - integer - 'null' antenna_mode: $ref: '#/components/schemas/radio_band_antenna_mode' bandwidth: $ref: '#/components/schemas/dot11_bandwidth24' channel: default: null description: For Device. (primary) channel for the band, 0 means using the Site Setting examples: - 6 maximum: 13 minimum: 1 type: - integer - 'null' channels: $ref: '#/components/schemas/radio_band_channels' disabled: default: false description: Whether to disable the radio type: boolean power: default: null description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …' examples: - 3 maximum: 25 minimum: 3 type: - integer - 'null' power_max: default: 17 description: When power=0, max tx power to use, HW-specific values will be used if not set maximum: 18 minimum: 3 type: - integer - 'null' power_min: default: 8 description: When power=0, min tx power to use, HW-specific values will be used if not set maximum: 18 minimum: 3 type: - integer - 'null' preamble: $ref: '#/components/schemas/radio_band_preamble' type: object site_setting_derived_accounts: additionalProperties: $ref: '#/components/schemas/account_oauth_info_account' type: object radius_config: additionalProperties: false description: Junos Radius config properties: acct_interim_interval: default: 0 description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from RADIUS Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled maximum: 65535 minimum: 0 type: integer acct_servers: $ref: '#/components/schemas/radius_acct_servers' auth_servers: $ref: '#/components/schemas/radius_auth_servers' auth_servers_retries: default: 3 description: radius auth session retries type: integer auth_servers_timeout: default: 5 description: radius auth session timeout type: integer coa_enabled: default: false type: boolean coa_port: default: 3799 maximum: 65535 minimum: 1 type: integer network: description: use `network`or `source_ip`, which network the RADIUS server resides, if there's static IP for this network, we'd use it as source-ip type: string source_ip: description: use `network`or `source_ip` type: string type: object switch_port_mirroring_ingress_port_ids: description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified items: examples: - ge-0/0/3 type: string type: array gateway_extra_routes6: additionalProperties: $ref: '#/components/schemas/gateway_extra_route6' description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64"), the destination Network name or a variable (e.g. "{{myvar}}") examples: - 2a02:1234:420a:10c9::/64: via: 2a02:1234:200a::100 type: object ap_led: additionalProperties: false description: LED AP settings properties: brightness: default: 255 examples: - 255 maximum: 255 minimum: 0 type: integer enabled: default: true type: boolean type: object dhcpd_config_dns_servers: description: If `type`==`local` or `type6`==`local` - optional, if not defined, system one will be used examples: - - 8.8.8.8 - 4.4.4.4 - 2001:4860:4860::8888 items: type: string type: array remote_syslog_cacerts: examples: - - '-----BEGIN CERTIFICATE-----\nMIIFZjCCA06gAwIBAgIIP61/1qm/uDowDQYJKoZIhvcNAQELBQE\n-----END CERTIFICATE-----' - '-----BEGIN CERTIFICATE-----\nBhMCRVMxFDASBgNVBAoMC1N0YXJ0Q29tIENBMSwwKgYDVn-----END CERTIFICATE-----' items: type: string type: array gateway_port_vpn_path_role: default: spoke description: 'If the VPN `type`==`hub_spoke`, enum: `hub`, `spoke`. If the VPN `type`==`mesh`, enum: `mesh`' enum: - hub - mesh - spoke type: string ospf_area_network_auth_type: default: none description: 'auth type. enum: `md5`, `none`, `password`' enum: - md5 - none - password examples: - md5 type: string site_setting_juniper_srx: additionalProperties: false properties: auto_upgrade: $ref: '#/components/schemas/juniper_srx_auto_upgrade' gateways: $ref: '#/components/schemas/site_setting_juniper_srx_gateways' send_mist_nac_user_info: type: boolean type: object gateway_extra_route: additionalProperties: false properties: via: format: ipv4 type: string type: object network_template: description: Network Template properties: acl_policies: $ref: '#/components/schemas/acl_policies' acl_tags: $ref: '#/components/schemas/acl_tags' additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' bgp_config: additionalProperties: $ref: '#/components/schemas/switch_bgp_config' type: object created_time: $ref: '#/components/schemas/created_time' dhcp_snooping: $ref: '#/components/schemas/dhcp_snooping' dns_servers: $ref: '#/components/schemas/dns_servers' dns_suffix: $ref: '#/components/schemas/dns_suffix' extra_routes: $ref: '#/components/schemas/extra_routes' extra_routes6: $ref: '#/components/schemas/extra_routes6' id: $ref: '#/components/schemas/id' import_org_networks: $ref: '#/components/schemas/network_template_import_org_networks' mist_nac: $ref: '#/components/schemas/switch_mist_nac' modified_time: $ref: '#/components/schemas/modified_time' name: type: string networks: $ref: '#/components/schemas/switch_networks' ntp_servers: $ref: '#/components/schemas/ntp_servers' org_id: $ref: '#/components/schemas/org_id' ospf_areas: $ref: '#/components/schemas/ospf_areas' port_mirroring: $ref: '#/components/schemas/switch_port_mirroring' port_usages: $ref: '#/components/schemas/switch_port_usages' radius_config: $ref: '#/components/schemas/switch_radius_config' remote_syslog: $ref: '#/components/schemas/remote_syslog' remove_existing_configs: default: false description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed. type: boolean routing_policies: $ref: '#/components/schemas/sw_routing_policies' snmp_config: $ref: '#/components/schemas/snmp_config' switch_matching: $ref: '#/components/schemas/switch_matching' switch_mgmt: $ref: '#/components/schemas/switch_mgmt' vrf_config: $ref: '#/components/schemas/vrf_config' vrf_instances: $ref: '#/components/schemas/switch_vrf_instances' type: object snmp_vacm_security_to_group: additionalProperties: false properties: content: $ref: '#/components/schemas/snmp_vacm_security_to_group_content' security_model: $ref: '#/components/schemas/snmp_vacm_security_model' type: object tunnel_provider_options_jse: additionalProperties: false description: For jse-ipsec, this allows provisioning of adequate resource on JSE. Make sure adequate licenses are added properties: num_users: examples: - 5 type: integer org_name: description: JSE Organization name. The list of available organizations can be retrieved with the [Get Org JSE Info](/#operations/getOrgJseInfo) API Call examples: - JSE_ORG1 type: string type: object network_vpn_access_destination_nat_property: additionalProperties: false properties: internal_ip: description: The Destination NAT destination IP Address. Must be an IP (i.e. "192.168.70.30") or a Variable (i.e. "{{myvar}}") examples: - 192.168.70.30 type: string name: examples: - web server type: string port: examples: - '443' type: string type: object dot11_bandwidth5: default: 40 description: 'channel width for the 5GHz band. enum: `0`(disabled, response only), `20`, `40`, `80`' enum: - 0 - 20 - 40 - 80 examples: - 40 type: integer tacacs_acct_servers: items: $ref: '#/components/schemas/tacacs_acct_server' type: array switch_bgp_config_hold_time_zero: enum: - 0 type: integer protect_re_allowed_services: description: Optionally, services we'll allow examples: - - icmp - ssh items: $ref: '#/components/schemas/protect_re_allowed_service' type: array dhcpd_config_servers6: description: If `type6`==`relay` examples: - - 2607:f8b0:4005:808::64 items: type: string type: array synthetictest_config_wan_speedtest: additionalProperties: false properties: enabled: type: boolean time_of_day: $ref: '#/components/schemas/time_of_day' type: object snmp_vacm_access_item_prefix_list_item: additionalProperties: false properties: context_prefix: description: Only required if `type`==`context_prefix` examples: - iil type: string notify_view: description: Refer to view name examples: - all type: string read_view: description: Refer to view name examples: - all type: string security_level: $ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item_level' security_model: $ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item_model' type: $ref: '#/components/schemas/snmp_vacm_access_item_type' write_view: description: Refer to view name examples: - all type: string type: object additional_vlan_ids: anyOf: - type: string - $ref: '#/components/schemas/additional_vlan_ids_array' description: List or Comma separated list of additional VLAN IDs (on the LAN side or from other WLANs) should we be forwarding bonjour queries/responses switch_port_usage_dynamic_vlan_networks: description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`, if dynamic vlan is used, specify the possible networks/vlans RADIUS can return examples: - - corp - user items: type: string type: array site_setting_auto_upgrade_esl: additionalProperties: false description: auto upgrade AP ESL. When both firmware and ESL auto-upgrade are enabled, ESL upgrade will be done only after firmware upgrade properties: allow_downgrade: default: false description: If true, it will allow downgrade to a lower version type: boolean custom_versions: additionalProperties: type: string description: Custom versions for different models. Property key is the model name (e.g. "AP41") examples: - AP41: 2.4.6 AP61: 2.5.0 type: object day_of_week: $ref: '#/components/schemas/day_of_week' enabled: default: false description: Whether auto upgrade should happen (Note that Mist may auto-upgrade if the version is not supported) type: boolean time_of_day: description: '`any` / HH:MM (24-hour format), upgrade will happen within up to 1-hour from this time' examples: - '12:00' type: string version: examples: - 2.5.0 type: string type: object next_hop_via: description: Next-hop IP Address. Can be a single IP address or an array of IP addresses for ECMP (Equal-Cost Multi-Path) load balancing across multiple next-hops. examples: - 10.2.1.1 - - 10.2.1.1 - 10.2.1.2 oneOf: - type: string - items: type: string type: array antenna_select: description: 'Antenna Mode for AP which supports selectable antennas. enum: `""` (default), `external`, `internal`' enum: - '' - external - internal examples: - external type: string protect_re_custom: additionalProperties: false description: Custom acls properties: port_range: default: '0' description: Matched dst port, "0" means any examples: - 80,1035-1040 type: string protocol: $ref: '#/components/schemas/protect_re_custom_protocol' subnets: $ref: '#/components/schemas/protect_re_custom_subnet' type: object switch_matching: additionalProperties: false description: Defines custom switch configuration based on different criteria properties: enable: type: boolean rules: $ref: '#/components/schemas/switch_matching_rules' type: object gateway_port_vpn_path_bfd_profile: default: broadband description: 'Only if the VPN `type`==`hub_spoke`. enum: `broadband`, `lte`' enum: - broadband - lte type: string synthetictest_config_custom_probes: additionalProperties: $ref: '#/components/schemas/synthetictest_config_custom_probe' description: Custom probes to be used for synthetic tests type: object radio_band_preamble: default: short description: 'enum: `auto`, `long`, `short`' enum: - auto - long - short type: string config_switch_local_accounts: additionalProperties: $ref: '#/components/schemas/config_switch_local_accounts_user' description: Property key is the user name. For Local user authentication type: object snmpv3_config_notify_filter_item_content: additionalProperties: false properties: include: type: boolean oid: examples: - 1.3.6.1.4.1 type: string type: object mist_nacedge: additionalProperties: false properties: auth_ttl: default: 604800 description: Cache of last auth result; in seconds maximum: 2592000 minimum: 60 type: integer default_dot1x_vlan: description: Default vlan for all dot1x devices, if different from default_vlan examples: - '20' type: string default_vlan: description: Default vlan to assign for devices not in the cache examples: - test_vlan type: string enabled: type: boolean mxedge_hosts: $ref: '#/components/schemas/mist_nacedge_mxedge_hosts' type: object site_setting_flags: additionalProperties: type: string description: Name/val pair objects for location engine to use type: object tunnel_config_ike_proposal: additionalProperties: false properties: auth_algo: $ref: '#/components/schemas/tunnel_config_auth_algo' dh_group: $ref: '#/components/schemas/tunnel_config_ike_dh_group' enc_algo: $ref: '#/components/schemas/tunnel_config_enc_algo' type: object account_oauth_info_account_service_connection: additionalProperties: false properties: region: description: Region of the service connection examples: - us-southwest type: string type: object sw_routing_policy_term_matching_protocol_enum: description: 'enum: `bgp`, `direct`, `evpn`, `ospf`, `static`' enum: - bgp - direct - evpn - ospf - static type: string gateway_ip_config_dns_servers: description: Except for out-of_band interface (vme/em0/fxp0) items: type: string type: array snmp_config_trap_group_categories: items: examples: - authentication type: string type: array remote_syslog_contents: items: $ref: '#/components/schemas/remote_syslog_content' type: array remote_syslog_user: additionalProperties: false properties: contents: $ref: '#/components/schemas/remote_syslog_contents' match: examples: - '"!alarm|ntp|errors.crc_error[chan]"' type: string user: examples: - '*' type: string type: object protect_re: additionalProperties: false description: "Restrict inbound-traffic to host\nwhen enabled, all traffic that is not essential to our operation will be dropped \ne.g. ntp / dns / traffic to mist will be allowed by default, if dhcpd is enabled, we'll make sure it works" properties: allowed_services: $ref: '#/components/schemas/protect_re_allowed_services' custom: $ref: '#/components/schemas/protect_re_customs' enabled: default: false description: "When enabled, all traffic that is not essential to our operation will be dropped\ne.g. ntp / dns / traffic to mist will be allowed by default\n if dhcpd is enabled, we'll make sure it works" type: boolean hit_count: default: false description: Whether to enable hit count for Protect_RE policy type: boolean trusted_hosts: $ref: '#/components/schemas/protect_re_trusted_hosts' type: object tunnel_config_probe: additionalProperties: false description: Only if `provider`==`custom-ipsec` properties: interval: description: How often to trigger the probe type: integer threshold: description: Number of consecutive misses before declaring the tunnel down type: integer timeout: description: Time within which to complete the connectivity check type: integer type: $ref: '#/components/schemas/tunnel_config_probe_type' type: object snmp_config_v2c_config: additionalProperties: false properties: authorization: examples: - read-only type: string client_list_name: description: Client_list_name here should refer to client_list above examples: - clist-1 type: string community_name: examples: - abc123 type: string view: description: View name here should be defined in views above examples: - all type: string type: object tunterm_monitoring_item: additionalProperties: false properties: host: description: Can be ip, ipv6, hostname examples: - 10.2.8.15 minLength: 1 type: string port: description: When `protocol`==`tcp` examples: - 80 type: integer protocol: $ref: '#/components/schemas/tunterm_monitoring_protocol' src_vlan_id: description: Optional source for the monitoring check, vlan_id configured in tunterm_other_ip_configs examples: - 5 type: integer timeout: default: 300 examples: - 300 type: integer type: object protect_re_trusted_hosts: description: host/subnets we'll allow traffic to/from items: examples: - 10.242.3.0/24 type: string type: array switch_bgp_config_type: description: 'enum: `external`, `internal`' enum: - external - internal type: string sw_routing_policy_term_action: additionalProperties: false description: When used as import policy properties: accept: type: boolean community: $ref: '#/components/schemas/routing_policy_term_action_community' local_preference: $ref: '#/components/schemas/routing_policy_local_preference' prepend_as_path: $ref: '#/components/schemas/routing_policy_term_action_prepend_as_path' type: object simple_alert_dns_failure: additionalProperties: false properties: client_count: default: 20 type: integer duration: default: 10 description: failing within minutes maximum: 60 minimum: 5 type: integer incident_count: default: 30 type: integer type: object snmp_config_engine_id_type: default: local description: 'enum: `local`, `use_mac_address`' enum: - local - use_mac_address type: string gateway_matching_rule: additionalProperties: description: 'Property key defines the type of matching. e.g: `match_name[0:3]`, `match_model[0-6]` or `match_role`' type: string properties: additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' name: type: string port_config: additionalProperties: $ref: '#/components/schemas/gateway_port_config' description: Property key is the port(s) name or range (e.g. "ge-0/0/0-10"). type: object type: object gateway_port_networks: description: If `usage`==`lan`, name of the [networks]($h/Orgs%20Networks/_overview) to attach to the interface items: type: string type: array remote_syslog_file_config: additionalProperties: false properties: archive: $ref: '#/components/schemas/remote_syslog_archive' contents: $ref: '#/components/schemas/remote_syslog_contents' enable_tls: description: Only if `protocol`==`tcp` type: boolean explicit_priority: type: boolean file: examples: - file-name type: string match: examples: - '!alarm|ntp|errors.crc_error[chan]' type: string structured_data: type: boolean type: object mxcluster_radsec_acct_servers: description: List of RADIUS accounting servers, optional, order matters where the first one is treated as primary items: $ref: '#/components/schemas/mxcluster_radsec_acct_server' type: array uniqueItems: true switch_auto_upgrade: additionalProperties: false properties: custom_versions: $ref: '#/components/schemas/switch_auto_upgrade_custom_versions' enabled: description: Enable auto upgrade for the switch type: boolean snapshot: default: false description: Enable snapshot during the upgrade process type: boolean type: object ap_uplink_port_config: additionalProperties: false description: AP Uplink port configuration properties: dot1x: default: false description: Whether to do 802.1x against uplink switch. When enabled, AP cert will be used to do EAP-TLS and the Org's CA Cert has to be provisioned at the switch type: boolean keep_wlans_up_if_down: default: false description: By default, WLANs are disabled when uplink is down. In some scenario, like SiteSurvey, one would want the AP to keep sending beacons. type: boolean type: object site_setting_vrrp_groups: additionalProperties: $ref: '#/components/schemas/vrrp_group' description: Property key is the vrrp group type: object ip_type: default: dhcp description: 'enum: `dhcp`, `static`' enum: - dhcp - static examples: - static type: string dhcp_snooping_networks: description: If `all_networks`==`false`, list of network with DHCP snooping enabled items: type: string type: array network_multicast_groups: additionalProperties: $ref: '#/components/schemas/network_multicast_group' description: Group address to RP (rendezvous point) mapping. Property Key is the CIDR (example "225.1.0.3/32") type: object vars: additionalProperties: type: string description: Dictionary of name->value, the vars can then be used in Wlans. This can overwrite those from Site Vars examples: - RADIUS_IP1: 172.31.2.5 RADIUS_SECRET: 11s64632d type: object gateway_port_wan_type: default: broadband description: 'Only if `usage`==`wan`. enum: `broadband`, `dsl`, `lte`' enum: - broadband - dsl - lte type: string site_id: examples: - 441a1214-6928-442a-8e92-e1d34b8ec6a6 format: uuid readOnly: true type: string ap_radio_band6: additionalProperties: false description: Radio Band AP settings properties: allow_rrm_disable: default: false type: boolean ant_gain: default: 0 maximum: 10 minimum: 0 type: - integer - 'null' antenna_beam_pattern: $ref: '#/components/schemas/radio_band_antenna_beam_pattern' antenna_mode: $ref: '#/components/schemas/radio_band_antenna_mode' bandwidth: $ref: '#/components/schemas/dot11_bandwidth6' channel: default: null description: For Device. (primary) channel for the band, 0 means using the Site Setting examples: - 0 type: - integer - 'null' channels: $ref: '#/components/schemas/radio_band_channels' disabled: default: false description: Whether to disable the radio type: boolean power: default: null description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …' examples: - 7 maximum: 25 minimum: 5 type: - integer - 'null' power_max: default: 18 description: When power=0, max tx power to use, HW-specific values will be used if not set maximum: 18 minimum: 5 type: - integer - 'null' power_min: default: 8 description: When power=0, min tx power to use, HW-specific values will be used if not set maximum: 18 minimum: 5 type: - integer - 'null' preamble: $ref: '#/components/schemas/radio_band_preamble' standard_power: default: false description: For 6GHz Only, standard-power operation, AFC (Automatic Frequency Coordination) will be performed, and we'll fall back to Low Power Indoor if AFC failed type: boolean type: object dhcpd_config_fixed_binding: additionalProperties: false properties: ip: examples: - 192.168.70.35 type: string ip6: examples: - 2607:f8b0:4005:808::2 type: string name: type: string type: object switch_networks: additionalProperties: $ref: '#/components/schemas/switch_network' description: Property key is network name type: object dhcpd_config_option: additionalProperties: false properties: type: $ref: '#/components/schemas/dhcpd_config_option_type' value: type: string type: object ospf_area_network_interface_type: default: broadcast description: 'interface type (nbma = non-broadcast multi-access). enum: `broadcast`, `nbma`, `p2mp`, `p2p`' enum: - broadcast - nbma - p2mp - p2p type: string mxedge_tunterm_multicast_config_mdns_vlan_ids: examples: - - 2 - 3 - 5 items: type: integer type: array ble_config_beam_disabled: description: List of AP BLE location beam numbers (1-8) which should be disabled at the AP and not transmit location information (where beam 1 is oriented at the top the AP, growing counter-clock-wise, with 9 being the omni BLE beam) examples: - - 1 - 3 - 6 items: type: integer type: array idp_profile_matching: additionalProperties: false properties: attack_name: $ref: '#/components/schemas/idp_profile_matching_attack_name' dst_subnet: $ref: '#/components/schemas/idp_profile_matching_dst_subnet' severity: $ref: '#/components/schemas/idp_profile_matching_severity' type: object switch_port_mirroring: additionalProperties: $ref: '#/components/schemas/switch_port_mirroring_property' description: Property key is the port mirroring instance name. `port_mirroring` can be added under device/site settings. It takes interface and ports as input for ingress, interface as input for egress and can take interface and port as output. A maximum 4 mirroring ports is allowed type: object snmp_vacm_access: items: $ref: '#/components/schemas/snmp_vacm_access_item' type: array network_vpn_access_static_nat: additionalProperties: $ref: '#/components/schemas/network_vpn_access_static_nat_property' description: Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}") type: object synthetictest_config_lan_networks: description: List of networks to be used for synthetic tests items: $ref: '#/components/schemas/synthetictest_config_lan_network' type: array radius_acct_servers: items: $ref: '#/components/schemas/radius_acct_server' type: array uniqueItems: true gw_routing_policy_term_action_exclude_community: items: examples: - '3900190' type: string type: array config_switch_local_accounts_user_role: default: none description: 'enum: `admin`, `helpdesk`, `none`, `read`' enum: - admin - helpdesk - none - read type: string site_mxtunnel_clusters: description: For AP, how to connect to tunterm or RadSec Proxy items: $ref: '#/components/schemas/site_mxtunnel_cluster' type: array setting_ssr_conductor_hosts: description: List of Conductor IP Addresses or Hosts to be used by the SSR Devices items: type: string type: array switch_port_usage_dot1x: description: 'Only if `mode`!=`dynamic`. If dot1x is desired, set to dot1x. enum: `dot1x`' enum: - dot1x type: - string - 'null' site_setting_critical_url_monitoring_monitors: items: $ref: '#/components/schemas/site_setting_critical_url_monitoring_monitor' type: array snmpv3_config_notify_filter: items: $ref: '#/components/schemas/snmpv3_config_notify_filter_item' type: array remote_syslog_facility: default: any description: 'enum: `any`, `authorization`, `change-log`, `config`, `conflict-log`, `daemon`, `dfc`, `external`, `firewall`, `ftp`, `interactive-commands`, `kernel`, `ntp`, `pfe`, `security`, `user`' enum: - any - authorization - change-log - config - conflict-log - daemon - dfc - external - firewall - ftp - interactive-commands - kernel - ntp - pfe - security - user examples: - config type: string remote_syslog_server_port: anyOf: - default: 514 maximum: 65545 minimum: 1 type: integer - type: string description: Syslog Service Port, value from 1 to 65535 synthetictest_config_custom_probe: additionalProperties: false properties: aggressiveness: $ref: '#/components/schemas/synthetictest_config_aggressiveness' target: description: Can be URL (e.g. http://x.com, https://x.com:8080/path/to/resource), IP address, or IP:port combination examples: - 10.3.5.3:8080 type: string threshold: description: In milliseconds examples: - 100 type: integer type: $ref: '#/components/schemas/synthetictest_config_custom_probe_type' type: object switch_vrf_instance: additionalProperties: false examples: - extra_routes: 0.0.0.0/0: via: 192.168.31.1 networks: - guest properties: aggregate_routes: $ref: '#/components/schemas/aggregate_routes' aggregate_routes6: $ref: '#/components/schemas/aggregate_routes6' evpn_auto_loopback_subnet: examples: - 100.101.0.0/24 type: string evpn_auto_loopback_subnet6: type: string extra_routes: $ref: '#/components/schemas/vrf_extra_routes' extra_routes6: $ref: '#/components/schemas/vrf_extra_routes6' networks: $ref: '#/components/schemas/strings' type: object evpn_options_overlay: additionalProperties: false properties: as: default: 65000 description: Overlay BGP Local AS Number examples: - 65000 maximum: 65535 minimum: 1 type: integer type: object iotproxy: additionalProperties: false description: IoT proxy configuration for the site properties: enabled: default: false type: boolean visionline: $ref: '#/components/schemas/iotproxy_visionline' type: object site_setting_tunterm_multicast_config: additionalProperties: false properties: mdns: $ref: '#/components/schemas/site_setting_tunterm_multicast_config_mdns' multicast_all: default: false type: boolean ssdp: $ref: '#/components/schemas/site_setting_tunterm_multicast_config_ssdp' type: object day_of_week: description: 'enum: `any`, `fri`, `mon`, `sat`, `sun`, `thu`, `tue`, `wed`' enum: - any - fri - mon - sat - sun - thu - tue - wed type: string time_of_day: default: any description: '`any` / HH:MM (24-hour format)' examples: - '12:00' type: string remote_syslog_server: additionalProperties: false properties: contents: $ref: '#/components/schemas/remote_syslog_contents' explicit_priority: type: boolean facility: $ref: '#/components/schemas/remote_syslog_facility' host: examples: - syslogd.internal type: string match: examples: - '!alarm|ntp|errors.crc_error[chan]' type: string port: $ref: '#/components/schemas/remote_syslog_server_port' protocol: $ref: '#/components/schemas/remote_syslog_server_protocol' routing_instance: examples: - routing-instance-name type: string server_name: description: Name of the server examples: - syslogd.internal type: string severity: $ref: '#/components/schemas/remote_syslog_severity' source_address: description: If source_address is configured, will use the vlan firstly otherwise use source_ip type: string structured_data: type: boolean tag: type: string type: object service_policy_skyatp_dns_dga_detection_profile: description: 'enum: `default`, `standard`, `strict`' enum: - default - standard - strict type: string gateway_port_config: additionalProperties: false description: Gateway port config properties: ae_disable_lacp: default: false description: If `aggregated`==`true`. To disable LCP support for the AE interface type: boolean ae_idx: description: If `aggregated`==`true`. Users could force to use the designated AE name (must be an integer between 0 and 127) type: - string - 'null' ae_lacp_force_up: default: false description: 'For SRX only, if `aggregated`==`true`.Sets the state of the interface as UP when the peer has limited LACP capability. Use case: When a device connected to this AE port is ZTPing for the first time, it will not have LACP configured on the other end. **Note:** Turning this on will enable force-up on one of the interfaces in the bundle only' type: boolean aggregated: default: false type: boolean critical: default: false description: To generate port up/down alarm, set it to true type: boolean description: description: Interface Description. Can be a variable (i.e. "{{myvar}}") type: string disable_autoneg: default: false type: boolean disabled: default: false description: Port admin up (true) / down (false) type: boolean dsl_type: $ref: '#/components/schemas/gateway_port_dsl_type' dsl_vci: default: 35 description: If `wan_type`==`dsl`, 16 bit int type: integer dsl_vpi: default: 0 description: If `wan_type`==`dsl`, 8 bit int type: integer duplex: $ref: '#/components/schemas/gateway_port_duplex' ip_config: $ref: '#/components/schemas/gateway_port_config_ip_config' lte_apn: description: If `wan_type`==`lte` type: string lte_auth: $ref: '#/components/schemas/gateway_port_lte_auth' lte_backup: type: boolean lte_password: description: If `wan_type`==`lte` type: string lte_username: description: If `wan_type`==`lte` type: string mtu: type: integer name: description: Name that we'll use to derive config type: string networks: $ref: '#/components/schemas/gateway_port_networks' outer_vlan_id: description: For Q-in-Q type: integer poe_disabled: default: false type: boolean poe_keep_state_when_reboot: default: false description: Whether Perpetual PoE capabilities are enabled for a port type: boolean port_network: description: Only for SRX and if `usage`==`lan`, the name of the Network to be used as the Untagged VLAN type: string preserve_dscp: default: true description: Whether to preserve dscp when sending traffic over VPN (SSR-only) type: boolean redundant: description: If HA mode type: boolean redundant_group: description: If HA mode, SRX Only - support redundancy-group. 1-128 for physical SRX, 1-64 for virtual SRX maximum: 128 minimum: 1 type: integer reth_idx: $ref: '#/components/schemas/gateway_port_config_reth_idx' reth_node: description: If HA mode type: string reth_nodes: $ref: '#/components/schemas/gateway_port_reth_nodes' speed: default: auto examples: - 1g type: string ssr_no_virtual_mac: default: false description: When SSR is running as VM, this is required on certain hosting platforms type: boolean svr_port_range: default: none description: For SSR only examples: - 60000-60005 type: string traffic_shaping: $ref: '#/components/schemas/gateway_traffic_shaping' usage: $ref: '#/components/schemas/gateway_port_usage' vlan_id: $ref: '#/components/schemas/gateway_port_vlan_id_with_variable' vpn_paths: $ref: '#/components/schemas/gateway_port_vpn_paths' wan_arp_policer: $ref: '#/components/schemas/gateway_port_wan_arp_policer' wan_ext_ip: description: Only if `usage`==`wan`, optional. If spoke should reach this port by a different IP examples: - 64.2.4.3 type: string wan_ext_ip6: description: Only if `usage`==`wan`, optional. If spoke should reach this port by a different IPv6 examples: - 2601:1700:43c0:dc0::10 type: string wan_extra_routes: additionalProperties: $ref: '#/components/schemas/wan_extra_routes' description: Only if `usage`==`wan`. Property Key is the destination CIDR (e.g. "100.100.100.0/24") type: object wan_extra_routes6: additionalProperties: $ref: '#/components/schemas/wan_extra_routes6' description: Only if `usage`==`wan`. Property Key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64") type: object wan_networks: $ref: '#/components/schemas/gateway_port_config_wan_networks' wan_probe_override: $ref: '#/components/schemas/gateway_wan_probe_override' wan_source_nat: $ref: '#/components/schemas/gateway_port_wan_source_nat' wan_speedtest_mode: $ref: '#/components/schemas/gateway_port_config_wan_speedtest_mode' wan_type: $ref: '#/components/schemas/gateway_port_wan_type' required: - usage type: object service_policy: additionalProperties: false properties: action: $ref: '#/components/schemas/allow_deny' antivirus: $ref: '#/components/schemas/service_policy_antivirus' appqoe: $ref: '#/components/schemas/service_policy_appqoe' ewf: $ref: '#/components/schemas/service_policy_ewf' idp: $ref: '#/components/schemas/idp_config' local_routing: description: access within the same VRF type: boolean name: type: string path_preference: description: By default, we derive all paths available and use them. Optionally, you can customize by using `path_preference` type: string secintel: $ref: '#/components/schemas/service_policy_secintel' servicepolicy_id: description: Used to link servicepolicy defined at org level and overwrite some attributes format: uuid type: string services: $ref: '#/components/schemas/strings' skyatp: $ref: '#/components/schemas/service_policy_skyatp' ssl_proxy: $ref: '#/components/schemas/service_policy_ssl_proxy' syslog: $ref: '#/components/schemas/service_policy_syslog' tenants: $ref: '#/components/schemas/strings' type: object site_setting_auto_placement: additionalProperties: false description: If we're able to determine its x/y/orientation, this will be populated properties: orientation: examples: - 45 type: integer x: examples: - 30 format: double type: number y: examples: - 60 format: double type: number type: object snmpv3_config_notify_type: description: 'enum: `inform`, `trap`' enum: - inform - trap type: string gateway_wan_probe_override_probe_profile: default: broadband description: 'enum: `broadband`, `lte`' enum: - broadband - lte type: string synthetictest_config_aggressiveness: default: auto description: 'enum: `auto`, `high`, `low`' enum: - auto - high - med - low type: string synthetictest_config_vlan_vlan_ids: examples: - - 10 - 20 - '{{vlan}}' items: $ref: '#/components/schemas/vlan_id_with_variable' type: array tunnel_config_local_subnets: description: List of Local protected subnet for policy-based IPSec negotiation items: type: string type: array gateway_port_usage: description: 'port usage name. enum: `ha_control`, `ha_data`, `lan`, `wan`' enum: - ha_control - ha_data - lan - wan type: string tacacs_acct_server: additionalProperties: false properties: host: type: string port: type: string secret: format: password type: string timeout: default: 10 type: integer type: object site_engagement_dwell_tag_names: additionalProperties: false description: Name associated to each tag properties: bounce: default: Visitor examples: - Bounce type: string engaged: default: Associates examples: - Engaged type: string passerby: default: Passerby examples: - Passer By type: string stationed: default: Assets examples: - Stationed type: string type: object evpn_options_vs_instances: additionalProperties: $ref: '#/components/schemas/evpn_options_vs_instance' description: Optional, for EX9200 only to segregate virtual-switches examples: - guest: networks: - guest iot: networks: - iot-wifi - iot-lan type: object dhcpd_config_type: default: local description: 'enum: `local` (DHCP Server), `none`, `relay` (DHCP Relay)' enum: - local - none - relay type: string switch_port_usage_networks: description: Only if `mode`==`trunk`, the list of network/vlans items: type: string type: array protect_re_custom_subnet: items: examples: - 10.1.2.0/24 type: string type: array gw_routing_policy_term_action: additionalProperties: false description: When used as import policy properties: accept: type: boolean add_community: $ref: '#/components/schemas/gw_routing_policy_term_action_add_community' add_target_vrfs: $ref: '#/components/schemas/gw_routing_policy_term_action_add_target_vrfs' community: $ref: '#/components/schemas/routing_policy_term_action_community' exclude_as_path: $ref: '#/components/schemas/gw_routing_policy_term_action_exclude_as_path' exclude_community: $ref: '#/components/schemas/gw_routing_policy_term_action_exclude_community' export_communities: $ref: '#/components/schemas/gw_routing_policy_term_action_export_communities' local_preference: $ref: '#/components/schemas/routing_policy_local_preference' prepend_as_path: $ref: '#/components/schemas/routing_policy_term_action_prepend_as_path' type: object switch_port_mirroring_egress_port_ids: description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified items: examples: - ge-0/0/3 type: string type: array ssr_proxy: additionalProperties: false description: SSR proxy configuration to talk to Mist properties: disabled: default: false examples: - true type: boolean url: examples: - https://proxy.corp.com:8080/ type: string type: object gateway_ip_configs: additionalProperties: $ref: '#/components/schemas/gateway_ip_config_property' description: Property key is the network name type: object gateway_path_type: description: 'enum: `local`, `tunnel`, `vpn`, `wan`' enum: - local - tunnel - vpn - wan type: string tunnel_config_remote_subnets: description: List of Remote protected subnet for policy-based IPSec negotiation items: type: string type: array site_setting_rtsa: additionalProperties: false description: Managed mobility properties: app_waking: default: false type: boolean disable_dead_reckoning: type: boolean disable_pressure_sensor: default: false type: boolean enabled: type: boolean track_asset: default: false description: Asset tracking related type: boolean type: object site_setting_status_portal_hostnames: items: examples: - my.misty.com type: string type: array snmp_vacm_security_to_group_content_item: additionalProperties: false properties: group: description: Refer to group_name under access type: string security_name: type: string type: object site_setting_skyatp: additionalProperties: false properties: enabled: type: boolean send_ip_mac_mapping: default: false description: Whether to send IP-MAC mapping to SkyATP type: boolean type: object tunnel_provider_options_zscaler_sub_location: additionalProperties: false properties: aup_block_internet_until_accepted: default: false type: boolean aup_enabled: default: false description: Can only be `true` when `auth_required`==`false`, display Acceptable Use Policy (AUP) type: boolean aup_force_ssl_inspection: default: false description: Proxy HTTPs traffic, requiring Zscaler cert to be installed in browser type: boolean aup_timeout_in_days: description: Required if `aup_enabled`==`true`. Days before AUP is requested again maximum: 180 minimum: 1 type: integer auth_required: default: false description: Enable this option to authenticate users type: boolean caution_enabled: default: false description: Can only be `true` when `auth_required`==`false`, display caution notification for non-authenticated users type: boolean dn_bandwidth: description: Download bandwidth cap of the link, in Mbps. Disabled if not set examples: - 200 format: double maximum: 99999 minimum: 0.1 type: - number - 'null' idle_time_in_minutes: description: Required if `surrogate_IP`==`true`, idle Time to Disassociation maximum: 43200 minimum: 0 type: integer name: description: '[network]($h/Orgs%20Networks/_overview) name' type: string ofw_enabled: default: false description: If `true`, enable the firewall control option type: boolean surrogate_IP: default: false description: Can only be `true` when `auth_required`==`true`. Map a user to a private IP address so it applies the user's policies, instead of the location's policies type: boolean surrogate_IP_enforced_for_known_browsers: description: Can only be `true` when `surrogate_IP`==`true`, enforce surrogate IP for known browsers type: boolean surrogate_refresh_time_in_minutes: description: Required if `surrogate_IP_enforced_for_known_browsers`==`true`, must be lower or equal than `idle_time_in_minutes`, refresh Time for re-validation of Surrogacy maximum: 43200 minimum: 1 type: integer up_bandwidth: description: Download bandwidth cap of the link, in Mbps. Disabled if not set examples: - 200 format: double maximum: 99999 minimum: 0.1 type: - number - 'null' type: object account_oauth_info_account_regions: additionalProperties: $ref: '#/components/schemas/account_oauth_info_account_region' description: For Prisma accounts only, property key is the region name. Regions with allocated bandwidth type: object snmpv3_config_notify_items: additionalProperties: false properties: name: type: string tag: type: string type: $ref: '#/components/schemas/snmpv3_config_notify_type' type: object gateway_ip_config_property: additionalProperties: false properties: ip: format: ipv4 type: string ip6: format: ipv6 type: string netmask: examples: - /24 type: string netmask6: examples: - 2001:db8:abcd:12::1 type: string secondary_ips: $ref: '#/components/schemas/gateway_ip_config_property_second_ips' type: $ref: '#/components/schemas/ip_type' type6: $ref: '#/components/schemas/ip_type6' type: object switch_radius: additionalProperties: false description: By default, `radius_config` will be used. if a different one has to be used set `use_different_radius properties: enabled: type: boolean radius_config: $ref: '#/components/schemas/switch_radius_config' use_different_radius: type: string type: object acl_tag_type: description: "enum: \n * `any`: matching anything not identified\n * `dynamic_gbp`: from the gbp_tag received from RADIUS\n * `gbp_resource`: can only be used in `dst_tags`\n * `mac`\n * `network`\n * `port_usage`\n * `radius_group`\n * `resource`: can only be used in `dst_tags`\n * `static_gbp`: applying gbp tag against matching conditions\n * `subnet`'" enum: - any - dynamic_gbp - gbp_resource - mac - network - port_usage - radius_group - resource - static_gbp - subnet type: string site_mxtunnel_protocol: description: 'enum: `ip`, `udp`' enum: - ip - udp examples: - udp type: string radio_band_antenna_beam_pattern: description: 'enum: `narrow`, `medium`, `wide`' enum: - narrow - medium - wide type: string site_rogue_whitelisted_bssids: description: 'list of BSSIDs to whitelist. Ex: "cc-:8e-:6f-:d4-:bf-:16", "cc-8e-6f-d4-bf-16", "cc-73-*", "cc:82:*"' examples: - - NeighborSSID items: type: string type: array site_wifi: additionalProperties: false description: Wi-Fi site settings properties: cisco_enabled: default: true type: boolean disable_11k: default: false description: Whether to disable 11k type: boolean disable_radios_when_power_constrained: default: false type: boolean enable_arp_spoof_check: default: false description: When proxy_arp is enabled, check for arp spoofing. type: boolean enable_shared_radio_scanning: default: true type: boolean enabled: default: true description: Enable Wi-Fi feature (using SUB-MAN license) type: boolean locate_connected: default: true description: Whether to locate connected clients type: boolean locate_unconnected: default: false description: Whether to locate unconnected clients type: boolean mesh_allow_dfs: default: false description: Whether to allow Mesh to use DFS channels. For DFS channels, Remote Mesh AP would have to do CAC when scanning for new Base AP, which is slow and will disrupt the connection. If roaming is desired, keep it disabled. type: boolean mesh_enable_crm: default: false description: Used to enable/disable CRM type: boolean mesh_enabled: default: false description: Whether to enable Mesh feature for the site type: boolean mesh_psk: description: Optional passphrase of mesh networking, default is generated randomly type: - string - 'null' mesh_ssid: description: Optional ssid of mesh networking, default is based on site_id type: - string - 'null' proxy_arp: $ref: '#/components/schemas/site_wifi_proxy_arp' type: object ospf_area_type: default: default description: 'OSPF type. enum: `default`, `nssa`, `stub`' enum: - default - nssa - stub examples: - default type: string site_occupancy_analytics: additionalProperties: false description: Occupancy Analytics settings properties: assets_enabled: default: false description: Indicate whether named BLE assets should be included in the zone occupancy calculation type: boolean clients_enabled: default: true description: Indicate whether connected Wi-Fi clients should be included in the zone occupancy calculation type: boolean min_duration: default: 3000 description: Minimum duration examples: - 3000 type: integer sdkclients_enabled: default: false description: Indicate whether SDK clients should be included in the zone occupancy calculation type: boolean unconnected_clients_enabled: default: false description: Indicate whether unconnected Wi-Fi clients should be included in the zone occupancy calculation type: boolean type: object tunnel_config_auto_provision_node: properties: probe_ips: $ref: '#/components/schemas/strings' wan_names: $ref: '#/components/schemas/tunnel_config_auto_provision_node_wan_names' idp_profile_overwrites: items: $ref: '#/components/schemas/idp_profile_overwrite' type: array network_vpn_access: additionalProperties: $ref: '#/components/schemas/network_vpn_access_config' description: Property key is the VPN name. Whether this network can be accessed from vpn type: object network_vpn_access_destination_nat: additionalProperties: $ref: '#/components/schemas/network_vpn_access_destination_nat_property' description: Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.16.0.0/30"), an External CIDR:Port (i.e. "63.16.0.0/30:443") or a Variable (i.e. "{{myvar}}"). At least one of the `internal_ip` or `port` must be defined type: object additional_vlan_ids_array: items: $ref: '#/components/schemas/vlan_id_with_variable' type: array switch_matching_rules: items: $ref: '#/components/schemas/switch_matching_rule' type: array uniqueItems: true acl_tag_spec: additionalProperties: false properties: port_range: default: '0' description: Matched dst port, "0" means any type: string protocol: default: any description: '`tcp` / `udp` / `icmp` / `icmp6` / `gre` / `any` / `:protocol_number`, `protocol_number` is between 1-254, default is `any` `protocol_number` is between 1-254' type: string type: object dhcpd_config_property: additionalProperties: false properties: dns_servers: $ref: '#/components/schemas/dhcpd_config_dns_servers' dns_suffix: $ref: '#/components/schemas/dhcpd_config_dns_suffix' fixed_bindings: $ref: '#/components/schemas/dhcpd_config_fixed_bindings' gateway: description: If `type`==`local` - optional, `ip` will be used if not provided examples: - 192.168.70.1 type: string ip6_end: description: If `type6`==`local` examples: - 2607:f8b0:4005:808::ff type: string ip6_start: description: If `type6`==`local` examples: - 2607:f8b0:4005:808::2 type: string ip_end: description: If `type`==`local` examples: - 192.168.70.200 type: string ip_start: description: If `type`==`local` examples: - 192.168.70.100 type: string lease_time: default: 86400 description: In seconds, lease time has to be between 3600 [1hr] - 604800 [1 week], default is 86400 [1 day] maximum: 604800 minimum: 3600 type: integer options: $ref: '#/components/schemas/dhcpd_config_options' server_id_override: default: false description: "`server_id_override`==`true` means the device, when acts as DHCP relay and forwards DHCP responses from DHCP server to clients, \nshould overwrite the Sever Identifier option (i.e. DHCP option 54) in DHCP responses with its own IP address." type: boolean servers: $ref: '#/components/schemas/dhcpd_config_servers' serversv6: $ref: '#/components/schemas/dhcpd_config_servers6' type: $ref: '#/components/schemas/dhcpd_config_type' type6: $ref: '#/components/schemas/dhcpd_config_type6' vendor_encapsulated: $ref: '#/components/schemas/dhcpd_config_vendor_options' type: object iotproxy_visionline: additionalProperties: false description: Visionline integration settings for IoT proxy properties: access_id: description: Access ID for the Visionline service examples: - 790e6c1790e6c18541d type: string enabled: default: false type: boolean host: description: Hostname or IP of the Visionline collector examples: - visionline_collector1.local type: string password: description: Password for the Visionline service format: password type: string port: default: 443 description: TCP port of the Visionline collector type: integer username: description: Username for the Visionline service examples: - card_administrator type: string type: object sw_routing_policy_terms: description: at least criteria/filter must be specified to match the term, all criteria have to be met items: $ref: '#/components/schemas/sw_routing_policy_term' minItems: 1 type: array uniqueItems: true service_policy_syslog: additionalProperties: false description: Required for syslog logging properties: enabled: default: false type: boolean server_names: examples: - - dc_syslog_server items: type: string type: array type: object gateway_path_preferences_path_networks: description: Required when `type`==`local` items: type: string type: array ssl_proxy_ciphers_category: default: strong description: 'enum: `medium`, `strong`, `weak`' enum: - medium - strong - weak type: string switch_stp_config: additionalProperties: false properties: bridge_priority: default: 32k description: Switch STP priority. Range [0, 4k, 8k.. 60k] in steps of 4k. Bridge priority applies to both VSTP and RSTP. examples: - 40k type: string type: object snmp_config_views: items: $ref: '#/components/schemas/snmp_config_view' type: array site_setting_critical_url_monitoring_monitor: additionalProperties: false properties: url: examples: - http://50.1.3.5:8080 type: string vlan_id: $ref: '#/components/schemas/vlan_id_with_variable' type: object gw_routing_policy_term_action_export_communities: description: When used as export policy, optional items: type: string type: array site_setting_ap_port_config: additionalProperties: false properties: model_specific: additionalProperties: additionalProperties: $ref: '#/components/schemas/ap_port_config' description: Property key is the interface(s) (e.g. "eth1,eth2") type: object description: Property key is the AP model (e.g. "AP32") examples: - AP32: eth1,eth2: port_vlan_id: 1 vlan_ids: - 1 - 10 - 50 type: object type: object mxcluster_radsec_acct_server: additionalProperties: false properties: host: description: IP / hostname of RADIUS server type: string port: default: 1813 description: Acct port of RADIUS server type: integer secret: description: Secret of RADIUS server format: password type: string ssids: $ref: '#/components/schemas/mxcluster_radsec_acct_server_ssids' type: object switch_port_usage_dynamic_rule: additionalProperties: false properties: description: description: Optional description of the rule type: string equals: type: string equals_any: $ref: '#/components/schemas/switch_port_usage_dynamic_rule_equals_any' expression: description: '"[0:3]":"abcdef" -> "abc" "split(.)[1]": "a.b.c" -> "b" "split(-)[1][0:3]: "a1234-b5678-c90" -> "b56"' type: string src: $ref: '#/components/schemas/switch_port_usage_dynamic_rule_src' usage: description: '`port_usage` name' type: string required: - src type: object remote_syslog_users: items: $ref: '#/components/schemas/remote_syslog_user' type: array gw_routing_policy_term_matching_route_exists: additionalProperties: false properties: route: examples: - 192.168.0.0/24 type: string vrf_name: default: default description: Name of the vrf instance, it can also be the name of the VPN or wan if they type: string type: object mist_nacedge_mxedge_hosts: description: List of NAC Edges in this site examples: - - mxedge1.local items: type: string type: array created_time: description: When the object has been created, in epoch format: double readOnly: true type: number mac_addresses_macs: examples: - - 683b679ac024 items: type: string minItems: 1 type: array uniqueItems: true vars_annotations: additionalProperties: $ref: '#/components/schemas/vars_annotation' description: Optional annotations for vars defined in this site. Keys match var names; values describe the var purpose and type for UI auto-complete. examples: - MXTUNNEL_GUEST: type: mxtunnel_id RADIUS_IP1: note: RADIUS server IP address for US East Campus type: object switch_port_usage: additionalProperties: false description: Junos port usages properties: all_networks: default: false description: Only if `mode`==`trunk`. Whether to trunk all network/vlans type: boolean allow_dhcpd: description: 'Only applies when `mode`!=`dynamic`. Controls whether DHCP server traffic is allowed on ports using this configuration if DHCP snooping is enabled. This is a tri-state setting; `true`: ports become trusted ports allowing DHCP server traffic, `false`: ports become untrusted blocking DHCP server traffic, undefined: use system defaults (access ports default to untrusted, trunk ports default to trusted).' type: boolean allow_multiple_supplicants: default: false description: Only if `mode`!=`dynamic` type: boolean bypass_auth_when_server_down: default: false description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Bypass auth for known clients if set to true when RADIUS server is down type: boolean bypass_auth_when_server_down_for_unknown_client: default: false description: Only if `mode`!=`dynamic` and `port_auth`=`dot1x`. Bypass auth for all (including unknown clients) if set to true when RADIUS server is down type: boolean bypass_auth_when_server_down_for_voip: default: false description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Bypass auth for VOIP if set to true when RADIUS server is down type: boolean community_vlan_id: description: Only if `mode`!=`dynamic`. To be used together with `isolation` under networks. Signaling that this port connects to the networks isolated but wired clients belong to the same community can talk to each other type: integer description: description: Only if `mode`!=`dynamic` type: string disable_autoneg: default: false description: Only if `mode`!=`dynamic`. If speed and duplex are specified, whether to disable autonegotiation type: boolean disabled: default: false description: Only if `mode`!=`dynamic`. Whether the port is disabled type: boolean duplex: $ref: '#/components/schemas/switch_port_usage_duplex' dynamic_vlan_networks: $ref: '#/components/schemas/switch_port_usage_dynamic_vlan_networks' enable_mac_auth: default: false description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Whether to enable MAC Auth type: boolean enable_qos: default: false description: Only if `mode`!=`dynamic` type: boolean guest_network: description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Which network to put the device into if the device cannot do dot1x. default is null (i.e. not allowed) type: - string - 'null' inter_isolation_network_link: default: false description: Only if `mode`!=`dynamic`. `inter_isolation_network_link` is used together with `isolation` under networks, signaling that this port connects to isolated networks type: boolean inter_switch_link: default: false description: 'Only if `mode`!=`dynamic`. `inter_switch_link` is used together with `isolation` under networks. NOTE: `inter_switch_link` works only between Juniper devices. This has to be applied to both ports connected together' type: boolean mac_auth_only: description: Only if `mode`!=`dynamic` and `enable_mac_auth`==`true` type: boolean mac_auth_preferred: description: Only if `mode`!=`dynamic` + `enable_mac_auth`==`true` + `mac_auth_only`==`false`, dot1x will be given priority then mac_auth. Enable this to prefer mac_auth over dot1x. type: boolean mac_auth_protocol: $ref: '#/components/schemas/switch_port_usage_mac_auth_protocol' mac_limit: $ref: '#/components/schemas/switch_port_usage_mac_limit' mode: $ref: '#/components/schemas/switch_port_usage_mode' mtu: $ref: '#/components/schemas/switch_port_usage_mtu' networks: $ref: '#/components/schemas/switch_port_usage_networks' persist_mac: default: false description: Only if `mode`==`access` and `port_auth`!=`dot1x`. Whether the port should retain dynamically learned MAC addresses type: boolean poe_disabled: default: false description: Only if `mode`!=`dynamic`. Whether PoE capabilities are disabled for a port type: boolean poe_keep_state_when_reboot: default: false description: Only if `mode`!=`dynamic`. Whether Perpetual PoE is enabled; keeps PoE state across reboots type: boolean poe_priority: $ref: '#/components/schemas/poe_priority' port_auth: $ref: '#/components/schemas/switch_port_usage_dot1x' port_network: description: Only if `mode`!=`dynamic`. Native network/vlan for untagged traffic type: string reauth_interval: $ref: '#/components/schemas/switch_port_usage_reauth_interval' reset_default_when: $ref: '#/components/schemas/switch_port_usage_dynamic_reset_default_when' rules: $ref: '#/components/schemas/switch_port_usage_dynamic_rules' server_fail_network: description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Sets server fail fallback vlan type: - string - 'null' server_reject_network: description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. When radius server reject / fails type: - string - 'null' speed: $ref: '#/components/schemas/switch_port_usage_speed' storm_control: $ref: '#/components/schemas/switch_port_usage_storm_control' stp_disable: default: false description: Only if `mode`!=`dynamic` and `stp_required`==`false`. Drop bridge protocol data units (BPDUs ) that enter any interface or a specified interface type: boolean stp_edge: default: false description: Only if `mode`!=`dynamic`. When enabled, the port is not expected to receive BPDU frames type: boolean stp_no_root_port: default: false description: Only if `mode`!=`dynamic` type: boolean stp_p2p: default: false description: Only if `mode`!=`dynamic` type: boolean stp_required: default: false description: Only if `mode`!=`dynamic`. Whether to remain in block state if no BPDU is received type: boolean ui_evpntopo_id: description: Optional for Campus Fabric Core-Distribution ESI-LAG profile. Helper used by the UI to select this port profile as the ESI-Lag between Distribution and Access switches format: uuid type: string use_vstp: default: false description: If this is connected to a vstp network type: boolean voip_network: description: Only if `mode`!=`dynamic`. Network/vlan for voip traffic, must also set port_network. to authenticate device, set port_auth type: - string - 'null' type: object aggregate_routes: additionalProperties: $ref: '#/components/schemas/aggregate_route' description: Property key is the destination subnet (e.g. "172.16.3.0/24") examples: - 172.16.3.0/24: discard: false metric: null preference: 30 type: object snmp_usm_user_encryption_type: description: 'enum: `privacy-3des`, `privacy-aes128`, `privacy-des`, `privacy-none`' enum: - privacy-3des - privacy-aes128 - privacy-des - privacy-none type: string service_policy_ewf: items: $ref: '#/components/schemas/service_policy_ewf_rule' type: array remote_syslog_content: additionalProperties: false properties: facility: $ref: '#/components/schemas/remote_syslog_facility' severity: $ref: '#/components/schemas/remote_syslog_severity' type: object gateway_vrf_instance: additionalProperties: false examples: - networks: - CORP_NET - MGMT_NET properties: networks: $ref: '#/components/schemas/strings' type: object mxedge_mgmt_oob_ip_type: default: dhcp description: 'enum: `dhcp`, `disabled`, `static`' enum: - dhcp - disabled - static type: string network_tenant: additionalProperties: false properties: addresses: $ref: '#/components/schemas/network_tenant_addresses' type: object setting_ssr_auto_upgrade_custom_versions: additionalProperties: description: Firmware version to deploy on the specified SSR model examples: - 6.3.0-107.r1 type: string description: Property key is the SSR model (e.g. "SSR130"). type: object service_policy_skyatp: additionalProperties: false description: SRX only properties: dns_dga_detection: $ref: '#/components/schemas/service_policy_skyatp_dns_dga_detection' dns_tunnel_detection: $ref: '#/components/schemas/service_policy_skyatp_dns_tunnel_detection' http_inspection: $ref: '#/components/schemas/service_policy_skyatp_http_inspection' iot_device_policy: $ref: '#/components/schemas/service_policy_skyatp_iot_device_policy' type: object ospf_area: additionalProperties: false description: Property key is the OSPF Area (Area should be a number (0-255) / IP address) properties: include_loopback: default: false type: boolean networks: additionalProperties: $ref: '#/components/schemas/ospf_areas_network' examples: - corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: object type: $ref: '#/components/schemas/ospf_area_type' type: object ble_config: additionalProperties: false description: BLE AP settings properties: beacon_enabled: default: true description: Whether Mist beacons is enabled type: boolean beacon_rate: description: Required if `beacon_rate_mode`==`custom`, 1-10, in number-beacons-per-second examples: - 3 type: integer beacon_rate_mode: $ref: '#/components/schemas/ble_config_beacon_rate_mode' beam_disabled: $ref: '#/components/schemas/ble_config_beam_disabled' custom_ble_packet_enabled: default: false description: Can be enabled if `beacon_enabled`==`true`, whether to send custom packet type: boolean custom_ble_packet_frame: default: '' description: The custom frame to be sent out in this beacon. The frame must be a hexstring examples: - 0x........ type: string custom_ble_packet_freq_msec: default: 0 description: Frequency (msec) of data emitted by custom ble beacon examples: - 300 minimum: 0 type: integer eddystone_uid_adv_power: default: 0 description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default examples: - -65 maximum: 20 minimum: -100 type: integer eddystone_uid_beams: default: '' examples: - 2-4,7 type: string eddystone_uid_enabled: default: false description: Only if `beacon_enabled`==`false`, Whether Eddystone-UID beacon is enabled type: boolean eddystone_uid_freq_msec: default: 0 description: Frequency (msec) of data emit by Eddystone-UID beacon examples: - 200 type: integer eddystone_uid_instance: default: '' description: Eddystone-UID instance for the device examples: - 5c5b35000001 type: string eddystone_uid_namespace: default: '' description: Eddystone-UID namespace examples: - 2818e3868dec25629ede type: string eddystone_url_adv_power: default: 0 description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default examples: - -65 maximum: 20 minimum: -100 type: integer eddystone_url_beams: default: '' examples: - 2-4,7 type: string eddystone_url_enabled: default: false description: Only if `beacon_enabled`==`false`, Whether Eddystone-URL beacon is enabled type: boolean eddystone_url_freq_msec: default: 0 description: Frequency (msec) of data emit by Eddystone-UID beacon examples: - 1000 type: integer eddystone_url_url: default: '' description: URL pointed by Eddystone-URL beacon examples: - https://www.abc.com type: string ibeacon_adv_power: default: 0 description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default examples: - -65 maximum: 20 minimum: -100 type: integer ibeacon_beams: default: '' examples: - 2-4,7 type: string ibeacon_enabled: default: false description: Can be enabled if `beacon_enabled`==`true`, whether to send iBeacon type: boolean ibeacon_freq_msec: default: 0 description: Frequency (msec) of data emit for iBeacon type: integer ibeacon_major: $ref: '#/components/schemas/ibeacon_major' ibeacon_minor: $ref: '#/components/schemas/ibeacon_minor' ibeacon_uuid: default: '' description: Optional, if not specified, the same UUID as the beacon will be used examples: - f3f17139-704a-f03a-2786-0400279e37c3 format: uuid type: string power: default: 9 description: Required if `power_mode`==`custom`; else use `power_mode` as default examples: - 6 maximum: 10 minimum: 1 type: integer power_mode: $ref: '#/components/schemas/ble_config_power_mode' type: object switch_port_usage_dynamic_rule_src: description: 'enum: `link_peermac`, `lldp_chassis_id`, `lldp_hardware_revision`, `lldp_manufacturer_name`, `lldp_oui`, `lldp_serial_number`, `lldp_system_description`, `lldp_system_name`, `radius_dynamicfilter`, `radius_usermac`, `radius_username`' enum: - link_peermac - lldp_chassis_id - lldp_hardware_revision - lldp_manufacturer_name - lldp_oui - lldp_serial_number - lldp_system_description - lldp_system_name - radius_dynamicfilter - radius_usermac - radius_username type: string dhcpd_config_option_type: description: 'enum: `boolean`, `hex`, `int16`, `int32`, `ip`, `string`, `uint16`, `uint32`' enum: - boolean - hex - int16 - int32 - ip - string - uint16 - uint32 type: string tunnel_via: default: primary description: 'If `via`==`tunnel`, specifies which tunnel (primary/secondary) this neighbor is associated with. enum: `primary`, `secondary`' enum: - primary - secondary type: string mxedge_mgmt: additionalProperties: false properties: config_auto_revert: default: false type: boolean fips_enabled: default: false type: boolean mist_password: examples: - MIST_PASSWORD type: string oob_ip_type: $ref: '#/components/schemas/mxedge_mgmt_oob_ip_type' oob_ip_type6: $ref: '#/components/schemas/mxedge_mgmt_oob_ip_type6' root_password: examples: - ROOT_PASSWORD format: password type: string type: object tunnel_config_node_wan_names: items: type: string type: array mac_addresses: properties: macs: $ref: '#/components/schemas/mac_addresses_macs' required: - macs type: object wired_port_config: additionalProperties: $ref: '#/components/schemas/junos_port_config' description: Property key is the port name or range (e.g. "ge-0/0/0-10") type: object mxcluster_nac_client_ip: additionalProperties: false properties: require_message_authenticator: default: false description: Whether to require Message-Authenticator in requests type: boolean secret: description: If different from above type: string site_id: description: Present only for 3rd party clients examples: - 00000000-0000-0000-1234-000000000000 format: uuid type: string vendor: $ref: '#/components/schemas/mxcluster_nac_client_vendor' type: object site_setting_tunterm_multicast_config_ssdp: additionalProperties: false properties: enabled: default: false type: boolean vlan_ids: $ref: '#/components/schemas/mxedge_tunterm_multicast_config_ssdp_vlan_ids' type: object bgp_as: anyOf: - type: string - maximum: 4294967294 minimum: 1 type: integer description: BGP AS, value in range 1-4294967294. Can be a Variable (e.g. `{{bgp_as}}` ) examples: - 65000 gw_routing_policy_term_matching: additionalProperties: false description: zero or more criteria/filter can be specified to match the term, all criteria have to be met properties: as_path: $ref: '#/components/schemas/routing_policy_term_matching_as_path' community: $ref: '#/components/schemas/routing_policy_term_matching_community' network: $ref: '#/components/schemas/strings' prefix: $ref: '#/components/schemas/routing_policy_term_matching_prefix' protocol: $ref: '#/components/schemas/gw_routing_policy_term_matching_protocol' route_exists: $ref: '#/components/schemas/gw_routing_policy_term_matching_route_exists' vpn_neighbor_mac: $ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_neighbor_mac' vpn_path: $ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_path' vpn_path_sla: $ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_path_sla' type: object ap_port_config: additionalProperties: false properties: disabled: default: false type: boolean dynamic_vlan: $ref: '#/components/schemas/ap_port_config_dynamic_vlan' enable_mac_auth: default: false type: boolean forwarding: $ref: '#/components/schemas/ap_port_config_forwarding' mac_auth_preferred: default: false description: When `true`, we'll do dot1x then mac_auth. enable this to prefer mac_auth type: boolean mac_auth_protocol: $ref: '#/components/schemas/ap_port_config_mac_auth_protocol' mist_nac: $ref: '#/components/schemas/wlan_mist_nac' mx_tunnel_id: default: '' description: If `forwarding`==`mxtunnel`, vlan_ids comes from mxtunnel examples: - 08cd7499-5841-51c8-e663-fb16b6f3b45e format: uuid type: string mxtunnel_name: default: '' description: If `forwarding`==`site_mxedge`, vlan_ids comes from site_mxedge (`mxtunnels` under site setting) type: string port_auth: $ref: '#/components/schemas/ap_port_config_port_auth' port_vlan_id: description: If `forwarding`==`limited` examples: - 1 maximum: 4094 minimum: 1 type: integer radius_config: $ref: '#/components/schemas/radius_config' radsec: $ref: '#/components/schemas/radsec' vlan_id: description: "Optional to specify the vlan id for a tunnel if forwarding is for `wxtunnel`, `mxtunnel` or `site_mxedge`.\n * if vlan_id is not specified then it will use first one in vlan_ids[] of the mxtunnel.\n * if forwarding == site_mxedge, vlan_ids comes from site_mxedge (`mxtunnels` under site setting)" examples: - 9 maximum: 4094 minimum: 1 type: integer vlan_ids: description: If `forwarding`==`limited`, comma separated list of additional vlan ids allowed on this port examples: - 10,20,30 type: string wxtunnel_id: default: '' description: If `forwarding`==`wxtunnel`, the port is bridged to the vlan of the session examples: - 7dae216d-7c98-a51b-e068-dd7d477b7216 format: uuid type: string wxtunnel_remote_id: default: '' description: If `forwarding`==`wxtunnel`, the port is bridged to the vlan of the session examples: - wifiguest type: string type: object gw_routing_policy: additionalProperties: false properties: terms: $ref: '#/components/schemas/gw_routing_policy_terms' type: object mxcluster_radsec_auth_servers: description: List of RADIUS authentication servers, order matters where the first one is treated as primary items: $ref: '#/components/schemas/mxcluster_radsec_auth_server' type: array uniqueItems: true switch_mgmt_mxedge_proxy_port: anyOf: - default: 2222 maximum: 65535 minimum: 1 type: integer - type: string description: Mist Edge port used to proxy the switch management traffic to the Mist Cloud. Value in range 1-65535 remote_syslog_files: items: $ref: '#/components/schemas/remote_syslog_file_config' type: array snmp_config_view: additionalProperties: false properties: include: description: If the root oid configured is included type: boolean oid: examples: - 1.3.6.1 type: string view_name: examples: - all type: string type: object response_http429: additionalProperties: false properties: detail: examples: - Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold type: string type: object ap_port_config_dynamic_vlan: additionalProperties: false description: Optional dynamic vlan properties: default_vlan_id: examples: - 999 maximum: 4094 minimum: 1 type: integer enabled: type: boolean type: type: string vlans: additionalProperties: type: - string - 'null' examples: - 1-10: null user: null type: object type: object idp_profile_action: default: alert description: "enum:\n * alert (default)\n * drop: silently dropping packets\n * close: notify client/server to close connection" enum: - alert - close - drop examples: - alert type: string gateway_vrf_instances: additionalProperties: $ref: '#/components/schemas/gateway_vrf_instance' description: Property key is the network name examples: - CORP_VRF: networks: - CORP_NET - MGMT_NET type: object gateway_traffic_shaping_class_percentages: description: 'percentages for different class of traffic: high / medium / low / best-effort. Sum must be equal to 100' items: type: integer type: array site_setting_paloalto_networks_gateways: items: $ref: '#/components/schemas/site_setting_paloalto_network_gateway' type: array acl_policy: additionalProperties: false description: "ACL Policy:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to" properties: actions: $ref: '#/components/schemas/acl_policy_actions' name: examples: - guest access type: string src_tags: $ref: '#/components/schemas/acl_policy_src_tags' type: object wan_extra_routes: additionalProperties: false properties: via: format: ipv4 type: string type: object service_policy_secintel: additionalProperties: false description: SRX only properties: enabled: default: false type: boolean profile: $ref: '#/components/schemas/service_policy_secintel_profile' secintelprofile_id: description: org-level secintel Profile can be used, this takes precedence over 'profile' type: string type: object tunterm_monitoring_protocol: description: 'enum: `arp`, `ping`, `tcp`' enum: - arp - ping - tcp examples: - tcp minLength: 1 type: string gw_routing_policy_term_action_exclude_as_path: description: When used as export policy, optional. To exclude certain AS items: examples: - '65002' type: string type: array switch_mgmt: additionalProperties: false description: Switch Management settings properties: ap_affinity_threshold: default: 10 description: AP_affinity_threshold ap_affinity_threshold can be added as a field under site/setting. By default, this value is set to 12. If the field is set in both site/setting and org/setting, the value from site/setting will be used. type: integer cli_banner: description: Set Banners for switches. Allows markup formatting examples: - \t\tWELCOME! type: string cli_idle_timeout: description: Sets timeout for switches maximum: 60 minimum: 1 type: integer config_revert_timer: default: 10 description: Rollback timer for commit confirmed maximum: 30 minimum: 1 type: integer dhcp_option_fqdn: default: false description: Enable to provide the FQDN with DHCP option 81 type: boolean disable_oob_down_alarm: type: boolean fips_enabled: default: false type: boolean local_accounts: $ref: '#/components/schemas/config_switch_local_accounts' mxedge_proxy_host: description: IP Address or FQDN of the Mist Edge used to proxy the switch management traffic to the Mist Cloud type: string mxedge_proxy_port: $ref: '#/components/schemas/switch_mgmt_mxedge_proxy_port' protect_re: $ref: '#/components/schemas/protect_re' radius: $ref: '#/components/schemas/switch_radius' remove_existing_configs: default: false description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed. type: boolean root_password: format: password type: string tacacs: $ref: '#/components/schemas/tacacs' use_mxedge_proxy: description: To use mxedge as proxy type: boolean type: object ip_type6: default: disabled description: 'enum: `autoconf`, `dhcp`, `disabled`, `static`' enum: - autoconf - dhcp - disabled - static examples: - static type: string acl_policies: items: $ref: '#/components/schemas/acl_policy' type: array site_mxtunnel_cluster: additionalProperties: false properties: name: examples: - primary type: string tunterm_hosts: $ref: '#/components/schemas/site_mxtunnel_cluster_tunterm_hosts' type: object gateway_mgmt: additionalProperties: false description: Gateway Management settings properties: admin_sshkeys: $ref: '#/components/schemas/gateway_mgmt_admin_sshkeys' app_probing: $ref: '#/components/schemas/app_probing' app_usage: description: Consumes uplink bandwidth, requires WA license type: boolean auto_signature_update: $ref: '#/components/schemas/gateway_mgmt_auto_signature_update' config_revert_timer: default: 10 description: Rollback timer for commit confirmed maximum: 30 minimum: 1 type: integer disable_console: default: false description: For SSR and SRX, disable console port type: boolean disable_oob: default: false description: For SSR and SRX, disable management interface type: boolean disable_usb: default: false description: For SSR and SRX, disable usb interface type: boolean fips_enabled: default: false type: boolean probe_hosts: $ref: '#/components/schemas/gateway_mgmt_probe_hosts' probe_hostsv6: $ref: '#/components/schemas/gateway_mgmt_probe_hostsv6' protect_re: $ref: '#/components/schemas/protect_re' root_password: description: SRX only format: password type: string security_log_source_address: examples: - 192.168.1.1 format: ipv4 type: string security_log_source_interface: examples: - ge-0/0/1.0 type: string type: object gateway_port_wan_source_nat: additionalProperties: false description: Only if `usage`==`wan`, optional. By default, source-NAT is performed on all WAN Ports using the interface-ip properties: disabled: default: false description: Or to disable the source-nat type: boolean nat6_pool: description: If alternative nat_pool is desired examples: - 2601:1700:43c0:dc0:20c:29ff:fea7:93bc/126 type: string nat_pool: description: If alternative nat_pool is desired examples: - 64.2.4.0/30 type: string type: object gateway_port_vpn_paths: additionalProperties: $ref: '#/components/schemas/gateway_port_vpn_path' description: Property key is the VPN name type: object network_internet_access_destination_nat: additionalProperties: $ref: '#/components/schemas/network_internet_access_destination_nat_property' description: Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.16.0.0/30"), an External CIDR:Port (i.e. "63.16.0.0/30:443") or a Variable (i.e. "{{myvar}}"). At least one of the `internal_ip` or `port` must be defined type: object snmpv3_config_target_param_security_level: description: 'enum: `authentication`, `none`, `privacy`' enum: - authentication - none - privacy type: string switch_port_usage_dynamic_reset_default_when: default: link_down description: 'Only if `mode`==`dynamic` Control when the DPC port should be changed to the default port usage. enum: `link_down`, `none` (let the DPC port keep at the current port usage)' enum: - link_down - none examples: - link_down type: string tunnel_provider_options_zscaler: additionalProperties: false description: For zscaler-ipsec and zscaler-gre properties: aup_block_internet_until_accepted: default: false type: boolean aup_enabled: default: false description: Can only be `true` when `auth_required`==`false`, display Acceptable Use Policy (AUP) type: boolean aup_force_ssl_inspection: default: false description: Proxy HTTPs traffic, requiring Zscaler cert to be installed in browser type: boolean aup_timeout_in_days: description: Required if `aup_enabled`==`true`. Days before AUP is requested again maximum: 180 minimum: 1 type: integer auth_required: default: false description: Enable this option to enforce user authentication type: boolean caution_enabled: default: false description: Can only be `true` when `auth_required`==`false`, display caution notification for non-authenticated users type: boolean dn_bandwidth: description: Download bandwidth cap of the link, in Mbps. Disabled if not set examples: - 200 format: double maximum: 99999 minimum: 0.1 type: - number - 'null' idle_time_in_minutes: description: Required if `surrogate_IP`==`true`, idle Time to Disassociation maximum: 43200 minimum: 0 type: integer ofw_enabled: default: false description: If `true`, enable the firewall control option type: boolean sub_locations: $ref: '#/components/schemas/zscaler_sub_locations' surrogate_IP: default: false description: Can only be `true` when `auth_required`==`true`. Map a user to a private IP address so it applies the user's policies, instead of the location's policies type: boolean surrogate_IP_enforced_for_known_browsers: description: Can only be `true` when `surrogate_IP`==`true`, enforce surrogate IP for known browsers type: boolean surrogate_refresh_time_in_minutes: description: Required if `surrogate_IP_enforced_for_known_browsers`==`true`, must be lower or equal than `idle_time_in_minutes`, refresh Time for re-validation of Surrogacy maximum: 43200 minimum: 1 type: integer up_bandwidth: description: Download bandwidth cap of the link, in Mbps. Disabled if not set examples: - 200 format: double maximum: 99999 minimum: 0.1 type: - number - 'null' xff_forward_enabled: default: false description: Location uses proxy chaining to forward traffic type: boolean type: object idp_profile_matching_dst_subnet: items: examples: - 63.1.2.0/24 type: string type: array response_http403: additionalProperties: false properties: detail: examples: - You do not have permission to perform this action. type: string type: object gateway_wan_type: default: dhcp description: 'enum: `dhcp`, `pppoe`, `static`' enum: - dhcp - pppoe - static type: string site_setting_wired_vna: additionalProperties: false properties: enabled: default: false type: boolean type: object aggregate_routes6: additionalProperties: $ref: '#/components/schemas/aggregate_route' description: Property key is the destination subnet (e.g. "2a02:1234:420a:10c9::/64") example: 2a02:1234:420a:10c9::/64: discard: false metric: null preference: 30 type: object snmp_vacm_security_model: description: 'enum: `usm`, `v1`, `v2c`' enum: - usm - v1 - v2c type: string evpn_options_underlay: additionalProperties: false properties: as_base: default: 65001 description: Underlay BGP Base AS Number examples: - 65001 maximum: 65535 minimum: 1 type: integer routed_id_prefix: examples: - /24 type: string subnet: description: Underlay subnet, by default, `10.255.240.0/20`, or `fd31:5700::/64` for ipv6 examples: - 10.255.240.0/20 type: string use_ipv6: default: false description: If v6 is desired for underlay type: boolean type: object switch_port_mirroring_property: additionalProperties: false properties: input_networks_ingress: $ref: '#/components/schemas/switch_port_mirroring_ingress_networks' input_port_ids_egress: $ref: '#/components/schemas/switch_port_mirroring_egress_port_ids' input_port_ids_ingress: $ref: '#/components/schemas/switch_port_mirroring_ingress_port_ids' output_ip_address: description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided examples: - 1.2.3.4 type: string output_network: description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided examples: - analyze type: string output_port_id: description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided examples: - ge-0/0/5 type: string type: object snmp_vacm_access_item_prefix_list_item_model: description: 'enum: `any`, `usm`, `v1`, `v2c`' enum: - any - usm - v1 - v2c type: string snmp_vacm_access_item: additionalProperties: false properties: group_name: type: string prefix_list: $ref: '#/components/schemas/snmp_vacm_access_item_prefix_list' type: object account_oauth_info_account: additionalProperties: false description: OAuth linked apps account info properties: account_id: description: Linked app account id examples: - iojzXIJWEuiD73ZvydOfg readOnly: true type: string auto_probe_subnet: description: For Prisma accounts only, tunnel auto probe subnet examples: - 11.0.0.0/8 readOnly: true type: string client_id: description: Customer account Client ID readOnly: true type: string cloud_name: description: Name of the company whose account mist has subscribed to examples: - Tapi.sase.paloaltonetworks.com readOnly: true type: string company: description: Name of the company whose account mist has subscribed to examples: - Test Company1 Ltd readOnly: true type: string enable_probe: description: For Prisma accounts only, tunnel probe enable/disable examples: - false readOnly: true type: boolean error: description: This error is provided when the account fails to fetch token/data examples: - OAuth token refresh failed, please re-link your account readOnly: true type: string errors: $ref: '#/components/schemas/oauth_account_errors' instance_url: description: Customer account instance URL readOnly: true type: string key_id: description: For ZDX Account only, Customer account API key ID examples: - L72frZcK3JvrZc type: string last_status: description: Is the last data pull for account is successful or not examples: - failed readOnly: true type: string last_sync: description: Last data pull timestamp, background jobs that pull account data examples: - 1665465339000 readOnly: true type: integer linked_by: description: First name of the user who linked the account examples: - Testname1 readOnly: true type: string linked_timestamp: examples: - 1665465339000 readOnly: true type: number max_daily_api_requests: description: Zoom daily api request quota, https://developers.zoom.us/docs/api/rest/rate-limits/ examples: - 5000 readOnly: true type: integer name: description: Name of the company whose account mist has subscribed to examples: - Test Compay1 Ltd readOnly: true type: string password: description: Customer account password instance URL format: password readOnly: true type: string region: description: For Prisma accounts only examples: - americas readOnly: true type: string regions: $ref: '#/components/schemas/account_oauth_info_account_regions' service_account_name: description: For Prisma accounts only examples: - Corp SA readOnly: true type: string service_connections: $ref: '#/components/schemas/account_oauth_info_account_service_connections' smartgroup_name: description: Smart group membership for determining compliance status examples: - CompliantGroup1 readOnly: true type: string tsg_id: description: For Prisma accounts only, Prisma Tenant Service Group id examples: - '189953456' readOnly: true type: string username: description: Customer account username readOnly: true type: string webhook_auth_type: description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only examples: - Basic - Bearer type: string webhook_enabled: description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only type: boolean webhook_password: description: For VMWare accounts only examples: - password_1234 format: password type: string webhook_secret: description: For Crowdstrike accounts only examples: - secret-value format: password type: string webhook_token: description: For JAMF and SentinelOne accounts only examples: - token-value type: string webhook_url: description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only examples: - https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/ae9dee49-69e7-4710-a114-5b827a777738/crowdstrike/edr - https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/ae9dee49-69e7-4710-a114-5b827a777738/jamf/mdm - https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/00fd8b39-cf92-4b43-a2ff-a461b48e7059/sentinelone/edr - https://websync.nac-staging.mistsys.com/v1/S_41b2525af1d8dcbe9005/f43ea4c48f22/vmware/mdm type: string webhook_username: description: For VMWare accounts only examples: - username_1234 type: string zdx_org_id: description: For ZDX Account only, ZDX organization id examples: - '123456' type: string type: object idp_profile_base_profile: description: 'enum: `critical`, `standard`, `strict`' enum: - critical - standard - strict examples: - strict type: string site_wids: additionalProperties: false description: WIDS site settings properties: repeated_auth_failures: $ref: '#/components/schemas/site_wids_repeated_auth_failures' type: object site_setting_mxedge: additionalProperties: false description: Site Mist Edges form a cluster of RadSec Proxy servers properties: mist_das: $ref: '#/components/schemas/mxedge_das' mist_nac: $ref: '#/components/schemas/mxcluster_nac' mist_nacedge: $ref: '#/components/schemas/mist_nacedge' radsec: $ref: '#/components/schemas/mxcluster_radsec' type: object tunterm_monitoring: items: $ref: '#/components/schemas/tunterm_monitoring_item' type: array gw_routing_policy_term_matching_vpn_neighbor_mac: description: overlay-facing criteria (used for bgp_config where via=vpn) items: type: string type: array switch_network: additionalProperties: false description: A network represents a network segment. It can either represent a VLAN (then usually ties to a L3 subnet), optionally associate it with a subnet which can later be used to create addition routes. Used for ports doing `family ethernet-switching`. It can also be a pure L3-subnet that can then be used against a port that with `family inet`. properties: gateway: description: Only required for EVPN-VXLAN networks, IPv4 Virtual Gateway type: string gateway6: description: Only required for EVPN-VXLAN networks, IPv6 Virtual Gateway type: string isolation: default: false description: 'whether to stop clients to talk to each other, default is false (when enabled, a unique isolation_vlan_id is required). NOTE: this features requires uplink device to also a be Juniper device and `inter_switch_link` to be set. See also `inter_isolation_network_link` and `community_vlan_id` in port_usage' type: boolean isolation_vlan_id: examples: - '3070' type: string subnet: description: Optional for pure switching, required when L3 / routing features are used type: string subnet6: description: Optional for pure switching, required when L3 / routing features are used type: string vlan_id: $ref: '#/components/schemas/vlan_id_with_variable' required: - vlan_id type: object snmpv3_config_target_param_mess_process_model: description: 'enum: `v1`, `v2c`, `v3`' enum: - v1 - v2c - v3 type: string response_http400: additionalProperties: false properties: detail: examples: - 'JSON parse error - Expecting value: line 5 column 8 (char 56)' type: string type: object mxcluster_radsec_auth_server: additionalProperties: false properties: host: description: IP / hostname of RADIUS server type: string inband_status_check: default: false description: Whether to enable inband status check type: boolean inband_status_interval: default: 300 description: Inband status interval, in seconds minimum: 0 type: integer keywrap_enabled: description: If used for Mist APs, enable keywrap algorithm. Default is false type: boolean keywrap_format: $ref: '#/components/schemas/mxcluster_rad_auth_server_keywrap_format' keywrap_kek: description: If used for Mist APs, encryption key type: string keywrap_mack: description: If used for Mist APs, Message Authentication Code Key type: string port: default: 1812 description: Auth port of RADIUS server type: integer retry: default: 2 description: Authentication request retry type: integer secret: description: Secret of RADIUS server format: password type: string ssids: $ref: '#/components/schemas/mxcluster_radsec_auth_server_ssids' timeout: default: 5 description: Authentication request timeout, in seconds type: integer type: object site_setting_ap_matching_rules: examples: - - match_model: string name: string port_config: eth1,eth2: disabled: true dynamic_vlan: default_vlan_id: 999 enabled: true port_vlan_id: 1 vlan_id: 9 vlan_ids: - 1 - 10 - 50 items: $ref: '#/components/schemas/site_setting_ap_matching_rule' type: array extra_routes: additionalProperties: $ref: '#/components/schemas/extra_route' description: Property key is the destination CIDR (e.g. "10.0.0.0/8") examples: - 0.0.0.0/0: via: 192.168.1.10 type: object extra_route_next_qualified_properties: additionalProperties: false properties: metric: type: - integer - 'null' preference: type: - integer - 'null' type: object vrf_extra_routes: additionalProperties: $ref: '#/components/schemas/vrf_extra_route' description: Property key is the destination CIDR (e.g. "10.0.0.0/8") examples: - 0.0.0.0/0: via: 192.168.1.10 type: object dot11_bandwidth6: default: 80 description: 'channel width for the 6GHz band. enum: `0`(disabled, response only), `20`, `40`, `80`, `160`' enum: - 0 - 20 - 40 - 80 - 160 examples: - 80 type: integer tunnel_config_networks: description: If `provider`==`custom-ipsec` or `provider`==`prisma-ipsec`, networks reachable via this tunnel items: type: string type: array setting_ssr_auto_upgrade: additionalProperties: false description: auto_upgrade device first time it is onboarded properties: channel: $ref: '#/components/schemas/ssr_upgrade_channel' custom_versions: $ref: '#/components/schemas/setting_ssr_auto_upgrade_custom_versions' enabled: default: false type: boolean version: description: Firmware version to deploy (e.g. 6.3.0-107.r1). Optional, used when custom_versions not specified examples: - 6.3.0-107.r1 type: string type: object site_rogue_whitelisted_ssids: description: List of SSIDs to whitelist examples: - - cc:8e:6f:d4:bf:16 - cc-8e-6f-d4-bf-16 - cc-73-* - cc:82:* items: type: string type: array vs_instance_property_networks: items: examples: - guest type: string type: array radio_band_channels: default: [] description: For RFTemplates. List of channels, null or empty array means auto items: type: integer type: - array - 'null' synthetictest_config_vlans: deprecated: true items: $ref: '#/components/schemas/synthetictest_config_vlan' type: array snmpv3_config_notify_filter_item: additionalProperties: false properties: contents: $ref: '#/components/schemas/snmpv3_config_notify_filter_item_contents' profile_name: type: string type: object bgp_config_via: default: lan description: 'enum: `lan`, `tunnel`, `vpn`, `wan`' enum: - lan - tunnel - vpn - wan type: string site_setting_analytic: additionalProperties: false properties: enabled: default: false description: Enable Advanced Analytic feature (using SUB-ANA license) type: boolean type: object remote_syslog_time_format: description: 'enum: `millisecond`, `year`, `year millisecond`' enum: - millisecond - year - year millisecond examples: - millisecond type: string juniper_srx_auto_upgrade: additionalProperties: false description: auto_upgrade device first time it is onboarded properties: custom_versions: $ref: '#/components/schemas/juniper_srx_auto_upgrade_custom_versions' enabled: default: false type: boolean snapshot: default: false type: boolean version: description: Firmware version to deploy (e.g. 23.4R2-S5.5). Optional, used when custom_versions not specified examples: - 23.4R2-S5.5 type: string type: object synthetictest_config_probes: description: app name comes from `custom_probes` above or /const/synthetic_test_probes items: type: string type: array tacacs_auth_server: additionalProperties: false properties: host: type: string port: type: string secret: format: password type: string timeout: default: 10 type: integer type: object evpn_options_vs_instance: additionalProperties: false properties: networks: $ref: '#/components/schemas/strings' type: object tunnel_config_version: default: '2' description: 'Only if `provider`==`custom-gre` or `provider`==`custom-ipsec`. enum: `1`, `2`' enum: - '1' - '2' type: string site_mxtunnel_radsec_auth_servers: items: $ref: '#/components/schemas/radius_auth_server' type: array tunnel_config_ipsec_proposals: description: Only if `provider`==`custom-ipsec` items: $ref: '#/components/schemas/tunnel_config_ipsec_proposal' type: array switch_port_mirroring_ingress_networks: description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified items: examples: - corp type: string type: array modified_time: description: When the object has been modified for the last time, in epoch format: double readOnly: true type: number acl_policy_actions: description: "ACL Policy Actions:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to" items: $ref: '#/components/schemas/acl_policy_action' type: array tunnel_config_ipsec_proposal: additionalProperties: false properties: auth_algo: $ref: '#/components/schemas/tunnel_config_auth_algo' dh_group: $ref: '#/components/schemas/tunnel_config_dh_group' enc_algo: $ref: '#/components/schemas/tunnel_config_enc_algo' type: object gw_routing_policy_term_matching_protocol: items: $ref: '#/components/schemas/gw_routing_policy_term_matching_protocol_enum' type: array site_zone_occupancy_alert: additionalProperties: false description: Zone Occupancy alert site settings properties: email_notifiers: $ref: '#/components/schemas/site_zone_occupancy_alert_email_notifiers' enabled: default: false description: Indicate whether zone occupancy alert is enabled for the site type: boolean threshold: default: 5 description: Sending zone-occupancy-alert webhook message only if a zone stays non-compliant (i.e. actual occupancy > occupancy_limit) for a minimum duration specified in the threshold, in minutes examples: - 5 maximum: 30 minimum: 0 type: integer type: object acl_tag_macs: description: "Required if \n- `type`==`mac`\n- `type`==`static_gbp` if from matching mac" items: type: string type: array simple_alert_dhcp_failure: additionalProperties: false properties: client_count: default: 10 type: integer duration: default: 10 description: failing within minutes maximum: 60 minimum: 5 type: integer incident_count: default: 20 type: integer type: object gateway_oob_ip_config: additionalProperties: false description: Out-of-band (vme/em0/fxp0) IP config properties: gateway: description: If `type`==`static` type: string ip: description: If `type`==`static` type: string netmask: description: If `type`==`static` type: string node1: $ref: '#/components/schemas/gateway_oob_ip_config_node1' type: $ref: '#/components/schemas/ip_type' use_mgmt_vrf: default: false description: If supported on the platform. If enabled, DNS will be using this routing-instance, too type: boolean use_mgmt_vrf_for_host_out: default: false description: For host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired type: boolean vlan_id: $ref: '#/components/schemas/gateway_port_vlan_id_with_variable' type: object routing_policy_term_matching_community: items: examples: - '3900062' type: string type: array tunnel_config_node: additionalProperties: false description: Only if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec` properties: hosts: $ref: '#/components/schemas/tunnel_config_node_hosts' internal_ips: $ref: '#/components/schemas/tunnel_config_node_internal_ips' probe_ips: $ref: '#/components/schemas/strings' remote_ids: $ref: '#/components/schemas/tunnel_config_node_remote_ids' wan_names: $ref: '#/components/schemas/tunnel_config_node_wan_names' required: - hosts - wan_names type: object site_setting_derived: allOf: - $ref: '#/components/schemas/site_setting' - $ref: '#/components/schemas/site_setting_derived_accounts' switch_port_usage_mtu: anyOf: - maximum: 9216 minimum: 256 type: integer - type: string - type: 'null' description: Only if `mode`!=`dynamic` media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation. The default value is 1514. tunnel_config_node_hosts: items: description: IP Address of the remote host type: string type: array gateway_mgmt_probe_hosts: examples: - - 8.8.8.8 format: ipv4 items: type: string type: array radius_acct_port: anyOf: - maximum: 65545 minimum: 1 type: integer - type: string description: Radius Auth Port, value from 1 to 65535, default is 1813 gateway_ip_config_dns_suffix: description: Except for out-of_band interface (vme/em0/fxp0) items: type: string type: array mxcluster_nac: additionalProperties: false properties: acct_server_port: default: 1813 type: integer auth_server_port: default: 1812 type: integer client_ips: additionalProperties: $ref: '#/components/schemas/mxcluster_nac_client_ips' description: Property key is the RADIUS Client IP/Subnet. type: object enabled: default: false type: boolean secret: examples: - testing123 type: string type: object site_wids_repeated_auth_failures: additionalProperties: false properties: duration: description: Window where a trigger will be detected and action to be taken (in seconds) examples: - 60 type: integer threshold: description: Count of events to trigger type: integer type: object vrrp_group_network: additionalProperties: false properties: ip: type: string type: object dhcpd_config_fixed_bindings: additionalProperties: $ref: '#/components/schemas/dhcpd_config_fixed_binding' description: If `type`==`local` or `type6`==`local`. Property key is the MAC Address. Format is `[0-9a-f]{12}` (e.g. "5684dae9ac8b") examples: - 5684dae9ac8b: ip: 192.168.70.35 name: John type: object ap_radio_band5: additionalProperties: false description: Radio Band AP settings properties: allow_rrm_disable: default: false type: boolean ant_gain: default: 0 maximum: 10 minimum: 0 type: - integer - 'null' antenna_beam_pattern: $ref: '#/components/schemas/radio_band_antenna_beam_pattern' antenna_mode: $ref: '#/components/schemas/radio_band_antenna_mode' bandwidth: $ref: '#/components/schemas/dot11_bandwidth5' channel: default: null description: For Device. (primary) channel for the band, 0 means using the Site Setting examples: - 100 type: - integer - 'null' channels: $ref: '#/components/schemas/radio_band_channels' disabled: default: false description: Whether to disable the radio type: boolean power: default: null description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …' examples: - 6 maximum: 25 minimum: 5 type: - integer - 'null' power_max: default: 17 description: When power=0, max tx power to use, HW-specific values will be used if not set maximum: 17 minimum: 5 type: - integer - 'null' power_min: default: 8 description: When power=0, min tx power to use, HW-specific values will be used if not set maximum: 17 minimum: 5 type: - integer - 'null' preamble: $ref: '#/components/schemas/radio_band_preamble' type: object tunnel_provider_options_prisma: additionalProperties: false properties: service_account_name: description: For prisma-ipsec, service account name to used for tunnel auto provisioning examples: - sa1@1823425211 type: string type: object service_policies: items: $ref: '#/components/schemas/service_policy' type: array gateway_path_preferences_paths: items: $ref: '#/components/schemas/gateway_path_preferences_path' type: array site_setting_ap_matching: additionalProperties: false properties: enabled: type: boolean rules: $ref: '#/components/schemas/site_setting_ap_matching_rules' type: object network_internet_access_destination_nat_property: additionalProperties: false properties: internal_ip: description: The Destination NAT destination IP Address. Must be an IP (i.e. "192.168.70.30") or a Variable (i.e. "{{myvar}}") examples: - 192.168.70.30 type: string name: examples: - web server type: string port: description: The Destination NAT destination IP Address. Must be a Port (i.e. "443") or a Variable (i.e. "{{myvar}}") examples: - '443' type: string wan_name: description: SRX Only. If not set, we configure the nat policies against all WAN ports for simplicity examples: - wan0 type: string type: object acl_tag: additionalProperties: false description: Resource tags (`type`==`resource` or `type`==`gbp_resource`) can only be used in `dst_tags` properties: ether_types: $ref: '#/components/schemas/acl_tag_ether_types' gbp_tag: description: "Required if\n - `type`==`dynamic_gbp` (gbp_tag received from RADIUS)\n - `type`==`gbp_resource`\n - `type`==`static_gbp` (applying gbp tag against matching conditions)" type: integer macs: $ref: '#/components/schemas/acl_tag_macs' network: description: "If:\n * `type`==`mac` (optional. default is `any`)\n * `type`==`subnet` (optional. default is `any`)\n * `type`==`network`\n * `type`==`resource` (optional. default is `any`)\n * `type`==`static_gbp` if from matching network (vlan)" type: string port_usage: description: Required if `type`==`port_usage` type: string radius_group: description: "Required if:\n * `type`==`radius_group`\n * `type`==`static_gbp`\nif from matching radius_group" type: string specs: $ref: '#/components/schemas/acl_tag_specs' subnets: $ref: '#/components/schemas/acl_tag_subnets' type: $ref: '#/components/schemas/acl_tag_type' required: - type type: object snmp_usm_engine_type: description: 'enum: `local_engine`, `remote_engine`' enum: - local_engine - remote_engine type: string snmp_config_trap_version: default: v2 description: 'enum: `all`, `v1`, `v2`' enum: - all - v1 - v2 type: string ap_radio: additionalProperties: false description: Radio AP settings properties: allow_rrm_disable: default: false type: boolean ant_gain_24: description: Antenna gain for 2.4G - for models with external antenna only examples: - 4 minimum: 0 type: integer ant_gain_5: description: Antenna gain for 5G - for models with external antenna only examples: - 5 minimum: 0 type: integer ant_gain_6: description: Antenna gain for 6G - for models with external antenna only examples: - 5 minimum: 0 type: integer antenna_mode: $ref: '#/components/schemas/ap_radio_antenna_mode' antenna_select: $ref: '#/components/schemas/antenna_select' band_24: $ref: '#/components/schemas/ap_radio_band24' band_24_usage: $ref: '#/components/schemas/radio_band_24_usage' band_5: $ref: '#/components/schemas/ap_radio_band5' band_5_on_24_radio: $ref: '#/components/schemas/ap_radio_band5' band_6: $ref: '#/components/schemas/ap_radio_band6' full_automatic_rrm: default: false description: Let RRM control everything, only the `channels` and `ant_gain` will be honored (i.e. disabled/bandwidth/power/band_24_usage are all controlled by RRM) type: boolean indoor_use: default: false description: To make an outdoor operate indoor. For an outdoor-ap, some channels are disallowed by default, this allows the user to use it as an indoor-ap type: boolean rrm_managed: description: Enable RRM to manage all radio settings (ignores all band_xxx configs) type: boolean scanning_enabled: description: Whether scanning radio is enabled examples: - true type: boolean type: object snmp_config_client_list_clients: items: examples: - 151.140.101.218/32 type: string type: array ap_port_config_forwarding: default: all description: "enum: \n * `all`: local breakout, All VLANs\n * `limited`: local breakout, only the VLANs configured in `port_vlan_id` and `vlan_ids`\n * `mxtunnel`: central breakout to an Org Mist Edge (requires `mxtunnel_id`)\n * `site_mxedge`: central breakout to a Site Mist Edge (requires `mxtunnel_name`)\n * `wxtunnel`': central breakout to an Org WxTunnel (requires `wxtunnel_id`)" enum: - all - limited - mxtunnel - site_mxedge - wxtunnel examples: - all type: string mxtunnel_vlan_ids: description: List of vlan_ids that will be used items: type: integer type: array service_policy_antivirus: additionalProperties: false description: For SRX-only properties: avprofile_id: description: org-level AV Profile can be used, this takes precedence over 'profile' format: uuid type: string enabled: default: false type: boolean profile: description: Default / noftp / httponly / or keys from av_profiles type: string type: object gateway_port_vlan_id_with_variable: description: If WAN interface is on a VLAN. Can be the VLAN ID (i.e. "10") or a Variable (i.e. "{{myvar}}") oneOf: - type: string - maximum: 4094 minimum: 1 type: integer routing_policy_term_action_prepend_as_path: description: When used as export policy, optional. By default, the local AS will be prepended, to change it. Can be a Variable (e.g. `{{as_path}}`) items: examples: - 65000 400 type: string type: array tunnel_config_auto_provision_provider: description: 'enum: `jse-ipsec`, `zscaler-ipsec`' enum: - jse-ipsec - zscaler-ipsec type: string mxcluster_nac_client_ips: additionalProperties: $ref: '#/components/schemas/mxcluster_nac_client_ip' type: object vlan_ids: description: list of VLAN IDs on which rogue APs are ignored items: maximum: 4096 minimum: 0 type: integer type: array gateway_mgmt_admin_sshkeys: description: For SSR only, as direct root access is not allowed examples: - - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host items: type: string type: array gateway_port_config_wan_speedtest_mode: default: auto description: 'Controls whether Marvis/scheduler can run speedtest on this port. enum: `auto`, `enabled`, `disabled`' enum: - auto - enabled - disabled examples: - auto type: string site_mxtunnel_ap_subnets: description: List of subnets where we allow AP to establish Mist Tunnels from items: examples: - 0.0.0.0/0 type: string type: array idp_config: additionalProperties: false properties: alert_only: type: boolean enabled: default: false type: boolean idpprofile_id: description: org_level IDP Profile can be used, this takes precedence over `profile` examples: - 89b9d208-84a4-fa8f-af57-78f92c639cf2 format: uuid type: string profile: default: strict description: 'enum: `Custom`, `strict` (default), `standard` or keys from idp_profiles' type: string type: object tunnel_config_auth_algo: description: 'enum: `md5`, `sha1`, `sha2`' enum: - md5 - sha1 - sha2 type: string radsec_proxy_hosts: description: Default is site.mxedge.radsec.proxy_hosts which must be a superset of all `wlans[*].radsec.proxy_hosts`. When `radsec.proxy_hosts` are not used, tunnel peers (org or site mxedges) are used irrespective of `use_site_mxedge` items: examples: - mxedge1.local type: string type: array snmp_vacm_access_item_prefix_list: items: $ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item' type: array synthetictest_config_lan_networks_networks: description: List of networks to be used for synthetic tests examples: - - pos-stations - pos-machines items: type: string type: array radius_auth_server: additionalProperties: false description: Authentication Server properties: host: description: IP/ hostname of RADIUS server examples: - 1.2.3.4 type: string keywrap_enabled: type: boolean keywrap_format: $ref: '#/components/schemas/radius_keywrap_format' keywrap_kek: examples: - '1122334455' type: string keywrap_mack: examples: - '1122334455' type: string port: $ref: '#/components/schemas/radius_auth_port' require_message_authenticator: default: false description: Whether to require Message-Authenticator in requests type: boolean secret: description: Secret of RADIUS server examples: - testing123 format: password type: string required: - host - secret type: object extra_routes6: additionalProperties: $ref: '#/components/schemas/extra_route6' description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64") examples: - 2a02:1234:420a:10c9::/64: via: 2a02:1234:200a::100 type: object tunnel_config_auto_provision_node_wan_names: description: Optional, only needed if `vars_only`==`false` items: examples: - wan0 type: string type: array snmp_config_engine_id: maxLength: 27 type: string account_oauth_info_account_service_connections: additionalProperties: $ref: '#/components/schemas/account_oauth_info_account_service_connection' description: For Prisma accounts only, property key is the service connection name vs_instance: additionalProperties: $ref: '#/components/schemas/vs_instance_property' description: Optional, for EX9200 only to segregate virtual-switches. Property key is the instance name type: object dns_suffix: description: Global dns settings. To keep compatibility, dns settings in `ip_config` and `oob_ip_config` will overwrite this setting items: type: string type: array dns_servers: description: Global dns settings. To keep compatibility, dns settings in `ip_config` and `oob_ip_config` will overwrite this setting items: type: string type: array config_switch_local_accounts_user: additionalProperties: false properties: password: examples: - Juniper123 format: password type: string role: $ref: '#/components/schemas/config_switch_local_accounts_user_role' type: object radius_auth_servers: items: $ref: '#/components/schemas/radius_auth_server' type: array uniqueItems: true network_routed_for_networks: description: For a Network (usually LAN), it can be routable to other networks (e.g. OSPF) items: examples: - pos type: string type: array site_mxtunnel_cluster_tunterm_hosts: examples: - - mxedge1 - mxedge2.local items: type: string type: array vlan_id_with_variable: oneOf: - type: string - maximum: 4094 minimum: 1 type: integer allow_deny: description: 'enum: `allow`, `deny`' enum: - allow - deny type: string idp_profile_overwrite: additionalProperties: false properties: action: $ref: '#/components/schemas/idp_profile_action' matching: $ref: '#/components/schemas/idp_profile_matching' name: type: string type: object evpn_options: additionalProperties: false description: EVPN Options properties: auto_loopback_subnet: default: 172.16.192.0/24 description: Optional, for dhcp_relay, unique loopback IPs are required for ERB or IPClos where we can set option-82 server_id-overrides type: string auto_loopback_subnet6: default: fd33:ab00:2::/64 description: Optional, for dhcp_relay, unique loopback IPs are required for ERB or IPClos where we can set option-82 server_id-overrides type: string auto_router_id_subnet: default: 172.16.254.0/23 description: Optional, this generates router_id automatically, if specified, `router_id_prefix` is ignored type: string auto_router_id_subnet6: description: Optional, this generates router_id automatically, if specified, `router_id_prefix` is ignored examples: - fd31:5700:1::/64 type: string core_as_border: default: false description: Optional, for ERB or CLOS, you can either use esilag to upstream routers or to also be the virtual-gateway. When `routed_at` != `core`, whether to do virtual-gateway at core as well type: boolean enable_inband_mgmt: default: false description: Whether to route management traffic inband; routes will be propagated to downstream switches type: boolean enable_inband_ztp: default: false description: if the mangement traffic goes inbnd, during installation, only the border/core switches are connected to the Internet to allow initial configuration to be pushed down and leave the downstream access switches stay in the Factory Default state enabling inband-ztp allows upstream switches to use LLDP to assign IP and gives Internet to downstream switches in that state type: boolean overlay: $ref: '#/components/schemas/evpn_options_overlay' per_vlan_vga_v4_mac: default: false description: Only for by Core-Distribution architecture when `evpn_options.routed_at`==`core`. By default, JUNOS uses 00-00-5e-00-01-01 as the virtual-gateway-address's v4_mac. If enabled, 00-00-5e-00-0X-YY will be used (where XX=vlan_id/256, YY=vlan_id%256) type: boolean per_vlan_vga_v6_mac: default: false description: Only for by Core-Distribution architecture when `evpn_options.routed_at`==`core`. By default, JUNOS uses 00-00-5e-00-02-01 as the virtual-gateway-address's v6_mac. If enabled, 00-00-5e-00-1X-YY will be used (where XX=vlan_id/256, YY=vlan_id%256) type: boolean routed_at: $ref: '#/components/schemas/evpn_options_routed_at' underlay: $ref: '#/components/schemas/evpn_options_underlay' vs_instances: $ref: '#/components/schemas/evpn_options_vs_instances' type: object ap_port_config_mac_auth_protocol: default: pap description: 'if `enable_mac_auth`==`true`, allows user to select an authentication protocol. enum: `eap-md5`, `eap-peap`, `pap`' enum: - eap-md5 - eap-peap - pap type: string vrf_extra_route: additionalProperties: false properties: via: description: Next-hop address format: ipv4 type: string type: object tunnel_config_probe_type: default: icmp description: 'enum: `http`, `icmp`' enum: - http - icmp type: string site_wifi_proxy_arp: description: 'enum: `default`, `disabled`, `enabled`' enum: - default - disabled - enabled type: - string - 'null' dhcpd_config_servers: description: If `type`==`relay` examples: - - 11.2.3.4 items: type: string type: array service_policy_skyatp_http_inspection_profile: description: 'enum: `standard`, `strict`' enum: - standard - strict type: string gateway_matching: additionalProperties: false description: Gateway matching properties: enable: type: boolean rules: $ref: '#/components/schemas/gateway_matching_rules' type: object simple_alert_arp_failure: additionalProperties: false properties: client_count: default: 10 type: integer duration: default: 20 description: failing within minutes maximum: 60 minimum: 5 type: integer incident_count: default: 10 type: integer type: object ibeacon_minor: description: Minor number for iBeacon examples: - 1234 maximum: 65535 minimum: 1 type: - integer - 'null' protect_re_allowed_service: description: 'enum: `icmp`, `ssh`' enum: - icmp - ssh type: string dhcpd_config_dns_suffix: description: If `type`==`local` or `type6`==`local` - optional, if not defined, system one will be used examples: - - .mist.local - .mist.com items: type: string type: array gateway_port_duplex: default: auto description: 'enum: `auto`, `full`, `half`' enum: - auto - full - half examples: - full type: string switch_matching_rule_oob_ip_config: additionalProperties: false description: Out-of-Band Management interface configuration properties: type: $ref: '#/components/schemas/ip_type' use_mgmt_vrf: default: false description: If supported on the platform. If enabled, DNS will be using this routing-instance, too type: boolean use_mgmt_vrf_for_host_out: default: false description: For host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired type: boolean type: object tunnel_config_protocol: description: 'Only if `provider`==`custom-ipsec`. enum: `gre`, `ipsec`' enum: - gre - ipsec type: string snmp_usms: items: $ref: '#/components/schemas/snmp_usm' type: array network_template_import_org_networks: description: Org Networks that we'd like to import items: examples: - ap type: string type: array tunnel_config_ike_proposals: description: If `provider`==`custom-ipsec` items: $ref: '#/components/schemas/tunnel_config_ike_proposal' type: array service_policy_ssl_proxy: additionalProperties: false description: For SRX-only properties: ciphers_category: $ref: '#/components/schemas/ssl_proxy_ciphers_category' enabled: default: false type: boolean type: object site_setting_status_portal: additionalProperties: false properties: enabled: default: false type: boolean hostnames: $ref: '#/components/schemas/site_setting_status_portal_hostnames' type: object switch_port_usages: additionalProperties: $ref: '#/components/schemas/switch_port_usage' description: Property key is the port usage name. Defines the profiles of port configuration configured on the switch type: object sw_routing_policy_term_matching_protocol: items: $ref: '#/components/schemas/sw_routing_policy_term_matching_protocol_enum' type: array dhcpd_config_options: additionalProperties: $ref: '#/components/schemas/dhcpd_config_option' description: If `type`==`local` or `type6`==`local`. Property key is the DHCP option number type: object networks: items: $ref: '#/components/schemas/network' type: array gateway_port_config_reth_idx: anyOf: - type: integer - type: string description: For SRX only and if HA Mode. `-1` means it will be managed by the device. Use `>= 0` values to manage it manually. Ensure no conflicting values are assigned across all ports. dhcp_snooping: additionalProperties: false properties: all_networks: type: boolean enable_arp_spoof_check: description: Enable for dynamic ARP inspection check type: boolean enable_ip_source_guard: description: Enable for check for forging source IP address type: boolean enabled: type: boolean networks: $ref: '#/components/schemas/dhcp_snooping_networks' type: object site_engagement_dwell_tags: additionalProperties: false description: add tags to visits within the duration (in seconds) properties: bounce: default: 301-14400 type: - string - 'null' engaged: default: 14401-28800 type: - string - 'null' passerby: default: 1-300 type: - string - 'null' stationed: default: 28801-42000 type: - string - 'null' type: object ssr_upgrade_channel: default: stable description: 'upgrade channel to follow. enum: `alpha`, `beta`, `stable`' enum: - alpha - beta - stable type: string ble_config_power_mode: default: default description: 'enum: `custom`, `default`' enum: - custom - default examples: - custom type: string site_setting_critical_url_monitoring: additionalProperties: false description: You can define some URLs that's critical to site operations the latency will be captured and considered for site health properties: enabled: default: true type: boolean monitors: $ref: '#/components/schemas/site_setting_critical_url_monitoring_monitors' type: object remote_syslog_server_protocol: default: udp description: 'enum: `tcp`, `udp`' enum: - tcp - udp type: string idp_profile_matching_severity: items: $ref: '#/components/schemas/idp_profile_matching_severity_value' type: array org_id: examples: - a97c1b22-a4e9-411e-9bfd-d8695a0f9e61 format: uuid readOnly: true type: string routing_policy_term_matching_prefix: description: zero or more criteria/filter can be specified to match the term, all criteria have to be met items: examples: - 192.168.0.0/16-30 type: string type: array aggregate_route: additionalProperties: false properties: discard: default: false type: boolean metric: maximum: 4294967295 minimum: 0 type: - integer - 'null' preference: maximum: 4294967295 minimum: 0 type: - integer - 'null' type: object site_setting_juniper_srx_gateways: items: $ref: '#/components/schemas/site_setting_juniper_srx_gateway' type: array site_setting_ssh_keys: description: When limit_ssh_access = true in Org Setting, list of SSH public keys provided by Mist Support to install onto APs (see Org:Setting) items: examples: - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host type: string type: array remote_syslog_servers: examples: - - facility: config host: syslogd.internal port: 514 protocol: udp severity: info tag: '' items: $ref: '#/components/schemas/remote_syslog_server' type: array snmp_config_client_lists: items: $ref: '#/components/schemas/snmp_config_client_list' type: array gateway_matching_rules: items: $ref: '#/components/schemas/gateway_matching_rule' type: array uniqueItems: true gw_routing_policy_term_matching_vpn_path: description: overlay-facing criteria (used for bgp_config where via=vpn). ordered- items: type: string type: array radsec: additionalProperties: false description: RadSec settings properties: coa_enabled: default: false type: boolean enabled: type: boolean idle_timeout: $ref: '#/components/schemas/radsec_idle_timeout' mxcluster_ids: $ref: '#/components/schemas/radsec_mxcluster_ids' proxy_hosts: $ref: '#/components/schemas/radsec_proxy_hosts' server_name: description: Name of the server to verify (against the cacerts in Org Setting). Only if not Mist Edge. examples: - radsec.abc.com type: string servers: $ref: '#/components/schemas/radsec_servers' use_mxedge: description: use mxedge(s) as RadSec Proxy type: boolean use_site_mxedge: default: false description: To use Site mxedges when this WLAN does not use mxtunnel type: boolean type: object radio_band_24_usage: description: 'enum: `24`, `5`, `6`, `auto`' enum: - '24' - '5' - '6' - auto type: string mxedge_das_coa_servers: description: Dynamic authorization clients configured to send CoA|DM to mist edges on port 3799 items: $ref: '#/components/schemas/mxedge_das_coa_server' type: array tunnel_config_ike_dh_group: default: '14' description: "enum:\n * 1\n * 2 (1024-bit)\n * 5\n * 14 (default, 2048-bit)\n * 15 (3072-bit)\n * 16 (4096-bit)\n * 19 (256-bit ECP)\n * 20 (384-bit ECP)\n * 21 (521-bit ECP)\n * 24 (2048-bit ECP)" enum: - '1' - '14' - '15' - '16' - '19' - '2' - '20' - '21' - '24' - '5' type: string gateway_path_preferences_path: additionalProperties: false properties: cost: type: integer disabled: description: For SSR Only. `true`, if this specific path is undesired type: boolean gateway_ip: description: Only if `type`==`local`, if a different gateway is desired type: string internet_access: description: Only if `type`==`vpn`, if this vpn path can be used for internet type: boolean name: description: "Required when \n * `type`==`vpn`: the name of the VPN Path to use \n * `type`==`wan`: the name of the WAN interface to use" type: string networks: $ref: '#/components/schemas/gateway_path_preferences_path_networks' target_ips: $ref: '#/components/schemas/gateway_path_preferences_path_target_ips' type: $ref: '#/components/schemas/gateway_path_type' wan_name: description: Optional if `type`==`vpn` examples: - wan0 type: string required: - type type: object service_policy_skyatp_iot_device_policy: additionalProperties: false properties: enabled: type: boolean type: object switch_port_usage_storm_control: additionalProperties: false description: Switch storm control. Only if `mode`!=`dynamic` properties: disable_port: default: false description: Whether to disable the port when storm control is triggered type: boolean no_broadcast: default: false description: Whether to disable storm control on broadcast traffic type: boolean no_multicast: default: false description: Whether to disable storm control on multicast traffic type: boolean no_registered_multicast: default: false description: Whether to disable storm control on registered multicast traffic type: boolean no_unknown_unicast: default: false description: Whether to disable storm control on unknown unicast traffic type: boolean percentage: default: 80 description: Bandwidth-percentage, configures the storm control level as a percentage of the available bandwidth maximum: 100 minimum: 0 type: integer type: object service_policy_skyatp_dns_tunnel_detection_profile: description: 'enum: `default`, `standard`, `strict`' enum: - default - standard - strict type: string mxedge_tunterm_multicast_config_ssdp_vlan_ids: examples: - - 2 - 3 - 5 items: type: integer type: array site_setting_wan_vna: additionalProperties: false properties: enabled: default: false type: boolean type: object system_defined_port_usages: description: 'system-default port usages. enum: `ap`, `iot`, `uplink``' enum: - ap - iot - uplink type: string mxcluster_radsec_server_selection: default: ordered description: 'When ordered, Mist Edge will prefer and go back to the first radius server if possible. enum: `ordered`, `unordered`' enum: - ordered - unordered type: string ap_port_config_port_auth: default: none description: 'When doing port auth. enum: `dot1x`, `none`' enum: - dot1x - none examples: - none type: string switch_vrf_instances: additionalProperties: $ref: '#/components/schemas/switch_vrf_instance' description: Property key is the network name examples: - guest: extra_routes: 0.0.0.0/0: via: 192.168.31.1 networks: - guest type: object snmp_vacm: additionalProperties: false properties: access: $ref: '#/components/schemas/snmp_vacm_access' security_to_group: $ref: '#/components/schemas/snmp_vacm_security_to_group' type: object gw_routing_policies: additionalProperties: $ref: '#/components/schemas/gw_routing_policy' description: Property key is the routing policy name type: object radio_band_antenna_mode: default: default description: 'enum: `1x1`, `2x2`, `3x3`, `4x4`, `default`' enum: - 1x1 - 2x2 - 3x3 - 4x4 - default examples: - default type: string gw_routing_policy_term_action_add_target_vrfs: description: For SSR, hub decides how VRF routes are leaked on spoke items: type: string type: array ibeacon_major: description: Major number for iBeacon examples: - 1234 maximum: 65535 minimum: 1 type: - integer - 'null' protect_re_customs: items: $ref: '#/components/schemas/protect_re_custom' type: array dhcpd_config_vendor_options: additionalProperties: $ref: '#/components/schemas/dhcpd_config_vendor_option' description: "If `type`==`local` or `type6`==`local`. Property key is :, with\n * enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers)\n * sub option code: 1-255, sub-option code" type: object network_internet_access_static_nat_property: additionalProperties: false properties: internal_ip: description: The Static NAT destination IP Address. Must be an IP Address (i.e. "192.168.70.3") or a Variable (i.e. "{{myvar}}") examples: - 192.168.70.3 type: string name: examples: - pos_station-1 type: string wan_name: description: SRX Only. If not set, we configure the nat policies against all WAN ports for simplicity. Can be a Variable (i.e. "{{myvar}}") examples: - wan0 type: string type: object tacacs_auth_servers: items: $ref: '#/components/schemas/tacacs_auth_server' type: array auto_preemption: additionalProperties: false description: Schedule to preempt ap’s which are not connected to preferred peer properties: day_of_week: $ref: '#/components/schemas/day_of_week' enabled: default: false description: Whether auto preemption should happen type: boolean time_of_day: $ref: '#/components/schemas/time_of_day' type: object gateway_port_reth_nodes: description: SSR only - supporting vlan-based redundancy (matching the size of `networks`) examples: - - node0 - node1 items: type: string type: array tunnel_config_node_internal_ips: description: Only if `provider`==`zscaler-gre`, `provider`==`jse-ipsec`, `provider`==`custom-ipsec` or `provider`==`custom-gre` items: type: string type: array switch_port_usage_reauth_interval: anyOf: - default: 3600 maximum: 65535 minimum: 10 type: integer - type: string description: 'Only if `mode`!=`dynamic` and `port_auth`=`dot1x` reauthentication interval range (min: 10, max: 65535, default: 3600). Set to 0 to disable reauthentication (no-reauthentication).' gateway_port_wan_arp_policer: default: default description: 'Only when `wan_type`==`broadband`. enum: `default`, `max`, `recommended`' enum: - default - max - recommended type: string snmp_vacm_access_item_type: description: 'enum: `context_prefix`, `default_context_prefix`' enum: - context_prefix - default_context_prefix type: string remote_syslog_archive: additionalProperties: false properties: files: $ref: '#/components/schemas/remote_syslog_archive_files' size: examples: - 5m type: string type: object junos_port_config_duplex: default: auto description: 'enum: `auto`, `full`, `half`' enum: - auto - full - half type: string switch_bgp_config_neighbor: additionalProperties: false properties: export_policy: description: Export policy must match one of the policy names defined in the `routing_policies` property. type: string hold_time: $ref: '#/components/schemas/switch_bgp_config_hold_time' import_policy: description: Import policy must match one of the policy names defined in the `routing_policies` property. type: string multihop_ttl: maximum: 255 minimum: 1 type: integer neighbor_as: $ref: '#/components/schemas/bgp_as' description: Autonomous System (AS) number of the BGP neighbor. For internal BGP, this must match `local_as`. For external BGP, this must differ from `local_as`. required: - neighbor_as type: object gateway_idp_profiles: additionalProperties: $ref: '#/components/schemas/idp_profile' description: Property key is the profile name type: object hour: default: '' description: Hour range of the day (e.g. `09:00-17:00`). If the hour is not defined then it's treated as 00:00-23:59. examples: - 09:00-17:00 type: string ble_config_beacon_rate_mode: default: default description: 'enum: `custom`, `default`' enum: - custom - default examples: - custom type: string gateway_port_vpn_path: additionalProperties: false properties: bfd_profile: $ref: '#/components/schemas/gateway_port_vpn_path_bfd_profile' bfd_use_tunnel_mode: default: false description: Only if the VPN `type`==`hub_spoke`. Whether to use tunnel mode. SSR only type: boolean preference: description: Only if the VPN `type`==`hub_spoke`. For a given VPN, when `path_selection.strategy`==`simple`, the preference for a path (lower is preferred) type: integer role: $ref: '#/components/schemas/gateway_port_vpn_path_role' traffic_shaping: $ref: '#/components/schemas/gateway_traffic_shaping' type: object radsec_idle_timeout: anyOf: - default: 60 type: integer - type: string description: Radsec Idle Timeout in seconds. Default is 60 site_setting_ap_matching_rule: additionalProperties: false properties: match_model: examples: - AP12 type: string name: examples: - AP12 type: string port_config: additionalProperties: $ref: '#/components/schemas/ap_port_config' description: Property key is the interface(s) (e.g. "eth1,eth2") type: object type: object remote_syslog_severity: default: any description: 'enum: `alert`, `any`, `critical`, `emergency`, `error`, `info`, `notice`, `warning`' enum: - alert - any - critical - emergency - error - info - notice - warning type: string gateway_mgmt_auto_signature_update: additionalProperties: false properties: day_of_week: $ref: '#/components/schemas/day_of_week' enable: default: true type: boolean time_of_day: description: Optional, Mist will decide the timing type: string type: object radius_coa_port: anyOf: - maximum: 65545 minimum: 1 type: integer - type: string description: Radius CoA Port, value from 1 to 65535, default is 3799 site_setting_juniper_srx_gateway: additionalProperties: false properties: api_key: examples: - 5abf7c8a-1a1c-4398-ba2d-b0c297094d1a type: string api_password: examples: - abc@123 type: string api_url: examples: - https://23.43.12.78:8443 type: string type: object service_policy_skyatp_dns_tunnel_detection: additionalProperties: false properties: enabled: type: boolean profile: $ref: '#/components/schemas/service_policy_skyatp_dns_tunnel_detection_profile' type: object routing_policy_local_preference: anyOf: - type: string - maximum: 4294967295 minimum: 1 type: integer description: Optional, for an import policy, local_preference can be changed, value in range 1-4294967294. Can be a Variable (e.g. `{{bgp_as}}`) vs_instance_property: additionalProperties: false properties: networks: $ref: '#/components/schemas/vs_instance_property_networks' type: object acl_policy_action: additionalProperties: false properties: action: $ref: '#/components/schemas/allow_deny' dst_tag: examples: - corp type: string required: - dst_tag type: object network_vpn_access_config_other_vrfs: description: By default, the routes are only readvertised toward the same vrf on spoke. To allow it to be leaked to other vrfs items: examples: - iot type: string type: array switch_mist_nac: additionalProperties: false description: Enable mist_nac to use RadSec properties: enabled: type: boolean network: type: string type: object response_http401: additionalProperties: false properties: detail: examples: - Authentication credentials were not provided. type: string type: object wan_extra_routes6: additionalProperties: false properties: via: format: ipv6 type: string type: object snmpv3_config_target_param_security_model: description: 'enum: `usm`, `v1`, `v2c`' enum: - usm - v1 - v2c type: string snmp_usm_user_authentication_type: description: 'sha224, sha256, sha384, sha512 are supported in 21.1 and newer release. enum: `authentication-md5`, `authentication-none`, `authentication-sha`, `authentication-sha224`, `authentication-sha256`, `authentication-sha384`, `authentication-sha512`' enum: - authentication-md5 - authentication-none - authentication-sha - authentication-sha224 - authentication-sha256 - authentication-sha384 - authentication-sha512 type: string acl_tag_subnets: description: "If \n- `type`==`subnet` \n- `type`==`resource` (optional. default is `any`)\n- `type`==`static_gbp` if from matching subnet" items: type: string type: array radius_auth_port: anyOf: - maximum: 65545 minimum: 1 type: integer - type: string description: Radius Auth Port, value from 1 to 65535, default is 1812 additional_config_cmds: description: 'additional CLI commands to append to the generated Junos config. **Note**: no check is done' items: description: JUNOS "set" command to add to the generated configuration examples: - set snmp community public type: string type: array gateway_path_strategy: default: ordered description: 'enum: `ecmp`, `ordered`, `weighted`' enum: - ecmp - ordered - weighted type: string snmp_config: additionalProperties: false properties: client_list: $ref: '#/components/schemas/snmp_config_client_lists' contact: examples: - cns@juniper.net type: string description: examples: - Juniper QFX Series Switch - 1K_5LA type: string enabled: default: true type: boolean engine_id: $ref: '#/components/schemas/snmp_config_engine_id' engine_id_type: $ref: '#/components/schemas/snmp_config_engine_id_type' location: examples: - Las Vegas, NV type: string name: examples: - TGH-1K-QFX10K type: string network: default: default type: string trap_groups: $ref: '#/components/schemas/snmp_config_trap_groups' v2c_config: $ref: '#/components/schemas/snmp_config_v2c_configs' v3_config: $ref: '#/components/schemas/snmpv3_config' views: $ref: '#/components/schemas/snmp_config_views' type: object remote_syslog_archive_files: anyOf: - type: string - type: integer examples: - 20 mxedge_das_coa_server: additionalProperties: false properties: disable_event_timestamp_check: default: false description: Whether to disable Event-Timestamp Check type: boolean enabled: type: boolean host: description: This server configured to send CoA|DM to mist edges type: string port: default: 3799 description: Mist edges will allow this host on this port type: integer require_message_authenticator: default: false description: Whether to require Message-Authenticator in requests type: boolean secret: format: password type: string type: object gateway_traffic_shaping: additionalProperties: false properties: class_percentages: $ref: '#/components/schemas/gateway_traffic_shaping_class_percentages' enabled: default: false type: boolean max_tx_kbps: description: Interface Transmit Cap in kbps type: integer type: object site_mxtunnel_additional_mxtunnels: additionalProperties: $ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel' type: object switch_radius_config: additionalProperties: false description: Junos Radius config properties: acct_immediate_update: type: boolean acct_interim_interval: default: 0 description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from RADIUS Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled maximum: 65535 minimum: 0 type: integer acct_servers: $ref: '#/components/schemas/radius_acct_servers' auth_server_selection: $ref: '#/components/schemas/switch_radius_config_auth_server_selection' auth_servers: $ref: '#/components/schemas/radius_auth_servers' auth_servers_retries: default: 3 description: Radius auth session retries type: integer auth_servers_timeout: default: 5 description: Radius auth session timeout type: integer coa_enabled: default: false type: boolean coa_port: $ref: '#/components/schemas/radius_coa_port' fast_dot1x_timers: default: false type: boolean network: description: Use `network`or `source_ip`. Which network the RADIUS server resides, if there's static IP for this network, we'd use it as source-ip type: string source_ip: description: Use `network`or `source_ip` type: string type: object zscaler_sub_locations: description: '`sub-locations` can be used for specific uses cases to define different configuration based on the user network' items: $ref: '#/components/schemas/tunnel_provider_options_zscaler_sub_location' type: array snmpv3_config_target_address_item: additionalProperties: false properties: address: examples: - 10.11.0.2 type: string address_mask: examples: - 255.255.255.0 type: string port: default: '161' type: - string - 'null' tag_list: description: Refer to notify tag, can be multiple with blank type: string target_address_name: examples: - target_address_name type: string target_parameters: description: Refer to notify target parameters name type: string type: object site_mxtunnel_radsec_acct_servers: items: $ref: '#/components/schemas/radius_acct_server' type: array network_vpn_access_static_nat_property: additionalProperties: false properties: internal_ip: description: The Static NAT destination IP Address. Must be an IP Address (i.e. "192.168.70.3") or a Variable (i.e. "{{myvar}}") examples: - 192.168.70.3 type: string name: examples: - pos_station-1 type: string type: object ospf_areas: additionalProperties: $ref: '#/components/schemas/ospf_area' description: Junos OSPF areas. Property key is the OSPF Area (Area should be a number (0-255) / IP address) type: object snmp_vacm_security_to_group_content: items: $ref: '#/components/schemas/snmp_vacm_security_to_group_content_item' type: array snmp_usm: additionalProperties: false properties: engine_type: $ref: '#/components/schemas/snmp_usm_engine_type' remote_engine_id: description: Required only if `engine_type`==`remote_engine` examples: - 00:00:00:0b:00:00:70:10:6f:08:b6:3f type: string users: $ref: '#/components/schemas/snmp_usm_users' type: object site_setting_disabled_system_defined_port_usages: description: If some system-default port usages are not desired - namely, ap / iot / uplink items: $ref: '#/components/schemas/system_defined_port_usages' type: array network_vpn_access_config: additionalProperties: false properties: advertised_subnet: description: If `routed`==`true`, whether to advertise an aggregated subnet toward HUB this is useful when there are multiple networks on SPOKE's side examples: - 172.16.0.0/24 type: string allow_ping: description: Whether to allow ping from vpn into this routed network type: boolean destination_nat: $ref: '#/components/schemas/network_vpn_access_destination_nat' nat_pool: description: If `routed`==`false` (usually at Spoke), but some hosts needs to be reachable from Hub, a subnet is required to create and advertise the route to Hub examples: - 172.16.0.0/26 type: string no_readvertise_to_lan_bgp: default: false description: toward LAN-side BGP peers type: boolean no_readvertise_to_lan_ospf: default: false description: toward LAN-side OSPF peers type: boolean no_readvertise_to_overlay: description: toward overlay, how HUB should deal with routes it received from Spokes type: boolean other_vrfs: $ref: '#/components/schemas/network_vpn_access_config_other_vrfs' routed: description: Whether this network is routable type: boolean source_nat: $ref: '#/components/schemas/network_source_nat' static_nat: $ref: '#/components/schemas/network_vpn_access_static_nat' summarized_subnet: description: toward overlay, how HUB should deal with routes it received from Spokes examples: - 172.16.0.0/16 type: string summarized_subnet_to_lan_bgp: description: toward LAN-side BGP peers examples: - 172.16.0.0/16 type: string summarized_subnet_to_lan_ospf: description: toward LAN-side OSPF peers examples: - 172.16.0.0/16 type: string type: object dot11_bandwidth24: default: 20 description: 'channel width for the 2.4GHz band. enum: `0`(disabled, response only), `20`, `40`' enum: - 0 - 20 - 40 examples: - 20 type: integer site_setting_paloalto_network_gateway: additionalProperties: false properties: api_key: examples: - 5abf7c8a-1a1c-4398-ba2d-b0c297094d1a type: string api_url: examples: - https://23.43.12.78:8443 type: string type: object site_setting_tunterm_multicast_config_mdns: additionalProperties: false properties: enabled: default: false type: boolean vlan_ids: $ref: '#/components/schemas/mxedge_tunterm_multicast_config_mdns_vlan_ids' type: object tunnel_config_auto_provision: additionalProperties: false description: Auto Provisioning configuration for the tunne. This takes precedence over the `primary` and `secondary` nodes. properties: enabled: description: Enable auto provisioning for the tunnel. If enabled, the `primary` and `secondary` nodes will be ignored. type: boolean latlng: $ref: '#/components/schemas/tunnel_config_auto_provision_lat_lng' primary: $ref: '#/components/schemas/tunnel_config_auto_provision_node' provider: $ref: '#/components/schemas/tunnel_config_auto_provision_provider' region: description: API override for POP selection in the case user wants to override the auto discovery of remote network location and force the tunnel to use the specified peer location. type: string secondary: $ref: '#/components/schemas/tunnel_config_auto_provision_node' service_connection: description: if `provider`==`prisma-ipsec`. By default, we'll use the location of the site to determine the optimal Remote Network location, optionally, service_connection can be considered, then we'll also consider this along with the site location. Define service_connection if the traffic is to be routed to a specific service connection. This field takes a service connection name that is configured in the Prisma cloud, Prisma Access Setup -> Service Connections. examples: - Juniper-Lab-SC-1 type: string required: - provider type: object vrf_extra_routes6: additionalProperties: $ref: '#/components/schemas/vrf_extra_route6' description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64") examples: - 2a02:1234:420a:10c9::/64: via: 2a02:1234:200a::100 type: object snmp_usm_users: items: $ref: '#/components/schemas/snmp_usm_user' type: array switch_port_usage_dynamic_rules: description: Only if `mode`==`dynamic` items: $ref: '#/components/schemas/switch_port_usage_dynamic_rule' type: array ap_radio_antenna_mode: default: default description: 'enum: `1x1`, `2x2`, `3x3`, `4x4`, `default`' enum: - 1x1 - 2x2 - 3x3 - 4x4 - default type: string junos_port_config_speed: default: auto description: 'enum: `100m`, `10m`, `1g`, `2.5g`, `5g`, `10g`, `25g`, `40g`, `100g`,`auto`' enum: - 10m - 100m - 1g - 2.5g - 5g - 10g - 25g - 40g - 100g - auto type: string idp_profile_matching_attack_name: items: examples: - HTTP:INVALID:HDR-FIELD type: string type: array snmp_config_client_list: additionalProperties: false properties: client_list_name: examples: - clist-1 type: string clients: $ref: '#/components/schemas/snmp_config_client_list_clients' type: object network_multicast: additionalProperties: false description: Whether to enable multicast support (only PIM-sparse mode is supported) properties: disable_igmp: default: false description: If the network will only be the source of the multicast traffic, IGMP can be disabled type: boolean enabled: default: false type: boolean groups: $ref: '#/components/schemas/network_multicast_groups' type: object site_mxtunnel_hosts: description: Hostnames or IPs where a Mist Tunnel will use as the Peer (i.e. they are reachable from AP) items: type: string type: array switch_port_usage_mac_limit: anyOf: - default: 0 maximum: 16383 minimum: 0 type: integer - type: string description: Only if `mode`!=`dynamic`, max number of mac addresses, default is 0 for unlimited, otherwise range is 1 to 16383 (upper bound constrained by platform) site_setting_auto_upgrade: additionalProperties: false description: Auto Upgrade Settings properties: custom_versions: additionalProperties: type: string description: Custom versions for different models. Property key is the model name (e.g. "AP41") examples: - AP21: stable AP41: 0.1.5135 AP61: 0.1.7215 type: object day_of_week: $ref: '#/components/schemas/day_of_week' enabled: default: false description: Whether auto upgrade should happen (Note that Mist may auto-upgrade if the version is not supported) type: boolean time_of_day: description: '`any` / HH:MM (24-hour format), upgrade will happen within up to 1-hour from this time' examples: - '12:00' type: string version: $ref: '#/components/schemas/site_auto_upgrade_version' type: object mxcluster_radsec_acct_server_ssids: description: List of ssids that will use this server if match_ssid is true and match is found items: type: string type: array switch_port_usage_speed: default: auto description: 'Only if `mode`!=`dynamic`, Port speed, default is auto to automatically negotiate speed enum: `100m`, `10m`, `1g`, `2.5g`, `5g`, `10g`, `25g`, `40g`, `100g`,`auto`' enum: - 10m - 100m - 1g - 2.5g - 5g - 10g - 25g - 40g - 100g - auto type: string site_setting_switch: allOf: - $ref: '#/components/schemas/network_template' - $ref: '#/components/schemas/switch_auto_upgrade_container' app_probing_custom_apps: items: $ref: '#/components/schemas/app_probing_custom_app' type: array synthetictest_config: additionalProperties: false properties: aggressiveness: $ref: '#/components/schemas/synthetictest_config_aggressiveness' custom_probes: $ref: '#/components/schemas/synthetictest_config_custom_probes' disabled: default: false type: boolean lan_networks: $ref: '#/components/schemas/synthetictest_config_lan_networks' vlans: $ref: '#/components/schemas/synthetictest_config_vlans' wan_speedtest: $ref: '#/components/schemas/synthetictest_config_wan_speedtest' type: object site_setting_ap_synthetic_test: additionalProperties: false description: AP Synthetic Test configuration properties: additional_vlan_ids: $ref: '#/components/schemas/additional_vlan_ids' type: object sw_routing_policies: additionalProperties: $ref: '#/components/schemas/sw_routing_policy' description: Property key is the routing policy name type: object gateway_oob_ip_config_node1: additionalProperties: false description: For HA Cluster, node1 can have different IP Config properties: gateway: description: If `type`==`static` type: string ip: type: string netmask: description: Used only if `subnet` is not specified in `networks` type: string type: $ref: '#/components/schemas/ip_type' use_mgmt_vrf: default: false description: If supported on the platform. If enabled, DNS will be using this routing-instance, too type: boolean use_mgmt_vrf_for_host_out: default: false description: Whether to use `mgmt_junos` for host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired type: boolean vlan_id: $ref: '#/components/schemas/gateway_port_vlan_id_with_variable' type: object site_zone_occupancy_alert_email_notifiers: description: List of email addresses to send email notifications when the alert threshold is reached examples: - - foo@juniper.net - bar@juniper.net items: type: string type: array switch_radius_config_auth_server_selection: default: ordered description: 'enum: `ordered`, `unordered`' enum: - ordered - unordered type: string gw_routing_policy_term_matching_vpn_path_sla: additionalProperties: false properties: max_jitter: type: - integer - 'null' max_latency: examples: - 1500 type: - integer - 'null' max_loss: examples: - 30 type: - integer - 'null' type: object site_mxtunnel: additionalProperties: false description: Site MxTunnel properties: additional_mxtunnels: $ref: '#/components/schemas/site_mxtunnel_additional_mxtunnels' ap_subnets: $ref: '#/components/schemas/site_mxtunnel_ap_subnets' auto_preemption: $ref: '#/components/schemas/auto_preemption' clusters: $ref: '#/components/schemas/site_mxtunnel_clusters' created_time: $ref: '#/components/schemas/created_time' enabled: type: boolean for_site: readOnly: true type: boolean hello_interval: default: 60 description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by hello_retries examples: - 60 maximum: 300 minimum: 1 type: integer hello_retries: default: 7 examples: - 3 maximum: 30 minimum: 2 type: integer hosts: $ref: '#/components/schemas/site_mxtunnel_hosts' id: $ref: '#/components/schemas/id' modified_time: $ref: '#/components/schemas/modified_time' mtu: default: 0 description: 0 to enable MTU, 552-1500 to start MTU with a lower MTU examples: - 1100 maximum: 1500 minimum: 0 type: integer org_id: $ref: '#/components/schemas/org_id' protocol: $ref: '#/components/schemas/mxtunnel_protocol' radsec: $ref: '#/components/schemas/site_mxtunnel_radsec' site_id: $ref: '#/components/schemas/site_id' vlan_ids: $ref: '#/components/schemas/mxtunnel_vlan_ids' type: object gateway_path_preferences_path_target_ips: description: If `type`==`local`, if destination IP is to be replaced items: type: string type: array acl_tag_ether_types: default: - any description: ARP / IPv6. Default is `any` items: type: string type: array snmp_config_v2c_configs: items: $ref: '#/components/schemas/snmp_config_v2c_config' type: array snmpv3_config_notify: items: $ref: '#/components/schemas/snmpv3_config_notify_items' type: array vrf_config: additionalProperties: false properties: enabled: description: Whether to enable VRF (when supported on the device) type: boolean type: object switch_matching_rule: additionalProperties: type: string description: "Property key defines the type of matching, value is the string to match. e.g:\n * `match_name[0:3]`: switch name must match the first 3 letters of the property value\n * `match_name[2:6]`: switch name must match the property value from the 2nd to the 6th letter\n * `match_model[0-8]`: switch model must match the first 8 letters of the property value\n * `match_role`: switch role must match the property value" examples: - match_model: EX4300 match_name[0:3]: abc properties: additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' default_port_usage: default: default description: 'Port usage to assign to switch ports without any port usage assigned. Default: `default` to preserve default behavior' type: string ip_config: $ref: '#/components/schemas/switch_matching_rule_ip_config' name: description: 'Rule name. WARNING: the name `default` is reserved and can only be used for the last rule in the list' maxLength: 32 minLength: 1 type: string oob_ip_config: $ref: '#/components/schemas/switch_matching_rule_oob_ip_config' port_config: $ref: '#/components/schemas/wired_port_config' port_mirroring: $ref: '#/components/schemas/switch_port_mirroring' stp_config: $ref: '#/components/schemas/switch_stp_config' switch_mgmt: $ref: '#/components/schemas/switch_mgmt' type: object radius_keywrap_format: description: 'enum: `ascii`, `hex`' enum: - ascii - hex type: string vrrp_group_networks: additionalProperties: $ref: '#/components/schemas/vrrp_group_network' description: Property key is the network name examples: - data: ip: 10.182.96.1 mgmt: ip: 10.182.104.1 v10: ip: 10.182.104.129 wap: ip: 10.182.102.1 type: object setting_ssr: additionalProperties: false properties: auto_upgrade: $ref: '#/components/schemas/setting_ssr_auto_upgrade' conductor_hosts: $ref: '#/components/schemas/setting_ssr_conductor_hosts' conductor_token: description: Token to be used by the SSR Devices to connect to the Conductor type: string disable_stats: description: Disable stats collection on SSR devices type: boolean proxy: $ref: '#/components/schemas/ssr_proxy' type: object mxcluster_nac_client_vendor: description: 'convention to be followed is : "-", could be an os/platform/model/company. For ex: for cisco vendor, there could variants wrt os (such as ios, nxos etc), platforms (asa etc), or acquired companies (such as meraki, aironet) etc. enum: `aruba`, `cisco-aironet`, `cisco-dnac`, `cisco-ios`, `cisco-meraki`, `brocade`, `generic`, `juniper`, `paloalto`' enum: - aruba - cisco-aironet - cisco-dnac - cisco-ios - cisco-meraki - brocade - generic - juniper - paloalto examples: - cisco-ios type: string service_policy_skyatp_http_inspection: additionalProperties: false properties: enabled: type: boolean profile: $ref: '#/components/schemas/service_policy_skyatp_http_inspection_profile' type: object remote_syslog_console: additionalProperties: false properties: contents: $ref: '#/components/schemas/remote_syslog_contents' type: object mxcluster_radsec_nas_ip_source: default: any description: 'SSpecify NAS-IP-ADDRESS, NAS-IPv6-ADDRESS to use with auth_servers. enum: `any`, `oob`, `oob6`, `tunnel`, `tunnel6`' enum: - any - oob - oob6 - tunnel - tunnel6 type: string acl_tag_specs: description: If `type`==`resource`, `type`==`radius_group`, `type`==`port_usage` or `type`==`gbp_resource`. Empty means unrestricted, i.e. any items: $ref: '#/components/schemas/acl_tag_spec' type: array bgp_local_as: anyOf: - type: string - maximum: 4294967295 minimum: 1 type: integer description: Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. BGP AS, value in range 1-4294967295 examples: - 65000 wlan_mist_nac: additionalProperties: false properties: acct_interim_interval: default: 0 description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled. examples: - 60 maximum: 65535 minimum: 0 type: integer auth_servers_retries: default: 2 description: Radius auth session retries. Following fast timers are set if `fast_dot1x_timers` knob is enabled. "retries" are set to value of `auth_servers_timeout`. "max-requests" is also set when setting `auth_servers_retries` is set to default value to 3. examples: - 3 maximum: 10 minimum: 1 type: integer auth_servers_timeout: default: 5 description: Radius auth session timeout. Following fast timers are set if `fast_dot1x_timers` knob is enabled. "quite-period" and "transmit-period" are set to half the value of `auth_servers_timeout`. "supplicant-timeout" is also set when setting `auth_servers_timeout` is set to default value of 10. examples: - 5 maximum: 30 minimum: 1 type: integer coa_enabled: default: false description: Allows a RADIUS server to dynamically modify the authorization status of a user session. type: boolean coa_port: description: the communication port used for “Change of Authorization” (CoA) messages examples: - 3799 maximum: 65535 minimum: 1 type: integer enabled: default: false description: "When enabled:\n * `auth_servers` is ignored\n * `acct_servers` is ignored\n * `auth_servers_*` are ignored\n * `coa_servers` is ignored\n * `radsec` is ignored\n * `coa_enabled` is assumed" type: boolean fast_dot1x_timers: default: false description: If set to true, sets default fast-timers with values calculated from `auth_servers_timeout` and `auth_server_retries`. type: boolean network: description: Which network the mist nac server resides in examples: - default type: - string - 'null' source_ip: description: In case there is a static IP for this network, we can specify it using source ip examples: - 1.2.3.4 type: - string - 'null' type: object extra_route6: additionalProperties: false properties: discard: default: false description: This takes precedence type: boolean metric: examples: - null maximum: 2147483647 minimum: 0 type: - integer - 'null' next_qualified: additionalProperties: $ref: '#/components/schemas/extra_route6_next_qualified_properties' examples: - 2a02:1234:200a::100: metric: null preference: 40 type: object no_resolve: default: false type: boolean preference: examples: - 30 maximum: 2147483647 minimum: 0 type: - integer - 'null' via: $ref: '#/components/schemas/next_hop_via' type: object dhcpd_config: additionalProperties: $ref: '#/components/schemas/dhcpd_config_property' properties: enabled: default: true description: If set to `false`, disable the DHCP server type: boolean type: object bgp_config_networks: description: Optional if `via`==`lan`. List of networks where we expect BGP neighbor to connect to/from items: type: string type: array snmp_config_trap_group: additionalProperties: false properties: categories: $ref: '#/components/schemas/snmp_config_trap_group_categories' group_name: description: Categories list can refer to https://www.juniper.net/documentation/software/topics/task/configuration/snmp_trap-groups-configuring-junos-nm.html examples: - profiler type: string targets: $ref: '#/components/schemas/snmp_config_trap_group_targets' version: $ref: '#/components/schemas/snmp_config_trap_version' type: object bgp_config_neighbors: additionalProperties: false properties: disabled: default: false description: If true, the BGP session to this neighbor will be administratively disabled/shutdown type: boolean export_policy: type: string hold_time: default: 90 maximum: 65535 minimum: 0 type: integer import_policy: type: string multihop_ttl: description: Assuming BGP neighbor is directly connected maximum: 255 minimum: 0 type: integer neighbor_as: $ref: '#/components/schemas/bgp_as' tunnel_via: $ref: '#/components/schemas/tunnel_via' required: - neighbor_as type: object snmpv3_config_target_params: items: $ref: '#/components/schemas/snmpv3_config_target_param' type: array switch_bgp_config: additionalProperties: false properties: auth_key: type: string bfd_minimum_interval: description: Minimum interval in milliseconds for BFD hello packets. A neighbor is considered failed when the device stops receiving replies after the specified interval. Value must be between 1 and 255000. maximum: 255000 minimum: 1 type: integer export_policy: description: Export policy must match one of the policy names defined in the `routing_policies` property. type: string hold_time: $ref: '#/components/schemas/switch_bgp_config_hold_time' import_policy: description: Import policy must match one of the policy names defined in the `routing_policies` property. type: string local_as: $ref: '#/components/schemas/bgp_as' neighbors: $ref: '#/components/schemas/switch_bgp_config_neighbors' networks: $ref: '#/components/schemas/switch_bgp_config_networks' type: $ref: '#/components/schemas/switch_bgp_config_type' required: - type - local_as type: object hours: additionalProperties: false description: Days/Hours of operation filter, the available days (mon, tue, wed, thu, fri, sat, sun) properties: fri: $ref: '#/components/schemas/hour' mon: $ref: '#/components/schemas/hour' sat: $ref: '#/components/schemas/hour' sun: $ref: '#/components/schemas/hour' thu: $ref: '#/components/schemas/hour' tue: $ref: '#/components/schemas/hour' wed: $ref: '#/components/schemas/hour' type: object mxedge_mgmt_oob_ip_type6: default: autoconf description: 'enum: `autoconf`, `dhcp`, `disabled`, `static`' enum: - autoconf - dhcp - disabled - static type: string network_tenants: additionalProperties: $ref: '#/components/schemas/network_tenant' description: Property key must be the user/tenant name (i.e. "printer-1") or a Variable (i.e. "{{myvar}}") type: object tunnel_config_enc_algo: default: aes256 description: 'enum: `3des`, `aes128`, `aes256`, `aes_gcm128`, `aes_gcm256`' enum: - 3des - aes128 - aes256 - aes_gcm128 - aes_gcm256 type: - string - 'null' gw_routing_policy_term_matching_protocol_enum: description: 'enum: `aggregate`, `bgp`, `direct`, `ospf`, `static` (SRX Only)' enum: - aggregate - bgp - direct - ospf - static type: string mxcluster_radsec_proxy_hosts: description: Hostnames or IPs for Mist AP to use as the TLS Server (i.e. they are reachable from AP) in addition to `tunterm_hosts` items: type: string type: array mxedge_das: additionalProperties: false description: Configure cloud-assisted dynamic authorization service on this cluster of mist edges properties: coa_servers: $ref: '#/components/schemas/mxedge_das_coa_servers' enabled: default: false type: boolean type: object gateway_extra_routes: additionalProperties: $ref: '#/components/schemas/gateway_extra_route' description: Property key is the destination CIDR (e.g. "10.0.0.0/8"), the destination Network name or a variable (e.g. "{{myvar}}") type: object site_engagement: additionalProperties: false description: '**Note**: if hours does not exist, it''s treated as everyday of the week, 00:00-23:59. Currently, we don''t allow multiple ranges for the same day' properties: dwell_tag_names: $ref: '#/components/schemas/site_engagement_dwell_tag_names' dwell_tags: $ref: '#/components/schemas/site_engagement_dwell_tags' hours: $ref: '#/components/schemas/hours' max_dwell: default: 43200 description: Max time, default is 43200(12h), max is 68400 (18h) examples: - 43200 maximum: 68400 minimum: 1 type: integer min_dwell: description: min time minimum: 0 type: integer type: object tunnel_config_provider: description: 'Only if `auto_provision.enabled`==`false`. enum: `custom-ipsec`, `custom-gre`, `jse-ipsec`, `prisma-ipsec`, `zscaler-gre`, `zscaler-ipsec`' enum: - custom-ipsec - custom-gre - jse-ipsec - prisma-ipsec - zscaler-gre - zscaler-ipsec type: string service_policy_appqoe: additionalProperties: false description: SRX only properties: enabled: default: false type: boolean type: object synthetictest_config_vlan: additionalProperties: false properties: custom_test_urls: $ref: '#/components/schemas/synthetictest_config_vlan_custom_test_urls' disabled: default: false description: For some vlans where we don't want this to run type: boolean probes: $ref: '#/components/schemas/synthetictest_config_probes' vlan_ids: $ref: '#/components/schemas/synthetictest_config_vlan_vlan_ids' type: object account_oauth_info_account_region: additionalProperties: false properties: aggregate_region: description: Bandwidth Aggregate region for this region examples: - us-southwest type: string allocated_bandwidth: description: Allocated bandwidth for the region, in Mbps examples: - 1000 readOnly: true type: integer name: description: Display name for this region examples: - US West type: string type: object id: description: Unique ID of the object instance in the Mist Organization examples: - 53f10664-3ce8-4c27-b382-0ef66432349f format: uuid readOnly: true type: string radsec_mxcluster_ids: description: To use Org mxedges when this WLAN does not use mxtunnel, specify their mxcluster_ids. Org mxedge(s) identified by mxcluster_ids items: examples: - 572586b7-f97b-a22b-526c-8b97a3f609c4 format: uuid type: string type: array tacacs: additionalProperties: false properties: acct_servers: $ref: '#/components/schemas/tacacs_acct_servers' default_role: $ref: '#/components/schemas/tacacs_default_role' enabled: type: boolean network: description: Which network the TACACS server resides type: string tacplus_servers: $ref: '#/components/schemas/tacacs_auth_servers' type: object snmpv3_config_notify_filter_item_contents: items: $ref: '#/components/schemas/snmpv3_config_notify_filter_item_content' type: array bgp_config: additionalProperties: false description: BFD is enabled when either bfd_minimum_interval or bfd_multiplier is configured properties: auth_key: description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan` type: string bfd_minimum_interval: default: 350 description: "Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`, when bfd_multiplier is configured alone. Default:\n * 1000 if `type`==`external`\n * 350 `type`==`internal`" maximum: 255000 minimum: 1 type: - integer - 'null' bfd_multiplier: default: 3 description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`, when bfd_minimum_interval_is_configured alone maximum: 255 minimum: 1 type: - integer - 'null' disable_bfd: default: false description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. BFD provides faster path failure detection and is enabled by default type: boolean export: type: string export_policy: description: Default export policies if no per-neighbor policies defined type: string extended_v4_nexthop: description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. By default, either inet/net6 unicast depending on neighbor IP family (v4 or v6). For v6 neighbors, to exchange v4 nexthop, which allows dual-stack support, enable this type: boolean graceful_restart_time: default: 0 description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. `0` means disable maximum: 4095 minimum: 0 type: integer hold_time: default: 90 description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. Default is 90. maximum: 65535 minimum: 0 type: integer import: type: string import_policy: description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. Default import policies if no per-neighbor policies defined type: string local_as: $ref: '#/components/schemas/bgp_local_as' neighbor_as: $ref: '#/components/schemas/bgp_as' neighbors: additionalProperties: $ref: '#/components/schemas/bgp_config_neighbors' description: Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. If per-neighbor as is desired. Property key is the neighbor address type: object networks: $ref: '#/components/schemas/bgp_config_networks' no_private_as: default: false description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. If true, we will not advertise private ASNs (AS 64512-65534) to this neighbor type: boolean no_readvertise_to_overlay: default: false description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. By default, we'll re-advertise all learned BGP routers toward overlay type: boolean tunnel_name: description: Optional if `via`==`tunnel` type: string type: $ref: '#/components/schemas/bgp_config_type' via: $ref: '#/components/schemas/bgp_config_via' vpn_name: description: Optional if `via`==`vpn` type: string wan_name: description: Optional if `via`==`wan` type: string required: - via type: object marvis: additionalProperties: false properties: auto_operations: $ref: '#/components/schemas/marvis_auto_operations' type: object switch_bgp_config_hold_time_integer: maximum: 65535 minimum: 3 type: integer network_multicast_group: additionalProperties: false properties: rp_ip: description: RP (rendezvous point) IP Address type: string type: object site_auto_upgrade_version: default: stable description: 'desired version. enum: `beta`, `custom`, `stable`' enum: - beta - custom - stable examples: - beta type: string synthetictest_config_vlan_custom_test_urls: deprecated: true examples: - - https://www.abc.com/ - https://10.3.5.1:8080/about items: type: string type: array service_policy_ewf_rule: additionalProperties: false properties: alert_only: type: boolean block_message: examples: - Access to this URL Category has been blocked type: string enabled: default: false type: boolean profile: $ref: '#/components/schemas/service_policy_ewf_rule_profile' type: object evpn_options_routed_at: default: edge description: 'optional, where virtual-gateway should reside. enum: `core`, `distribution`, `edge`' enum: - core - distribution - edge type: string switch_port_usage_mode: description: '`mode`==`dynamic` must only be used if the port usage name is `dynamic`. enum: `access`, `dynamic`, `inet`, `trunk`' enum: - access - dynamic - inet - trunk type: string gateway_path_preferences: additionalProperties: false properties: paths: $ref: '#/components/schemas/gateway_path_preferences_paths' strategy: $ref: '#/components/schemas/gateway_path_strategy' type: object radsec_server: additionalProperties: false properties: host: examples: - 1.1.1.1 type: string port: examples: - 1812 maximum: 65535 minimum: 1 type: integer type: object vrf_extra_route6: additionalProperties: false properties: via: description: Next-hop address format: ipv6 type: string type: object switch_port_usage_duplex: default: auto description: 'Only if `mode`!=`dynamic`. Link connection mode. enum: `auto`, `full`, `half`' enum: - auto - full - half type: string idp_profile_matching_severity_value: description: 'enum: `critical`, `info`, `major`, `minor`' enum: - critical - info - major - minor examples: - major type: string proxy: additionalProperties: false description: Proxy Configuration to talk to Mist properties: disabled: default: false examples: - true type: boolean url: examples: - https://proxy.corp.com:8080/ type: string type: object site_setting_ntp_servers: description: List of NTP servers items: type: string type: array ntp_servers: description: List of NTP servers specific to this device. By default, those in Site Settings will be used items: type: string type: array site_mxtunnel_additional_mxtunnel_vlan_ids: examples: - - 300 - 310 - 320 items: type: integer type: array switch_bgp_config_neighbors: additionalProperties: $ref: '#/components/schemas/switch_bgp_config_neighbor' description: Property key is the BGP Neighbor IP Address. type: object response_http404: additionalProperties: false properties: id: type: string type: object snmp_config_trap_groups: items: $ref: '#/components/schemas/snmp_config_trap_group' type: array marvis_auto_operations: additionalProperties: false properties: ap_insufficient_capacity: default: false type: boolean ap_loop: default: false type: boolean ap_non_compliant: default: false type: boolean bounce_port_for_abnormal_poe_client: default: false type: boolean disable_port_when_ddos_protocol_violation: default: false type: boolean disable_port_when_rogue_dhcp_server_detected: default: false type: boolean gateway_non_compliant: default: false type: boolean switch_misconfigured_port: default: false type: boolean switch_port_stuck: default: false type: boolean type: object dhcpd_config_vendor_option_type: description: 'enum: `boolean`, `hex`, `int16`, `int32`, `ip`, `string`, `uint16`, `uint32`' enum: - boolean - hex - int16 - int32 - ip - string - uint16 - uint32 type: string ospf_areas_network: additionalProperties: false description: Property key is the network name. Networks to participate in an OSPF area properties: auth_keys: additionalProperties: type: string description: Required if `auth_type`==`md5`. Property key is the key number examples: - '1': auth-key-1 type: object auth_password: description: Required if `auth_type`==`password`, the password, max length is 8 examples: - simple type: string auth_type: $ref: '#/components/schemas/ospf_area_network_auth_type' bfd_minimum_interval: examples: - 500 maximum: 255000 minimum: 1 type: integer dead_interval: examples: - 40 maximum: 65535 minimum: 1 type: integer export_policy: examples: - export_policy type: string hello_interval: maximum: 255 minimum: 1 type: integer import_policy: examples: - import_policy type: string interface_type: $ref: '#/components/schemas/ospf_area_network_interface_type' metric: examples: - 10000 maximum: 65535 minimum: 1 type: - integer - 'null' no_readvertise_to_overlay: default: false description: By default, we'll re-advertise all learned OSPF routes toward overlay type: boolean passive: default: false description: Whether to send OSPF-Hello type: boolean type: object dhcpd_config_vendor_option: additionalProperties: false properties: type: $ref: '#/components/schemas/dhcpd_config_vendor_option_type' value: type: string type: object mxtunnel_protocol: default: udp description: 'enum: `ip`, `udp`' enum: - ip - udp type: string synthetictest_config_lan_network: additionalProperties: false description: configure minis probes to be tested on lan networks of gateways properties: networks: $ref: '#/components/schemas/synthetictest_config_lan_networks_networks' probes: $ref: '#/components/schemas/synthetictest_config_probes' type: object site_setting: description: Site Settings properties: acl_policies: $ref: '#/components/schemas/acl_policies' acl_tags: $ref: '#/components/schemas/acl_tags' additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' allow_mist: default: false description: whether to allow Mist to look at this org type: boolean analytic: $ref: '#/components/schemas/site_setting_analytic' ap_matching: $ref: '#/components/schemas/site_setting_ap_matching' ap_port_config: $ref: '#/components/schemas/site_setting_ap_port_config' ap_synthetic_test: $ref: '#/components/schemas/site_setting_ap_synthetic_test' ap_updown_threshold: default: 0 description: Enable threshold-based device down delivery for AP devices only. When configured it takes effect for AP devices and `device_updown_threshold` is ignored. examples: - null maximum: 240 minimum: 0 type: - integer - 'null' auto_placement: $ref: '#/components/schemas/site_setting_auto_placement' auto_upgrade: $ref: '#/components/schemas/site_setting_auto_upgrade' auto_upgrade_esl: $ref: '#/components/schemas/site_setting_auto_upgrade_esl' auto_upgrade_linecard: default: true type: boolean bgp_neighbor_updown_threshold: description: enable threshold-based bgp neighbor down delivery. examples: - null minimum: 0 type: - integer - 'null' blacklist_url: examples: - https://papi.s3.amazonaws.com/blacklist/xxx... readOnly: true type: string ble_config: $ref: '#/components/schemas/ble_config' config_auto_revert: default: false description: Whether to enable ap auto config revert type: boolean config_push_policy: $ref: '#/components/schemas/site_setting_config_push_policy' created_time: $ref: '#/components/schemas/created_time' critical_url_monitoring: $ref: '#/components/schemas/site_setting_critical_url_monitoring' device_updown_threshold: default: 0 description: By default, device_updown_threshold, if set, will apply to all devices types if different values for specific device type is desired, use the following examples: - null maximum: 240 minimum: 0 type: - integer - 'null' dhcp_snooping: $ref: '#/components/schemas/dhcp_snooping' disabled_system_defined_port_usages: $ref: '#/components/schemas/site_setting_disabled_system_defined_port_usages' dns_servers: $ref: '#/components/schemas/dns_servers' dns_suffix: $ref: '#/components/schemas/dns_suffix' enable_unii_4: default: false type: boolean engagement: $ref: '#/components/schemas/site_engagement' evpn_options: $ref: '#/components/schemas/evpn_options' extra_routes: $ref: '#/components/schemas/extra_routes' extra_routes6: $ref: '#/components/schemas/extra_routes6' flags: $ref: '#/components/schemas/site_setting_flags' for_site: readOnly: true type: boolean gateway: $ref: '#/components/schemas/gateway_template' gateway_additional_config_cmds: $ref: '#/components/schemas/additional_config_cmds' gateway_mgmt: $ref: '#/components/schemas/gateway_mgmt' gateway_tunnel_updown_threshold: description: enable threshold-based gateway tunnel (secure edge tunnels) up-down delivery. examples: - null minimum: 0 type: - integer - 'null' gateway_updown_threshold: default: 0 description: Enable threshold-based device down delivery for Gateway devices only. When configured it takes effect for GW devices and `device_updown_threshold` is ignored. examples: - null maximum: 240 minimum: 0 type: - integer - 'null' id: $ref: '#/components/schemas/id' iotproxy: $ref: '#/components/schemas/iotproxy' juniper_srx: $ref: '#/components/schemas/site_setting_juniper_srx' led: $ref: '#/components/schemas/ap_led' marvis: $ref: '#/components/schemas/marvis' mist_nac: $ref: '#/components/schemas/switch_mist_nac' modified_time: $ref: '#/components/schemas/modified_time' mxedge: $ref: '#/components/schemas/site_setting_mxedge' mxedge_mgmt: $ref: '#/components/schemas/mxedge_mgmt' mxtunnels: $ref: '#/components/schemas/site_mxtunnel' networks: $ref: '#/components/schemas/switch_networks' ntp_servers: $ref: '#/components/schemas/site_setting_ntp_servers' occupancy: $ref: '#/components/schemas/site_occupancy_analytics' org_id: $ref: '#/components/schemas/org_id' ospf_areas: $ref: '#/components/schemas/ospf_areas' paloalto_networks: $ref: '#/components/schemas/site_setting_paloalto_networks' persist_config_on_device: default: false description: Whether to store the config on AP type: boolean port_mirroring: $ref: '#/components/schemas/switch_port_mirroring' port_usages: $ref: '#/components/schemas/switch_port_usages' proxy: $ref: '#/components/schemas/proxy' radio_config: $ref: '#/components/schemas/ap_radio' radius_config: $ref: '#/components/schemas/switch_radius_config' remote_syslog: $ref: '#/components/schemas/remote_syslog' remove_existing_configs: default: false description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed. type: boolean report_gatt: default: false description: Whether AP should periodically connect to BLE devices and report GATT device info (device name, manufacturer name, serial number, battery %, temperature, humidity) type: boolean rogue: $ref: '#/components/schemas/site_rogue' routing_policies: $ref: '#/components/schemas/sw_routing_policies' rtsa: $ref: '#/components/schemas/site_setting_rtsa' simple_alert: $ref: '#/components/schemas/simple_alert' site_id: $ref: '#/components/schemas/site_id' skyatp: $ref: '#/components/schemas/site_setting_skyatp' sle_thresholds: $ref: '#/components/schemas/sle_thresholds' snmp_config: $ref: '#/components/schemas/snmp_config' srx_app: $ref: '#/components/schemas/site_setting_srx_app' ssh_keys: $ref: '#/components/schemas/site_setting_ssh_keys' ssr: $ref: '#/components/schemas/setting_ssr' status_portal: $ref: '#/components/schemas/site_setting_status_portal' switch: $ref: '#/components/schemas/site_setting_switch' switch_matching: $ref: '#/components/schemas/switch_matching' switch_mgmt: $ref: '#/components/schemas/switch_mgmt' switch_updown_threshold: default: 0 description: Enable threshold-based device down delivery for Switch devices only. When configured it takes effect for SW devices and `device_updown_threshold` is ignored. examples: - null maximum: 240 minimum: 0 type: - integer - 'null' synthetic_test: $ref: '#/components/schemas/synthetictest_config' track_anonymous_devices: default: false description: Whether to track anonymous BLE assets (requires ‘track_asset’ enabled) type: boolean tunterm_monitoring: $ref: '#/components/schemas/tunterm_monitoring' tunterm_monitoring_disabled: default: false type: boolean tunterm_multicast_config: $ref: '#/components/schemas/site_setting_tunterm_multicast_config' uplink_port_config: $ref: '#/components/schemas/ap_uplink_port_config' uses_description_from_port_usage: default: false description: by default, we only honor description provided in port_config. This allows fallback to those defined in port_usages type: boolean vars: $ref: '#/components/schemas/vars' vars_annotations: $ref: '#/components/schemas/vars_annotations' vna: $ref: '#/components/schemas/site_setting_vna' vpn_path_updown_threshold: description: enable threshold-based vpn path down delivery. examples: - null minimum: 0 type: - integer - 'null' vpn_peer_updown_threshold: description: enable threshold-based vpn peer down delivery. examples: - null minimum: 0 type: - integer - 'null' vrf_config: $ref: '#/components/schemas/vrf_config' vrf_instances: $ref: '#/components/schemas/switch_vrf_instances' vrrp_groups: $ref: '#/components/schemas/site_setting_vrrp_groups' vs_instance: $ref: '#/components/schemas/vs_instance' wan_vna: $ref: '#/components/schemas/site_setting_wan_vna' watched_station_url: examples: - https://papi.s3.amazonaws.com/watched_station/xxx... readOnly: true type: string whitelist_url: examples: - https://papi.s3.amazonaws.com/whitelist/xxx... readOnly: true type: string wids: $ref: '#/components/schemas/site_wids' wifi: $ref: '#/components/schemas/site_wifi' wired_vna: $ref: '#/components/schemas/site_setting_wired_vna' zone_occupancy_alert: $ref: '#/components/schemas/site_zone_occupancy_alert' type: object site_mxtunnel_radsec: additionalProperties: false properties: acct_servers: $ref: '#/components/schemas/site_mxtunnel_radsec_acct_servers' auth_servers: $ref: '#/components/schemas/site_mxtunnel_radsec_auth_servers' enabled: default: false type: boolean use_mxedge: type: boolean type: object poe_priority: description: 'PoE priority. enum: `low`, `high`' enum: - low - high type: string vrrp_group: additionalProperties: false description: Junos VRRP group properties: auth_key: description: If `auth_type`==`md5` examples: - auth-key-1 type: string auth_password: description: If `auth_type`==`simple` format: password type: string auth_type: $ref: '#/components/schemas/vrrp_group_auth_type' networks: $ref: '#/components/schemas/vrrp_group_networks' type: object gateway_wan_type6: default: autoconf description: 'enum: `autoconf`, `dhcp`, `static`' enum: - autoconf - dhcp - static type: string extra_route6_next_qualified_properties: additionalProperties: false properties: metric: type: - integer - 'null' preference: type: - integer - 'null' type: object sw_routing_policy: additionalProperties: false properties: terms: $ref: '#/components/schemas/sw_routing_policy_terms' type: object network: description: Networks are usually subnets that have cross-site significance. `networks`in Org Settings will got merged into `networks`in Site Setting. For gateways, they can be used to define Service Routes. properties: created_time: $ref: '#/components/schemas/created_time' disallow_mist_services: default: false description: Whether to disallow Mist Devices in the network type: boolean gateway: examples: - 192.168.70.1 format: ipv4 type: string gateway6: examples: - fdad:b0bc:f29e::1 format: ipv6 type: string id: $ref: '#/components/schemas/id' internal_access: $ref: '#/components/schemas/network_internal_access' internet_access: $ref: '#/components/schemas/network_internet_access' isolation: description: Whether to allow clients in the network to talk to each other type: boolean modified_time: $ref: '#/components/schemas/modified_time' multicast: $ref: '#/components/schemas/network_multicast' name: type: string org_id: $ref: '#/components/schemas/org_id' routed_for_networks: $ref: '#/components/schemas/network_routed_for_networks' subnet: examples: - 192.168.70.0/24 type: string subnet6: examples: - fdad:b0bc:f29e::/32 type: string tenants: $ref: '#/components/schemas/network_tenants' vlan_id: $ref: '#/components/schemas/vlan_id_with_variable' vpn_access: $ref: '#/components/schemas/network_vpn_access' required: - name type: object oauth_account_errors: examples: - - OAuth token refresh failed, please re-link your account - API daily rate limit reached for your account items: type: string readOnly: true type: array bgp_config_type: description: 'Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. enum: `external`, `internal`' enum: - external - internal minLength: 1 type: string synthetictest_config_custom_probe_type: default: icmp description: 'enum: `application`, `curl`, `icmp`, `reachability`, `tcp`' enum: - application - curl - icmp - reachability - tcp type: string push_policy_push_window: additionalProperties: false description: If enabled, new config will only be pushed to device within the specified time window properties: enabled: default: false type: boolean hours: $ref: '#/components/schemas/hours' type: object tunnel_config_dh_group: default: '14' description: "Only if `provider`==`custom-ipsec`. enum:\n * 1\n * 2 (1024-bit)\n * 5\n * 14 (default, 2048-bit)\n * 15 (3072-bit)\n * 16 (4096-bit)\n * 19 (256-bit ECP)\n * 20 (384-bit ECP)\n * 21 (521-bit ECP)\n * 24 (2048-bit ECP)" enum: - '1' - '14' - '15' - '16' - '19' - '2' - '20' - '21' - '24' - '5' type: string routing_policy_term_action_community: description: When used as export policy, optional items: examples: - '3900190' type: string type: array gateway_port_config_wan_networks: description: Only if `usage`==`wan`. If some networks are connected to this WAN port, it can be added here so policies can be defined items: type: string type: array service_policy_skyatp_dns_dga_detection: additionalProperties: false properties: enabled: type: boolean profile: $ref: '#/components/schemas/service_policy_skyatp_dns_dga_detection_profile' type: object responses: SiteSettings: content: application/json: examples: Example: $ref: '#/components/examples/SiteSettingsExample' schema: $ref: '#/components/schemas/site_setting' application/vnd.api+json: examples: Example: $ref: '#/components/examples/SiteSettingsExample' schema: $ref: '#/components/schemas/site_setting' description: OK OK: description: OK HTTP404: content: application/json: schema: $ref: '#/components/schemas/response_http404' application/vnd.api+json: schema: $ref: '#/components/schemas/response_http404' description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist SiteSettingsDerived: content: application/json: examples: Example: $ref: '#/components/examples/SiteSettingsDerivedExample' schema: $ref: '#/components/schemas/site_setting_derived' application/vnd.api+json: examples: Example: $ref: '#/components/examples/SiteSettingsDerivedExample' schema: $ref: '#/components/schemas/site_setting_derived' description: OK HTTP403: content: application/json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP403Example' schema: $ref: '#/components/schemas/response_http403' description: Permission Denied HTTP401: content: application/json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP401Example' schema: $ref: '#/components/schemas/response_http401' description: Unauthorized MacsArray: content: application/json: examples: Example: $ref: '#/components/examples/MacsArrayExample' schema: $ref: '#/components/schemas/mac_addresses' application/vnd.api+json: examples: Example: $ref: '#/components/examples/MacsArrayExample' schema: $ref: '#/components/schemas/mac_addresses' description: OK HTTP429: content: application/json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP429Example' schema: $ref: '#/components/schemas/response_http429' description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold HTTP400: content: application/json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' application/vnd.api+json: examples: Example: $ref: '#/components/examples/HTTP400Example' schema: $ref: '#/components/schemas/response_http400' description: Bad Syntax examples: HTTP400Example: value: detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)' HTTP401Example: value: detail: Authentication credentials were not provided. SiteSettingsExample: value: additional_config_cmds: - set snmp community public analytic: enabled: false ap_matching: enabled: true rules: - match_model: string name: string port_config: eth1,eth2: disabled: true dynamic_vlan: default_vlan_id: 999 enabled: true port_vlan_id: 1 vlan_id: 9 vlan_ids: 1, 10, 50 ap_port_config: model_specific: AP32: eth1,eth2: port_vlan_id: 1 vlan_ids: 1, 10, 50 auto_placement: orientation: 45 x: 30 y: 60 auto_upgrade: custom_versions: AP21: stable AP41: 0.1.5135 AP61: 0.1.7215 day_of_week: sun enabled: false time_of_day: '12:00' version: beta blacklist_url: https://papi.s3.amazonaws.com/blacklist/xxx... ble_config: beacon_enabled: false beacon_rate: 3 beacon_rate_mode: custom beam_disabled: - 1 - 3 - 6 custom_ble_packet_enabled: false custom_ble_packet_frame: 0x........ custom_ble_packet_freq_msec: 300 eddystone_uid_adv_power: -65 eddystone_uid_beams: 2-4,7 eddystone_uid_enabled: false eddystone_uid_freq_msec: 200 eddystone_uid_instance: 5c5b35000001 eddystone_uid_namespace: 2818e3868dec25629ede eddystone_url_adv_power: -65 eddystone_url_beams: 2-4,7 eddystone_url_enabled: true eddystone_url_freq_msec: 1000 eddystone_url_url: https://www.abc.com ibeacon_adv_power: -65 ibeacon_beams: 2-4,7 ibeacon_enabled: false ibeacon_freq_msec: 0 ibeacon_major: 13 ibeacon_minor: 138 ibeacon_uuid: f3f17139-704a-f03a-2786-0400279e37c3 power: 6 power_mode: custom config_auto_revert: false created_time: 0 device_updown_threshold: 0 dns_servers: - string dns_suffix: - string engagement: dwell_tag_names: bounce: Bounce engaged: Engaged passerby: Passer By stationed: Stationed dwell_tags: bounce: null engaged: 300-14400 passerby: null stationed: 14400-43200 hours: fri: 09:00-17:00 mon: 09:00-17:00 sat: 09:00-12:00 sun: 09:00-12:00 thu: 09:00-17:00 tue: 09:00-17:00 wed: 09:00-17:00 max_dwell: 43200 min_dwell: 0 evpn_options: auto_loopback_subnet: 100.101.0.0/16 auto_router_id_subnet: 100.100.0.0/24 core_as_border: false overlay: as: 65000 per_vlan_vga_v4_mac: false routed_at: edge underlay: as_base: 65001 routed_id_prefix: /24 subnet: 10.255.240.0/20 flags: property1: string property2: string for_site: true gateway_additional_config_cmds: - set snmp community public gateway_mgmt: admin_sshkeys: - string app_probing: apps: - string custom_apps: - app_type: string hostnames: - string name: string protocol: http enabled: true app_usage: true auto_signature_update: day_of_week: mon enable: true time_of_day: string config_revert_timer: 10 probe_hosts: - string root_password: string security_log_source_address: 192.168.1.1 security_log_source_interface: string id: 497f6eca-6276-4993-bfeb-53cbbbba6f09 led: brightness: 255 enabled: true modified_time: 0 mxedge: mist_das: coa_servers: - disable_event_timestamp_check: false enabled: true host: string port: 3799 secret: string enabled: false radsec: acct_servers: - host: string port: 1813 secret: string ssids: - string auth_servers: - host: string keywrap_enabled: true keywrap_format: hex keywrap_kek: string keywrap_mack: string port: 1812 secret: string ssids: - string enabled: true match_ssid: true proxy_hosts: - string server_selection: ordered mxedge_mgmt: mist_password: MIST_PASSWORD root_password: ROOT_PASSWORD ntp_servers: - pool.ntp.org occupancy: assets_enabled: false clients_enabled: true min_duration: 3000 sdkclients_enabled: false unconnected_clients_enabled: false org_id: a40f5d1f-d889-42e9-94ea-b9b33585fc6b ospf_areas: property1: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default property2: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default persist_config_on_device: false port_mirroring: property1: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_network: analyze output_port_id: ge-0/0/5 property2: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_network: analyze output_port_id: ge-0/0/5 port_usages: dynamic: mode: dynamic reset_default_when: link_down rules: - equals: string equals_any: - string expression: string src: lldp_chassis_id usage: string property1: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_auth: dot1x port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string property2: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string proxy: url: http://proxy.internal:8080/ radius_config: acct_interim_interval: 0 acct_servers: - host: 1.2.3.4 keywrap_enabled: true keywrap_format: hex keywrap_kek: '1122334455' keywrap_mack: '1122334455' port: 1813 secret: testing123 auth_servers: - host: 1.2.3.4 keywrap_enabled: true keywrap_format: hex keywrap_kek: '1122334455' keywrap_mack: '1122334455' port: 1812 secret: testing123 auth_servers_retries: 3 auth_servers_timeout: 5 coa_enabled: false coa_port: 3799 network: string source_ip: string remote_syslog: archive: files: 20 size: 5m console: contents: - facility: config severity: warning enabled: false files: - archive: files: 10 size: 5m contents: - facility: config severity: warning explicit_priority: true file: file-name match: '!alarm|ntp|errors.crc_error[chan]' structured_data: true network: default send_to_all_servers: false servers: - facility: config host: syslogd.internal port: 514 protocol: udp severity: info tag: '' time_format: millisecond users: - contents: - facility: config severity: warning match: '"!alarm|ntp|errors.crc_error[chan]"' user: '*' report_gatt: false rogue: enabled: false honeypot_enabled: false min_duration: 10 min_rssi: -80 whitelisted_bssids: - NeighborSSID whitelisted_ssids: - cc:8e:6f:d4:bf:16 - cc-8e-6f-d4-bf-16 - cc-73-* - cc:82:* rtsa: app_waking: false disable_dead_reckoning: true disable_pressure_sensor: false enabled: true track_asset: false simple_alert: arp_failure: client_count: 10 duration: 20 incident_count: 10 dhcp_failure: client_count: 10 duration: 10 incident_count: 20 dns_failure: client_count: 20 duration: 10 incident_count: 30 site_id: 72771e6a-6f5e-4de4-a5b9-1266c4197811 skyatp: enabled: true send_ip_mac_mapping: true srx_app: enabled: false ssh_keys: - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host ssr: conductor_hosts: - '"1.1.1.1", "2.2.2.2"' disable_stats: true status_portal: enabled: false hostnames: - my.misty.com switch_mgmt: ap_affinity_threshold: 10 config_revert_timer: 10 dhcp_option_fqdn: false mxedge_proxy_host: string mxedge_proxy_port: 2222 root_password: string tacacs: acct_servers: - host: 198.51.100.1 port: '49' secret: string timeout: 10 enabled: true network: string tacplus_servers: - host: 198.51.100.1 port: '49' secret: string timeout: 10 use_mxedge_proxy: true vars: RADIUS_IP1: 172.31.2.5 RADIUS_SECRET: 11s64632d vna: enabled: false vrf_instances: guest: extra_routes: 0.0.0.0/0: via: 192.168.31.1 networks: - guest vrrp_groups: property1: auth_key: auth-key-1 auth_password: string auth_type: md5 networks: data: ip: 10.182.96.1 mgmt: ip: 10.182.104.1 v10: ip: 10.182.104.129 wap: ip: 10.182.102.1 property2: auth_key: auth-key-1 auth_password: string auth_type: md5 networks: data: ip: 10.182.96.1 mgmt: ip: 10.182.104.1 v10: ip: 10.182.104.129 wap: ip: 10.182.102.1 wan_vna: enabled: false watched_station_url: https://papi.s3.amazonaws.com/watched_station/xxx... whitelist_url: https://papi.s3.amazonaws.com/whitelist/xxx... wids: repeated_auth_failures: duration: 60 threshold: 0 wifi: cisco_enabled: true disable_11k: false disable_radios_when_power_constrained: false enable_arp_spoof_check: false enable_shared_radio_scanning: true enabled: true locate_connected: true locate_unconnected: false mesh_allow_dfs: false mesh_enable_crm: false mesh_enabled: false mesh_psk: string mesh_ssid: string proxy_arp: default wired_vna: enabled: false zone_occupancy_alert: email_notifiers: - foo@juniper.net - bar@juniper.net enabled: false threshold: 5 HTTP403Example: value: detail: You do not have permission to perform this action. MacsArrayExample: value: macs: - 18-65-90-de-f4-c6 - 84-89-ad-5d-69-0d HTTP429Example: value: detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold SiteSettingsDerivedExample: value: additional_config_cmds: - set snmp community public analytic: enabled: false ap_matching: enabled: true rules: - match_model: string name: string port_config: eth1,eth2: disabled: true dynamic_vlan: default_vlan_id: 999 enabled: true port_vlan_id: 1 vlan_id: 9 vlan_ids: 1, 10, 50 ap_port_config: model_specific: AP32: eth1,eth2: port_vlan_id: 1 vlan_ids: 1, 10, 50 auto_placement: orientation: 45 x: 30 y: 60 auto_upgrade: custom_versions: AP21: stable AP41: 0.1.5135 AP61: 0.1.7215 day_of_week: sun enabled: false time_of_day: '12:00' version: beta blacklist_url: https://papi.s3.amazonaws.com/blacklist/xxx... ble_config: beacon_enabled: false beacon_rate: 3 beacon_rate_mode: custom beam_disabled: - 1 - 3 - 6 custom_ble_packet_enabled: false custom_ble_packet_frame: 0x........ custom_ble_packet_freq_msec: 300 eddystone_uid_adv_power: -65 eddystone_uid_beams: 2-4,7 eddystone_uid_enabled: false eddystone_uid_freq_msec: 200 eddystone_uid_instance: 5c5b35000001 eddystone_uid_namespace: 2818e3868dec25629ede eddystone_url_adv_power: -65 eddystone_url_beams: 2-4,7 eddystone_url_enabled: true eddystone_url_freq_msec: 1000 eddystone_url_url: https://www.abc.com ibeacon_adv_power: -65 ibeacon_beams: 2-4,7 ibeacon_enabled: false ibeacon_freq_msec: 0 ibeacon_major: 13 ibeacon_minor: 138 ibeacon_uuid: f3f17139-704a-f03a-2786-0400279e37c3 power: 6 power_mode: custom config_auto_revert: false created_time: 0 device_updown_threshold: 0 dns_servers: - string dns_suffix: - string engagement: dwell_tag_names: bounce: Bounce engaged: Engaged passerby: Passer By stationed: Stationed dwell_tags: bounce: null engaged: 300-14400 passerby: null stationed: 14400-43200 hours: fri: 09:00-17:00 mon: 09:00-17:00 sat: 09:00-12:00 sun: 09:00-12:00 thu: 09:00-17:00 tue: 09:00-17:00 wed: 09:00-17:00 max_dwell: 43200 min_dwell: 0 evpn_options: auto_loopback_subnet: 100.101.0.0/16 auto_router_id_subnet: 100.100.0.0/24 core_as_border: false overlay: as: 65000 per_vlan_vga_v4_mac: false routed_at: edge underlay: as_base: 65001 routed_id_prefix: /24 subnet: 10.255.240.0/20 flags: property1: string property2: string for_site: true gateway_additional_config_cmds: - set snmp community public gateway_mgmt: admin_sshkeys: - string app_probing: apps: - string custom_apps: - app_type: string hostnames: - string name: string protocol: http enabled: true app_usage: true auto_signature_update: day_of_week: mon enable: true time_of_day: string config_revert_timer: 10 probe_hosts: - string root_password: string security_log_source_address: 192.168.1.1 security_log_source_interface: string id: 497f6eca-6276-4993-bfeb-53cbbbba6f09 led: brightness: 255 enabled: true modified_time: 0 mxedge: mist_das: coa_servers: - disable_event_timestamp_check: false enabled: true host: string port: 3799 secret: string enabled: false radsec: acct_servers: - host: string port: 1813 secret: string ssids: - string auth_servers: - host: string keywrap_enabled: true keywrap_format: hex keywrap_kek: string keywrap_mack: string port: 1812 secret: string ssids: - string enabled: true match_ssid: true proxy_hosts: - string server_selection: ordered mxedge_mgmt: mist_password: MIST_PASSWORD root_password: ROOT_PASSWORD ntp_servers: - pool.ntp.org occupancy: assets_enabled: false clients_enabled: true min_duration: 3000 sdkclients_enabled: false unconnected_clients_enabled: false org_id: a40f5d1f-d889-42e9-94ea-b9b33585fc6b ospf_areas: property1: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default property2: include_loopback: false networks: corp: auth_keys: '1': auth-key-1 auth_type: md5 bfd_minimum_interval: 500 dead_interval: 40 hello_interval: 10 interface_type: nbma metric: 10000 guest: passive: true type: default persist_config_on_device: false port_mirroring: property1: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_port_id: ge-0/0/5 property2: input_networks_ingress: - corp input_port_ids_egress: - ge-0/0/3 input_port_ids_ingress: - ge-0/0/3 output_network: analyze port_usages: dynamic: mode: dynamic reset_default_when: link_down rules: - equals: string equals_any: - string expression: string src: lldp_chassis_id usage: string property1: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_auth: dot1x port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string property2: all_networks: false allow_dhcpd: true bypass_auth_when_server_down: true description: string disable_autoneg: false disabled: false duplex: auto enable_mac_auth: true enable_qos: true guest_network: string mac_auth_only: true mac_auth_protocol: pap mac_limit: 0 mode: access networks: - string persist_mac: false poe_disabled: false port_network: string server_reject_network: null speed: auto storm_control: no_broadcast: false no_multicast: false no_registered_multicast: false no_unknown_unicast: false percentage: 80 stp_edge: true voip_network: string proxy: url: http://proxy.internal:8080/ radius_config: acct_interim_interval: 0 acct_servers: - host: 1.2.3.4 keywrap_enabled: true keywrap_format: hex keywrap_kek: '1122334455' keywrap_mack: '1122334455' port: 1813 secret: testing123 auth_servers: - host: 1.2.3.4 keywrap_enabled: true keywrap_format: hex keywrap_kek: '1122334455' keywrap_mack: '1122334455' port: 1812 secret: testing123 auth_servers_retries: 3 auth_servers_timeout: 5 coa_enabled: false coa_port: 3799 network: string source_ip: string remote_syslog: archive: files: 20 size: 5m console: contents: - facility: config severity: warning enabled: false files: - archive: files: 10 size: 5m contents: - facility: config severity: warning explicit_priority: true file: file-name match: '!alarm|ntp|errors.crc_error[chan]' structured_data: true network: default send_to_all_servers: false servers: - facility: config host: syslogd.internal port: 514 protocol: udp severity: info tag: '' time_format: millisecond users: - contents: - facility: config severity: warning match: '"!alarm|ntp|errors.crc_error[chan]"' user: '*' report_gatt: false rogue: enabled: false honeypot_enabled: false min_duration: 10 min_rssi: -80 whitelisted_bssids: - NeighborSSID whitelisted_ssids: - cc:8e:6f:d4:bf:16 - cc-8e-6f-d4-bf-16 - cc-73-* - cc:82:* rtsa: app_waking: false disable_dead_reckoning: true disable_pressure_sensor: false enabled: true track_asset: false simple_alert: arp_failure: client_count: 10 duration: 20 incident_count: 10 dhcp_failure: client_count: 10 duration: 10 incident_count: 20 dns_failure: client_count: 20 duration: 10 incident_count: 30 site_id: 72771e6a-6f5e-4de4-a5b9-1266c4197811 skyatp: enabled: true send_ip_mac_mapping: true srx_app: enabled: false ssh_keys: - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host ssr: conductor_hosts: - '"1.1.1.1", "2.2.2.2"' disable_stats: true status_portal: enabled: false hostnames: - my.misty.com switch_mgmt: ap_affinity_threshold: 10 config_revert_timer: 10 dhcp_option_fqdn: false mxedge_proxy_host: string mxedge_proxy_port: 2222 root_password: string tacacs: acct_servers: - host: 198.51.100.1 port: '49' secret: string timeout: 10 enabled: true network: string tacplus_servers: - host: 198.51.100.1 port: '49' secret: string timeout: 10 use_mxedge_proxy: true teams_accounts: - account_id: aaaaaaaa-1bed-4a49-9fd6-123456789012 last_status: success last_sync: 1738119600 vars: RADIUS_IP1: 172.31.2.5 RADIUS_SECRET: 11s64632d vna: enabled: false vrf_instances: guest: extra_routes: 0.0.0.0/0: via: 192.168.31.1 networks: - guest vrrp_groups: property1: auth_key: auth-key-1 auth_password: string auth_type: md5 networks: data: ip: 10.182.96.1 mgmt: ip: 10.182.104.1 v10: ip: 10.182.104.129 wap: ip: 10.182.102.1 property2: auth_key: auth-key-1 auth_password: string auth_type: md5 networks: data: ip: 10.182.96.1 mgmt: ip: 10.182.104.1 v10: ip: 10.182.104.129 wap: ip: 10.182.102.1 wan_vna: enabled: false watched_station_url: https://papi.s3.amazonaws.com/watched_station/xxx... whitelist_url: https://papi.s3.amazonaws.com/whitelist/xxx... wids: repeated_auth_failures: duration: 60 threshold: 0 wifi: cisco_enabled: true disable_11k: false disable_radios_when_power_constrained: false enable_arp_spoof_check: false enable_shared_radio_scanning: true enabled: true locate_connected: true locate_unconnected: false mesh_allow_dfs: false mesh_enable_crm: false mesh_enabled: false mesh_psk: string mesh_ssid: string proxy_arp: default wired_vna: enabled: false zone_occupancy_alert: email_notifiers: - foo@juniper.net - bar@juniper.net enabled: false threshold: 5 zoom_accounts: - account_id: '123451111' errors: - OAuth token refresh failed, please re-link your account last_status: failed last_sync: 1738119600 parameters: site_id: in: path name: site_id required: true schema: examples: - 000000ab-00ab-00ab-00ab-0000000000ab format: uuid type: string securitySchemes: apiToken: description: "Like many other API providers, it’s also possible to generate API Tokens to be used (in HTTP Header) for authentication. An API token ties to a Admin with equal or less privileges.\n\n**Format**:\n API Token value format is `Token {apitoken}`\n\n**Notes**:\n* an API token generated for a specific admin has the same privilege as the user\n* an API token will be automatically removed if not used for > 90 days\n* SSO admins cannot generate these API tokens. Refer Org level API tokens which can have privileges of a specific Org/Site for more information." in: header name: Authorization type: apiKey basicAuth: description: While our current UI uses Session / Cookie-based authentication, it’s also possible to do Basic Auth. scheme: basic type: http csrfToken: description: "This protects the website against [Cross Site Request Forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery), all the POST / PUT / DELETE APIs needs to have CSRF token in the AJAX Request header when using Login/Password authentication (with or without MFA)\n\n\nThe CSRF Token is sent back by Mist in the Cookies from the Login Response API Call:\n`cookies[csrftoken]` \n\nThe CSRF Token must be added in the HTTP Request Headers:\n```\nX-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx\n```" in: header name: X-CSRFToken type: apiKey