openapi: 3.1.0
info:
contact:
email: tmunzer@juniper.net
name: Thomas Munzer
description: '> Version: **2604.1.1**
>
> Date: **May 13, 2026**
NOTE:
Some important API changes will be introduced. Please make sure to read the
announcements
---
## Additional Documentation
* [Mist Automation Guide](https://www.juniper.net/documentation/us/en/software/mist/automation-integration/index.html)
* [Mist Location SDK](https://www.juniper.net/documentation/us/en/software/mist/location-services/topics/concept/mist-how-get-mist-sdk.html)
* [Mist Product Updates](https://www.juniper.net/documentation/us/en/software/mist/product-updates/)
## Helpful Resources
* [API Sandbox and Exercises](https://api-class.mist.com/)
* [Postman Collection, Runners and Webhook Samples](https://www.postman.com/juniper-mist/workspace/mist-systems-s-public-workspace)
* [Python Script Examples](https://github.com/tmunzer/mist_library)
* [API Demo Apps](https://apps.mist-lab.fr/)
* [Juniper Blog](https://blogs.juniper.net/)
## Mist Web Browser Extension:
* Google Chrome, Microsoft Edge and other Chromium-based browser: [Chrome Web Store](https://chromewebstore.google.com/detail/mist-extension/ejhpdcljeamillfhdihkkmoakanpbplh)
* Firefox: [Firefox Add-ons](https://addons.mozilla.org/en-US/firefox/addon/mist-extension/)
---'
license:
name: MIT
url: https://raw.githubusercontent.com/tmunzer/Mist-OAS3.0/main/LICENSE
title: Mist Admins Sites Setting API
version: 2604.1.1
x-logo:
altText: Juniper-MistAI
backgroundColor: '#FFFFFF'
url: https://www.mist.com/wp-content/uploads/logo.png
servers:
- description: Mist Global 01
url: https://api.mist.com
- description: Mist Global 02
url: https://api.gc1.mist.com
- description: Mist Global 03
url: https://api.ac2.mist.com
- description: Mist Global 04
url: https://api.gc2.mist.com
- description: Mist Global 05
url: https://api.gc4.mist.com
- description: Mist EMEA 01
url: https://api.eu.mist.com
- description: Mist EMEA 02
url: https://api.gc3.mist.com
- description: Mist EMEA 03
url: https://api.ac6.mist.com
- description: Mist EMEA 04
url: https://api.gc6.mist.com
- description: Mist APAC 01
url: https://api.ac5.mist.com
- description: Mist APAC 02
url: https://api.gc5.mist.com
- description: Mist APAC 03
url: https://api.gc7.mist.com
security:
- apiToken: []
- basicAuth: []
- basicAuth: []
csrfToken: []
tags:
- description: 'Site settings refer to the configuration and management of of site within a Mist Organization.
These settings include access point settings, firmware upgrade schedules, and various features such as location services, occupancy analytics, and engagement analytics.'
name: Sites Setting
paths:
/api/v1/sites/{site_id}/setting:
parameters:
- $ref: '#/components/parameters/site_id'
get:
description: Get the Site Settings
operationId: getSiteSetting
responses:
'200':
$ref: '#/components/responses/SiteSettings'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: getSiteSetting
tags:
- Sites Setting
put:
description: Update Site Settings
operationId: updateSiteSettings
requestBody:
content:
application/json:
examples:
Example:
value:
additional_config_cmds:
- set snmp community public
analytic:
enabled: false
ap_matching:
enabled: true
rules:
- match_model: string
name: string
port_config:
eth1,eth2:
disabled: true
dynamic_vlan:
default_vlan_id: 999
enabled: true
port_vlan_id: 1
vlan_id: 9
vlan_ids: 1, 10, 50
ap_port_config:
model_specific:
AP32:
eth1,eth2:
port_vlan_id: 1
vlan_ids: 1, 10, 50
auto_upgrade:
custom_versions:
AP21: stable
AP41: 0.1.5135
AP61: 0.1.7215
day_of_week: sun
enabled: false
time_of_day: '12:00'
version: beta
config_auto_revert: false
device_updown_threshold: 0
dns_servers:
- string
dns_suffix:
- string
engagement:
dwell_tag_names:
bounce: Bounce
engaged: Engaged
passerby: Passer By
stationed: Stationed
dwell_tags:
bounce: null
engaged: 300-14400
passerby: null
stationed: 14400-43200
hours:
fri: 09:00-17:00
mon: 09:00-17:00
sat: 09:00-12:00
sun: 09:00-12:00
thu: 09:00-17:00
tue: 09:00-17:00
wed: 09:00-17:00
max_dwell: 43200
min_dwell: 0
evpn_options:
auto_loopback_subnet: 100.101.0.0/16
auto_router_id_subnet: 100.100.0.0/24
core_as_border: false
overlay:
as: 65000
per_vlan_vga_v4_mac: false
routed_at: edge
underlay:
as_base: 65001
routed_id_prefix: /24
subnet: 10.255.240.0/20
gateway_additional_config_cmds:
- set snmp community public
gateway_mgmt:
admin_sshkeys:
- string
app_probing:
apps:
- string
custom_apps:
- app_type: string
hostnames:
- string
name: string
protocol: http
enabled: true
app_usage: true
auto_signature_update:
day_of_week: any
enable: true
time_of_day: string
config_revert_timer: 10
probe_hosts:
- string
root_password: string
security_log_source_address: 192.168.1.1
security_log_source_interface: string
led:
brightness: 255
enabled: true
mxedge_mgmt:
mist_password: MIST_PASSWORD
root_password: ROOT_PASSWORD
networks:
property1:
gateway: string
subnet: string
vlan_id: 10
property2:
gateway: string
subnet: string
vlan_id: 10
ntp_servers:
- string
occupancy:
assets_enabled: false
clients_enabled: true
min_duration: 3000
sdkclients_enabled: false
unconnected_clients_enabled: false
ospf_areas:
property1:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
property2:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
persist_config_on_device: false
port_mirroring:
property1:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_network: analyze
output_port_id: ge-0/0/5
property2:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_network: analyze
output_port_id: ge-0/0/5
port_usages:
dynamic:
mode: dynamic
reset_default_when: link_down
rules:
- equals: string
equals_any:
- string
expression: string
src: lldp_chassis_id
usage: string
property1:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_auth: dot1x
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
property2:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
proxy:
url: http://proxy.internal:8080/*
rogue:
enabled: false
honeypot_enabled: false
min_duration: 10
min_rssi: -80
whitelisted_bssids:
- NeighborSSID
whitelisted_ssids:
- cc:8e:6f:d4:bf:16
- cc-8e-6f-d4-bf-16
- cc-73-*
- cc:82:*
simple_alert:
arp_failure:
client_count: 10
duration: 20
incident_count: 10
dhcp_failure:
client_count: 10
duration: 10
incident_count: 20
dns_failure:
client_count: 20
duration: 10
incident_count: 30
skyatp:
enabled: true
send_ip_mac_mapping: true
srx_app:
enabled: false
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host
ssr:
conductor_hosts:
- '"1.1.1.1", "2.2.2.2"'
disable_stats: true
status_portal:
enabled: false
hostnames:
- my.misty.com
vars:
RADIUS_IP1: 172.31.2.5
RADIUS_SECRET: 11s64632d
vna:
enabled: false
wan_vna:
enabled: false
wids:
repeated_auth_failures:
duration: 60
threshold: 0
wifi:
cisco_enabled: true
disable_11k: false
disable_radios_when_power_constrained: false
enable_arp_spoof_check: false
enable_shared_radio_scanning: true
enabled: true
locate_connected: true
locate_unconnected: false
mesh_allow_dfs: false
mesh_enable_crm: false
mesh_enabled: false
mesh_psk: string
mesh_ssid: string
proxy_arp: default
wired_vna:
enabled: false
zone_occupancy_alert:
email_notifiers:
- foo@juniper.net
- bar@juniper.net
enabled: false
threshold: 5
schema:
$ref: '#/components/schemas/site_setting'
description: Request Body
responses:
'200':
$ref: '#/components/responses/SiteSettings'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: updateSiteSettings
tags:
- Sites Setting
/api/v1/sites/{site_id}/setting/blacklist:
parameters:
- $ref: '#/components/parameters/site_id'
delete:
description: Delete Site Blacklist Station Clients
operationId: deleteSiteWirelessClientsBlocklist
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: deleteSiteWirelessClientsBlocklist
tags:
- Sites Setting
post:
description: 'This endpoint is to provide list of client macs for annotation blacklist.
Retrieve the current clients list `blacklist_url` under Site:Setting'
operationId: createSiteWirelessClientsBlocklist
requestBody:
content:
application/json:
examples:
Example:
value:
macs:
- 18-65-90-de-f4-c6
- 84-89-ad-5d-69-0d
schema:
$ref: '#/components/schemas/mac_addresses'
description: Request Body
responses:
'200':
$ref: '#/components/responses/MacsArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: createSiteWirelessClientsBlocklist
tags:
- Sites Setting
/api/v1/sites/{site_id}/setting/derived:
parameters:
- $ref: '#/components/parameters/site_id'
get:
description: Get the Derived Site Settings, generated by merging the Org level templates (network templates, gateway templates) and the Site level configuration. If the same parameter is defined in both scopes, the Site level one is used. In addition, the Zoom and Teams accounts are also merged into the derived settings.
operationId: getSiteSettingDerived
responses:
'200':
$ref: '#/components/responses/SiteSettingsDerived'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: getSiteSettingDerived
tags:
- Sites Setting
/api/v1/sites/{site_id}/setting/watched_station:
parameters:
- $ref: '#/components/parameters/site_id'
delete:
description: Delete Site Watched Station Clients
operationId: deleteSiteWatchedStations
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: deleteSiteWatchedStations
tags:
- Sites Setting
post:
description: 'This endpoint is to provide list of client macs for annotation as watched station.
Retrieve the current clients list from `watched_station_url` under Site:Setting'
operationId: createSiteWatchedStations
requestBody:
content:
application/json:
examples:
Example:
value:
macs:
- 18-65-90-de-f4-c6
- 84-89-ad-5d-69-0d
schema:
$ref: '#/components/schemas/mac_addresses'
description: Request Body
responses:
'200':
$ref: '#/components/responses/MacsArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: createSiteWatchedStations
tags:
- Sites Setting
/api/v1/sites/{site_id}/setting/whitelist:
parameters:
- $ref: '#/components/parameters/site_id'
delete:
description: Delete Site Whitelist Station Clients
operationId: deleteSiteWirelessClientsAllowlist
responses:
'200':
$ref: '#/components/responses/OK'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: deleteSiteWirelessClientsAllowlist
tags:
- Sites Setting
post:
description: 'This endpoint is to provide list of client macs for annotation as whitelist.
Retrieve the current clients list from `whitelist_url` under Site:Setting'
operationId: createSiteWirelessClientsAllowlist
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/mac_addresses'
description: Request Body
responses:
'200':
$ref: '#/components/responses/MacsArray'
'400':
$ref: '#/components/responses/HTTP400'
'401':
$ref: '#/components/responses/HTTP401'
'403':
$ref: '#/components/responses/HTTP403'
'404':
$ref: '#/components/responses/HTTP404'
'429':
$ref: '#/components/responses/HTTP429'
summary: createSiteWirelessClientsAllowlist
tags:
- Sites Setting
components:
schemas:
switch_auto_upgrade_custom_versions:
additionalProperties:
type: string
description: Custom version to be used. The Property Key is the switch hardware and the property value is the firmware version
examples:
- QFX5120-32C: 23.4R2-S2.1
QFX5130-32CD: 23.4R2-S2.3
type: object
protect_re_custom_protocol:
default: any
description: 'enum: `any`, `icmp`, `tcp`, `udp`'
enum:
- any
- icmp
- tcp
- udp
type: string
service_policy_ewf_rule_profile:
default: strict
description: 'enum: `critical`, `standard`, `strict`'
enum:
- critical
- standard
- strict
type: string
strings:
items:
type: string
type: array
uniqueItems: true
mxcluster_rad_auth_server_keywrap_format:
default: ascii
description: 'if used for Mist APs. enum: `ascii`, `hex`'
enum:
- ascii
- hex
type:
- string
- 'null'
site_setting_paloalto_networks:
additionalProperties: false
properties:
gateways:
$ref: '#/components/schemas/site_setting_paloalto_networks_gateways'
send_mist_nac_user_info:
default: false
type: boolean
type: object
network_internal_access:
additionalProperties: false
properties:
enabled:
type: boolean
type: object
app_probing_apps:
description: APp-keys from [List Applications](/#operations/listApplications)
examples:
- - facebook
items:
type: string
type: array
juniper_srx_auto_upgrade_custom_versions:
additionalProperties:
description: Firmware version to deploy on the specified SRX hardware
examples:
- 23.4R2-S2.1
type: string
description: Property key is the SRX Hardware model (e.g. "SRX4600")
type: object
app_probing_custom_app:
additionalProperties: false
properties:
address:
description: Required if `protocol`==`icmp`
examples:
- 192.168.1.1
type: string
app_type:
type: string
hostnames:
$ref: '#/components/schemas/app_probing_custom_app_hostname'
key:
type: string
name:
examples:
- pos_app
type: string
network:
examples:
- lan
type: string
packetSize:
description: If `protocol`==`icmp`
maximum: 65400
minimum: 0
type: integer
protocol:
$ref: '#/components/schemas/app_probing_custom_app_protocol'
url:
description: If `protocol`==`http`
examples:
- www.abc.com
type: string
vrf:
examples:
- lan
type: string
type: object
tunnel_config_node_remote_ids:
description: Only if `provider`==`jse-ipsec` or `provider`==`custom-ipsec`
items:
type: string
type: array
service_policy_secintel_profile:
default: default
description: 'enum: `default`, `standard`, `strict`'
enum:
- default
- standard
- strict
type: string
network_internet_access:
additionalProperties: false
description: Whether this network has direct internet access
properties:
create_simple_service_policy:
default: false
type: boolean
destination_nat:
$ref: '#/components/schemas/network_internet_access_destination_nat'
enabled:
type: boolean
restricted:
default: false
description: By default, all access is allowed, to only allow certain traffic, make `restricted`=`true` and define service_policies
type: boolean
static_nat:
$ref: '#/components/schemas/network_internet_access_static_nat'
type: object
gw_routing_policy_term:
additionalProperties: false
properties:
actions:
$ref: '#/components/schemas/gw_routing_policy_term_action'
matching:
$ref: '#/components/schemas/gw_routing_policy_term_matching'
type: object
switch_bgp_config_networks:
description: List of network names for BGP configuration. When a network is specified, a BGP group will be added to the VRF that network is part of.
items:
type: string
type: array
gateway_extra_route6:
additionalProperties: false
properties:
via:
format: ipv6
type: string
type: object
mxcluster_radsec:
additionalProperties: false
description: MxEdge RadSec Configuration
properties:
acct_servers:
$ref: '#/components/schemas/mxcluster_radsec_acct_servers'
auth_servers:
$ref: '#/components/schemas/mxcluster_radsec_auth_servers'
enabled:
description: Whether to enable service on Mist Edge i.e. RADIUS proxy over TLS
type: boolean
match_ssid:
description: Whether to match ssid in request message to select from a subset of RADIUS servers
type: boolean
nas_ip_source:
$ref: '#/components/schemas/mxcluster_radsec_nas_ip_source'
proxy_hosts:
$ref: '#/components/schemas/mxcluster_radsec_proxy_hosts'
server_selection:
$ref: '#/components/schemas/mxcluster_radsec_server_selection'
src_ip_source:
$ref: '#/components/schemas/mxcluster_radsec_src_ip_source'
type: object
vrrp_group_auth_type:
default: md5
description: 'enum: `md5`, `simple`'
enum:
- md5
- simple
examples:
- md5
type: string
tunnel_config:
additionalProperties: false
properties:
auto_provision:
$ref: '#/components/schemas/tunnel_config_auto_provision'
ike_lifetime:
description: Only if `provider`==`custom-ipsec`
type: integer
ike_mode:
$ref: '#/components/schemas/tunnel_config_ike_mode'
ike_proposals:
$ref: '#/components/schemas/tunnel_config_ike_proposals'
ipsec_lifetime:
description: If `provider`==`custom-ipsec`
type: integer
ipsec_proposals:
$ref: '#/components/schemas/tunnel_config_ipsec_proposals'
local_id:
description: Required if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec`
type: string
local_subnets:
$ref: '#/components/schemas/tunnel_config_local_subnets'
mode:
$ref: '#/components/schemas/tunnel_config_tunnel_mode'
networks:
$ref: '#/components/schemas/tunnel_config_networks'
primary:
$ref: '#/components/schemas/tunnel_config_node'
probe:
$ref: '#/components/schemas/tunnel_config_probe'
protocol:
$ref: '#/components/schemas/tunnel_config_protocol'
provider:
$ref: '#/components/schemas/tunnel_config_provider'
psk:
description: Required if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec`
type: string
remote_subnets:
$ref: '#/components/schemas/tunnel_config_remote_subnets'
secondary:
$ref: '#/components/schemas/tunnel_config_node'
version:
$ref: '#/components/schemas/tunnel_config_version'
type: object
site_rogue:
additionalProperties: false
description: Rogue site settings
properties:
allowed_vlan_ids:
$ref: '#/components/schemas/vlan_ids'
enabled:
default: false
description: Whether rogue detection is enabled
type: boolean
honeypot_enabled:
default: false
description: Whether honeypot detection is enabled
type: boolean
min_duration:
default: 10
description: Minimum duration for a bssid to be considered neighbor
examples:
- 10
maximum: 59
type: integer
min_rogue_duration:
default: 10
description: Minimum duration for a bssid to be considered rogue
examples:
- 10
maximum: 59
type: integer
min_rogue_rssi:
default: -80
description: Minimum RSSI for an AP to be considered rogue
examples:
- -80
minimum: -85
type: integer
min_rssi:
default: -80
description: Minimum RSSI for an AP to be considered neighbor (ignoring APs that’s far away)
examples:
- -80
minimum: -85
type: integer
whitelisted_bssids:
$ref: '#/components/schemas/site_rogue_whitelisted_bssids'
whitelisted_ssids:
$ref: '#/components/schemas/site_rogue_whitelisted_ssids'
type: object
vars_annotation:
additionalProperties: false
description: Annotation for a single var, helping identify its purpose and enabling auto-complete/enumeration in UI
properties:
note:
description: User-provided note to describe what this var was created for
type: string
type:
default: generic
description: 'Used to identify where to enumerate / auto-complete the field from. Default is `generic` (plain string, no special handling).
enum: `generic`, `mxtunnel_id`'
type: string
type: object
switch_bgp_config_hold_time:
description: Hold time is three times the interval at which keepalive messages are sent. It indicates to the peer the length of time that it should consider the sender valid. Must be 0 or a number in the range 3-65535.
oneOf:
- $ref: '#/components/schemas/switch_bgp_config_hold_time_zero'
- $ref: '#/components/schemas/switch_bgp_config_hold_time_integer'
sw_routing_policy_term_matching:
additionalProperties: false
description: zero or more criteria/filter can be specified to match the term, all criteria have to be met
properties:
as_path:
$ref: '#/components/schemas/routing_policy_term_matching_as_path'
community:
$ref: '#/components/schemas/routing_policy_term_matching_community'
prefix:
$ref: '#/components/schemas/routing_policy_term_matching_prefix'
protocol:
$ref: '#/components/schemas/sw_routing_policy_term_matching_protocol'
type: object
app_probing_custom_app_protocol:
default: http
description: 'enum: `http`, `icmp`'
enum:
- http
- icmp
type: string
tunnel_config_tunnel_mode:
default: active-standby
description: 'Required if `provider`==`zscaler-gre`, `provider`==`jse-ipsec`. enum: `active-active`, `active-standby`'
enum:
- active-active
- active-standby
type: string
gw_routing_policy_terms:
description: zero or more criteria/filter can be specified to match the term, all criteria have to be met
items:
$ref: '#/components/schemas/gw_routing_policy_term'
type: array
uniqueItems: true
gateway_port_dsl_type:
default: vdsl
description: 'if `wan_type`==`dsl`. enum: `adsl`, `vdsl`'
enum:
- adsl
- vdsl
type: string
switch_auto_upgrade_container:
additionalProperties: false
properties:
auto_upgrade:
$ref: '#/components/schemas/switch_auto_upgrade'
type: object
acl_policy_src_tags:
description: "ACL Policy Source Tags:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to"
items:
examples:
- macs
type: string
type: array
site_setting_srx_app:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
type: object
site_mxtunnel_additional_mxtunnel:
additionalProperties: false
properties:
clusters:
$ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel_clusters'
hello_interval:
default: 60
description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by hello_retries
examples:
- 60
maximum: 300
minimum: 1
type: integer
hello_retries:
default: 7
examples:
- 3
maximum: 30
minimum: 2
type: integer
protocol:
$ref: '#/components/schemas/site_mxtunnel_protocol'
vlan_ids:
$ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel_vlan_ids'
type: object
sle_thresholds:
additionalProperties: false
properties:
capacity:
default: 20
description: Capacity, in %
maximum: 50
minimum: 5
type: integer
coverage:
default: -72
description: Coverage, in dBm
maximum: -60
minimum: -90
type: integer
throughput:
default: 10
description: Throughput, in Mbps
maximum: 100
minimum: 1
type: integer
time-to-connect:
default: 4
description: Time to connect, in seconds
maximum: 10
minimum: 2
type: integer
type: object
snmpv3_config_target_address:
items:
$ref: '#/components/schemas/snmpv3_config_target_address_item'
type: array
acl_tags:
additionalProperties:
$ref: '#/components/schemas/acl_tag'
description: ACL Tags to identify traffic source or destination. Key name is the tag name
type: object
site_setting_config_push_policy:
additionalProperties: false
description: Mist also uses some heuristic rules to prevent destructive configs from being pushed
properties:
no_push:
default: false
description: Stop any new config from being pushed to the device
type: boolean
push_window:
$ref: '#/components/schemas/push_policy_push_window'
type: object
tacacs_default_role:
default: none
description: 'enum: `admin`, `helpdesk`, `none`, `read`'
enum:
- admin
- helpdesk
- none
- read
type: string
switch_port_usage_mac_auth_protocol:
default: eap-md5
description: 'Only if `mode`!=`dynamic` and `enable_mac_auth` ==`true`. This type is ignored if mist_nac is enabled. enum: `eap-md5`, `eap-peap`, `pap`'
enum:
- eap-md5
- eap-peap
- pap
type: string
mxcluster_radsec_src_ip_source:
default: any
description: 'Specify IP address to connect to auth_servers and acct_servers. enum: `any`, `oob`, `oob6`, `tunnel`, `tunnel6`'
enum:
- any
- oob
- oob6
- tunnel
- tunnel6
type: string
gateway_port_config_ip_config:
additionalProperties: false
description: Junos IP Config
properties:
dns:
$ref: '#/components/schemas/gateway_ip_config_dns_servers'
dns_suffix:
$ref: '#/components/schemas/gateway_ip_config_dns_suffix'
gateway:
description: Except for out-of_band interface (vme/em0/fxp0). Interface Default Gateway IP Address (i.e. "192.168.1.1") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.1.1
type: string
gateway6:
description: Except for out-of_band interface (vme/em0/fxp0). Interface Default Gateway IPv6 Address (i.e. "2001:db8::1") or a Variable (i.e. "{{myvar}}")
examples:
- 2001:db8::1
type: string
ip:
description: Interface IP Address (i.e. "192.168.1.8") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.1.8
format: ipv4
type: string
ip6:
description: Interface IPv6 Address (i.e. "2001:db8::123") or a Variable (i.e. "{{myvar}}")
examples:
- 2001:db8::123
format: ipv6
type: string
netmask:
description: Used only if `subnet` is not specified in `networks`. Interface Netmask (i.e. "/24") or a Variable (i.e. "{{myvar}}")
examples:
- /24
type: string
netmask6:
description: Used only if `subnet` is not specified in `networks`. Interface IPv6 Netmask (i.e. "/64") or a Variable (i.e. "{{myvar}}")
examples:
- /64
type: string
network:
description: Optional, the network to be used for mgmt
type: string
poser_password:
description: If `type`==`pppoe`
type: string
pppoe_auth:
$ref: '#/components/schemas/gateway_wan_ppoe_auth'
pppoe_username:
description: If `type`==`pppoe`
type: string
type:
$ref: '#/components/schemas/gateway_wan_type'
type6:
$ref: '#/components/schemas/gateway_wan_type6'
type: object
gateway_wan_probe_override:
additionalProperties: false
description: Only if `usage`==`wan`
properties:
ip6s:
$ref: '#/components/schemas/strings'
ips:
$ref: '#/components/schemas/strings'
probe_profile:
$ref: '#/components/schemas/gateway_wan_probe_override_probe_profile'
type: object
snmp_vacm_access_item_prefix_list_item_level:
description: 'enum: `authentication`, `none`, `privacy`'
enum:
- authentication
- none
- privacy
type: string
radsec_servers:
description: List of RadSec Servers. Only if not Mist Edge.
items:
$ref: '#/components/schemas/radsec_server'
type: array
uniqueItems: true
app_probing_custom_app_hostname:
description: If `protocol`==`http`
examples:
- - https://www.abc.com
items:
type: string
type: array
extra_route:
additionalProperties: false
properties:
discard:
default: false
description: This takes precedence
type: boolean
metric:
examples:
- null
maximum: 2147483647
minimum: 0
type:
- integer
- 'null'
next_qualified:
additionalProperties:
$ref: '#/components/schemas/extra_route_next_qualified_properties'
examples:
- 10.3.1.1:
metric: null
preference: 40
type: object
no_resolve:
default: false
type: boolean
preference:
examples:
- 30
maximum: 2147483647
minimum: 0
type:
- integer
- 'null'
via:
$ref: '#/components/schemas/next_hop_via'
type: object
gateway_port_lte_auth:
default: none
description: 'if `wan_type`==`lte`. enum: `chap`, `none`, `pap`'
enum:
- chap
- none
- pap
type: string
gw_routing_policy_term_action_add_community:
items:
examples:
- '3900190'
type: string
type: array
snmp_usm_user:
additionalProperties: false
properties:
authentication_password:
description: Not required if `authentication_type`==`authentication-none`. Include alphabetic, numeric, and special characters, but it cannot include control characters.
minLength: 7
type: string
authentication_type:
$ref: '#/components/schemas/snmp_usm_user_authentication_type'
encryption_password:
description: Not required if `encryption_type`==`privacy-none`. Include alphabetic, numeric, and special characters, but it cannot include control characters
minLength: 8
type: string
encryption_type:
$ref: '#/components/schemas/snmp_usm_user_encryption_type'
name:
type: string
type: object
routing_policy_term_matching_as_path:
items:
$ref: '#/components/schemas/bgp_as'
type: array
switch_matching_rule_ip_config:
additionalProperties: false
description: In-Band Management interface configuration
properties:
network:
description: VLAN Name for the management interface
type: string
type:
$ref: '#/components/schemas/ip_type'
type: object
tunnel_provider_options:
additionalProperties: false
properties:
jse:
$ref: '#/components/schemas/tunnel_provider_options_jse'
prisma:
$ref: '#/components/schemas/tunnel_provider_options_prisma'
zscaler:
$ref: '#/components/schemas/tunnel_provider_options_zscaler'
type: object
radius_acct_server:
additionalProperties: false
properties:
host:
description: IP/ hostname of RADIUS server
examples:
- 1.2.3.4
type: string
keywrap_enabled:
type: boolean
keywrap_format:
$ref: '#/components/schemas/radius_keywrap_format'
keywrap_kek:
examples:
- '1122334455'
type: string
keywrap_mack:
examples:
- '1122334455'
type: string
port:
$ref: '#/components/schemas/radius_acct_port'
secret:
description: Secret of RADIUS server
examples:
- testing123
format: password
type: string
required:
- host
- secret
type: object
gateway_mgmt_probe_hostsv6:
examples:
- - 2001:4860:4860::8888
format: ipv6
items:
type: string
type: array
network_internet_access_static_nat:
additionalProperties:
$ref: '#/components/schemas/network_internet_access_static_nat_property'
description: Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
type: object
idp_profile:
properties:
base_profile:
$ref: '#/components/schemas/idp_profile_base_profile'
created_time:
$ref: '#/components/schemas/created_time'
id:
$ref: '#/components/schemas/id'
modified_time:
$ref: '#/components/schemas/modified_time'
name:
examples:
- relaxed
type: string
org_id:
$ref: '#/components/schemas/org_id'
overwrites:
$ref: '#/components/schemas/idp_profile_overwrites'
type: object
remote_syslog:
additionalProperties: false
properties:
archive:
$ref: '#/components/schemas/remote_syslog_archive'
cacerts:
$ref: '#/components/schemas/remote_syslog_cacerts'
console:
$ref: '#/components/schemas/remote_syslog_console'
enabled:
default: false
type: boolean
files:
$ref: '#/components/schemas/remote_syslog_files'
network:
description: If source_address is configured, will use the vlan firstly otherwise use source_ip
examples:
- default
type: string
send_to_all_servers:
default: false
type: boolean
servers:
$ref: '#/components/schemas/remote_syslog_servers'
time_format:
$ref: '#/components/schemas/remote_syslog_time_format'
users:
$ref: '#/components/schemas/remote_syslog_users'
type: object
switch_port_usage_dynamic_rule_equals_any:
description: Use `equals_any` to match any item in a list
items:
type: string
type: array
gateway_wan_ppoe_auth:
default: none
description: 'if `type`==`pppoe`. enum: `chap`, `none`, `pap`'
enum:
- chap
- none
- pap
type: string
snmp_config_trap_group_targets:
items:
examples:
- 172.29.158.19
type: string
type: array
site_mxtunnel_additional_mxtunnel_clusters:
description: For AP, how to connect to tunterm or RadSec Proxy
items:
$ref: '#/components/schemas/site_mxtunnel_cluster'
type: array
network_source_nat:
additionalProperties: false
description: If `routed`==`false` (usually at Spoke), but some hosts needs to be reachable from Hub
properties:
external_ip:
examples:
- 172.16.0.8/30
type: string
type: object
network_tenant_addresses:
items:
description: The user/tenant IP Address (i.e. "192.168.70.30"), an Subnet (i.e. "192.168.70.0/24") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.70.30
type: string
type: array
snmpv3_config_target_param:
additionalProperties: false
properties:
message_processing_model:
$ref: '#/components/schemas/snmpv3_config_target_param_mess_process_model'
name:
type: string
notify_filter:
description: Refer to profile-name in notify_filter
type: string
security_level:
$ref: '#/components/schemas/snmpv3_config_target_param_security_level'
security_model:
$ref: '#/components/schemas/snmpv3_config_target_param_security_model'
security_name:
description: Refer to security_name in usm
examples:
- m01620
type: string
type: object
mxcluster_radsec_auth_server_ssids:
description: List of ssids that will use this server if match_ssid is true and match is found
items:
type: string
type: array
simple_alert:
additionalProperties: false
description: Set of heuristic rules will be enabled when marvis subscription is not available. It triggers when, in a Z minute window, there are more than Y distinct client encountering over X failures
properties:
arp_failure:
$ref: '#/components/schemas/simple_alert_arp_failure'
dhcp_failure:
$ref: '#/components/schemas/simple_alert_dhcp_failure'
dns_failure:
$ref: '#/components/schemas/simple_alert_dns_failure'
type: object
gateway_template_type:
default: standalone
description: 'enum: `spoke`, `standalone`'
enum:
- spoke
- standalone
examples:
- standalone
type: string
gateway_ip_config_property_second_ips:
description: Optional list of secondary IPs in CIDR format
examples:
- - 192.168.50.1/24
- 192.168.60.1/26
items:
type: string
type: array
app_probing:
additionalProperties: false
properties:
apps:
$ref: '#/components/schemas/app_probing_apps'
custom_apps:
$ref: '#/components/schemas/app_probing_custom_apps'
enabled:
type: boolean
type: object
junos_port_config:
additionalProperties: false
description: Switch port config
properties:
ae_disable_lacp:
description: To disable LACP support for the AE interface
type: boolean
ae_idx:
description: Users could force to use the designated AE name
type: integer
ae_lacp_force_up:
default: false
description: 'If `aggregated`==`true`, sets the state of the interface as UP when the peer has limited LACP capability. Use case: When a device connected to this AE port is ZTPing for the first time, it will not have LACP configured on the other end. **Note:** Turning this on will enable force-up on one of the interfaces in the bundle only'
type: boolean
ae_lacp_slow:
description: To use slow timeout
type: boolean
aggregated:
default: false
type: boolean
critical:
default: false
description: To generate port up/down alarm
type: boolean
description:
type: string
disable_autoneg:
default: false
description: If `speed` and `duplex` are specified, whether to disable autonegotiation
type: boolean
duplex:
$ref: '#/components/schemas/junos_port_config_duplex'
dynamic_usage:
description: Enable dynamic usage for this port. Set to `dynamic` to enable.
type:
- string
- 'null'
esilag:
type: boolean
mtu:
default: 1514
description: Media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation
type: integer
networks:
description: List of network names. Required if `usage`==`inet`
items:
type: string
type: array
no_local_overwrite:
default: true
description: Prevent helpdesk to override the port config
type: boolean
poe_disabled:
default: false
type: boolean
port_network:
description: Required if `usage`==`vlan_tunnel`. Q-in-Q tunneling using All-in-one bundling. This also enables standard L2PT for interfaces that are not encapsulation tunnel interfaces and uses MAC rewrite operation. [View more information](https://www.juniper.net/documentation/us/en/software/junos/multicast-l2/topics/topic-map/q-in-q.html#id-understanding-qinq-tunneling-and-vlan-translation)
type: string
speed:
$ref: '#/components/schemas/junos_port_config_speed'
usage:
description: Port usage name. For Q-in-Q, use `vlan_tunnel`. If EVPN is used, use `evpn_uplink`or `evpn_downlink`
type: string
required:
- usage
type: object
tunnel_config_ike_mode:
default: main
description: 'Only if `provider`==`custom-ipsec`. enum: `aggressive`, `main`'
enum:
- aggressive
- main
type: string
gateway_template:
description: Gateway Template is applied to a site for gateway(s) in a site.
properties:
additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
bgp_config:
additionalProperties:
$ref: '#/components/schemas/bgp_config'
type: object
created_time:
$ref: '#/components/schemas/created_time'
dhcpd_config:
$ref: '#/components/schemas/dhcpd_config'
dnsOverride:
default: false
type: boolean
dns_servers:
$ref: '#/components/schemas/dns_servers'
dns_suffix:
$ref: '#/components/schemas/dns_suffix'
extra_routes:
$ref: '#/components/schemas/gateway_extra_routes'
extra_routes6:
$ref: '#/components/schemas/gateway_extra_routes6'
gateway_matching:
$ref: '#/components/schemas/gateway_matching'
gateway_mgmt:
$ref: '#/components/schemas/gateway_mgmt'
id:
$ref: '#/components/schemas/id'
idp_profiles:
$ref: '#/components/schemas/gateway_idp_profiles'
ip_configs:
$ref: '#/components/schemas/gateway_ip_configs'
modified_time:
$ref: '#/components/schemas/modified_time'
name:
examples:
- gw_template
type: string
networks:
$ref: '#/components/schemas/networks'
ntpOverride:
default: false
type: boolean
ntp_servers:
$ref: '#/components/schemas/ntp_servers'
oob_ip_config:
$ref: '#/components/schemas/gateway_oob_ip_config'
org_id:
$ref: '#/components/schemas/org_id'
path_preferences:
additionalProperties:
$ref: '#/components/schemas/gateway_path_preferences'
description: Property key is the path name
type: object
port_config:
additionalProperties:
$ref: '#/components/schemas/gateway_port_config'
description: Property key is the Port Name (i.e. "ge-0/0/0"), the Ports Range (i.e. "ge-0/0/0-10"), the List of Ports (i.e. "ge-0/0/0,ge-1/0/0", only allowed for Aggregated or Redundant interfaces) or a Variable (i.e. "{{myvar}}").
type: object
router_id:
description: Auto assigned if not set
examples:
- 10.2.1.10
type: string
routing_policies:
$ref: '#/components/schemas/gw_routing_policies'
service_policies:
$ref: '#/components/schemas/service_policies'
tunnel_configs:
additionalProperties:
$ref: '#/components/schemas/tunnel_config'
description: Property key is the tunnel name
type: object
tunnel_provider_options:
$ref: '#/components/schemas/tunnel_provider_options'
type:
$ref: '#/components/schemas/gateway_template_type'
url_filtering_deny_msg:
default: Access to this URL Category has been blocked
description: When a service policy denies a app_category, what message to show in user's browser
examples:
- Access to this URL Category has been blocked
type: string
vrf_config:
$ref: '#/components/schemas/vrf_config'
vrf_instances:
$ref: '#/components/schemas/gateway_vrf_instances'
required:
- name
type: object
tunnel_config_auto_provision_lat_lng:
additionalProperties: false
description: API override for POP selection
properties:
lat:
examples:
- 37.295833
format: double
type: number
lng:
examples:
- -122.032946
format: double
type: number
required:
- lat
- lng
type: object
sw_routing_policy_term:
additionalProperties: false
properties:
actions:
$ref: '#/components/schemas/sw_routing_policy_term_action'
matching:
$ref: '#/components/schemas/sw_routing_policy_term_matching'
name:
type: string
required:
- name
type: object
snmpv3_config:
additionalProperties: false
properties:
notify:
$ref: '#/components/schemas/snmpv3_config_notify'
notify_filter:
$ref: '#/components/schemas/snmpv3_config_notify_filter'
target_address:
$ref: '#/components/schemas/snmpv3_config_target_address'
target_parameters:
$ref: '#/components/schemas/snmpv3_config_target_params'
usm:
$ref: '#/components/schemas/snmp_usms'
vacm:
$ref: '#/components/schemas/snmp_vacm'
type: object
site_setting_vna:
additionalProperties: false
properties:
enabled:
default: false
description: Enable Virtual Network Assistant (using SUB-VNA license). This applied to AP / Switch / Gateway
type: boolean
type: object
dhcpd_config_type6:
default: none
description: 'enum: `local` (DHCP Server), `none`, `relay` (DHCP Relay)'
enum:
- local
- none
- relay
type: string
ap_radio_band24:
additionalProperties: false
description: Radio Band AP settings
properties:
allow_rrm_disable:
default: false
type: boolean
ant_gain:
default: 0
maximum: 10
minimum: 0
type:
- integer
- 'null'
antenna_mode:
$ref: '#/components/schemas/radio_band_antenna_mode'
bandwidth:
$ref: '#/components/schemas/dot11_bandwidth24'
channel:
default: null
description: For Device. (primary) channel for the band, 0 means using the Site Setting
examples:
- 6
maximum: 13
minimum: 1
type:
- integer
- 'null'
channels:
$ref: '#/components/schemas/radio_band_channels'
disabled:
default: false
description: Whether to disable the radio
type: boolean
power:
default: null
description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …'
examples:
- 3
maximum: 25
minimum: 3
type:
- integer
- 'null'
power_max:
default: 17
description: When power=0, max tx power to use, HW-specific values will be used if not set
maximum: 18
minimum: 3
type:
- integer
- 'null'
power_min:
default: 8
description: When power=0, min tx power to use, HW-specific values will be used if not set
maximum: 18
minimum: 3
type:
- integer
- 'null'
preamble:
$ref: '#/components/schemas/radio_band_preamble'
type: object
site_setting_derived_accounts:
additionalProperties:
$ref: '#/components/schemas/account_oauth_info_account'
type: object
radius_config:
additionalProperties: false
description: Junos Radius config
properties:
acct_interim_interval:
default: 0
description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from RADIUS Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled
maximum: 65535
minimum: 0
type: integer
acct_servers:
$ref: '#/components/schemas/radius_acct_servers'
auth_servers:
$ref: '#/components/schemas/radius_auth_servers'
auth_servers_retries:
default: 3
description: radius auth session retries
type: integer
auth_servers_timeout:
default: 5
description: radius auth session timeout
type: integer
coa_enabled:
default: false
type: boolean
coa_port:
default: 3799
maximum: 65535
minimum: 1
type: integer
network:
description: use `network`or `source_ip`, which network the RADIUS server resides, if there's static IP for this network, we'd use it as source-ip
type: string
source_ip:
description: use `network`or `source_ip`
type: string
type: object
switch_port_mirroring_ingress_port_ids:
description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified
items:
examples:
- ge-0/0/3
type: string
type: array
gateway_extra_routes6:
additionalProperties:
$ref: '#/components/schemas/gateway_extra_route6'
description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64"), the destination Network name or a variable (e.g. "{{myvar}}")
examples:
- 2a02:1234:420a:10c9::/64:
via: 2a02:1234:200a::100
type: object
ap_led:
additionalProperties: false
description: LED AP settings
properties:
brightness:
default: 255
examples:
- 255
maximum: 255
minimum: 0
type: integer
enabled:
default: true
type: boolean
type: object
dhcpd_config_dns_servers:
description: If `type`==`local` or `type6`==`local` - optional, if not defined, system one will be used
examples:
- - 8.8.8.8
- 4.4.4.4
- 2001:4860:4860::8888
items:
type: string
type: array
remote_syslog_cacerts:
examples:
- - '-----BEGIN CERTIFICATE-----\nMIIFZjCCA06gAwIBAgIIP61/1qm/uDowDQYJKoZIhvcNAQELBQE\n-----END CERTIFICATE-----'
- '-----BEGIN CERTIFICATE-----\nBhMCRVMxFDASBgNVBAoMC1N0YXJ0Q29tIENBMSwwKgYDVn-----END CERTIFICATE-----'
items:
type: string
type: array
gateway_port_vpn_path_role:
default: spoke
description: 'If the VPN `type`==`hub_spoke`, enum: `hub`, `spoke`. If the VPN `type`==`mesh`, enum: `mesh`'
enum:
- hub
- mesh
- spoke
type: string
ospf_area_network_auth_type:
default: none
description: 'auth type. enum: `md5`, `none`, `password`'
enum:
- md5
- none
- password
examples:
- md5
type: string
site_setting_juniper_srx:
additionalProperties: false
properties:
auto_upgrade:
$ref: '#/components/schemas/juniper_srx_auto_upgrade'
gateways:
$ref: '#/components/schemas/site_setting_juniper_srx_gateways'
send_mist_nac_user_info:
type: boolean
type: object
gateway_extra_route:
additionalProperties: false
properties:
via:
format: ipv4
type: string
type: object
network_template:
description: Network Template
properties:
acl_policies:
$ref: '#/components/schemas/acl_policies'
acl_tags:
$ref: '#/components/schemas/acl_tags'
additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
bgp_config:
additionalProperties:
$ref: '#/components/schemas/switch_bgp_config'
type: object
created_time:
$ref: '#/components/schemas/created_time'
dhcp_snooping:
$ref: '#/components/schemas/dhcp_snooping'
dns_servers:
$ref: '#/components/schemas/dns_servers'
dns_suffix:
$ref: '#/components/schemas/dns_suffix'
extra_routes:
$ref: '#/components/schemas/extra_routes'
extra_routes6:
$ref: '#/components/schemas/extra_routes6'
id:
$ref: '#/components/schemas/id'
import_org_networks:
$ref: '#/components/schemas/network_template_import_org_networks'
mist_nac:
$ref: '#/components/schemas/switch_mist_nac'
modified_time:
$ref: '#/components/schemas/modified_time'
name:
type: string
networks:
$ref: '#/components/schemas/switch_networks'
ntp_servers:
$ref: '#/components/schemas/ntp_servers'
org_id:
$ref: '#/components/schemas/org_id'
ospf_areas:
$ref: '#/components/schemas/ospf_areas'
port_mirroring:
$ref: '#/components/schemas/switch_port_mirroring'
port_usages:
$ref: '#/components/schemas/switch_port_usages'
radius_config:
$ref: '#/components/schemas/switch_radius_config'
remote_syslog:
$ref: '#/components/schemas/remote_syslog'
remove_existing_configs:
default: false
description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed.
type: boolean
routing_policies:
$ref: '#/components/schemas/sw_routing_policies'
snmp_config:
$ref: '#/components/schemas/snmp_config'
switch_matching:
$ref: '#/components/schemas/switch_matching'
switch_mgmt:
$ref: '#/components/schemas/switch_mgmt'
vrf_config:
$ref: '#/components/schemas/vrf_config'
vrf_instances:
$ref: '#/components/schemas/switch_vrf_instances'
type: object
snmp_vacm_security_to_group:
additionalProperties: false
properties:
content:
$ref: '#/components/schemas/snmp_vacm_security_to_group_content'
security_model:
$ref: '#/components/schemas/snmp_vacm_security_model'
type: object
tunnel_provider_options_jse:
additionalProperties: false
description: For jse-ipsec, this allows provisioning of adequate resource on JSE. Make sure adequate licenses are added
properties:
num_users:
examples:
- 5
type: integer
org_name:
description: JSE Organization name. The list of available organizations can be retrieved with the [Get Org JSE Info](/#operations/getOrgJseInfo) API Call
examples:
- JSE_ORG1
type: string
type: object
network_vpn_access_destination_nat_property:
additionalProperties: false
properties:
internal_ip:
description: The Destination NAT destination IP Address. Must be an IP (i.e. "192.168.70.30") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.70.30
type: string
name:
examples:
- web server
type: string
port:
examples:
- '443'
type: string
type: object
dot11_bandwidth5:
default: 40
description: 'channel width for the 5GHz band. enum: `0`(disabled, response only), `20`, `40`, `80`'
enum:
- 0
- 20
- 40
- 80
examples:
- 40
type: integer
tacacs_acct_servers:
items:
$ref: '#/components/schemas/tacacs_acct_server'
type: array
switch_bgp_config_hold_time_zero:
enum:
- 0
type: integer
protect_re_allowed_services:
description: Optionally, services we'll allow
examples:
- - icmp
- ssh
items:
$ref: '#/components/schemas/protect_re_allowed_service'
type: array
dhcpd_config_servers6:
description: If `type6`==`relay`
examples:
- - 2607:f8b0:4005:808::64
items:
type: string
type: array
synthetictest_config_wan_speedtest:
additionalProperties: false
properties:
enabled:
type: boolean
time_of_day:
$ref: '#/components/schemas/time_of_day'
type: object
snmp_vacm_access_item_prefix_list_item:
additionalProperties: false
properties:
context_prefix:
description: Only required if `type`==`context_prefix`
examples:
- iil
type: string
notify_view:
description: Refer to view name
examples:
- all
type: string
read_view:
description: Refer to view name
examples:
- all
type: string
security_level:
$ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item_level'
security_model:
$ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item_model'
type:
$ref: '#/components/schemas/snmp_vacm_access_item_type'
write_view:
description: Refer to view name
examples:
- all
type: string
type: object
additional_vlan_ids:
anyOf:
- type: string
- $ref: '#/components/schemas/additional_vlan_ids_array'
description: List or Comma separated list of additional VLAN IDs (on the LAN side or from other WLANs) should we be forwarding bonjour queries/responses
switch_port_usage_dynamic_vlan_networks:
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`, if dynamic vlan is used, specify the possible networks/vlans RADIUS can return
examples:
- - corp
- user
items:
type: string
type: array
site_setting_auto_upgrade_esl:
additionalProperties: false
description: auto upgrade AP ESL. When both firmware and ESL auto-upgrade are enabled, ESL upgrade will be done only after firmware upgrade
properties:
allow_downgrade:
default: false
description: If true, it will allow downgrade to a lower version
type: boolean
custom_versions:
additionalProperties:
type: string
description: Custom versions for different models. Property key is the model name (e.g. "AP41")
examples:
- AP41: 2.4.6
AP61: 2.5.0
type: object
day_of_week:
$ref: '#/components/schemas/day_of_week'
enabled:
default: false
description: Whether auto upgrade should happen (Note that Mist may auto-upgrade if the version is not supported)
type: boolean
time_of_day:
description: '`any` / HH:MM (24-hour format), upgrade will happen within up to 1-hour from this time'
examples:
- '12:00'
type: string
version:
examples:
- 2.5.0
type: string
type: object
next_hop_via:
description: Next-hop IP Address. Can be a single IP address or an array of IP addresses for ECMP (Equal-Cost Multi-Path) load balancing across multiple next-hops.
examples:
- 10.2.1.1
- - 10.2.1.1
- 10.2.1.2
oneOf:
- type: string
- items:
type: string
type: array
antenna_select:
description: 'Antenna Mode for AP which supports selectable antennas. enum: `""` (default), `external`, `internal`'
enum:
- ''
- external
- internal
examples:
- external
type: string
protect_re_custom:
additionalProperties: false
description: Custom acls
properties:
port_range:
default: '0'
description: Matched dst port, "0" means any
examples:
- 80,1035-1040
type: string
protocol:
$ref: '#/components/schemas/protect_re_custom_protocol'
subnets:
$ref: '#/components/schemas/protect_re_custom_subnet'
type: object
switch_matching:
additionalProperties: false
description: Defines custom switch configuration based on different criteria
properties:
enable:
type: boolean
rules:
$ref: '#/components/schemas/switch_matching_rules'
type: object
gateway_port_vpn_path_bfd_profile:
default: broadband
description: 'Only if the VPN `type`==`hub_spoke`. enum: `broadband`, `lte`'
enum:
- broadband
- lte
type: string
synthetictest_config_custom_probes:
additionalProperties:
$ref: '#/components/schemas/synthetictest_config_custom_probe'
description: Custom probes to be used for synthetic tests
type: object
radio_band_preamble:
default: short
description: 'enum: `auto`, `long`, `short`'
enum:
- auto
- long
- short
type: string
config_switch_local_accounts:
additionalProperties:
$ref: '#/components/schemas/config_switch_local_accounts_user'
description: Property key is the user name. For Local user authentication
type: object
snmpv3_config_notify_filter_item_content:
additionalProperties: false
properties:
include:
type: boolean
oid:
examples:
- 1.3.6.1.4.1
type: string
type: object
mist_nacedge:
additionalProperties: false
properties:
auth_ttl:
default: 604800
description: Cache of last auth result; in seconds
maximum: 2592000
minimum: 60
type: integer
default_dot1x_vlan:
description: Default vlan for all dot1x devices, if different from default_vlan
examples:
- '20'
type: string
default_vlan:
description: Default vlan to assign for devices not in the cache
examples:
- test_vlan
type: string
enabled:
type: boolean
mxedge_hosts:
$ref: '#/components/schemas/mist_nacedge_mxedge_hosts'
type: object
site_setting_flags:
additionalProperties:
type: string
description: Name/val pair objects for location engine to use
type: object
tunnel_config_ike_proposal:
additionalProperties: false
properties:
auth_algo:
$ref: '#/components/schemas/tunnel_config_auth_algo'
dh_group:
$ref: '#/components/schemas/tunnel_config_ike_dh_group'
enc_algo:
$ref: '#/components/schemas/tunnel_config_enc_algo'
type: object
account_oauth_info_account_service_connection:
additionalProperties: false
properties:
region:
description: Region of the service connection
examples:
- us-southwest
type: string
type: object
sw_routing_policy_term_matching_protocol_enum:
description: 'enum: `bgp`, `direct`, `evpn`, `ospf`, `static`'
enum:
- bgp
- direct
- evpn
- ospf
- static
type: string
gateway_ip_config_dns_servers:
description: Except for out-of_band interface (vme/em0/fxp0)
items:
type: string
type: array
snmp_config_trap_group_categories:
items:
examples:
- authentication
type: string
type: array
remote_syslog_contents:
items:
$ref: '#/components/schemas/remote_syslog_content'
type: array
remote_syslog_user:
additionalProperties: false
properties:
contents:
$ref: '#/components/schemas/remote_syslog_contents'
match:
examples:
- '"!alarm|ntp|errors.crc_error[chan]"'
type: string
user:
examples:
- '*'
type: string
type: object
protect_re:
additionalProperties: false
description: "Restrict inbound-traffic to host\nwhen enabled, all traffic that is not essential to our operation will be dropped \ne.g. ntp / dns / traffic to mist will be allowed by default, if dhcpd is enabled, we'll make sure it works"
properties:
allowed_services:
$ref: '#/components/schemas/protect_re_allowed_services'
custom:
$ref: '#/components/schemas/protect_re_customs'
enabled:
default: false
description: "When enabled, all traffic that is not essential to our operation will be dropped\ne.g. ntp / dns / traffic to mist will be allowed by default\n if dhcpd is enabled, we'll make sure it works"
type: boolean
hit_count:
default: false
description: Whether to enable hit count for Protect_RE policy
type: boolean
trusted_hosts:
$ref: '#/components/schemas/protect_re_trusted_hosts'
type: object
tunnel_config_probe:
additionalProperties: false
description: Only if `provider`==`custom-ipsec`
properties:
interval:
description: How often to trigger the probe
type: integer
threshold:
description: Number of consecutive misses before declaring the tunnel down
type: integer
timeout:
description: Time within which to complete the connectivity check
type: integer
type:
$ref: '#/components/schemas/tunnel_config_probe_type'
type: object
snmp_config_v2c_config:
additionalProperties: false
properties:
authorization:
examples:
- read-only
type: string
client_list_name:
description: Client_list_name here should refer to client_list above
examples:
- clist-1
type: string
community_name:
examples:
- abc123
type: string
view:
description: View name here should be defined in views above
examples:
- all
type: string
type: object
tunterm_monitoring_item:
additionalProperties: false
properties:
host:
description: Can be ip, ipv6, hostname
examples:
- 10.2.8.15
minLength: 1
type: string
port:
description: When `protocol`==`tcp`
examples:
- 80
type: integer
protocol:
$ref: '#/components/schemas/tunterm_monitoring_protocol'
src_vlan_id:
description: Optional source for the monitoring check, vlan_id configured in tunterm_other_ip_configs
examples:
- 5
type: integer
timeout:
default: 300
examples:
- 300
type: integer
type: object
protect_re_trusted_hosts:
description: host/subnets we'll allow traffic to/from
items:
examples:
- 10.242.3.0/24
type: string
type: array
switch_bgp_config_type:
description: 'enum: `external`, `internal`'
enum:
- external
- internal
type: string
sw_routing_policy_term_action:
additionalProperties: false
description: When used as import policy
properties:
accept:
type: boolean
community:
$ref: '#/components/schemas/routing_policy_term_action_community'
local_preference:
$ref: '#/components/schemas/routing_policy_local_preference'
prepend_as_path:
$ref: '#/components/schemas/routing_policy_term_action_prepend_as_path'
type: object
simple_alert_dns_failure:
additionalProperties: false
properties:
client_count:
default: 20
type: integer
duration:
default: 10
description: failing within minutes
maximum: 60
minimum: 5
type: integer
incident_count:
default: 30
type: integer
type: object
snmp_config_engine_id_type:
default: local
description: 'enum: `local`, `use_mac_address`'
enum:
- local
- use_mac_address
type: string
gateway_matching_rule:
additionalProperties:
description: 'Property key defines the type of matching. e.g: `match_name[0:3]`, `match_model[0-6]` or `match_role`'
type: string
properties:
additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
name:
type: string
port_config:
additionalProperties:
$ref: '#/components/schemas/gateway_port_config'
description: Property key is the port(s) name or range (e.g. "ge-0/0/0-10").
type: object
type: object
gateway_port_networks:
description: If `usage`==`lan`, name of the [networks]($h/Orgs%20Networks/_overview) to attach to the interface
items:
type: string
type: array
remote_syslog_file_config:
additionalProperties: false
properties:
archive:
$ref: '#/components/schemas/remote_syslog_archive'
contents:
$ref: '#/components/schemas/remote_syslog_contents'
enable_tls:
description: Only if `protocol`==`tcp`
type: boolean
explicit_priority:
type: boolean
file:
examples:
- file-name
type: string
match:
examples:
- '!alarm|ntp|errors.crc_error[chan]'
type: string
structured_data:
type: boolean
type: object
mxcluster_radsec_acct_servers:
description: List of RADIUS accounting servers, optional, order matters where the first one is treated as primary
items:
$ref: '#/components/schemas/mxcluster_radsec_acct_server'
type: array
uniqueItems: true
switch_auto_upgrade:
additionalProperties: false
properties:
custom_versions:
$ref: '#/components/schemas/switch_auto_upgrade_custom_versions'
enabled:
description: Enable auto upgrade for the switch
type: boolean
snapshot:
default: false
description: Enable snapshot during the upgrade process
type: boolean
type: object
ap_uplink_port_config:
additionalProperties: false
description: AP Uplink port configuration
properties:
dot1x:
default: false
description: Whether to do 802.1x against uplink switch. When enabled, AP cert will be used to do EAP-TLS and the Org's CA Cert has to be provisioned at the switch
type: boolean
keep_wlans_up_if_down:
default: false
description: By default, WLANs are disabled when uplink is down. In some scenario, like SiteSurvey, one would want the AP to keep sending beacons.
type: boolean
type: object
site_setting_vrrp_groups:
additionalProperties:
$ref: '#/components/schemas/vrrp_group'
description: Property key is the vrrp group
type: object
ip_type:
default: dhcp
description: 'enum: `dhcp`, `static`'
enum:
- dhcp
- static
examples:
- static
type: string
dhcp_snooping_networks:
description: If `all_networks`==`false`, list of network with DHCP snooping enabled
items:
type: string
type: array
network_multicast_groups:
additionalProperties:
$ref: '#/components/schemas/network_multicast_group'
description: Group address to RP (rendezvous point) mapping. Property Key is the CIDR (example "225.1.0.3/32")
type: object
vars:
additionalProperties:
type: string
description: Dictionary of name->value, the vars can then be used in Wlans. This can overwrite those from Site Vars
examples:
- RADIUS_IP1: 172.31.2.5
RADIUS_SECRET: 11s64632d
type: object
gateway_port_wan_type:
default: broadband
description: 'Only if `usage`==`wan`. enum: `broadband`, `dsl`, `lte`'
enum:
- broadband
- dsl
- lte
type: string
site_id:
examples:
- 441a1214-6928-442a-8e92-e1d34b8ec6a6
format: uuid
readOnly: true
type: string
ap_radio_band6:
additionalProperties: false
description: Radio Band AP settings
properties:
allow_rrm_disable:
default: false
type: boolean
ant_gain:
default: 0
maximum: 10
minimum: 0
type:
- integer
- 'null'
antenna_beam_pattern:
$ref: '#/components/schemas/radio_band_antenna_beam_pattern'
antenna_mode:
$ref: '#/components/schemas/radio_band_antenna_mode'
bandwidth:
$ref: '#/components/schemas/dot11_bandwidth6'
channel:
default: null
description: For Device. (primary) channel for the band, 0 means using the Site Setting
examples:
- 0
type:
- integer
- 'null'
channels:
$ref: '#/components/schemas/radio_band_channels'
disabled:
default: false
description: Whether to disable the radio
type: boolean
power:
default: null
description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …'
examples:
- 7
maximum: 25
minimum: 5
type:
- integer
- 'null'
power_max:
default: 18
description: When power=0, max tx power to use, HW-specific values will be used if not set
maximum: 18
minimum: 5
type:
- integer
- 'null'
power_min:
default: 8
description: When power=0, min tx power to use, HW-specific values will be used if not set
maximum: 18
minimum: 5
type:
- integer
- 'null'
preamble:
$ref: '#/components/schemas/radio_band_preamble'
standard_power:
default: false
description: For 6GHz Only, standard-power operation, AFC (Automatic Frequency Coordination) will be performed, and we'll fall back to Low Power Indoor if AFC failed
type: boolean
type: object
dhcpd_config_fixed_binding:
additionalProperties: false
properties:
ip:
examples:
- 192.168.70.35
type: string
ip6:
examples:
- 2607:f8b0:4005:808::2
type: string
name:
type: string
type: object
switch_networks:
additionalProperties:
$ref: '#/components/schemas/switch_network'
description: Property key is network name
type: object
dhcpd_config_option:
additionalProperties: false
properties:
type:
$ref: '#/components/schemas/dhcpd_config_option_type'
value:
type: string
type: object
ospf_area_network_interface_type:
default: broadcast
description: 'interface type (nbma = non-broadcast multi-access). enum: `broadcast`, `nbma`, `p2mp`, `p2p`'
enum:
- broadcast
- nbma
- p2mp
- p2p
type: string
mxedge_tunterm_multicast_config_mdns_vlan_ids:
examples:
- - 2
- 3
- 5
items:
type: integer
type: array
ble_config_beam_disabled:
description: List of AP BLE location beam numbers (1-8) which should be disabled at the AP and not transmit location information (where beam 1 is oriented at the top the AP, growing counter-clock-wise, with 9 being the omni BLE beam)
examples:
- - 1
- 3
- 6
items:
type: integer
type: array
idp_profile_matching:
additionalProperties: false
properties:
attack_name:
$ref: '#/components/schemas/idp_profile_matching_attack_name'
dst_subnet:
$ref: '#/components/schemas/idp_profile_matching_dst_subnet'
severity:
$ref: '#/components/schemas/idp_profile_matching_severity'
type: object
switch_port_mirroring:
additionalProperties:
$ref: '#/components/schemas/switch_port_mirroring_property'
description: Property key is the port mirroring instance name. `port_mirroring` can be added under device/site settings. It takes interface and ports as input for ingress, interface as input for egress and can take interface and port as output. A maximum 4 mirroring ports is allowed
type: object
snmp_vacm_access:
items:
$ref: '#/components/schemas/snmp_vacm_access_item'
type: array
network_vpn_access_static_nat:
additionalProperties:
$ref: '#/components/schemas/network_vpn_access_static_nat_property'
description: Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
type: object
synthetictest_config_lan_networks:
description: List of networks to be used for synthetic tests
items:
$ref: '#/components/schemas/synthetictest_config_lan_network'
type: array
radius_acct_servers:
items:
$ref: '#/components/schemas/radius_acct_server'
type: array
uniqueItems: true
gw_routing_policy_term_action_exclude_community:
items:
examples:
- '3900190'
type: string
type: array
config_switch_local_accounts_user_role:
default: none
description: 'enum: `admin`, `helpdesk`, `none`, `read`'
enum:
- admin
- helpdesk
- none
- read
type: string
site_mxtunnel_clusters:
description: For AP, how to connect to tunterm or RadSec Proxy
items:
$ref: '#/components/schemas/site_mxtunnel_cluster'
type: array
setting_ssr_conductor_hosts:
description: List of Conductor IP Addresses or Hosts to be used by the SSR Devices
items:
type: string
type: array
switch_port_usage_dot1x:
description: 'Only if `mode`!=`dynamic`. If dot1x is desired, set to dot1x. enum: `dot1x`'
enum:
- dot1x
type:
- string
- 'null'
site_setting_critical_url_monitoring_monitors:
items:
$ref: '#/components/schemas/site_setting_critical_url_monitoring_monitor'
type: array
snmpv3_config_notify_filter:
items:
$ref: '#/components/schemas/snmpv3_config_notify_filter_item'
type: array
remote_syslog_facility:
default: any
description: 'enum: `any`, `authorization`, `change-log`, `config`, `conflict-log`, `daemon`, `dfc`, `external`, `firewall`, `ftp`, `interactive-commands`, `kernel`, `ntp`, `pfe`, `security`, `user`'
enum:
- any
- authorization
- change-log
- config
- conflict-log
- daemon
- dfc
- external
- firewall
- ftp
- interactive-commands
- kernel
- ntp
- pfe
- security
- user
examples:
- config
type: string
remote_syslog_server_port:
anyOf:
- default: 514
maximum: 65545
minimum: 1
type: integer
- type: string
description: Syslog Service Port, value from 1 to 65535
synthetictest_config_custom_probe:
additionalProperties: false
properties:
aggressiveness:
$ref: '#/components/schemas/synthetictest_config_aggressiveness'
target:
description: Can be URL (e.g. http://x.com, https://x.com:8080/path/to/resource), IP address, or IP:port combination
examples:
- 10.3.5.3:8080
type: string
threshold:
description: In milliseconds
examples:
- 100
type: integer
type:
$ref: '#/components/schemas/synthetictest_config_custom_probe_type'
type: object
switch_vrf_instance:
additionalProperties: false
examples:
- extra_routes:
0.0.0.0/0:
via: 192.168.31.1
networks:
- guest
properties:
aggregate_routes:
$ref: '#/components/schemas/aggregate_routes'
aggregate_routes6:
$ref: '#/components/schemas/aggregate_routes6'
evpn_auto_loopback_subnet:
examples:
- 100.101.0.0/24
type: string
evpn_auto_loopback_subnet6:
type: string
extra_routes:
$ref: '#/components/schemas/vrf_extra_routes'
extra_routes6:
$ref: '#/components/schemas/vrf_extra_routes6'
networks:
$ref: '#/components/schemas/strings'
type: object
evpn_options_overlay:
additionalProperties: false
properties:
as:
default: 65000
description: Overlay BGP Local AS Number
examples:
- 65000
maximum: 65535
minimum: 1
type: integer
type: object
iotproxy:
additionalProperties: false
description: IoT proxy configuration for the site
properties:
enabled:
default: false
type: boolean
visionline:
$ref: '#/components/schemas/iotproxy_visionline'
type: object
site_setting_tunterm_multicast_config:
additionalProperties: false
properties:
mdns:
$ref: '#/components/schemas/site_setting_tunterm_multicast_config_mdns'
multicast_all:
default: false
type: boolean
ssdp:
$ref: '#/components/schemas/site_setting_tunterm_multicast_config_ssdp'
type: object
day_of_week:
description: 'enum: `any`, `fri`, `mon`, `sat`, `sun`, `thu`, `tue`, `wed`'
enum:
- any
- fri
- mon
- sat
- sun
- thu
- tue
- wed
type: string
time_of_day:
default: any
description: '`any` / HH:MM (24-hour format)'
examples:
- '12:00'
type: string
remote_syslog_server:
additionalProperties: false
properties:
contents:
$ref: '#/components/schemas/remote_syslog_contents'
explicit_priority:
type: boolean
facility:
$ref: '#/components/schemas/remote_syslog_facility'
host:
examples:
- syslogd.internal
type: string
match:
examples:
- '!alarm|ntp|errors.crc_error[chan]'
type: string
port:
$ref: '#/components/schemas/remote_syslog_server_port'
protocol:
$ref: '#/components/schemas/remote_syslog_server_protocol'
routing_instance:
examples:
- routing-instance-name
type: string
server_name:
description: Name of the server
examples:
- syslogd.internal
type: string
severity:
$ref: '#/components/schemas/remote_syslog_severity'
source_address:
description: If source_address is configured, will use the vlan firstly otherwise use source_ip
type: string
structured_data:
type: boolean
tag:
type: string
type: object
service_policy_skyatp_dns_dga_detection_profile:
description: 'enum: `default`, `standard`, `strict`'
enum:
- default
- standard
- strict
type: string
gateway_port_config:
additionalProperties: false
description: Gateway port config
properties:
ae_disable_lacp:
default: false
description: If `aggregated`==`true`. To disable LCP support for the AE interface
type: boolean
ae_idx:
description: If `aggregated`==`true`. Users could force to use the designated AE name (must be an integer between 0 and 127)
type:
- string
- 'null'
ae_lacp_force_up:
default: false
description: 'For SRX only, if `aggregated`==`true`.Sets the state of the interface as UP when the peer has limited LACP capability. Use case: When a device connected to this AE port is ZTPing for the first time, it will not have LACP configured on the other end. **Note:** Turning this on will enable force-up on one of the interfaces in the bundle only'
type: boolean
aggregated:
default: false
type: boolean
critical:
default: false
description: To generate port up/down alarm, set it to true
type: boolean
description:
description: Interface Description. Can be a variable (i.e. "{{myvar}}")
type: string
disable_autoneg:
default: false
type: boolean
disabled:
default: false
description: Port admin up (true) / down (false)
type: boolean
dsl_type:
$ref: '#/components/schemas/gateway_port_dsl_type'
dsl_vci:
default: 35
description: If `wan_type`==`dsl`, 16 bit int
type: integer
dsl_vpi:
default: 0
description: If `wan_type`==`dsl`, 8 bit int
type: integer
duplex:
$ref: '#/components/schemas/gateway_port_duplex'
ip_config:
$ref: '#/components/schemas/gateway_port_config_ip_config'
lte_apn:
description: If `wan_type`==`lte`
type: string
lte_auth:
$ref: '#/components/schemas/gateway_port_lte_auth'
lte_backup:
type: boolean
lte_password:
description: If `wan_type`==`lte`
type: string
lte_username:
description: If `wan_type`==`lte`
type: string
mtu:
type: integer
name:
description: Name that we'll use to derive config
type: string
networks:
$ref: '#/components/schemas/gateway_port_networks'
outer_vlan_id:
description: For Q-in-Q
type: integer
poe_disabled:
default: false
type: boolean
poe_keep_state_when_reboot:
default: false
description: Whether Perpetual PoE capabilities are enabled for a port
type: boolean
port_network:
description: Only for SRX and if `usage`==`lan`, the name of the Network to be used as the Untagged VLAN
type: string
preserve_dscp:
default: true
description: Whether to preserve dscp when sending traffic over VPN (SSR-only)
type: boolean
redundant:
description: If HA mode
type: boolean
redundant_group:
description: If HA mode, SRX Only - support redundancy-group. 1-128 for physical SRX, 1-64 for virtual SRX
maximum: 128
minimum: 1
type: integer
reth_idx:
$ref: '#/components/schemas/gateway_port_config_reth_idx'
reth_node:
description: If HA mode
type: string
reth_nodes:
$ref: '#/components/schemas/gateway_port_reth_nodes'
speed:
default: auto
examples:
- 1g
type: string
ssr_no_virtual_mac:
default: false
description: When SSR is running as VM, this is required on certain hosting platforms
type: boolean
svr_port_range:
default: none
description: For SSR only
examples:
- 60000-60005
type: string
traffic_shaping:
$ref: '#/components/schemas/gateway_traffic_shaping'
usage:
$ref: '#/components/schemas/gateway_port_usage'
vlan_id:
$ref: '#/components/schemas/gateway_port_vlan_id_with_variable'
vpn_paths:
$ref: '#/components/schemas/gateway_port_vpn_paths'
wan_arp_policer:
$ref: '#/components/schemas/gateway_port_wan_arp_policer'
wan_ext_ip:
description: Only if `usage`==`wan`, optional. If spoke should reach this port by a different IP
examples:
- 64.2.4.3
type: string
wan_ext_ip6:
description: Only if `usage`==`wan`, optional. If spoke should reach this port by a different IPv6
examples:
- 2601:1700:43c0:dc0::10
type: string
wan_extra_routes:
additionalProperties:
$ref: '#/components/schemas/wan_extra_routes'
description: Only if `usage`==`wan`. Property Key is the destination CIDR (e.g. "100.100.100.0/24")
type: object
wan_extra_routes6:
additionalProperties:
$ref: '#/components/schemas/wan_extra_routes6'
description: Only if `usage`==`wan`. Property Key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
type: object
wan_networks:
$ref: '#/components/schemas/gateway_port_config_wan_networks'
wan_probe_override:
$ref: '#/components/schemas/gateway_wan_probe_override'
wan_source_nat:
$ref: '#/components/schemas/gateway_port_wan_source_nat'
wan_speedtest_mode:
$ref: '#/components/schemas/gateway_port_config_wan_speedtest_mode'
wan_type:
$ref: '#/components/schemas/gateway_port_wan_type'
required:
- usage
type: object
service_policy:
additionalProperties: false
properties:
action:
$ref: '#/components/schemas/allow_deny'
antivirus:
$ref: '#/components/schemas/service_policy_antivirus'
appqoe:
$ref: '#/components/schemas/service_policy_appqoe'
ewf:
$ref: '#/components/schemas/service_policy_ewf'
idp:
$ref: '#/components/schemas/idp_config'
local_routing:
description: access within the same VRF
type: boolean
name:
type: string
path_preference:
description: By default, we derive all paths available and use them. Optionally, you can customize by using `path_preference`
type: string
secintel:
$ref: '#/components/schemas/service_policy_secintel'
servicepolicy_id:
description: Used to link servicepolicy defined at org level and overwrite some attributes
format: uuid
type: string
services:
$ref: '#/components/schemas/strings'
skyatp:
$ref: '#/components/schemas/service_policy_skyatp'
ssl_proxy:
$ref: '#/components/schemas/service_policy_ssl_proxy'
syslog:
$ref: '#/components/schemas/service_policy_syslog'
tenants:
$ref: '#/components/schemas/strings'
type: object
site_setting_auto_placement:
additionalProperties: false
description: If we're able to determine its x/y/orientation, this will be populated
properties:
orientation:
examples:
- 45
type: integer
x:
examples:
- 30
format: double
type: number
y:
examples:
- 60
format: double
type: number
type: object
snmpv3_config_notify_type:
description: 'enum: `inform`, `trap`'
enum:
- inform
- trap
type: string
gateway_wan_probe_override_probe_profile:
default: broadband
description: 'enum: `broadband`, `lte`'
enum:
- broadband
- lte
type: string
synthetictest_config_aggressiveness:
default: auto
description: 'enum: `auto`, `high`, `low`'
enum:
- auto
- high
- med
- low
type: string
synthetictest_config_vlan_vlan_ids:
examples:
- - 10
- 20
- '{{vlan}}'
items:
$ref: '#/components/schemas/vlan_id_with_variable'
type: array
tunnel_config_local_subnets:
description: List of Local protected subnet for policy-based IPSec negotiation
items:
type: string
type: array
gateway_port_usage:
description: 'port usage name. enum: `ha_control`, `ha_data`, `lan`, `wan`'
enum:
- ha_control
- ha_data
- lan
- wan
type: string
tacacs_acct_server:
additionalProperties: false
properties:
host:
type: string
port:
type: string
secret:
format: password
type: string
timeout:
default: 10
type: integer
type: object
site_engagement_dwell_tag_names:
additionalProperties: false
description: Name associated to each tag
properties:
bounce:
default: Visitor
examples:
- Bounce
type: string
engaged:
default: Associates
examples:
- Engaged
type: string
passerby:
default: Passerby
examples:
- Passer By
type: string
stationed:
default: Assets
examples:
- Stationed
type: string
type: object
evpn_options_vs_instances:
additionalProperties:
$ref: '#/components/schemas/evpn_options_vs_instance'
description: Optional, for EX9200 only to segregate virtual-switches
examples:
- guest:
networks:
- guest
iot:
networks:
- iot-wifi
- iot-lan
type: object
dhcpd_config_type:
default: local
description: 'enum: `local` (DHCP Server), `none`, `relay` (DHCP Relay)'
enum:
- local
- none
- relay
type: string
switch_port_usage_networks:
description: Only if `mode`==`trunk`, the list of network/vlans
items:
type: string
type: array
protect_re_custom_subnet:
items:
examples:
- 10.1.2.0/24
type: string
type: array
gw_routing_policy_term_action:
additionalProperties: false
description: When used as import policy
properties:
accept:
type: boolean
add_community:
$ref: '#/components/schemas/gw_routing_policy_term_action_add_community'
add_target_vrfs:
$ref: '#/components/schemas/gw_routing_policy_term_action_add_target_vrfs'
community:
$ref: '#/components/schemas/routing_policy_term_action_community'
exclude_as_path:
$ref: '#/components/schemas/gw_routing_policy_term_action_exclude_as_path'
exclude_community:
$ref: '#/components/schemas/gw_routing_policy_term_action_exclude_community'
export_communities:
$ref: '#/components/schemas/gw_routing_policy_term_action_export_communities'
local_preference:
$ref: '#/components/schemas/routing_policy_local_preference'
prepend_as_path:
$ref: '#/components/schemas/routing_policy_term_action_prepend_as_path'
type: object
switch_port_mirroring_egress_port_ids:
description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified
items:
examples:
- ge-0/0/3
type: string
type: array
ssr_proxy:
additionalProperties: false
description: SSR proxy configuration to talk to Mist
properties:
disabled:
default: false
examples:
- true
type: boolean
url:
examples:
- https://proxy.corp.com:8080/
type: string
type: object
gateway_ip_configs:
additionalProperties:
$ref: '#/components/schemas/gateway_ip_config_property'
description: Property key is the network name
type: object
gateway_path_type:
description: 'enum: `local`, `tunnel`, `vpn`, `wan`'
enum:
- local
- tunnel
- vpn
- wan
type: string
tunnel_config_remote_subnets:
description: List of Remote protected subnet for policy-based IPSec negotiation
items:
type: string
type: array
site_setting_rtsa:
additionalProperties: false
description: Managed mobility
properties:
app_waking:
default: false
type: boolean
disable_dead_reckoning:
type: boolean
disable_pressure_sensor:
default: false
type: boolean
enabled:
type: boolean
track_asset:
default: false
description: Asset tracking related
type: boolean
type: object
site_setting_status_portal_hostnames:
items:
examples:
- my.misty.com
type: string
type: array
snmp_vacm_security_to_group_content_item:
additionalProperties: false
properties:
group:
description: Refer to group_name under access
type: string
security_name:
type: string
type: object
site_setting_skyatp:
additionalProperties: false
properties:
enabled:
type: boolean
send_ip_mac_mapping:
default: false
description: Whether to send IP-MAC mapping to SkyATP
type: boolean
type: object
tunnel_provider_options_zscaler_sub_location:
additionalProperties: false
properties:
aup_block_internet_until_accepted:
default: false
type: boolean
aup_enabled:
default: false
description: Can only be `true` when `auth_required`==`false`, display Acceptable Use Policy (AUP)
type: boolean
aup_force_ssl_inspection:
default: false
description: Proxy HTTPs traffic, requiring Zscaler cert to be installed in browser
type: boolean
aup_timeout_in_days:
description: Required if `aup_enabled`==`true`. Days before AUP is requested again
maximum: 180
minimum: 1
type: integer
auth_required:
default: false
description: Enable this option to authenticate users
type: boolean
caution_enabled:
default: false
description: Can only be `true` when `auth_required`==`false`, display caution notification for non-authenticated users
type: boolean
dn_bandwidth:
description: Download bandwidth cap of the link, in Mbps. Disabled if not set
examples:
- 200
format: double
maximum: 99999
minimum: 0.1
type:
- number
- 'null'
idle_time_in_minutes:
description: Required if `surrogate_IP`==`true`, idle Time to Disassociation
maximum: 43200
minimum: 0
type: integer
name:
description: '[network]($h/Orgs%20Networks/_overview) name'
type: string
ofw_enabled:
default: false
description: If `true`, enable the firewall control option
type: boolean
surrogate_IP:
default: false
description: Can only be `true` when `auth_required`==`true`. Map a user to a private IP address so it applies the user's policies, instead of the location's policies
type: boolean
surrogate_IP_enforced_for_known_browsers:
description: Can only be `true` when `surrogate_IP`==`true`, enforce surrogate IP for known browsers
type: boolean
surrogate_refresh_time_in_minutes:
description: Required if `surrogate_IP_enforced_for_known_browsers`==`true`, must be lower or equal than `idle_time_in_minutes`, refresh Time for re-validation of Surrogacy
maximum: 43200
minimum: 1
type: integer
up_bandwidth:
description: Download bandwidth cap of the link, in Mbps. Disabled if not set
examples:
- 200
format: double
maximum: 99999
minimum: 0.1
type:
- number
- 'null'
type: object
account_oauth_info_account_regions:
additionalProperties:
$ref: '#/components/schemas/account_oauth_info_account_region'
description: For Prisma accounts only, property key is the region name. Regions with allocated bandwidth
type: object
snmpv3_config_notify_items:
additionalProperties: false
properties:
name:
type: string
tag:
type: string
type:
$ref: '#/components/schemas/snmpv3_config_notify_type'
type: object
gateway_ip_config_property:
additionalProperties: false
properties:
ip:
format: ipv4
type: string
ip6:
format: ipv6
type: string
netmask:
examples:
- /24
type: string
netmask6:
examples:
- 2001:db8:abcd:12::1
type: string
secondary_ips:
$ref: '#/components/schemas/gateway_ip_config_property_second_ips'
type:
$ref: '#/components/schemas/ip_type'
type6:
$ref: '#/components/schemas/ip_type6'
type: object
switch_radius:
additionalProperties: false
description: By default, `radius_config` will be used. if a different one has to be used set `use_different_radius
properties:
enabled:
type: boolean
radius_config:
$ref: '#/components/schemas/switch_radius_config'
use_different_radius:
type: string
type: object
acl_tag_type:
description: "enum: \n * `any`: matching anything not identified\n * `dynamic_gbp`: from the gbp_tag received from RADIUS\n * `gbp_resource`: can only be used in `dst_tags`\n * `mac`\n * `network`\n * `port_usage`\n * `radius_group`\n * `resource`: can only be used in `dst_tags`\n * `static_gbp`: applying gbp tag against matching conditions\n * `subnet`'"
enum:
- any
- dynamic_gbp
- gbp_resource
- mac
- network
- port_usage
- radius_group
- resource
- static_gbp
- subnet
type: string
site_mxtunnel_protocol:
description: 'enum: `ip`, `udp`'
enum:
- ip
- udp
examples:
- udp
type: string
radio_band_antenna_beam_pattern:
description: 'enum: `narrow`, `medium`, `wide`'
enum:
- narrow
- medium
- wide
type: string
site_rogue_whitelisted_bssids:
description: 'list of BSSIDs to whitelist. Ex: "cc-:8e-:6f-:d4-:bf-:16", "cc-8e-6f-d4-bf-16", "cc-73-*", "cc:82:*"'
examples:
- - NeighborSSID
items:
type: string
type: array
site_wifi:
additionalProperties: false
description: Wi-Fi site settings
properties:
cisco_enabled:
default: true
type: boolean
disable_11k:
default: false
description: Whether to disable 11k
type: boolean
disable_radios_when_power_constrained:
default: false
type: boolean
enable_arp_spoof_check:
default: false
description: When proxy_arp is enabled, check for arp spoofing.
type: boolean
enable_shared_radio_scanning:
default: true
type: boolean
enabled:
default: true
description: Enable Wi-Fi feature (using SUB-MAN license)
type: boolean
locate_connected:
default: true
description: Whether to locate connected clients
type: boolean
locate_unconnected:
default: false
description: Whether to locate unconnected clients
type: boolean
mesh_allow_dfs:
default: false
description: Whether to allow Mesh to use DFS channels. For DFS channels, Remote Mesh AP would have to do CAC when scanning for new Base AP, which is slow and will disrupt the connection. If roaming is desired, keep it disabled.
type: boolean
mesh_enable_crm:
default: false
description: Used to enable/disable CRM
type: boolean
mesh_enabled:
default: false
description: Whether to enable Mesh feature for the site
type: boolean
mesh_psk:
description: Optional passphrase of mesh networking, default is generated randomly
type:
- string
- 'null'
mesh_ssid:
description: Optional ssid of mesh networking, default is based on site_id
type:
- string
- 'null'
proxy_arp:
$ref: '#/components/schemas/site_wifi_proxy_arp'
type: object
ospf_area_type:
default: default
description: 'OSPF type. enum: `default`, `nssa`, `stub`'
enum:
- default
- nssa
- stub
examples:
- default
type: string
site_occupancy_analytics:
additionalProperties: false
description: Occupancy Analytics settings
properties:
assets_enabled:
default: false
description: Indicate whether named BLE assets should be included in the zone occupancy calculation
type: boolean
clients_enabled:
default: true
description: Indicate whether connected Wi-Fi clients should be included in the zone occupancy calculation
type: boolean
min_duration:
default: 3000
description: Minimum duration
examples:
- 3000
type: integer
sdkclients_enabled:
default: false
description: Indicate whether SDK clients should be included in the zone occupancy calculation
type: boolean
unconnected_clients_enabled:
default: false
description: Indicate whether unconnected Wi-Fi clients should be included in the zone occupancy calculation
type: boolean
type: object
tunnel_config_auto_provision_node:
properties:
probe_ips:
$ref: '#/components/schemas/strings'
wan_names:
$ref: '#/components/schemas/tunnel_config_auto_provision_node_wan_names'
idp_profile_overwrites:
items:
$ref: '#/components/schemas/idp_profile_overwrite'
type: array
network_vpn_access:
additionalProperties:
$ref: '#/components/schemas/network_vpn_access_config'
description: Property key is the VPN name. Whether this network can be accessed from vpn
type: object
network_vpn_access_destination_nat:
additionalProperties:
$ref: '#/components/schemas/network_vpn_access_destination_nat_property'
description: Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.16.0.0/30"), an External CIDR:Port (i.e. "63.16.0.0/30:443") or a Variable (i.e. "{{myvar}}"). At least one of the `internal_ip` or `port` must be defined
type: object
additional_vlan_ids_array:
items:
$ref: '#/components/schemas/vlan_id_with_variable'
type: array
switch_matching_rules:
items:
$ref: '#/components/schemas/switch_matching_rule'
type: array
uniqueItems: true
acl_tag_spec:
additionalProperties: false
properties:
port_range:
default: '0'
description: Matched dst port, "0" means any
type: string
protocol:
default: any
description: '`tcp` / `udp` / `icmp` / `icmp6` / `gre` / `any` / `:protocol_number`, `protocol_number` is between 1-254, default is `any` `protocol_number` is between 1-254'
type: string
type: object
dhcpd_config_property:
additionalProperties: false
properties:
dns_servers:
$ref: '#/components/schemas/dhcpd_config_dns_servers'
dns_suffix:
$ref: '#/components/schemas/dhcpd_config_dns_suffix'
fixed_bindings:
$ref: '#/components/schemas/dhcpd_config_fixed_bindings'
gateway:
description: If `type`==`local` - optional, `ip` will be used if not provided
examples:
- 192.168.70.1
type: string
ip6_end:
description: If `type6`==`local`
examples:
- 2607:f8b0:4005:808::ff
type: string
ip6_start:
description: If `type6`==`local`
examples:
- 2607:f8b0:4005:808::2
type: string
ip_end:
description: If `type`==`local`
examples:
- 192.168.70.200
type: string
ip_start:
description: If `type`==`local`
examples:
- 192.168.70.100
type: string
lease_time:
default: 86400
description: In seconds, lease time has to be between 3600 [1hr] - 604800 [1 week], default is 86400 [1 day]
maximum: 604800
minimum: 3600
type: integer
options:
$ref: '#/components/schemas/dhcpd_config_options'
server_id_override:
default: false
description: "`server_id_override`==`true` means the device, when acts as DHCP relay and forwards DHCP responses from DHCP server to clients, \nshould overwrite the Sever Identifier option (i.e. DHCP option 54) in DHCP responses with its own IP address."
type: boolean
servers:
$ref: '#/components/schemas/dhcpd_config_servers'
serversv6:
$ref: '#/components/schemas/dhcpd_config_servers6'
type:
$ref: '#/components/schemas/dhcpd_config_type'
type6:
$ref: '#/components/schemas/dhcpd_config_type6'
vendor_encapsulated:
$ref: '#/components/schemas/dhcpd_config_vendor_options'
type: object
iotproxy_visionline:
additionalProperties: false
description: Visionline integration settings for IoT proxy
properties:
access_id:
description: Access ID for the Visionline service
examples:
- 790e6c1790e6c18541d
type: string
enabled:
default: false
type: boolean
host:
description: Hostname or IP of the Visionline collector
examples:
- visionline_collector1.local
type: string
password:
description: Password for the Visionline service
format: password
type: string
port:
default: 443
description: TCP port of the Visionline collector
type: integer
username:
description: Username for the Visionline service
examples:
- card_administrator
type: string
type: object
sw_routing_policy_terms:
description: at least criteria/filter must be specified to match the term, all criteria have to be met
items:
$ref: '#/components/schemas/sw_routing_policy_term'
minItems: 1
type: array
uniqueItems: true
service_policy_syslog:
additionalProperties: false
description: Required for syslog logging
properties:
enabled:
default: false
type: boolean
server_names:
examples:
- - dc_syslog_server
items:
type: string
type: array
type: object
gateway_path_preferences_path_networks:
description: Required when `type`==`local`
items:
type: string
type: array
ssl_proxy_ciphers_category:
default: strong
description: 'enum: `medium`, `strong`, `weak`'
enum:
- medium
- strong
- weak
type: string
switch_stp_config:
additionalProperties: false
properties:
bridge_priority:
default: 32k
description: Switch STP priority. Range [0, 4k, 8k.. 60k] in steps of 4k. Bridge priority applies to both VSTP and RSTP.
examples:
- 40k
type: string
type: object
snmp_config_views:
items:
$ref: '#/components/schemas/snmp_config_view'
type: array
site_setting_critical_url_monitoring_monitor:
additionalProperties: false
properties:
url:
examples:
- http://50.1.3.5:8080
type: string
vlan_id:
$ref: '#/components/schemas/vlan_id_with_variable'
type: object
gw_routing_policy_term_action_export_communities:
description: When used as export policy, optional
items:
type: string
type: array
site_setting_ap_port_config:
additionalProperties: false
properties:
model_specific:
additionalProperties:
additionalProperties:
$ref: '#/components/schemas/ap_port_config'
description: Property key is the interface(s) (e.g. "eth1,eth2")
type: object
description: Property key is the AP model (e.g. "AP32")
examples:
- AP32:
eth1,eth2:
port_vlan_id: 1
vlan_ids:
- 1
- 10
- 50
type: object
type: object
mxcluster_radsec_acct_server:
additionalProperties: false
properties:
host:
description: IP / hostname of RADIUS server
type: string
port:
default: 1813
description: Acct port of RADIUS server
type: integer
secret:
description: Secret of RADIUS server
format: password
type: string
ssids:
$ref: '#/components/schemas/mxcluster_radsec_acct_server_ssids'
type: object
switch_port_usage_dynamic_rule:
additionalProperties: false
properties:
description:
description: Optional description of the rule
type: string
equals:
type: string
equals_any:
$ref: '#/components/schemas/switch_port_usage_dynamic_rule_equals_any'
expression:
description: '"[0:3]":"abcdef" -> "abc"
"split(.)[1]": "a.b.c" -> "b"
"split(-)[1][0:3]: "a1234-b5678-c90" -> "b56"'
type: string
src:
$ref: '#/components/schemas/switch_port_usage_dynamic_rule_src'
usage:
description: '`port_usage` name'
type: string
required:
- src
type: object
remote_syslog_users:
items:
$ref: '#/components/schemas/remote_syslog_user'
type: array
gw_routing_policy_term_matching_route_exists:
additionalProperties: false
properties:
route:
examples:
- 192.168.0.0/24
type: string
vrf_name:
default: default
description: Name of the vrf instance, it can also be the name of the VPN or wan if they
type: string
type: object
mist_nacedge_mxedge_hosts:
description: List of NAC Edges in this site
examples:
- - mxedge1.local
items:
type: string
type: array
created_time:
description: When the object has been created, in epoch
format: double
readOnly: true
type: number
mac_addresses_macs:
examples:
- - 683b679ac024
items:
type: string
minItems: 1
type: array
uniqueItems: true
vars_annotations:
additionalProperties:
$ref: '#/components/schemas/vars_annotation'
description: Optional annotations for vars defined in this site. Keys match var names; values describe the var purpose and type for UI auto-complete.
examples:
- MXTUNNEL_GUEST:
type: mxtunnel_id
RADIUS_IP1:
note: RADIUS server IP address for US East Campus
type: object
switch_port_usage:
additionalProperties: false
description: Junos port usages
properties:
all_networks:
default: false
description: Only if `mode`==`trunk`. Whether to trunk all network/vlans
type: boolean
allow_dhcpd:
description: 'Only applies when `mode`!=`dynamic`. Controls whether DHCP server traffic is allowed on ports using this configuration if DHCP snooping is enabled. This is a tri-state setting; `true`: ports become trusted ports allowing DHCP server traffic, `false`: ports become untrusted blocking DHCP server traffic, undefined: use system defaults (access ports default to untrusted, trunk ports default to trusted).'
type: boolean
allow_multiple_supplicants:
default: false
description: Only if `mode`!=`dynamic`
type: boolean
bypass_auth_when_server_down:
default: false
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Bypass auth for known clients if set to true when RADIUS server is down
type: boolean
bypass_auth_when_server_down_for_unknown_client:
default: false
description: Only if `mode`!=`dynamic` and `port_auth`=`dot1x`. Bypass auth for all (including unknown clients) if set to true when RADIUS server is down
type: boolean
bypass_auth_when_server_down_for_voip:
default: false
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Bypass auth for VOIP if set to true when RADIUS server is down
type: boolean
community_vlan_id:
description: Only if `mode`!=`dynamic`. To be used together with `isolation` under networks. Signaling that this port connects to the networks isolated but wired clients belong to the same community can talk to each other
type: integer
description:
description: Only if `mode`!=`dynamic`
type: string
disable_autoneg:
default: false
description: Only if `mode`!=`dynamic`. If speed and duplex are specified, whether to disable autonegotiation
type: boolean
disabled:
default: false
description: Only if `mode`!=`dynamic`. Whether the port is disabled
type: boolean
duplex:
$ref: '#/components/schemas/switch_port_usage_duplex'
dynamic_vlan_networks:
$ref: '#/components/schemas/switch_port_usage_dynamic_vlan_networks'
enable_mac_auth:
default: false
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Whether to enable MAC Auth
type: boolean
enable_qos:
default: false
description: Only if `mode`!=`dynamic`
type: boolean
guest_network:
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Which network to put the device into if the device cannot do dot1x. default is null (i.e. not allowed)
type:
- string
- 'null'
inter_isolation_network_link:
default: false
description: Only if `mode`!=`dynamic`. `inter_isolation_network_link` is used together with `isolation` under networks, signaling that this port connects to isolated networks
type: boolean
inter_switch_link:
default: false
description: 'Only if `mode`!=`dynamic`. `inter_switch_link` is used together with `isolation` under networks. NOTE: `inter_switch_link` works only between Juniper devices. This has to be applied to both ports connected together'
type: boolean
mac_auth_only:
description: Only if `mode`!=`dynamic` and `enable_mac_auth`==`true`
type: boolean
mac_auth_preferred:
description: Only if `mode`!=`dynamic` + `enable_mac_auth`==`true` + `mac_auth_only`==`false`, dot1x will be given priority then mac_auth. Enable this to prefer mac_auth over dot1x.
type: boolean
mac_auth_protocol:
$ref: '#/components/schemas/switch_port_usage_mac_auth_protocol'
mac_limit:
$ref: '#/components/schemas/switch_port_usage_mac_limit'
mode:
$ref: '#/components/schemas/switch_port_usage_mode'
mtu:
$ref: '#/components/schemas/switch_port_usage_mtu'
networks:
$ref: '#/components/schemas/switch_port_usage_networks'
persist_mac:
default: false
description: Only if `mode`==`access` and `port_auth`!=`dot1x`. Whether the port should retain dynamically learned MAC addresses
type: boolean
poe_disabled:
default: false
description: Only if `mode`!=`dynamic`. Whether PoE capabilities are disabled for a port
type: boolean
poe_keep_state_when_reboot:
default: false
description: Only if `mode`!=`dynamic`. Whether Perpetual PoE is enabled; keeps PoE state across reboots
type: boolean
poe_priority:
$ref: '#/components/schemas/poe_priority'
port_auth:
$ref: '#/components/schemas/switch_port_usage_dot1x'
port_network:
description: Only if `mode`!=`dynamic`. Native network/vlan for untagged traffic
type: string
reauth_interval:
$ref: '#/components/schemas/switch_port_usage_reauth_interval'
reset_default_when:
$ref: '#/components/schemas/switch_port_usage_dynamic_reset_default_when'
rules:
$ref: '#/components/schemas/switch_port_usage_dynamic_rules'
server_fail_network:
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. Sets server fail fallback vlan
type:
- string
- 'null'
server_reject_network:
description: Only if `mode`!=`dynamic` and `port_auth`==`dot1x`. When radius server reject / fails
type:
- string
- 'null'
speed:
$ref: '#/components/schemas/switch_port_usage_speed'
storm_control:
$ref: '#/components/schemas/switch_port_usage_storm_control'
stp_disable:
default: false
description: Only if `mode`!=`dynamic` and `stp_required`==`false`. Drop bridge protocol data units (BPDUs ) that enter any interface or a specified interface
type: boolean
stp_edge:
default: false
description: Only if `mode`!=`dynamic`. When enabled, the port is not expected to receive BPDU frames
type: boolean
stp_no_root_port:
default: false
description: Only if `mode`!=`dynamic`
type: boolean
stp_p2p:
default: false
description: Only if `mode`!=`dynamic`
type: boolean
stp_required:
default: false
description: Only if `mode`!=`dynamic`. Whether to remain in block state if no BPDU is received
type: boolean
ui_evpntopo_id:
description: Optional for Campus Fabric Core-Distribution ESI-LAG profile. Helper used by the UI to select this port profile as the ESI-Lag between Distribution and Access switches
format: uuid
type: string
use_vstp:
default: false
description: If this is connected to a vstp network
type: boolean
voip_network:
description: Only if `mode`!=`dynamic`. Network/vlan for voip traffic, must also set port_network. to authenticate device, set port_auth
type:
- string
- 'null'
type: object
aggregate_routes:
additionalProperties:
$ref: '#/components/schemas/aggregate_route'
description: Property key is the destination subnet (e.g. "172.16.3.0/24")
examples:
- 172.16.3.0/24:
discard: false
metric: null
preference: 30
type: object
snmp_usm_user_encryption_type:
description: 'enum: `privacy-3des`, `privacy-aes128`, `privacy-des`, `privacy-none`'
enum:
- privacy-3des
- privacy-aes128
- privacy-des
- privacy-none
type: string
service_policy_ewf:
items:
$ref: '#/components/schemas/service_policy_ewf_rule'
type: array
remote_syslog_content:
additionalProperties: false
properties:
facility:
$ref: '#/components/schemas/remote_syslog_facility'
severity:
$ref: '#/components/schemas/remote_syslog_severity'
type: object
gateway_vrf_instance:
additionalProperties: false
examples:
- networks:
- CORP_NET
- MGMT_NET
properties:
networks:
$ref: '#/components/schemas/strings'
type: object
mxedge_mgmt_oob_ip_type:
default: dhcp
description: 'enum: `dhcp`, `disabled`, `static`'
enum:
- dhcp
- disabled
- static
type: string
network_tenant:
additionalProperties: false
properties:
addresses:
$ref: '#/components/schemas/network_tenant_addresses'
type: object
setting_ssr_auto_upgrade_custom_versions:
additionalProperties:
description: Firmware version to deploy on the specified SSR model
examples:
- 6.3.0-107.r1
type: string
description: Property key is the SSR model (e.g. "SSR130").
type: object
service_policy_skyatp:
additionalProperties: false
description: SRX only
properties:
dns_dga_detection:
$ref: '#/components/schemas/service_policy_skyatp_dns_dga_detection'
dns_tunnel_detection:
$ref: '#/components/schemas/service_policy_skyatp_dns_tunnel_detection'
http_inspection:
$ref: '#/components/schemas/service_policy_skyatp_http_inspection'
iot_device_policy:
$ref: '#/components/schemas/service_policy_skyatp_iot_device_policy'
type: object
ospf_area:
additionalProperties: false
description: Property key is the OSPF Area (Area should be a number (0-255) / IP address)
properties:
include_loopback:
default: false
type: boolean
networks:
additionalProperties:
$ref: '#/components/schemas/ospf_areas_network'
examples:
- corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: object
type:
$ref: '#/components/schemas/ospf_area_type'
type: object
ble_config:
additionalProperties: false
description: BLE AP settings
properties:
beacon_enabled:
default: true
description: Whether Mist beacons is enabled
type: boolean
beacon_rate:
description: Required if `beacon_rate_mode`==`custom`, 1-10, in number-beacons-per-second
examples:
- 3
type: integer
beacon_rate_mode:
$ref: '#/components/schemas/ble_config_beacon_rate_mode'
beam_disabled:
$ref: '#/components/schemas/ble_config_beam_disabled'
custom_ble_packet_enabled:
default: false
description: Can be enabled if `beacon_enabled`==`true`, whether to send custom packet
type: boolean
custom_ble_packet_frame:
default: ''
description: The custom frame to be sent out in this beacon. The frame must be a hexstring
examples:
- 0x........
type: string
custom_ble_packet_freq_msec:
default: 0
description: Frequency (msec) of data emitted by custom ble beacon
examples:
- 300
minimum: 0
type: integer
eddystone_uid_adv_power:
default: 0
description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default
examples:
- -65
maximum: 20
minimum: -100
type: integer
eddystone_uid_beams:
default: ''
examples:
- 2-4,7
type: string
eddystone_uid_enabled:
default: false
description: Only if `beacon_enabled`==`false`, Whether Eddystone-UID beacon is enabled
type: boolean
eddystone_uid_freq_msec:
default: 0
description: Frequency (msec) of data emit by Eddystone-UID beacon
examples:
- 200
type: integer
eddystone_uid_instance:
default: ''
description: Eddystone-UID instance for the device
examples:
- 5c5b35000001
type: string
eddystone_uid_namespace:
default: ''
description: Eddystone-UID namespace
examples:
- 2818e3868dec25629ede
type: string
eddystone_url_adv_power:
default: 0
description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default
examples:
- -65
maximum: 20
minimum: -100
type: integer
eddystone_url_beams:
default: ''
examples:
- 2-4,7
type: string
eddystone_url_enabled:
default: false
description: Only if `beacon_enabled`==`false`, Whether Eddystone-URL beacon is enabled
type: boolean
eddystone_url_freq_msec:
default: 0
description: Frequency (msec) of data emit by Eddystone-UID beacon
examples:
- 1000
type: integer
eddystone_url_url:
default: ''
description: URL pointed by Eddystone-URL beacon
examples:
- https://www.abc.com
type: string
ibeacon_adv_power:
default: 0
description: Advertised TX Power, -100 to 20 (dBm), omit this attribute to use default
examples:
- -65
maximum: 20
minimum: -100
type: integer
ibeacon_beams:
default: ''
examples:
- 2-4,7
type: string
ibeacon_enabled:
default: false
description: Can be enabled if `beacon_enabled`==`true`, whether to send iBeacon
type: boolean
ibeacon_freq_msec:
default: 0
description: Frequency (msec) of data emit for iBeacon
type: integer
ibeacon_major:
$ref: '#/components/schemas/ibeacon_major'
ibeacon_minor:
$ref: '#/components/schemas/ibeacon_minor'
ibeacon_uuid:
default: ''
description: Optional, if not specified, the same UUID as the beacon will be used
examples:
- f3f17139-704a-f03a-2786-0400279e37c3
format: uuid
type: string
power:
default: 9
description: Required if `power_mode`==`custom`; else use `power_mode` as default
examples:
- 6
maximum: 10
minimum: 1
type: integer
power_mode:
$ref: '#/components/schemas/ble_config_power_mode'
type: object
switch_port_usage_dynamic_rule_src:
description: 'enum: `link_peermac`, `lldp_chassis_id`, `lldp_hardware_revision`, `lldp_manufacturer_name`, `lldp_oui`, `lldp_serial_number`, `lldp_system_description`, `lldp_system_name`, `radius_dynamicfilter`, `radius_usermac`, `radius_username`'
enum:
- link_peermac
- lldp_chassis_id
- lldp_hardware_revision
- lldp_manufacturer_name
- lldp_oui
- lldp_serial_number
- lldp_system_description
- lldp_system_name
- radius_dynamicfilter
- radius_usermac
- radius_username
type: string
dhcpd_config_option_type:
description: 'enum: `boolean`, `hex`, `int16`, `int32`, `ip`, `string`, `uint16`, `uint32`'
enum:
- boolean
- hex
- int16
- int32
- ip
- string
- uint16
- uint32
type: string
tunnel_via:
default: primary
description: 'If `via`==`tunnel`, specifies which tunnel (primary/secondary) this neighbor is associated with. enum: `primary`, `secondary`'
enum:
- primary
- secondary
type: string
mxedge_mgmt:
additionalProperties: false
properties:
config_auto_revert:
default: false
type: boolean
fips_enabled:
default: false
type: boolean
mist_password:
examples:
- MIST_PASSWORD
type: string
oob_ip_type:
$ref: '#/components/schemas/mxedge_mgmt_oob_ip_type'
oob_ip_type6:
$ref: '#/components/schemas/mxedge_mgmt_oob_ip_type6'
root_password:
examples:
- ROOT_PASSWORD
format: password
type: string
type: object
tunnel_config_node_wan_names:
items:
type: string
type: array
mac_addresses:
properties:
macs:
$ref: '#/components/schemas/mac_addresses_macs'
required:
- macs
type: object
wired_port_config:
additionalProperties:
$ref: '#/components/schemas/junos_port_config'
description: Property key is the port name or range (e.g. "ge-0/0/0-10")
type: object
mxcluster_nac_client_ip:
additionalProperties: false
properties:
require_message_authenticator:
default: false
description: Whether to require Message-Authenticator in requests
type: boolean
secret:
description: If different from above
type: string
site_id:
description: Present only for 3rd party clients
examples:
- 00000000-0000-0000-1234-000000000000
format: uuid
type: string
vendor:
$ref: '#/components/schemas/mxcluster_nac_client_vendor'
type: object
site_setting_tunterm_multicast_config_ssdp:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
vlan_ids:
$ref: '#/components/schemas/mxedge_tunterm_multicast_config_ssdp_vlan_ids'
type: object
bgp_as:
anyOf:
- type: string
- maximum: 4294967294
minimum: 1
type: integer
description: BGP AS, value in range 1-4294967294. Can be a Variable (e.g. `{{bgp_as}}` )
examples:
- 65000
gw_routing_policy_term_matching:
additionalProperties: false
description: zero or more criteria/filter can be specified to match the term, all criteria have to be met
properties:
as_path:
$ref: '#/components/schemas/routing_policy_term_matching_as_path'
community:
$ref: '#/components/schemas/routing_policy_term_matching_community'
network:
$ref: '#/components/schemas/strings'
prefix:
$ref: '#/components/schemas/routing_policy_term_matching_prefix'
protocol:
$ref: '#/components/schemas/gw_routing_policy_term_matching_protocol'
route_exists:
$ref: '#/components/schemas/gw_routing_policy_term_matching_route_exists'
vpn_neighbor_mac:
$ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_neighbor_mac'
vpn_path:
$ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_path'
vpn_path_sla:
$ref: '#/components/schemas/gw_routing_policy_term_matching_vpn_path_sla'
type: object
ap_port_config:
additionalProperties: false
properties:
disabled:
default: false
type: boolean
dynamic_vlan:
$ref: '#/components/schemas/ap_port_config_dynamic_vlan'
enable_mac_auth:
default: false
type: boolean
forwarding:
$ref: '#/components/schemas/ap_port_config_forwarding'
mac_auth_preferred:
default: false
description: When `true`, we'll do dot1x then mac_auth. enable this to prefer mac_auth
type: boolean
mac_auth_protocol:
$ref: '#/components/schemas/ap_port_config_mac_auth_protocol'
mist_nac:
$ref: '#/components/schemas/wlan_mist_nac'
mx_tunnel_id:
default: ''
description: If `forwarding`==`mxtunnel`, vlan_ids comes from mxtunnel
examples:
- 08cd7499-5841-51c8-e663-fb16b6f3b45e
format: uuid
type: string
mxtunnel_name:
default: ''
description: If `forwarding`==`site_mxedge`, vlan_ids comes from site_mxedge (`mxtunnels` under site setting)
type: string
port_auth:
$ref: '#/components/schemas/ap_port_config_port_auth'
port_vlan_id:
description: If `forwarding`==`limited`
examples:
- 1
maximum: 4094
minimum: 1
type: integer
radius_config:
$ref: '#/components/schemas/radius_config'
radsec:
$ref: '#/components/schemas/radsec'
vlan_id:
description: "Optional to specify the vlan id for a tunnel if forwarding is for `wxtunnel`, `mxtunnel` or `site_mxedge`.\n * if vlan_id is not specified then it will use first one in vlan_ids[] of the mxtunnel.\n * if forwarding == site_mxedge, vlan_ids comes from site_mxedge (`mxtunnels` under site setting)"
examples:
- 9
maximum: 4094
minimum: 1
type: integer
vlan_ids:
description: If `forwarding`==`limited`, comma separated list of additional vlan ids allowed on this port
examples:
- 10,20,30
type: string
wxtunnel_id:
default: ''
description: If `forwarding`==`wxtunnel`, the port is bridged to the vlan of the session
examples:
- 7dae216d-7c98-a51b-e068-dd7d477b7216
format: uuid
type: string
wxtunnel_remote_id:
default: ''
description: If `forwarding`==`wxtunnel`, the port is bridged to the vlan of the session
examples:
- wifiguest
type: string
type: object
gw_routing_policy:
additionalProperties: false
properties:
terms:
$ref: '#/components/schemas/gw_routing_policy_terms'
type: object
mxcluster_radsec_auth_servers:
description: List of RADIUS authentication servers, order matters where the first one is treated as primary
items:
$ref: '#/components/schemas/mxcluster_radsec_auth_server'
type: array
uniqueItems: true
switch_mgmt_mxedge_proxy_port:
anyOf:
- default: 2222
maximum: 65535
minimum: 1
type: integer
- type: string
description: Mist Edge port used to proxy the switch management traffic to the Mist Cloud. Value in range 1-65535
remote_syslog_files:
items:
$ref: '#/components/schemas/remote_syslog_file_config'
type: array
snmp_config_view:
additionalProperties: false
properties:
include:
description: If the root oid configured is included
type: boolean
oid:
examples:
- 1.3.6.1
type: string
view_name:
examples:
- all
type: string
type: object
response_http429:
additionalProperties: false
properties:
detail:
examples:
- Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
type: string
type: object
ap_port_config_dynamic_vlan:
additionalProperties: false
description: Optional dynamic vlan
properties:
default_vlan_id:
examples:
- 999
maximum: 4094
minimum: 1
type: integer
enabled:
type: boolean
type:
type: string
vlans:
additionalProperties:
type:
- string
- 'null'
examples:
- 1-10: null
user: null
type: object
type: object
idp_profile_action:
default: alert
description: "enum:\n * alert (default)\n * drop: silently dropping packets\n * close: notify client/server to close connection"
enum:
- alert
- close
- drop
examples:
- alert
type: string
gateway_vrf_instances:
additionalProperties:
$ref: '#/components/schemas/gateway_vrf_instance'
description: Property key is the network name
examples:
- CORP_VRF:
networks:
- CORP_NET
- MGMT_NET
type: object
gateway_traffic_shaping_class_percentages:
description: 'percentages for different class of traffic: high / medium / low / best-effort. Sum must be equal to 100'
items:
type: integer
type: array
site_setting_paloalto_networks_gateways:
items:
$ref: '#/components/schemas/site_setting_paloalto_network_gateway'
type: array
acl_policy:
additionalProperties: false
description: "ACL Policy:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to"
properties:
actions:
$ref: '#/components/schemas/acl_policy_actions'
name:
examples:
- guest access
type: string
src_tags:
$ref: '#/components/schemas/acl_policy_src_tags'
type: object
wan_extra_routes:
additionalProperties: false
properties:
via:
format: ipv4
type: string
type: object
service_policy_secintel:
additionalProperties: false
description: SRX only
properties:
enabled:
default: false
type: boolean
profile:
$ref: '#/components/schemas/service_policy_secintel_profile'
secintelprofile_id:
description: org-level secintel Profile can be used, this takes precedence over 'profile'
type: string
type: object
tunterm_monitoring_protocol:
description: 'enum: `arp`, `ping`, `tcp`'
enum:
- arp
- ping
- tcp
examples:
- tcp
minLength: 1
type: string
gw_routing_policy_term_action_exclude_as_path:
description: When used as export policy, optional. To exclude certain AS
items:
examples:
- '65002'
type: string
type: array
switch_mgmt:
additionalProperties: false
description: Switch Management settings
properties:
ap_affinity_threshold:
default: 10
description: AP_affinity_threshold ap_affinity_threshold can be added as a field under site/setting. By default, this value is set to 12. If the field is set in both site/setting and org/setting, the value from site/setting will be used.
type: integer
cli_banner:
description: Set Banners for switches. Allows markup formatting
examples:
- \t\tWELCOME!
type: string
cli_idle_timeout:
description: Sets timeout for switches
maximum: 60
minimum: 1
type: integer
config_revert_timer:
default: 10
description: Rollback timer for commit confirmed
maximum: 30
minimum: 1
type: integer
dhcp_option_fqdn:
default: false
description: Enable to provide the FQDN with DHCP option 81
type: boolean
disable_oob_down_alarm:
type: boolean
fips_enabled:
default: false
type: boolean
local_accounts:
$ref: '#/components/schemas/config_switch_local_accounts'
mxedge_proxy_host:
description: IP Address or FQDN of the Mist Edge used to proxy the switch management traffic to the Mist Cloud
type: string
mxedge_proxy_port:
$ref: '#/components/schemas/switch_mgmt_mxedge_proxy_port'
protect_re:
$ref: '#/components/schemas/protect_re'
radius:
$ref: '#/components/schemas/switch_radius'
remove_existing_configs:
default: false
description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed.
type: boolean
root_password:
format: password
type: string
tacacs:
$ref: '#/components/schemas/tacacs'
use_mxedge_proxy:
description: To use mxedge as proxy
type: boolean
type: object
ip_type6:
default: disabled
description: 'enum: `autoconf`, `dhcp`, `disabled`, `static`'
enum:
- autoconf
- dhcp
- disabled
- static
examples:
- static
type: string
acl_policies:
items:
$ref: '#/components/schemas/acl_policy'
type: array
site_mxtunnel_cluster:
additionalProperties: false
properties:
name:
examples:
- primary
type: string
tunterm_hosts:
$ref: '#/components/schemas/site_mxtunnel_cluster_tunterm_hosts'
type: object
gateway_mgmt:
additionalProperties: false
description: Gateway Management settings
properties:
admin_sshkeys:
$ref: '#/components/schemas/gateway_mgmt_admin_sshkeys'
app_probing:
$ref: '#/components/schemas/app_probing'
app_usage:
description: Consumes uplink bandwidth, requires WA license
type: boolean
auto_signature_update:
$ref: '#/components/schemas/gateway_mgmt_auto_signature_update'
config_revert_timer:
default: 10
description: Rollback timer for commit confirmed
maximum: 30
minimum: 1
type: integer
disable_console:
default: false
description: For SSR and SRX, disable console port
type: boolean
disable_oob:
default: false
description: For SSR and SRX, disable management interface
type: boolean
disable_usb:
default: false
description: For SSR and SRX, disable usb interface
type: boolean
fips_enabled:
default: false
type: boolean
probe_hosts:
$ref: '#/components/schemas/gateway_mgmt_probe_hosts'
probe_hostsv6:
$ref: '#/components/schemas/gateway_mgmt_probe_hostsv6'
protect_re:
$ref: '#/components/schemas/protect_re'
root_password:
description: SRX only
format: password
type: string
security_log_source_address:
examples:
- 192.168.1.1
format: ipv4
type: string
security_log_source_interface:
examples:
- ge-0/0/1.0
type: string
type: object
gateway_port_wan_source_nat:
additionalProperties: false
description: Only if `usage`==`wan`, optional. By default, source-NAT is performed on all WAN Ports using the interface-ip
properties:
disabled:
default: false
description: Or to disable the source-nat
type: boolean
nat6_pool:
description: If alternative nat_pool is desired
examples:
- 2601:1700:43c0:dc0:20c:29ff:fea7:93bc/126
type: string
nat_pool:
description: If alternative nat_pool is desired
examples:
- 64.2.4.0/30
type: string
type: object
gateway_port_vpn_paths:
additionalProperties:
$ref: '#/components/schemas/gateway_port_vpn_path'
description: Property key is the VPN name
type: object
network_internet_access_destination_nat:
additionalProperties:
$ref: '#/components/schemas/network_internet_access_destination_nat_property'
description: Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.16.0.0/30"), an External CIDR:Port (i.e. "63.16.0.0/30:443") or a Variable (i.e. "{{myvar}}"). At least one of the `internal_ip` or `port` must be defined
type: object
snmpv3_config_target_param_security_level:
description: 'enum: `authentication`, `none`, `privacy`'
enum:
- authentication
- none
- privacy
type: string
switch_port_usage_dynamic_reset_default_when:
default: link_down
description: 'Only if `mode`==`dynamic` Control when the DPC port should be changed to the default port usage. enum: `link_down`, `none` (let the DPC port keep at the current port usage)'
enum:
- link_down
- none
examples:
- link_down
type: string
tunnel_provider_options_zscaler:
additionalProperties: false
description: For zscaler-ipsec and zscaler-gre
properties:
aup_block_internet_until_accepted:
default: false
type: boolean
aup_enabled:
default: false
description: Can only be `true` when `auth_required`==`false`, display Acceptable Use Policy (AUP)
type: boolean
aup_force_ssl_inspection:
default: false
description: Proxy HTTPs traffic, requiring Zscaler cert to be installed in browser
type: boolean
aup_timeout_in_days:
description: Required if `aup_enabled`==`true`. Days before AUP is requested again
maximum: 180
minimum: 1
type: integer
auth_required:
default: false
description: Enable this option to enforce user authentication
type: boolean
caution_enabled:
default: false
description: Can only be `true` when `auth_required`==`false`, display caution notification for non-authenticated users
type: boolean
dn_bandwidth:
description: Download bandwidth cap of the link, in Mbps. Disabled if not set
examples:
- 200
format: double
maximum: 99999
minimum: 0.1
type:
- number
- 'null'
idle_time_in_minutes:
description: Required if `surrogate_IP`==`true`, idle Time to Disassociation
maximum: 43200
minimum: 0
type: integer
ofw_enabled:
default: false
description: If `true`, enable the firewall control option
type: boolean
sub_locations:
$ref: '#/components/schemas/zscaler_sub_locations'
surrogate_IP:
default: false
description: Can only be `true` when `auth_required`==`true`. Map a user to a private IP address so it applies the user's policies, instead of the location's policies
type: boolean
surrogate_IP_enforced_for_known_browsers:
description: Can only be `true` when `surrogate_IP`==`true`, enforce surrogate IP for known browsers
type: boolean
surrogate_refresh_time_in_minutes:
description: Required if `surrogate_IP_enforced_for_known_browsers`==`true`, must be lower or equal than `idle_time_in_minutes`, refresh Time for re-validation of Surrogacy
maximum: 43200
minimum: 1
type: integer
up_bandwidth:
description: Download bandwidth cap of the link, in Mbps. Disabled if not set
examples:
- 200
format: double
maximum: 99999
minimum: 0.1
type:
- number
- 'null'
xff_forward_enabled:
default: false
description: Location uses proxy chaining to forward traffic
type: boolean
type: object
idp_profile_matching_dst_subnet:
items:
examples:
- 63.1.2.0/24
type: string
type: array
response_http403:
additionalProperties: false
properties:
detail:
examples:
- You do not have permission to perform this action.
type: string
type: object
gateway_wan_type:
default: dhcp
description: 'enum: `dhcp`, `pppoe`, `static`'
enum:
- dhcp
- pppoe
- static
type: string
site_setting_wired_vna:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
type: object
aggregate_routes6:
additionalProperties:
$ref: '#/components/schemas/aggregate_route'
description: Property key is the destination subnet (e.g. "2a02:1234:420a:10c9::/64")
example:
2a02:1234:420a:10c9::/64:
discard: false
metric: null
preference: 30
type: object
snmp_vacm_security_model:
description: 'enum: `usm`, `v1`, `v2c`'
enum:
- usm
- v1
- v2c
type: string
evpn_options_underlay:
additionalProperties: false
properties:
as_base:
default: 65001
description: Underlay BGP Base AS Number
examples:
- 65001
maximum: 65535
minimum: 1
type: integer
routed_id_prefix:
examples:
- /24
type: string
subnet:
description: Underlay subnet, by default, `10.255.240.0/20`, or `fd31:5700::/64` for ipv6
examples:
- 10.255.240.0/20
type: string
use_ipv6:
default: false
description: If v6 is desired for underlay
type: boolean
type: object
switch_port_mirroring_property:
additionalProperties: false
properties:
input_networks_ingress:
$ref: '#/components/schemas/switch_port_mirroring_ingress_networks'
input_port_ids_egress:
$ref: '#/components/schemas/switch_port_mirroring_egress_port_ids'
input_port_ids_ingress:
$ref: '#/components/schemas/switch_port_mirroring_ingress_port_ids'
output_ip_address:
description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided
examples:
- 1.2.3.4
type: string
output_network:
description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided
examples:
- analyze
type: string
output_port_id:
description: Exactly one of the `output_ip_address`, `output_port_id` or `output_network` should be provided
examples:
- ge-0/0/5
type: string
type: object
snmp_vacm_access_item_prefix_list_item_model:
description: 'enum: `any`, `usm`, `v1`, `v2c`'
enum:
- any
- usm
- v1
- v2c
type: string
snmp_vacm_access_item:
additionalProperties: false
properties:
group_name:
type: string
prefix_list:
$ref: '#/components/schemas/snmp_vacm_access_item_prefix_list'
type: object
account_oauth_info_account:
additionalProperties: false
description: OAuth linked apps account info
properties:
account_id:
description: Linked app account id
examples:
- iojzXIJWEuiD73ZvydOfg
readOnly: true
type: string
auto_probe_subnet:
description: For Prisma accounts only, tunnel auto probe subnet
examples:
- 11.0.0.0/8
readOnly: true
type: string
client_id:
description: Customer account Client ID
readOnly: true
type: string
cloud_name:
description: Name of the company whose account mist has subscribed to
examples:
- Tapi.sase.paloaltonetworks.com
readOnly: true
type: string
company:
description: Name of the company whose account mist has subscribed to
examples:
- Test Company1 Ltd
readOnly: true
type: string
enable_probe:
description: For Prisma accounts only, tunnel probe enable/disable
examples:
- false
readOnly: true
type: boolean
error:
description: This error is provided when the account fails to fetch token/data
examples:
- OAuth token refresh failed, please re-link your account
readOnly: true
type: string
errors:
$ref: '#/components/schemas/oauth_account_errors'
instance_url:
description: Customer account instance URL
readOnly: true
type: string
key_id:
description: For ZDX Account only, Customer account API key ID
examples:
- L72frZcK3JvrZc
type: string
last_status:
description: Is the last data pull for account is successful or not
examples:
- failed
readOnly: true
type: string
last_sync:
description: Last data pull timestamp, background jobs that pull account data
examples:
- 1665465339000
readOnly: true
type: integer
linked_by:
description: First name of the user who linked the account
examples:
- Testname1
readOnly: true
type: string
linked_timestamp:
examples:
- 1665465339000
readOnly: true
type: number
max_daily_api_requests:
description: Zoom daily api request quota, https://developers.zoom.us/docs/api/rest/rate-limits/
examples:
- 5000
readOnly: true
type: integer
name:
description: Name of the company whose account mist has subscribed to
examples:
- Test Compay1 Ltd
readOnly: true
type: string
password:
description: Customer account password instance URL
format: password
readOnly: true
type: string
region:
description: For Prisma accounts only
examples:
- americas
readOnly: true
type: string
regions:
$ref: '#/components/schemas/account_oauth_info_account_regions'
service_account_name:
description: For Prisma accounts only
examples:
- Corp SA
readOnly: true
type: string
service_connections:
$ref: '#/components/schemas/account_oauth_info_account_service_connections'
smartgroup_name:
description: Smart group membership for determining compliance status
examples:
- CompliantGroup1
readOnly: true
type: string
tsg_id:
description: For Prisma accounts only, Prisma Tenant Service Group id
examples:
- '189953456'
readOnly: true
type: string
username:
description: Customer account username
readOnly: true
type: string
webhook_auth_type:
description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only
examples:
- Basic
- Bearer
type: string
webhook_enabled:
description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only
type: boolean
webhook_password:
description: For VMWare accounts only
examples:
- password_1234
format: password
type: string
webhook_secret:
description: For Crowdstrike accounts only
examples:
- secret-value
format: password
type: string
webhook_token:
description: For JAMF and SentinelOne accounts only
examples:
- token-value
type: string
webhook_url:
description: For Crowdstrike, JAMF, SentinelOne and VMWare accounts only
examples:
- https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/ae9dee49-69e7-4710-a114-5b827a777738/crowdstrike/edr
- https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/ae9dee49-69e7-4710-a114-5b827a777738/jamf/mdm
- https://websync.nac-staging.mistsys.com/v1/S_org-8dcbe9005/00fd8b39-cf92-4b43-a2ff-a461b48e7059/sentinelone/edr
- https://websync.nac-staging.mistsys.com/v1/S_41b2525af1d8dcbe9005/f43ea4c48f22/vmware/mdm
type: string
webhook_username:
description: For VMWare accounts only
examples:
- username_1234
type: string
zdx_org_id:
description: For ZDX Account only, ZDX organization id
examples:
- '123456'
type: string
type: object
idp_profile_base_profile:
description: 'enum: `critical`, `standard`, `strict`'
enum:
- critical
- standard
- strict
examples:
- strict
type: string
site_wids:
additionalProperties: false
description: WIDS site settings
properties:
repeated_auth_failures:
$ref: '#/components/schemas/site_wids_repeated_auth_failures'
type: object
site_setting_mxedge:
additionalProperties: false
description: Site Mist Edges form a cluster of RadSec Proxy servers
properties:
mist_das:
$ref: '#/components/schemas/mxedge_das'
mist_nac:
$ref: '#/components/schemas/mxcluster_nac'
mist_nacedge:
$ref: '#/components/schemas/mist_nacedge'
radsec:
$ref: '#/components/schemas/mxcluster_radsec'
type: object
tunterm_monitoring:
items:
$ref: '#/components/schemas/tunterm_monitoring_item'
type: array
gw_routing_policy_term_matching_vpn_neighbor_mac:
description: overlay-facing criteria (used for bgp_config where via=vpn)
items:
type: string
type: array
switch_network:
additionalProperties: false
description: A network represents a network segment. It can either represent a VLAN (then usually ties to a L3 subnet), optionally associate it with a subnet which can later be used to create addition routes. Used for ports doing `family ethernet-switching`. It can also be a pure L3-subnet that can then be used against a port that with `family inet`.
properties:
gateway:
description: Only required for EVPN-VXLAN networks, IPv4 Virtual Gateway
type: string
gateway6:
description: Only required for EVPN-VXLAN networks, IPv6 Virtual Gateway
type: string
isolation:
default: false
description: 'whether to stop clients to talk to each other, default is false (when enabled, a unique isolation_vlan_id is required). NOTE: this features requires uplink device to also a be Juniper device and `inter_switch_link` to be set. See also `inter_isolation_network_link` and `community_vlan_id` in port_usage'
type: boolean
isolation_vlan_id:
examples:
- '3070'
type: string
subnet:
description: Optional for pure switching, required when L3 / routing features are used
type: string
subnet6:
description: Optional for pure switching, required when L3 / routing features are used
type: string
vlan_id:
$ref: '#/components/schemas/vlan_id_with_variable'
required:
- vlan_id
type: object
snmpv3_config_target_param_mess_process_model:
description: 'enum: `v1`, `v2c`, `v3`'
enum:
- v1
- v2c
- v3
type: string
response_http400:
additionalProperties: false
properties:
detail:
examples:
- 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
type: string
type: object
mxcluster_radsec_auth_server:
additionalProperties: false
properties:
host:
description: IP / hostname of RADIUS server
type: string
inband_status_check:
default: false
description: Whether to enable inband status check
type: boolean
inband_status_interval:
default: 300
description: Inband status interval, in seconds
minimum: 0
type: integer
keywrap_enabled:
description: If used for Mist APs, enable keywrap algorithm. Default is false
type: boolean
keywrap_format:
$ref: '#/components/schemas/mxcluster_rad_auth_server_keywrap_format'
keywrap_kek:
description: If used for Mist APs, encryption key
type: string
keywrap_mack:
description: If used for Mist APs, Message Authentication Code Key
type: string
port:
default: 1812
description: Auth port of RADIUS server
type: integer
retry:
default: 2
description: Authentication request retry
type: integer
secret:
description: Secret of RADIUS server
format: password
type: string
ssids:
$ref: '#/components/schemas/mxcluster_radsec_auth_server_ssids'
timeout:
default: 5
description: Authentication request timeout, in seconds
type: integer
type: object
site_setting_ap_matching_rules:
examples:
- - match_model: string
name: string
port_config:
eth1,eth2:
disabled: true
dynamic_vlan:
default_vlan_id: 999
enabled: true
port_vlan_id: 1
vlan_id: 9
vlan_ids:
- 1
- 10
- 50
items:
$ref: '#/components/schemas/site_setting_ap_matching_rule'
type: array
extra_routes:
additionalProperties:
$ref: '#/components/schemas/extra_route'
description: Property key is the destination CIDR (e.g. "10.0.0.0/8")
examples:
- 0.0.0.0/0:
via: 192.168.1.10
type: object
extra_route_next_qualified_properties:
additionalProperties: false
properties:
metric:
type:
- integer
- 'null'
preference:
type:
- integer
- 'null'
type: object
vrf_extra_routes:
additionalProperties:
$ref: '#/components/schemas/vrf_extra_route'
description: Property key is the destination CIDR (e.g. "10.0.0.0/8")
examples:
- 0.0.0.0/0:
via: 192.168.1.10
type: object
dot11_bandwidth6:
default: 80
description: 'channel width for the 6GHz band. enum: `0`(disabled, response only), `20`, `40`, `80`, `160`'
enum:
- 0
- 20
- 40
- 80
- 160
examples:
- 80
type: integer
tunnel_config_networks:
description: If `provider`==`custom-ipsec` or `provider`==`prisma-ipsec`, networks reachable via this tunnel
items:
type: string
type: array
setting_ssr_auto_upgrade:
additionalProperties: false
description: auto_upgrade device first time it is onboarded
properties:
channel:
$ref: '#/components/schemas/ssr_upgrade_channel'
custom_versions:
$ref: '#/components/schemas/setting_ssr_auto_upgrade_custom_versions'
enabled:
default: false
type: boolean
version:
description: Firmware version to deploy (e.g. 6.3.0-107.r1). Optional, used when custom_versions not specified
examples:
- 6.3.0-107.r1
type: string
type: object
site_rogue_whitelisted_ssids:
description: List of SSIDs to whitelist
examples:
- - cc:8e:6f:d4:bf:16
- cc-8e-6f-d4-bf-16
- cc-73-*
- cc:82:*
items:
type: string
type: array
vs_instance_property_networks:
items:
examples:
- guest
type: string
type: array
radio_band_channels:
default: []
description: For RFTemplates. List of channels, null or empty array means auto
items:
type: integer
type:
- array
- 'null'
synthetictest_config_vlans:
deprecated: true
items:
$ref: '#/components/schemas/synthetictest_config_vlan'
type: array
snmpv3_config_notify_filter_item:
additionalProperties: false
properties:
contents:
$ref: '#/components/schemas/snmpv3_config_notify_filter_item_contents'
profile_name:
type: string
type: object
bgp_config_via:
default: lan
description: 'enum: `lan`, `tunnel`, `vpn`, `wan`'
enum:
- lan
- tunnel
- vpn
- wan
type: string
site_setting_analytic:
additionalProperties: false
properties:
enabled:
default: false
description: Enable Advanced Analytic feature (using SUB-ANA license)
type: boolean
type: object
remote_syslog_time_format:
description: 'enum: `millisecond`, `year`, `year millisecond`'
enum:
- millisecond
- year
- year millisecond
examples:
- millisecond
type: string
juniper_srx_auto_upgrade:
additionalProperties: false
description: auto_upgrade device first time it is onboarded
properties:
custom_versions:
$ref: '#/components/schemas/juniper_srx_auto_upgrade_custom_versions'
enabled:
default: false
type: boolean
snapshot:
default: false
type: boolean
version:
description: Firmware version to deploy (e.g. 23.4R2-S5.5). Optional, used when custom_versions not specified
examples:
- 23.4R2-S5.5
type: string
type: object
synthetictest_config_probes:
description: app name comes from `custom_probes` above or /const/synthetic_test_probes
items:
type: string
type: array
tacacs_auth_server:
additionalProperties: false
properties:
host:
type: string
port:
type: string
secret:
format: password
type: string
timeout:
default: 10
type: integer
type: object
evpn_options_vs_instance:
additionalProperties: false
properties:
networks:
$ref: '#/components/schemas/strings'
type: object
tunnel_config_version:
default: '2'
description: 'Only if `provider`==`custom-gre` or `provider`==`custom-ipsec`. enum: `1`, `2`'
enum:
- '1'
- '2'
type: string
site_mxtunnel_radsec_auth_servers:
items:
$ref: '#/components/schemas/radius_auth_server'
type: array
tunnel_config_ipsec_proposals:
description: Only if `provider`==`custom-ipsec`
items:
$ref: '#/components/schemas/tunnel_config_ipsec_proposal'
type: array
switch_port_mirroring_ingress_networks:
description: At least one of the `input_port_ids_ingress`, `input_port_ids_egress` or `input_networks_ingress ` should be specified
items:
examples:
- corp
type: string
type: array
modified_time:
description: When the object has been modified for the last time, in epoch
format: double
readOnly: true
type: number
acl_policy_actions:
description: "ACL Policy Actions:\n - for GBP-based policy, all src_tags and dst_tags have to be gbp-based\n - for ACL-based policy, `network` is required in either the source or destination so that we know where to attach the policy to"
items:
$ref: '#/components/schemas/acl_policy_action'
type: array
tunnel_config_ipsec_proposal:
additionalProperties: false
properties:
auth_algo:
$ref: '#/components/schemas/tunnel_config_auth_algo'
dh_group:
$ref: '#/components/schemas/tunnel_config_dh_group'
enc_algo:
$ref: '#/components/schemas/tunnel_config_enc_algo'
type: object
gw_routing_policy_term_matching_protocol:
items:
$ref: '#/components/schemas/gw_routing_policy_term_matching_protocol_enum'
type: array
site_zone_occupancy_alert:
additionalProperties: false
description: Zone Occupancy alert site settings
properties:
email_notifiers:
$ref: '#/components/schemas/site_zone_occupancy_alert_email_notifiers'
enabled:
default: false
description: Indicate whether zone occupancy alert is enabled for the site
type: boolean
threshold:
default: 5
description: Sending zone-occupancy-alert webhook message only if a zone stays non-compliant (i.e. actual occupancy > occupancy_limit) for a minimum duration specified in the threshold, in minutes
examples:
- 5
maximum: 30
minimum: 0
type: integer
type: object
acl_tag_macs:
description: "Required if \n- `type`==`mac`\n- `type`==`static_gbp` if from matching mac"
items:
type: string
type: array
simple_alert_dhcp_failure:
additionalProperties: false
properties:
client_count:
default: 10
type: integer
duration:
default: 10
description: failing within minutes
maximum: 60
minimum: 5
type: integer
incident_count:
default: 20
type: integer
type: object
gateway_oob_ip_config:
additionalProperties: false
description: Out-of-band (vme/em0/fxp0) IP config
properties:
gateway:
description: If `type`==`static`
type: string
ip:
description: If `type`==`static`
type: string
netmask:
description: If `type`==`static`
type: string
node1:
$ref: '#/components/schemas/gateway_oob_ip_config_node1'
type:
$ref: '#/components/schemas/ip_type'
use_mgmt_vrf:
default: false
description: If supported on the platform. If enabled, DNS will be using this routing-instance, too
type: boolean
use_mgmt_vrf_for_host_out:
default: false
description: For host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired
type: boolean
vlan_id:
$ref: '#/components/schemas/gateway_port_vlan_id_with_variable'
type: object
routing_policy_term_matching_community:
items:
examples:
- '3900062'
type: string
type: array
tunnel_config_node:
additionalProperties: false
description: Only if `provider`==`zscaler-ipsec`, `provider`==`jse-ipsec` or `provider`==`custom-ipsec`
properties:
hosts:
$ref: '#/components/schemas/tunnel_config_node_hosts'
internal_ips:
$ref: '#/components/schemas/tunnel_config_node_internal_ips'
probe_ips:
$ref: '#/components/schemas/strings'
remote_ids:
$ref: '#/components/schemas/tunnel_config_node_remote_ids'
wan_names:
$ref: '#/components/schemas/tunnel_config_node_wan_names'
required:
- hosts
- wan_names
type: object
site_setting_derived:
allOf:
- $ref: '#/components/schemas/site_setting'
- $ref: '#/components/schemas/site_setting_derived_accounts'
switch_port_usage_mtu:
anyOf:
- maximum: 9216
minimum: 256
type: integer
- type: string
- type: 'null'
description: Only if `mode`!=`dynamic` media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation. The default value is 1514.
tunnel_config_node_hosts:
items:
description: IP Address of the remote host
type: string
type: array
gateway_mgmt_probe_hosts:
examples:
- - 8.8.8.8
format: ipv4
items:
type: string
type: array
radius_acct_port:
anyOf:
- maximum: 65545
minimum: 1
type: integer
- type: string
description: Radius Auth Port, value from 1 to 65535, default is 1813
gateway_ip_config_dns_suffix:
description: Except for out-of_band interface (vme/em0/fxp0)
items:
type: string
type: array
mxcluster_nac:
additionalProperties: false
properties:
acct_server_port:
default: 1813
type: integer
auth_server_port:
default: 1812
type: integer
client_ips:
additionalProperties:
$ref: '#/components/schemas/mxcluster_nac_client_ips'
description: Property key is the RADIUS Client IP/Subnet.
type: object
enabled:
default: false
type: boolean
secret:
examples:
- testing123
type: string
type: object
site_wids_repeated_auth_failures:
additionalProperties: false
properties:
duration:
description: Window where a trigger will be detected and action to be taken (in seconds)
examples:
- 60
type: integer
threshold:
description: Count of events to trigger
type: integer
type: object
vrrp_group_network:
additionalProperties: false
properties:
ip:
type: string
type: object
dhcpd_config_fixed_bindings:
additionalProperties:
$ref: '#/components/schemas/dhcpd_config_fixed_binding'
description: If `type`==`local` or `type6`==`local`. Property key is the MAC Address. Format is `[0-9a-f]{12}` (e.g. "5684dae9ac8b")
examples:
- 5684dae9ac8b:
ip: 192.168.70.35
name: John
type: object
ap_radio_band5:
additionalProperties: false
description: Radio Band AP settings
properties:
allow_rrm_disable:
default: false
type: boolean
ant_gain:
default: 0
maximum: 10
minimum: 0
type:
- integer
- 'null'
antenna_beam_pattern:
$ref: '#/components/schemas/radio_band_antenna_beam_pattern'
antenna_mode:
$ref: '#/components/schemas/radio_band_antenna_mode'
bandwidth:
$ref: '#/components/schemas/dot11_bandwidth5'
channel:
default: null
description: For Device. (primary) channel for the band, 0 means using the Site Setting
examples:
- 100
type:
- integer
- 'null'
channels:
$ref: '#/components/schemas/radio_band_channels'
disabled:
default: false
description: Whether to disable the radio
type: boolean
power:
default: null
description: 'TX power of the radio. For Devices, 0 means auto. -1 / -2 / -3 / …: treated as 0 / -1 / -2 / …'
examples:
- 6
maximum: 25
minimum: 5
type:
- integer
- 'null'
power_max:
default: 17
description: When power=0, max tx power to use, HW-specific values will be used if not set
maximum: 17
minimum: 5
type:
- integer
- 'null'
power_min:
default: 8
description: When power=0, min tx power to use, HW-specific values will be used if not set
maximum: 17
minimum: 5
type:
- integer
- 'null'
preamble:
$ref: '#/components/schemas/radio_band_preamble'
type: object
tunnel_provider_options_prisma:
additionalProperties: false
properties:
service_account_name:
description: For prisma-ipsec, service account name to used for tunnel auto provisioning
examples:
- sa1@1823425211
type: string
type: object
service_policies:
items:
$ref: '#/components/schemas/service_policy'
type: array
gateway_path_preferences_paths:
items:
$ref: '#/components/schemas/gateway_path_preferences_path'
type: array
site_setting_ap_matching:
additionalProperties: false
properties:
enabled:
type: boolean
rules:
$ref: '#/components/schemas/site_setting_ap_matching_rules'
type: object
network_internet_access_destination_nat_property:
additionalProperties: false
properties:
internal_ip:
description: The Destination NAT destination IP Address. Must be an IP (i.e. "192.168.70.30") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.70.30
type: string
name:
examples:
- web server
type: string
port:
description: The Destination NAT destination IP Address. Must be a Port (i.e. "443") or a Variable (i.e. "{{myvar}}")
examples:
- '443'
type: string
wan_name:
description: SRX Only. If not set, we configure the nat policies against all WAN ports for simplicity
examples:
- wan0
type: string
type: object
acl_tag:
additionalProperties: false
description: Resource tags (`type`==`resource` or `type`==`gbp_resource`) can only be used in `dst_tags`
properties:
ether_types:
$ref: '#/components/schemas/acl_tag_ether_types'
gbp_tag:
description: "Required if\n - `type`==`dynamic_gbp` (gbp_tag received from RADIUS)\n - `type`==`gbp_resource`\n - `type`==`static_gbp` (applying gbp tag against matching conditions)"
type: integer
macs:
$ref: '#/components/schemas/acl_tag_macs'
network:
description: "If:\n * `type`==`mac` (optional. default is `any`)\n * `type`==`subnet` (optional. default is `any`)\n * `type`==`network`\n * `type`==`resource` (optional. default is `any`)\n * `type`==`static_gbp` if from matching network (vlan)"
type: string
port_usage:
description: Required if `type`==`port_usage`
type: string
radius_group:
description: "Required if:\n * `type`==`radius_group`\n * `type`==`static_gbp`\nif from matching radius_group"
type: string
specs:
$ref: '#/components/schemas/acl_tag_specs'
subnets:
$ref: '#/components/schemas/acl_tag_subnets'
type:
$ref: '#/components/schemas/acl_tag_type'
required:
- type
type: object
snmp_usm_engine_type:
description: 'enum: `local_engine`, `remote_engine`'
enum:
- local_engine
- remote_engine
type: string
snmp_config_trap_version:
default: v2
description: 'enum: `all`, `v1`, `v2`'
enum:
- all
- v1
- v2
type: string
ap_radio:
additionalProperties: false
description: Radio AP settings
properties:
allow_rrm_disable:
default: false
type: boolean
ant_gain_24:
description: Antenna gain for 2.4G - for models with external antenna only
examples:
- 4
minimum: 0
type: integer
ant_gain_5:
description: Antenna gain for 5G - for models with external antenna only
examples:
- 5
minimum: 0
type: integer
ant_gain_6:
description: Antenna gain for 6G - for models with external antenna only
examples:
- 5
minimum: 0
type: integer
antenna_mode:
$ref: '#/components/schemas/ap_radio_antenna_mode'
antenna_select:
$ref: '#/components/schemas/antenna_select'
band_24:
$ref: '#/components/schemas/ap_radio_band24'
band_24_usage:
$ref: '#/components/schemas/radio_band_24_usage'
band_5:
$ref: '#/components/schemas/ap_radio_band5'
band_5_on_24_radio:
$ref: '#/components/schemas/ap_radio_band5'
band_6:
$ref: '#/components/schemas/ap_radio_band6'
full_automatic_rrm:
default: false
description: Let RRM control everything, only the `channels` and `ant_gain` will be honored (i.e. disabled/bandwidth/power/band_24_usage are all controlled by RRM)
type: boolean
indoor_use:
default: false
description: To make an outdoor operate indoor. For an outdoor-ap, some channels are disallowed by default, this allows the user to use it as an indoor-ap
type: boolean
rrm_managed:
description: Enable RRM to manage all radio settings (ignores all band_xxx configs)
type: boolean
scanning_enabled:
description: Whether scanning radio is enabled
examples:
- true
type: boolean
type: object
snmp_config_client_list_clients:
items:
examples:
- 151.140.101.218/32
type: string
type: array
ap_port_config_forwarding:
default: all
description: "enum: \n * `all`: local breakout, All VLANs\n * `limited`: local breakout, only the VLANs configured in `port_vlan_id` and `vlan_ids`\n * `mxtunnel`: central breakout to an Org Mist Edge (requires `mxtunnel_id`)\n * `site_mxedge`: central breakout to a Site Mist Edge (requires `mxtunnel_name`)\n * `wxtunnel`': central breakout to an Org WxTunnel (requires `wxtunnel_id`)"
enum:
- all
- limited
- mxtunnel
- site_mxedge
- wxtunnel
examples:
- all
type: string
mxtunnel_vlan_ids:
description: List of vlan_ids that will be used
items:
type: integer
type: array
service_policy_antivirus:
additionalProperties: false
description: For SRX-only
properties:
avprofile_id:
description: org-level AV Profile can be used, this takes precedence over 'profile'
format: uuid
type: string
enabled:
default: false
type: boolean
profile:
description: Default / noftp / httponly / or keys from av_profiles
type: string
type: object
gateway_port_vlan_id_with_variable:
description: If WAN interface is on a VLAN. Can be the VLAN ID (i.e. "10") or a Variable (i.e. "{{myvar}}")
oneOf:
- type: string
- maximum: 4094
minimum: 1
type: integer
routing_policy_term_action_prepend_as_path:
description: When used as export policy, optional. By default, the local AS will be prepended, to change it. Can be a Variable (e.g. `{{as_path}}`)
items:
examples:
- 65000 400
type: string
type: array
tunnel_config_auto_provision_provider:
description: 'enum: `jse-ipsec`, `zscaler-ipsec`'
enum:
- jse-ipsec
- zscaler-ipsec
type: string
mxcluster_nac_client_ips:
additionalProperties:
$ref: '#/components/schemas/mxcluster_nac_client_ip'
type: object
vlan_ids:
description: list of VLAN IDs on which rogue APs are ignored
items:
maximum: 4096
minimum: 0
type: integer
type: array
gateway_mgmt_admin_sshkeys:
description: For SSR only, as direct root access is not allowed
examples:
- - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host
items:
type: string
type: array
gateway_port_config_wan_speedtest_mode:
default: auto
description: 'Controls whether Marvis/scheduler can run speedtest on this port. enum: `auto`, `enabled`, `disabled`'
enum:
- auto
- enabled
- disabled
examples:
- auto
type: string
site_mxtunnel_ap_subnets:
description: List of subnets where we allow AP to establish Mist Tunnels from
items:
examples:
- 0.0.0.0/0
type: string
type: array
idp_config:
additionalProperties: false
properties:
alert_only:
type: boolean
enabled:
default: false
type: boolean
idpprofile_id:
description: org_level IDP Profile can be used, this takes precedence over `profile`
examples:
- 89b9d208-84a4-fa8f-af57-78f92c639cf2
format: uuid
type: string
profile:
default: strict
description: 'enum: `Custom`, `strict` (default), `standard` or keys from idp_profiles'
type: string
type: object
tunnel_config_auth_algo:
description: 'enum: `md5`, `sha1`, `sha2`'
enum:
- md5
- sha1
- sha2
type: string
radsec_proxy_hosts:
description: Default is site.mxedge.radsec.proxy_hosts which must be a superset of all `wlans[*].radsec.proxy_hosts`. When `radsec.proxy_hosts` are not used, tunnel peers (org or site mxedges) are used irrespective of `use_site_mxedge`
items:
examples:
- mxedge1.local
type: string
type: array
snmp_vacm_access_item_prefix_list:
items:
$ref: '#/components/schemas/snmp_vacm_access_item_prefix_list_item'
type: array
synthetictest_config_lan_networks_networks:
description: List of networks to be used for synthetic tests
examples:
- - pos-stations
- pos-machines
items:
type: string
type: array
radius_auth_server:
additionalProperties: false
description: Authentication Server
properties:
host:
description: IP/ hostname of RADIUS server
examples:
- 1.2.3.4
type: string
keywrap_enabled:
type: boolean
keywrap_format:
$ref: '#/components/schemas/radius_keywrap_format'
keywrap_kek:
examples:
- '1122334455'
type: string
keywrap_mack:
examples:
- '1122334455'
type: string
port:
$ref: '#/components/schemas/radius_auth_port'
require_message_authenticator:
default: false
description: Whether to require Message-Authenticator in requests
type: boolean
secret:
description: Secret of RADIUS server
examples:
- testing123
format: password
type: string
required:
- host
- secret
type: object
extra_routes6:
additionalProperties:
$ref: '#/components/schemas/extra_route6'
description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
examples:
- 2a02:1234:420a:10c9::/64:
via: 2a02:1234:200a::100
type: object
tunnel_config_auto_provision_node_wan_names:
description: Optional, only needed if `vars_only`==`false`
items:
examples:
- wan0
type: string
type: array
snmp_config_engine_id:
maxLength: 27
type: string
account_oauth_info_account_service_connections:
additionalProperties:
$ref: '#/components/schemas/account_oauth_info_account_service_connection'
description: For Prisma accounts only, property key is the service connection name
vs_instance:
additionalProperties:
$ref: '#/components/schemas/vs_instance_property'
description: Optional, for EX9200 only to segregate virtual-switches. Property key is the instance name
type: object
dns_suffix:
description: Global dns settings. To keep compatibility, dns settings in `ip_config` and `oob_ip_config` will overwrite this setting
items:
type: string
type: array
dns_servers:
description: Global dns settings. To keep compatibility, dns settings in `ip_config` and `oob_ip_config` will overwrite this setting
items:
type: string
type: array
config_switch_local_accounts_user:
additionalProperties: false
properties:
password:
examples:
- Juniper123
format: password
type: string
role:
$ref: '#/components/schemas/config_switch_local_accounts_user_role'
type: object
radius_auth_servers:
items:
$ref: '#/components/schemas/radius_auth_server'
type: array
uniqueItems: true
network_routed_for_networks:
description: For a Network (usually LAN), it can be routable to other networks (e.g. OSPF)
items:
examples:
- pos
type: string
type: array
site_mxtunnel_cluster_tunterm_hosts:
examples:
- - mxedge1
- mxedge2.local
items:
type: string
type: array
vlan_id_with_variable:
oneOf:
- type: string
- maximum: 4094
minimum: 1
type: integer
allow_deny:
description: 'enum: `allow`, `deny`'
enum:
- allow
- deny
type: string
idp_profile_overwrite:
additionalProperties: false
properties:
action:
$ref: '#/components/schemas/idp_profile_action'
matching:
$ref: '#/components/schemas/idp_profile_matching'
name:
type: string
type: object
evpn_options:
additionalProperties: false
description: EVPN Options
properties:
auto_loopback_subnet:
default: 172.16.192.0/24
description: Optional, for dhcp_relay, unique loopback IPs are required for ERB or IPClos where we can set option-82 server_id-overrides
type: string
auto_loopback_subnet6:
default: fd33:ab00:2::/64
description: Optional, for dhcp_relay, unique loopback IPs are required for ERB or IPClos where we can set option-82 server_id-overrides
type: string
auto_router_id_subnet:
default: 172.16.254.0/23
description: Optional, this generates router_id automatically, if specified, `router_id_prefix` is ignored
type: string
auto_router_id_subnet6:
description: Optional, this generates router_id automatically, if specified, `router_id_prefix` is ignored
examples:
- fd31:5700:1::/64
type: string
core_as_border:
default: false
description: Optional, for ERB or CLOS, you can either use esilag to upstream routers or to also be the virtual-gateway. When `routed_at` != `core`, whether to do virtual-gateway at core as well
type: boolean
enable_inband_mgmt:
default: false
description: Whether to route management traffic inband; routes will be propagated to downstream switches
type: boolean
enable_inband_ztp:
default: false
description: if the mangement traffic goes inbnd, during installation, only the border/core switches are connected to the Internet to allow initial configuration to be pushed down and leave the downstream access switches stay in the Factory Default state enabling inband-ztp allows upstream switches to use LLDP to assign IP and gives Internet to downstream switches in that state
type: boolean
overlay:
$ref: '#/components/schemas/evpn_options_overlay'
per_vlan_vga_v4_mac:
default: false
description: Only for by Core-Distribution architecture when `evpn_options.routed_at`==`core`. By default, JUNOS uses 00-00-5e-00-01-01 as the virtual-gateway-address's v4_mac. If enabled, 00-00-5e-00-0X-YY will be used (where XX=vlan_id/256, YY=vlan_id%256)
type: boolean
per_vlan_vga_v6_mac:
default: false
description: Only for by Core-Distribution architecture when `evpn_options.routed_at`==`core`. By default, JUNOS uses 00-00-5e-00-02-01 as the virtual-gateway-address's v6_mac. If enabled, 00-00-5e-00-1X-YY will be used (where XX=vlan_id/256, YY=vlan_id%256)
type: boolean
routed_at:
$ref: '#/components/schemas/evpn_options_routed_at'
underlay:
$ref: '#/components/schemas/evpn_options_underlay'
vs_instances:
$ref: '#/components/schemas/evpn_options_vs_instances'
type: object
ap_port_config_mac_auth_protocol:
default: pap
description: 'if `enable_mac_auth`==`true`, allows user to select an authentication protocol. enum: `eap-md5`, `eap-peap`, `pap`'
enum:
- eap-md5
- eap-peap
- pap
type: string
vrf_extra_route:
additionalProperties: false
properties:
via:
description: Next-hop address
format: ipv4
type: string
type: object
tunnel_config_probe_type:
default: icmp
description: 'enum: `http`, `icmp`'
enum:
- http
- icmp
type: string
site_wifi_proxy_arp:
description: 'enum: `default`, `disabled`, `enabled`'
enum:
- default
- disabled
- enabled
type:
- string
- 'null'
dhcpd_config_servers:
description: If `type`==`relay`
examples:
- - 11.2.3.4
items:
type: string
type: array
service_policy_skyatp_http_inspection_profile:
description: 'enum: `standard`, `strict`'
enum:
- standard
- strict
type: string
gateway_matching:
additionalProperties: false
description: Gateway matching
properties:
enable:
type: boolean
rules:
$ref: '#/components/schemas/gateway_matching_rules'
type: object
simple_alert_arp_failure:
additionalProperties: false
properties:
client_count:
default: 10
type: integer
duration:
default: 20
description: failing within minutes
maximum: 60
minimum: 5
type: integer
incident_count:
default: 10
type: integer
type: object
ibeacon_minor:
description: Minor number for iBeacon
examples:
- 1234
maximum: 65535
minimum: 1
type:
- integer
- 'null'
protect_re_allowed_service:
description: 'enum: `icmp`, `ssh`'
enum:
- icmp
- ssh
type: string
dhcpd_config_dns_suffix:
description: If `type`==`local` or `type6`==`local` - optional, if not defined, system one will be used
examples:
- - .mist.local
- .mist.com
items:
type: string
type: array
gateway_port_duplex:
default: auto
description: 'enum: `auto`, `full`, `half`'
enum:
- auto
- full
- half
examples:
- full
type: string
switch_matching_rule_oob_ip_config:
additionalProperties: false
description: Out-of-Band Management interface configuration
properties:
type:
$ref: '#/components/schemas/ip_type'
use_mgmt_vrf:
default: false
description: If supported on the platform. If enabled, DNS will be using this routing-instance, too
type: boolean
use_mgmt_vrf_for_host_out:
default: false
description: For host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired
type: boolean
type: object
tunnel_config_protocol:
description: 'Only if `provider`==`custom-ipsec`. enum: `gre`, `ipsec`'
enum:
- gre
- ipsec
type: string
snmp_usms:
items:
$ref: '#/components/schemas/snmp_usm'
type: array
network_template_import_org_networks:
description: Org Networks that we'd like to import
items:
examples:
- ap
type: string
type: array
tunnel_config_ike_proposals:
description: If `provider`==`custom-ipsec`
items:
$ref: '#/components/schemas/tunnel_config_ike_proposal'
type: array
service_policy_ssl_proxy:
additionalProperties: false
description: For SRX-only
properties:
ciphers_category:
$ref: '#/components/schemas/ssl_proxy_ciphers_category'
enabled:
default: false
type: boolean
type: object
site_setting_status_portal:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
hostnames:
$ref: '#/components/schemas/site_setting_status_portal_hostnames'
type: object
switch_port_usages:
additionalProperties:
$ref: '#/components/schemas/switch_port_usage'
description: Property key is the port usage name. Defines the profiles of port configuration configured on the switch
type: object
sw_routing_policy_term_matching_protocol:
items:
$ref: '#/components/schemas/sw_routing_policy_term_matching_protocol_enum'
type: array
dhcpd_config_options:
additionalProperties:
$ref: '#/components/schemas/dhcpd_config_option'
description: If `type`==`local` or `type6`==`local`. Property key is the DHCP option number
type: object
networks:
items:
$ref: '#/components/schemas/network'
type: array
gateway_port_config_reth_idx:
anyOf:
- type: integer
- type: string
description: For SRX only and if HA Mode. `-1` means it will be managed by the device. Use `>= 0` values to manage it manually. Ensure no conflicting values are assigned across all ports.
dhcp_snooping:
additionalProperties: false
properties:
all_networks:
type: boolean
enable_arp_spoof_check:
description: Enable for dynamic ARP inspection check
type: boolean
enable_ip_source_guard:
description: Enable for check for forging source IP address
type: boolean
enabled:
type: boolean
networks:
$ref: '#/components/schemas/dhcp_snooping_networks'
type: object
site_engagement_dwell_tags:
additionalProperties: false
description: add tags to visits within the duration (in seconds)
properties:
bounce:
default: 301-14400
type:
- string
- 'null'
engaged:
default: 14401-28800
type:
- string
- 'null'
passerby:
default: 1-300
type:
- string
- 'null'
stationed:
default: 28801-42000
type:
- string
- 'null'
type: object
ssr_upgrade_channel:
default: stable
description: 'upgrade channel to follow. enum: `alpha`, `beta`, `stable`'
enum:
- alpha
- beta
- stable
type: string
ble_config_power_mode:
default: default
description: 'enum: `custom`, `default`'
enum:
- custom
- default
examples:
- custom
type: string
site_setting_critical_url_monitoring:
additionalProperties: false
description: You can define some URLs that's critical to site operations the latency will be captured and considered for site health
properties:
enabled:
default: true
type: boolean
monitors:
$ref: '#/components/schemas/site_setting_critical_url_monitoring_monitors'
type: object
remote_syslog_server_protocol:
default: udp
description: 'enum: `tcp`, `udp`'
enum:
- tcp
- udp
type: string
idp_profile_matching_severity:
items:
$ref: '#/components/schemas/idp_profile_matching_severity_value'
type: array
org_id:
examples:
- a97c1b22-a4e9-411e-9bfd-d8695a0f9e61
format: uuid
readOnly: true
type: string
routing_policy_term_matching_prefix:
description: zero or more criteria/filter can be specified to match the term, all criteria have to be met
items:
examples:
- 192.168.0.0/16-30
type: string
type: array
aggregate_route:
additionalProperties: false
properties:
discard:
default: false
type: boolean
metric:
maximum: 4294967295
minimum: 0
type:
- integer
- 'null'
preference:
maximum: 4294967295
minimum: 0
type:
- integer
- 'null'
type: object
site_setting_juniper_srx_gateways:
items:
$ref: '#/components/schemas/site_setting_juniper_srx_gateway'
type: array
site_setting_ssh_keys:
description: When limit_ssh_access = true in Org Setting, list of SSH public keys provided by Mist Support to install onto APs (see Org:Setting)
items:
examples:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host
type: string
type: array
remote_syslog_servers:
examples:
- - facility: config
host: syslogd.internal
port: 514
protocol: udp
severity: info
tag: ''
items:
$ref: '#/components/schemas/remote_syslog_server'
type: array
snmp_config_client_lists:
items:
$ref: '#/components/schemas/snmp_config_client_list'
type: array
gateway_matching_rules:
items:
$ref: '#/components/schemas/gateway_matching_rule'
type: array
uniqueItems: true
gw_routing_policy_term_matching_vpn_path:
description: overlay-facing criteria (used for bgp_config where via=vpn). ordered-
items:
type: string
type: array
radsec:
additionalProperties: false
description: RadSec settings
properties:
coa_enabled:
default: false
type: boolean
enabled:
type: boolean
idle_timeout:
$ref: '#/components/schemas/radsec_idle_timeout'
mxcluster_ids:
$ref: '#/components/schemas/radsec_mxcluster_ids'
proxy_hosts:
$ref: '#/components/schemas/radsec_proxy_hosts'
server_name:
description: Name of the server to verify (against the cacerts in Org Setting). Only if not Mist Edge.
examples:
- radsec.abc.com
type: string
servers:
$ref: '#/components/schemas/radsec_servers'
use_mxedge:
description: use mxedge(s) as RadSec Proxy
type: boolean
use_site_mxedge:
default: false
description: To use Site mxedges when this WLAN does not use mxtunnel
type: boolean
type: object
radio_band_24_usage:
description: 'enum: `24`, `5`, `6`, `auto`'
enum:
- '24'
- '5'
- '6'
- auto
type: string
mxedge_das_coa_servers:
description: Dynamic authorization clients configured to send CoA|DM to mist edges on port 3799
items:
$ref: '#/components/schemas/mxedge_das_coa_server'
type: array
tunnel_config_ike_dh_group:
default: '14'
description: "enum:\n * 1\n * 2 (1024-bit)\n * 5\n * 14 (default, 2048-bit)\n * 15 (3072-bit)\n * 16 (4096-bit)\n * 19 (256-bit ECP)\n * 20 (384-bit ECP)\n * 21 (521-bit ECP)\n * 24 (2048-bit ECP)"
enum:
- '1'
- '14'
- '15'
- '16'
- '19'
- '2'
- '20'
- '21'
- '24'
- '5'
type: string
gateway_path_preferences_path:
additionalProperties: false
properties:
cost:
type: integer
disabled:
description: For SSR Only. `true`, if this specific path is undesired
type: boolean
gateway_ip:
description: Only if `type`==`local`, if a different gateway is desired
type: string
internet_access:
description: Only if `type`==`vpn`, if this vpn path can be used for internet
type: boolean
name:
description: "Required when \n * `type`==`vpn`: the name of the VPN Path to use \n * `type`==`wan`: the name of the WAN interface to use"
type: string
networks:
$ref: '#/components/schemas/gateway_path_preferences_path_networks'
target_ips:
$ref: '#/components/schemas/gateway_path_preferences_path_target_ips'
type:
$ref: '#/components/schemas/gateway_path_type'
wan_name:
description: Optional if `type`==`vpn`
examples:
- wan0
type: string
required:
- type
type: object
service_policy_skyatp_iot_device_policy:
additionalProperties: false
properties:
enabled:
type: boolean
type: object
switch_port_usage_storm_control:
additionalProperties: false
description: Switch storm control. Only if `mode`!=`dynamic`
properties:
disable_port:
default: false
description: Whether to disable the port when storm control is triggered
type: boolean
no_broadcast:
default: false
description: Whether to disable storm control on broadcast traffic
type: boolean
no_multicast:
default: false
description: Whether to disable storm control on multicast traffic
type: boolean
no_registered_multicast:
default: false
description: Whether to disable storm control on registered multicast traffic
type: boolean
no_unknown_unicast:
default: false
description: Whether to disable storm control on unknown unicast traffic
type: boolean
percentage:
default: 80
description: Bandwidth-percentage, configures the storm control level as a percentage of the available bandwidth
maximum: 100
minimum: 0
type: integer
type: object
service_policy_skyatp_dns_tunnel_detection_profile:
description: 'enum: `default`, `standard`, `strict`'
enum:
- default
- standard
- strict
type: string
mxedge_tunterm_multicast_config_ssdp_vlan_ids:
examples:
- - 2
- 3
- 5
items:
type: integer
type: array
site_setting_wan_vna:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
type: object
system_defined_port_usages:
description: 'system-default port usages. enum: `ap`, `iot`, `uplink``'
enum:
- ap
- iot
- uplink
type: string
mxcluster_radsec_server_selection:
default: ordered
description: 'When ordered, Mist Edge will prefer and go back to the first radius server if possible. enum: `ordered`, `unordered`'
enum:
- ordered
- unordered
type: string
ap_port_config_port_auth:
default: none
description: 'When doing port auth. enum: `dot1x`, `none`'
enum:
- dot1x
- none
examples:
- none
type: string
switch_vrf_instances:
additionalProperties:
$ref: '#/components/schemas/switch_vrf_instance'
description: Property key is the network name
examples:
- guest:
extra_routes:
0.0.0.0/0:
via: 192.168.31.1
networks:
- guest
type: object
snmp_vacm:
additionalProperties: false
properties:
access:
$ref: '#/components/schemas/snmp_vacm_access'
security_to_group:
$ref: '#/components/schemas/snmp_vacm_security_to_group'
type: object
gw_routing_policies:
additionalProperties:
$ref: '#/components/schemas/gw_routing_policy'
description: Property key is the routing policy name
type: object
radio_band_antenna_mode:
default: default
description: 'enum: `1x1`, `2x2`, `3x3`, `4x4`, `default`'
enum:
- 1x1
- 2x2
- 3x3
- 4x4
- default
examples:
- default
type: string
gw_routing_policy_term_action_add_target_vrfs:
description: For SSR, hub decides how VRF routes are leaked on spoke
items:
type: string
type: array
ibeacon_major:
description: Major number for iBeacon
examples:
- 1234
maximum: 65535
minimum: 1
type:
- integer
- 'null'
protect_re_customs:
items:
$ref: '#/components/schemas/protect_re_custom'
type: array
dhcpd_config_vendor_options:
additionalProperties:
$ref: '#/components/schemas/dhcpd_config_vendor_option'
description: "If `type`==`local` or `type6`==`local`. Property key is :, with\n * enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers)\n * sub option code: 1-255, sub-option code"
type: object
network_internet_access_static_nat_property:
additionalProperties: false
properties:
internal_ip:
description: The Static NAT destination IP Address. Must be an IP Address (i.e. "192.168.70.3") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.70.3
type: string
name:
examples:
- pos_station-1
type: string
wan_name:
description: SRX Only. If not set, we configure the nat policies against all WAN ports for simplicity. Can be a Variable (i.e. "{{myvar}}")
examples:
- wan0
type: string
type: object
tacacs_auth_servers:
items:
$ref: '#/components/schemas/tacacs_auth_server'
type: array
auto_preemption:
additionalProperties: false
description: Schedule to preempt ap’s which are not connected to preferred peer
properties:
day_of_week:
$ref: '#/components/schemas/day_of_week'
enabled:
default: false
description: Whether auto preemption should happen
type: boolean
time_of_day:
$ref: '#/components/schemas/time_of_day'
type: object
gateway_port_reth_nodes:
description: SSR only - supporting vlan-based redundancy (matching the size of `networks`)
examples:
- - node0
- node1
items:
type: string
type: array
tunnel_config_node_internal_ips:
description: Only if `provider`==`zscaler-gre`, `provider`==`jse-ipsec`, `provider`==`custom-ipsec` or `provider`==`custom-gre`
items:
type: string
type: array
switch_port_usage_reauth_interval:
anyOf:
- default: 3600
maximum: 65535
minimum: 10
type: integer
- type: string
description: 'Only if `mode`!=`dynamic` and `port_auth`=`dot1x` reauthentication interval range (min: 10, max: 65535, default: 3600). Set to 0 to disable reauthentication (no-reauthentication).'
gateway_port_wan_arp_policer:
default: default
description: 'Only when `wan_type`==`broadband`. enum: `default`, `max`, `recommended`'
enum:
- default
- max
- recommended
type: string
snmp_vacm_access_item_type:
description: 'enum: `context_prefix`, `default_context_prefix`'
enum:
- context_prefix
- default_context_prefix
type: string
remote_syslog_archive:
additionalProperties: false
properties:
files:
$ref: '#/components/schemas/remote_syslog_archive_files'
size:
examples:
- 5m
type: string
type: object
junos_port_config_duplex:
default: auto
description: 'enum: `auto`, `full`, `half`'
enum:
- auto
- full
- half
type: string
switch_bgp_config_neighbor:
additionalProperties: false
properties:
export_policy:
description: Export policy must match one of the policy names defined in the `routing_policies` property.
type: string
hold_time:
$ref: '#/components/schemas/switch_bgp_config_hold_time'
import_policy:
description: Import policy must match one of the policy names defined in the `routing_policies` property.
type: string
multihop_ttl:
maximum: 255
minimum: 1
type: integer
neighbor_as:
$ref: '#/components/schemas/bgp_as'
description: Autonomous System (AS) number of the BGP neighbor. For internal BGP, this must match `local_as`. For external BGP, this must differ from `local_as`.
required:
- neighbor_as
type: object
gateway_idp_profiles:
additionalProperties:
$ref: '#/components/schemas/idp_profile'
description: Property key is the profile name
type: object
hour:
default: ''
description: Hour range of the day (e.g. `09:00-17:00`). If the hour is not defined then it's treated as 00:00-23:59.
examples:
- 09:00-17:00
type: string
ble_config_beacon_rate_mode:
default: default
description: 'enum: `custom`, `default`'
enum:
- custom
- default
examples:
- custom
type: string
gateway_port_vpn_path:
additionalProperties: false
properties:
bfd_profile:
$ref: '#/components/schemas/gateway_port_vpn_path_bfd_profile'
bfd_use_tunnel_mode:
default: false
description: Only if the VPN `type`==`hub_spoke`. Whether to use tunnel mode. SSR only
type: boolean
preference:
description: Only if the VPN `type`==`hub_spoke`. For a given VPN, when `path_selection.strategy`==`simple`, the preference for a path (lower is preferred)
type: integer
role:
$ref: '#/components/schemas/gateway_port_vpn_path_role'
traffic_shaping:
$ref: '#/components/schemas/gateway_traffic_shaping'
type: object
radsec_idle_timeout:
anyOf:
- default: 60
type: integer
- type: string
description: Radsec Idle Timeout in seconds. Default is 60
site_setting_ap_matching_rule:
additionalProperties: false
properties:
match_model:
examples:
- AP12
type: string
name:
examples:
- AP12
type: string
port_config:
additionalProperties:
$ref: '#/components/schemas/ap_port_config'
description: Property key is the interface(s) (e.g. "eth1,eth2")
type: object
type: object
remote_syslog_severity:
default: any
description: 'enum: `alert`, `any`, `critical`, `emergency`, `error`, `info`, `notice`, `warning`'
enum:
- alert
- any
- critical
- emergency
- error
- info
- notice
- warning
type: string
gateway_mgmt_auto_signature_update:
additionalProperties: false
properties:
day_of_week:
$ref: '#/components/schemas/day_of_week'
enable:
default: true
type: boolean
time_of_day:
description: Optional, Mist will decide the timing
type: string
type: object
radius_coa_port:
anyOf:
- maximum: 65545
minimum: 1
type: integer
- type: string
description: Radius CoA Port, value from 1 to 65535, default is 3799
site_setting_juniper_srx_gateway:
additionalProperties: false
properties:
api_key:
examples:
- 5abf7c8a-1a1c-4398-ba2d-b0c297094d1a
type: string
api_password:
examples:
- abc@123
type: string
api_url:
examples:
- https://23.43.12.78:8443
type: string
type: object
service_policy_skyatp_dns_tunnel_detection:
additionalProperties: false
properties:
enabled:
type: boolean
profile:
$ref: '#/components/schemas/service_policy_skyatp_dns_tunnel_detection_profile'
type: object
routing_policy_local_preference:
anyOf:
- type: string
- maximum: 4294967295
minimum: 1
type: integer
description: Optional, for an import policy, local_preference can be changed, value in range 1-4294967294. Can be a Variable (e.g. `{{bgp_as}}`)
vs_instance_property:
additionalProperties: false
properties:
networks:
$ref: '#/components/schemas/vs_instance_property_networks'
type: object
acl_policy_action:
additionalProperties: false
properties:
action:
$ref: '#/components/schemas/allow_deny'
dst_tag:
examples:
- corp
type: string
required:
- dst_tag
type: object
network_vpn_access_config_other_vrfs:
description: By default, the routes are only readvertised toward the same vrf on spoke. To allow it to be leaked to other vrfs
items:
examples:
- iot
type: string
type: array
switch_mist_nac:
additionalProperties: false
description: Enable mist_nac to use RadSec
properties:
enabled:
type: boolean
network:
type: string
type: object
response_http401:
additionalProperties: false
properties:
detail:
examples:
- Authentication credentials were not provided.
type: string
type: object
wan_extra_routes6:
additionalProperties: false
properties:
via:
format: ipv6
type: string
type: object
snmpv3_config_target_param_security_model:
description: 'enum: `usm`, `v1`, `v2c`'
enum:
- usm
- v1
- v2c
type: string
snmp_usm_user_authentication_type:
description: 'sha224, sha256, sha384, sha512 are supported in 21.1 and newer release. enum: `authentication-md5`, `authentication-none`, `authentication-sha`, `authentication-sha224`, `authentication-sha256`, `authentication-sha384`, `authentication-sha512`'
enum:
- authentication-md5
- authentication-none
- authentication-sha
- authentication-sha224
- authentication-sha256
- authentication-sha384
- authentication-sha512
type: string
acl_tag_subnets:
description: "If \n- `type`==`subnet` \n- `type`==`resource` (optional. default is `any`)\n- `type`==`static_gbp` if from matching subnet"
items:
type: string
type: array
radius_auth_port:
anyOf:
- maximum: 65545
minimum: 1
type: integer
- type: string
description: Radius Auth Port, value from 1 to 65535, default is 1812
additional_config_cmds:
description: 'additional CLI commands to append to the generated Junos config. **Note**: no check is done'
items:
description: JUNOS "set" command to add to the generated configuration
examples:
- set snmp community public
type: string
type: array
gateway_path_strategy:
default: ordered
description: 'enum: `ecmp`, `ordered`, `weighted`'
enum:
- ecmp
- ordered
- weighted
type: string
snmp_config:
additionalProperties: false
properties:
client_list:
$ref: '#/components/schemas/snmp_config_client_lists'
contact:
examples:
- cns@juniper.net
type: string
description:
examples:
- Juniper QFX Series Switch - 1K_5LA
type: string
enabled:
default: true
type: boolean
engine_id:
$ref: '#/components/schemas/snmp_config_engine_id'
engine_id_type:
$ref: '#/components/schemas/snmp_config_engine_id_type'
location:
examples:
- Las Vegas, NV
type: string
name:
examples:
- TGH-1K-QFX10K
type: string
network:
default: default
type: string
trap_groups:
$ref: '#/components/schemas/snmp_config_trap_groups'
v2c_config:
$ref: '#/components/schemas/snmp_config_v2c_configs'
v3_config:
$ref: '#/components/schemas/snmpv3_config'
views:
$ref: '#/components/schemas/snmp_config_views'
type: object
remote_syslog_archive_files:
anyOf:
- type: string
- type: integer
examples:
- 20
mxedge_das_coa_server:
additionalProperties: false
properties:
disable_event_timestamp_check:
default: false
description: Whether to disable Event-Timestamp Check
type: boolean
enabled:
type: boolean
host:
description: This server configured to send CoA|DM to mist edges
type: string
port:
default: 3799
description: Mist edges will allow this host on this port
type: integer
require_message_authenticator:
default: false
description: Whether to require Message-Authenticator in requests
type: boolean
secret:
format: password
type: string
type: object
gateway_traffic_shaping:
additionalProperties: false
properties:
class_percentages:
$ref: '#/components/schemas/gateway_traffic_shaping_class_percentages'
enabled:
default: false
type: boolean
max_tx_kbps:
description: Interface Transmit Cap in kbps
type: integer
type: object
site_mxtunnel_additional_mxtunnels:
additionalProperties:
$ref: '#/components/schemas/site_mxtunnel_additional_mxtunnel'
type: object
switch_radius_config:
additionalProperties: false
description: Junos Radius config
properties:
acct_immediate_update:
type: boolean
acct_interim_interval:
default: 0
description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from RADIUS Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled
maximum: 65535
minimum: 0
type: integer
acct_servers:
$ref: '#/components/schemas/radius_acct_servers'
auth_server_selection:
$ref: '#/components/schemas/switch_radius_config_auth_server_selection'
auth_servers:
$ref: '#/components/schemas/radius_auth_servers'
auth_servers_retries:
default: 3
description: Radius auth session retries
type: integer
auth_servers_timeout:
default: 5
description: Radius auth session timeout
type: integer
coa_enabled:
default: false
type: boolean
coa_port:
$ref: '#/components/schemas/radius_coa_port'
fast_dot1x_timers:
default: false
type: boolean
network:
description: Use `network`or `source_ip`. Which network the RADIUS server resides, if there's static IP for this network, we'd use it as source-ip
type: string
source_ip:
description: Use `network`or `source_ip`
type: string
type: object
zscaler_sub_locations:
description: '`sub-locations` can be used for specific uses cases to define different configuration based on the user network'
items:
$ref: '#/components/schemas/tunnel_provider_options_zscaler_sub_location'
type: array
snmpv3_config_target_address_item:
additionalProperties: false
properties:
address:
examples:
- 10.11.0.2
type: string
address_mask:
examples:
- 255.255.255.0
type: string
port:
default: '161'
type:
- string
- 'null'
tag_list:
description: Refer to notify tag, can be multiple with blank
type: string
target_address_name:
examples:
- target_address_name
type: string
target_parameters:
description: Refer to notify target parameters name
type: string
type: object
site_mxtunnel_radsec_acct_servers:
items:
$ref: '#/components/schemas/radius_acct_server'
type: array
network_vpn_access_static_nat_property:
additionalProperties: false
properties:
internal_ip:
description: The Static NAT destination IP Address. Must be an IP Address (i.e. "192.168.70.3") or a Variable (i.e. "{{myvar}}")
examples:
- 192.168.70.3
type: string
name:
examples:
- pos_station-1
type: string
type: object
ospf_areas:
additionalProperties:
$ref: '#/components/schemas/ospf_area'
description: Junos OSPF areas. Property key is the OSPF Area (Area should be a number (0-255) / IP address)
type: object
snmp_vacm_security_to_group_content:
items:
$ref: '#/components/schemas/snmp_vacm_security_to_group_content_item'
type: array
snmp_usm:
additionalProperties: false
properties:
engine_type:
$ref: '#/components/schemas/snmp_usm_engine_type'
remote_engine_id:
description: Required only if `engine_type`==`remote_engine`
examples:
- 00:00:00:0b:00:00:70:10:6f:08:b6:3f
type: string
users:
$ref: '#/components/schemas/snmp_usm_users'
type: object
site_setting_disabled_system_defined_port_usages:
description: If some system-default port usages are not desired - namely, ap / iot / uplink
items:
$ref: '#/components/schemas/system_defined_port_usages'
type: array
network_vpn_access_config:
additionalProperties: false
properties:
advertised_subnet:
description: If `routed`==`true`, whether to advertise an aggregated subnet toward HUB this is useful when there are multiple networks on SPOKE's side
examples:
- 172.16.0.0/24
type: string
allow_ping:
description: Whether to allow ping from vpn into this routed network
type: boolean
destination_nat:
$ref: '#/components/schemas/network_vpn_access_destination_nat'
nat_pool:
description: If `routed`==`false` (usually at Spoke), but some hosts needs to be reachable from Hub, a subnet is required to create and advertise the route to Hub
examples:
- 172.16.0.0/26
type: string
no_readvertise_to_lan_bgp:
default: false
description: toward LAN-side BGP peers
type: boolean
no_readvertise_to_lan_ospf:
default: false
description: toward LAN-side OSPF peers
type: boolean
no_readvertise_to_overlay:
description: toward overlay, how HUB should deal with routes it received from Spokes
type: boolean
other_vrfs:
$ref: '#/components/schemas/network_vpn_access_config_other_vrfs'
routed:
description: Whether this network is routable
type: boolean
source_nat:
$ref: '#/components/schemas/network_source_nat'
static_nat:
$ref: '#/components/schemas/network_vpn_access_static_nat'
summarized_subnet:
description: toward overlay, how HUB should deal with routes it received from Spokes
examples:
- 172.16.0.0/16
type: string
summarized_subnet_to_lan_bgp:
description: toward LAN-side BGP peers
examples:
- 172.16.0.0/16
type: string
summarized_subnet_to_lan_ospf:
description: toward LAN-side OSPF peers
examples:
- 172.16.0.0/16
type: string
type: object
dot11_bandwidth24:
default: 20
description: 'channel width for the 2.4GHz band. enum: `0`(disabled, response only), `20`, `40`'
enum:
- 0
- 20
- 40
examples:
- 20
type: integer
site_setting_paloalto_network_gateway:
additionalProperties: false
properties:
api_key:
examples:
- 5abf7c8a-1a1c-4398-ba2d-b0c297094d1a
type: string
api_url:
examples:
- https://23.43.12.78:8443
type: string
type: object
site_setting_tunterm_multicast_config_mdns:
additionalProperties: false
properties:
enabled:
default: false
type: boolean
vlan_ids:
$ref: '#/components/schemas/mxedge_tunterm_multicast_config_mdns_vlan_ids'
type: object
tunnel_config_auto_provision:
additionalProperties: false
description: Auto Provisioning configuration for the tunne. This takes precedence over the `primary` and `secondary` nodes.
properties:
enabled:
description: Enable auto provisioning for the tunnel. If enabled, the `primary` and `secondary` nodes will be ignored.
type: boolean
latlng:
$ref: '#/components/schemas/tunnel_config_auto_provision_lat_lng'
primary:
$ref: '#/components/schemas/tunnel_config_auto_provision_node'
provider:
$ref: '#/components/schemas/tunnel_config_auto_provision_provider'
region:
description: API override for POP selection in the case user wants to override the auto discovery of remote network location and force the tunnel to use the specified peer location.
type: string
secondary:
$ref: '#/components/schemas/tunnel_config_auto_provision_node'
service_connection:
description: if `provider`==`prisma-ipsec`. By default, we'll use the location of the site to determine the optimal Remote Network location, optionally, service_connection can be considered, then we'll also consider this along with the site location. Define service_connection if the traffic is to be routed to a specific service connection. This field takes a service connection name that is configured in the Prisma cloud, Prisma Access Setup -> Service Connections.
examples:
- Juniper-Lab-SC-1
type: string
required:
- provider
type: object
vrf_extra_routes6:
additionalProperties:
$ref: '#/components/schemas/vrf_extra_route6'
description: Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
examples:
- 2a02:1234:420a:10c9::/64:
via: 2a02:1234:200a::100
type: object
snmp_usm_users:
items:
$ref: '#/components/schemas/snmp_usm_user'
type: array
switch_port_usage_dynamic_rules:
description: Only if `mode`==`dynamic`
items:
$ref: '#/components/schemas/switch_port_usage_dynamic_rule'
type: array
ap_radio_antenna_mode:
default: default
description: 'enum: `1x1`, `2x2`, `3x3`, `4x4`, `default`'
enum:
- 1x1
- 2x2
- 3x3
- 4x4
- default
type: string
junos_port_config_speed:
default: auto
description: 'enum: `100m`, `10m`, `1g`, `2.5g`, `5g`, `10g`, `25g`, `40g`, `100g`,`auto`'
enum:
- 10m
- 100m
- 1g
- 2.5g
- 5g
- 10g
- 25g
- 40g
- 100g
- auto
type: string
idp_profile_matching_attack_name:
items:
examples:
- HTTP:INVALID:HDR-FIELD
type: string
type: array
snmp_config_client_list:
additionalProperties: false
properties:
client_list_name:
examples:
- clist-1
type: string
clients:
$ref: '#/components/schemas/snmp_config_client_list_clients'
type: object
network_multicast:
additionalProperties: false
description: Whether to enable multicast support (only PIM-sparse mode is supported)
properties:
disable_igmp:
default: false
description: If the network will only be the source of the multicast traffic, IGMP can be disabled
type: boolean
enabled:
default: false
type: boolean
groups:
$ref: '#/components/schemas/network_multicast_groups'
type: object
site_mxtunnel_hosts:
description: Hostnames or IPs where a Mist Tunnel will use as the Peer (i.e. they are reachable from AP)
items:
type: string
type: array
switch_port_usage_mac_limit:
anyOf:
- default: 0
maximum: 16383
minimum: 0
type: integer
- type: string
description: Only if `mode`!=`dynamic`, max number of mac addresses, default is 0 for unlimited, otherwise range is 1 to 16383 (upper bound constrained by platform)
site_setting_auto_upgrade:
additionalProperties: false
description: Auto Upgrade Settings
properties:
custom_versions:
additionalProperties:
type: string
description: Custom versions for different models. Property key is the model name (e.g. "AP41")
examples:
- AP21: stable
AP41: 0.1.5135
AP61: 0.1.7215
type: object
day_of_week:
$ref: '#/components/schemas/day_of_week'
enabled:
default: false
description: Whether auto upgrade should happen (Note that Mist may auto-upgrade if the version is not supported)
type: boolean
time_of_day:
description: '`any` / HH:MM (24-hour format), upgrade will happen within up to 1-hour from this time'
examples:
- '12:00'
type: string
version:
$ref: '#/components/schemas/site_auto_upgrade_version'
type: object
mxcluster_radsec_acct_server_ssids:
description: List of ssids that will use this server if match_ssid is true and match is found
items:
type: string
type: array
switch_port_usage_speed:
default: auto
description: 'Only if `mode`!=`dynamic`, Port speed, default is auto to automatically negotiate speed enum: `100m`, `10m`, `1g`, `2.5g`, `5g`, `10g`, `25g`, `40g`, `100g`,`auto`'
enum:
- 10m
- 100m
- 1g
- 2.5g
- 5g
- 10g
- 25g
- 40g
- 100g
- auto
type: string
site_setting_switch:
allOf:
- $ref: '#/components/schemas/network_template'
- $ref: '#/components/schemas/switch_auto_upgrade_container'
app_probing_custom_apps:
items:
$ref: '#/components/schemas/app_probing_custom_app'
type: array
synthetictest_config:
additionalProperties: false
properties:
aggressiveness:
$ref: '#/components/schemas/synthetictest_config_aggressiveness'
custom_probes:
$ref: '#/components/schemas/synthetictest_config_custom_probes'
disabled:
default: false
type: boolean
lan_networks:
$ref: '#/components/schemas/synthetictest_config_lan_networks'
vlans:
$ref: '#/components/schemas/synthetictest_config_vlans'
wan_speedtest:
$ref: '#/components/schemas/synthetictest_config_wan_speedtest'
type: object
site_setting_ap_synthetic_test:
additionalProperties: false
description: AP Synthetic Test configuration
properties:
additional_vlan_ids:
$ref: '#/components/schemas/additional_vlan_ids'
type: object
sw_routing_policies:
additionalProperties:
$ref: '#/components/schemas/sw_routing_policy'
description: Property key is the routing policy name
type: object
gateway_oob_ip_config_node1:
additionalProperties: false
description: For HA Cluster, node1 can have different IP Config
properties:
gateway:
description: If `type`==`static`
type: string
ip:
type: string
netmask:
description: Used only if `subnet` is not specified in `networks`
type: string
type:
$ref: '#/components/schemas/ip_type'
use_mgmt_vrf:
default: false
description: If supported on the platform. If enabled, DNS will be using this routing-instance, too
type: boolean
use_mgmt_vrf_for_host_out:
default: false
description: Whether to use `mgmt_junos` for host-out traffic (NTP/TACPLUS/RADIUS/SYSLOG/SNMP), if alternative source network/ip is desired
type: boolean
vlan_id:
$ref: '#/components/schemas/gateway_port_vlan_id_with_variable'
type: object
site_zone_occupancy_alert_email_notifiers:
description: List of email addresses to send email notifications when the alert threshold is reached
examples:
- - foo@juniper.net
- bar@juniper.net
items:
type: string
type: array
switch_radius_config_auth_server_selection:
default: ordered
description: 'enum: `ordered`, `unordered`'
enum:
- ordered
- unordered
type: string
gw_routing_policy_term_matching_vpn_path_sla:
additionalProperties: false
properties:
max_jitter:
type:
- integer
- 'null'
max_latency:
examples:
- 1500
type:
- integer
- 'null'
max_loss:
examples:
- 30
type:
- integer
- 'null'
type: object
site_mxtunnel:
additionalProperties: false
description: Site MxTunnel
properties:
additional_mxtunnels:
$ref: '#/components/schemas/site_mxtunnel_additional_mxtunnels'
ap_subnets:
$ref: '#/components/schemas/site_mxtunnel_ap_subnets'
auto_preemption:
$ref: '#/components/schemas/auto_preemption'
clusters:
$ref: '#/components/schemas/site_mxtunnel_clusters'
created_time:
$ref: '#/components/schemas/created_time'
enabled:
type: boolean
for_site:
readOnly: true
type: boolean
hello_interval:
default: 60
description: In seconds, used as heartbeat to detect if a tunnel is alive. AP will try another peer after missing N hellos specified by hello_retries
examples:
- 60
maximum: 300
minimum: 1
type: integer
hello_retries:
default: 7
examples:
- 3
maximum: 30
minimum: 2
type: integer
hosts:
$ref: '#/components/schemas/site_mxtunnel_hosts'
id:
$ref: '#/components/schemas/id'
modified_time:
$ref: '#/components/schemas/modified_time'
mtu:
default: 0
description: 0 to enable MTU, 552-1500 to start MTU with a lower MTU
examples:
- 1100
maximum: 1500
minimum: 0
type: integer
org_id:
$ref: '#/components/schemas/org_id'
protocol:
$ref: '#/components/schemas/mxtunnel_protocol'
radsec:
$ref: '#/components/schemas/site_mxtunnel_radsec'
site_id:
$ref: '#/components/schemas/site_id'
vlan_ids:
$ref: '#/components/schemas/mxtunnel_vlan_ids'
type: object
gateway_path_preferences_path_target_ips:
description: If `type`==`local`, if destination IP is to be replaced
items:
type: string
type: array
acl_tag_ether_types:
default:
- any
description: ARP / IPv6. Default is `any`
items:
type: string
type: array
snmp_config_v2c_configs:
items:
$ref: '#/components/schemas/snmp_config_v2c_config'
type: array
snmpv3_config_notify:
items:
$ref: '#/components/schemas/snmpv3_config_notify_items'
type: array
vrf_config:
additionalProperties: false
properties:
enabled:
description: Whether to enable VRF (when supported on the device)
type: boolean
type: object
switch_matching_rule:
additionalProperties:
type: string
description: "Property key defines the type of matching, value is the string to match. e.g:\n * `match_name[0:3]`: switch name must match the first 3 letters of the property value\n * `match_name[2:6]`: switch name must match the property value from the 2nd to the 6th letter\n * `match_model[0-8]`: switch model must match the first 8 letters of the property value\n * `match_role`: switch role must match the property value"
examples:
- match_model: EX4300
match_name[0:3]: abc
properties:
additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
default_port_usage:
default: default
description: 'Port usage to assign to switch ports without any port usage assigned. Default: `default` to preserve default behavior'
type: string
ip_config:
$ref: '#/components/schemas/switch_matching_rule_ip_config'
name:
description: 'Rule name. WARNING: the name `default` is reserved and can only be used for the last rule in the list'
maxLength: 32
minLength: 1
type: string
oob_ip_config:
$ref: '#/components/schemas/switch_matching_rule_oob_ip_config'
port_config:
$ref: '#/components/schemas/wired_port_config'
port_mirroring:
$ref: '#/components/schemas/switch_port_mirroring'
stp_config:
$ref: '#/components/schemas/switch_stp_config'
switch_mgmt:
$ref: '#/components/schemas/switch_mgmt'
type: object
radius_keywrap_format:
description: 'enum: `ascii`, `hex`'
enum:
- ascii
- hex
type: string
vrrp_group_networks:
additionalProperties:
$ref: '#/components/schemas/vrrp_group_network'
description: Property key is the network name
examples:
- data:
ip: 10.182.96.1
mgmt:
ip: 10.182.104.1
v10:
ip: 10.182.104.129
wap:
ip: 10.182.102.1
type: object
setting_ssr:
additionalProperties: false
properties:
auto_upgrade:
$ref: '#/components/schemas/setting_ssr_auto_upgrade'
conductor_hosts:
$ref: '#/components/schemas/setting_ssr_conductor_hosts'
conductor_token:
description: Token to be used by the SSR Devices to connect to the Conductor
type: string
disable_stats:
description: Disable stats collection on SSR devices
type: boolean
proxy:
$ref: '#/components/schemas/ssr_proxy'
type: object
mxcluster_nac_client_vendor:
description: 'convention to be followed is : "-", could be an os/platform/model/company. For ex: for cisco vendor, there could variants wrt os (such as ios, nxos etc), platforms (asa etc), or acquired companies (such as meraki, aironet) etc. enum: `aruba`, `cisco-aironet`, `cisco-dnac`, `cisco-ios`, `cisco-meraki`, `brocade`, `generic`, `juniper`, `paloalto`'
enum:
- aruba
- cisco-aironet
- cisco-dnac
- cisco-ios
- cisco-meraki
- brocade
- generic
- juniper
- paloalto
examples:
- cisco-ios
type: string
service_policy_skyatp_http_inspection:
additionalProperties: false
properties:
enabled:
type: boolean
profile:
$ref: '#/components/schemas/service_policy_skyatp_http_inspection_profile'
type: object
remote_syslog_console:
additionalProperties: false
properties:
contents:
$ref: '#/components/schemas/remote_syslog_contents'
type: object
mxcluster_radsec_nas_ip_source:
default: any
description: 'SSpecify NAS-IP-ADDRESS, NAS-IPv6-ADDRESS to use with auth_servers. enum: `any`, `oob`, `oob6`, `tunnel`, `tunnel6`'
enum:
- any
- oob
- oob6
- tunnel
- tunnel6
type: string
acl_tag_specs:
description: If `type`==`resource`, `type`==`radius_group`, `type`==`port_usage` or `type`==`gbp_resource`. Empty means unrestricted, i.e. any
items:
$ref: '#/components/schemas/acl_tag_spec'
type: array
bgp_local_as:
anyOf:
- type: string
- maximum: 4294967295
minimum: 1
type: integer
description: Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. BGP AS, value in range 1-4294967295
examples:
- 65000
wlan_mist_nac:
additionalProperties: false
properties:
acct_interim_interval:
default: 0
description: How frequently should interim accounting be reported, 60-65535. default is 0 (use one specified in Access-Accept request from Server). Very frequent messages can affect the performance of the radius server, 600 and up is recommended when enabled.
examples:
- 60
maximum: 65535
minimum: 0
type: integer
auth_servers_retries:
default: 2
description: Radius auth session retries. Following fast timers are set if `fast_dot1x_timers` knob is enabled. "retries" are set to value of `auth_servers_timeout`. "max-requests" is also set when setting `auth_servers_retries` is set to default value to 3.
examples:
- 3
maximum: 10
minimum: 1
type: integer
auth_servers_timeout:
default: 5
description: Radius auth session timeout. Following fast timers are set if `fast_dot1x_timers` knob is enabled. "quite-period" and "transmit-period" are set to half the value of `auth_servers_timeout`. "supplicant-timeout" is also set when setting `auth_servers_timeout` is set to default value of 10.
examples:
- 5
maximum: 30
minimum: 1
type: integer
coa_enabled:
default: false
description: Allows a RADIUS server to dynamically modify the authorization status of a user session.
type: boolean
coa_port:
description: the communication port used for “Change of Authorization” (CoA) messages
examples:
- 3799
maximum: 65535
minimum: 1
type: integer
enabled:
default: false
description: "When enabled:\n * `auth_servers` is ignored\n * `acct_servers` is ignored\n * `auth_servers_*` are ignored\n * `coa_servers` is ignored\n * `radsec` is ignored\n * `coa_enabled` is assumed"
type: boolean
fast_dot1x_timers:
default: false
description: If set to true, sets default fast-timers with values calculated from `auth_servers_timeout` and `auth_server_retries`.
type: boolean
network:
description: Which network the mist nac server resides in
examples:
- default
type:
- string
- 'null'
source_ip:
description: In case there is a static IP for this network, we can specify it using source ip
examples:
- 1.2.3.4
type:
- string
- 'null'
type: object
extra_route6:
additionalProperties: false
properties:
discard:
default: false
description: This takes precedence
type: boolean
metric:
examples:
- null
maximum: 2147483647
minimum: 0
type:
- integer
- 'null'
next_qualified:
additionalProperties:
$ref: '#/components/schemas/extra_route6_next_qualified_properties'
examples:
- 2a02:1234:200a::100:
metric: null
preference: 40
type: object
no_resolve:
default: false
type: boolean
preference:
examples:
- 30
maximum: 2147483647
minimum: 0
type:
- integer
- 'null'
via:
$ref: '#/components/schemas/next_hop_via'
type: object
dhcpd_config:
additionalProperties:
$ref: '#/components/schemas/dhcpd_config_property'
properties:
enabled:
default: true
description: If set to `false`, disable the DHCP server
type: boolean
type: object
bgp_config_networks:
description: Optional if `via`==`lan`. List of networks where we expect BGP neighbor to connect to/from
items:
type: string
type: array
snmp_config_trap_group:
additionalProperties: false
properties:
categories:
$ref: '#/components/schemas/snmp_config_trap_group_categories'
group_name:
description: Categories list can refer to https://www.juniper.net/documentation/software/topics/task/configuration/snmp_trap-groups-configuring-junos-nm.html
examples:
- profiler
type: string
targets:
$ref: '#/components/schemas/snmp_config_trap_group_targets'
version:
$ref: '#/components/schemas/snmp_config_trap_version'
type: object
bgp_config_neighbors:
additionalProperties: false
properties:
disabled:
default: false
description: If true, the BGP session to this neighbor will be administratively disabled/shutdown
type: boolean
export_policy:
type: string
hold_time:
default: 90
maximum: 65535
minimum: 0
type: integer
import_policy:
type: string
multihop_ttl:
description: Assuming BGP neighbor is directly connected
maximum: 255
minimum: 0
type: integer
neighbor_as:
$ref: '#/components/schemas/bgp_as'
tunnel_via:
$ref: '#/components/schemas/tunnel_via'
required:
- neighbor_as
type: object
snmpv3_config_target_params:
items:
$ref: '#/components/schemas/snmpv3_config_target_param'
type: array
switch_bgp_config:
additionalProperties: false
properties:
auth_key:
type: string
bfd_minimum_interval:
description: Minimum interval in milliseconds for BFD hello packets. A neighbor is considered failed when the device stops receiving replies after the specified interval. Value must be between 1 and 255000.
maximum: 255000
minimum: 1
type: integer
export_policy:
description: Export policy must match one of the policy names defined in the `routing_policies` property.
type: string
hold_time:
$ref: '#/components/schemas/switch_bgp_config_hold_time'
import_policy:
description: Import policy must match one of the policy names defined in the `routing_policies` property.
type: string
local_as:
$ref: '#/components/schemas/bgp_as'
neighbors:
$ref: '#/components/schemas/switch_bgp_config_neighbors'
networks:
$ref: '#/components/schemas/switch_bgp_config_networks'
type:
$ref: '#/components/schemas/switch_bgp_config_type'
required:
- type
- local_as
type: object
hours:
additionalProperties: false
description: Days/Hours of operation filter, the available days (mon, tue, wed, thu, fri, sat, sun)
properties:
fri:
$ref: '#/components/schemas/hour'
mon:
$ref: '#/components/schemas/hour'
sat:
$ref: '#/components/schemas/hour'
sun:
$ref: '#/components/schemas/hour'
thu:
$ref: '#/components/schemas/hour'
tue:
$ref: '#/components/schemas/hour'
wed:
$ref: '#/components/schemas/hour'
type: object
mxedge_mgmt_oob_ip_type6:
default: autoconf
description: 'enum: `autoconf`, `dhcp`, `disabled`, `static`'
enum:
- autoconf
- dhcp
- disabled
- static
type: string
network_tenants:
additionalProperties:
$ref: '#/components/schemas/network_tenant'
description: Property key must be the user/tenant name (i.e. "printer-1") or a Variable (i.e. "{{myvar}}")
type: object
tunnel_config_enc_algo:
default: aes256
description: 'enum: `3des`, `aes128`, `aes256`, `aes_gcm128`, `aes_gcm256`'
enum:
- 3des
- aes128
- aes256
- aes_gcm128
- aes_gcm256
type:
- string
- 'null'
gw_routing_policy_term_matching_protocol_enum:
description: 'enum: `aggregate`, `bgp`, `direct`, `ospf`, `static` (SRX Only)'
enum:
- aggregate
- bgp
- direct
- ospf
- static
type: string
mxcluster_radsec_proxy_hosts:
description: Hostnames or IPs for Mist AP to use as the TLS Server (i.e. they are reachable from AP) in addition to `tunterm_hosts`
items:
type: string
type: array
mxedge_das:
additionalProperties: false
description: Configure cloud-assisted dynamic authorization service on this cluster of mist edges
properties:
coa_servers:
$ref: '#/components/schemas/mxedge_das_coa_servers'
enabled:
default: false
type: boolean
type: object
gateway_extra_routes:
additionalProperties:
$ref: '#/components/schemas/gateway_extra_route'
description: Property key is the destination CIDR (e.g. "10.0.0.0/8"), the destination Network name or a variable (e.g. "{{myvar}}")
type: object
site_engagement:
additionalProperties: false
description: '**Note**: if hours does not exist, it''s treated as everyday of the week, 00:00-23:59. Currently, we don''t allow multiple ranges for the same day'
properties:
dwell_tag_names:
$ref: '#/components/schemas/site_engagement_dwell_tag_names'
dwell_tags:
$ref: '#/components/schemas/site_engagement_dwell_tags'
hours:
$ref: '#/components/schemas/hours'
max_dwell:
default: 43200
description: Max time, default is 43200(12h), max is 68400 (18h)
examples:
- 43200
maximum: 68400
minimum: 1
type: integer
min_dwell:
description: min time
minimum: 0
type: integer
type: object
tunnel_config_provider:
description: 'Only if `auto_provision.enabled`==`false`. enum: `custom-ipsec`, `custom-gre`, `jse-ipsec`, `prisma-ipsec`, `zscaler-gre`, `zscaler-ipsec`'
enum:
- custom-ipsec
- custom-gre
- jse-ipsec
- prisma-ipsec
- zscaler-gre
- zscaler-ipsec
type: string
service_policy_appqoe:
additionalProperties: false
description: SRX only
properties:
enabled:
default: false
type: boolean
type: object
synthetictest_config_vlan:
additionalProperties: false
properties:
custom_test_urls:
$ref: '#/components/schemas/synthetictest_config_vlan_custom_test_urls'
disabled:
default: false
description: For some vlans where we don't want this to run
type: boolean
probes:
$ref: '#/components/schemas/synthetictest_config_probes'
vlan_ids:
$ref: '#/components/schemas/synthetictest_config_vlan_vlan_ids'
type: object
account_oauth_info_account_region:
additionalProperties: false
properties:
aggregate_region:
description: Bandwidth Aggregate region for this region
examples:
- us-southwest
type: string
allocated_bandwidth:
description: Allocated bandwidth for the region, in Mbps
examples:
- 1000
readOnly: true
type: integer
name:
description: Display name for this region
examples:
- US West
type: string
type: object
id:
description: Unique ID of the object instance in the Mist Organization
examples:
- 53f10664-3ce8-4c27-b382-0ef66432349f
format: uuid
readOnly: true
type: string
radsec_mxcluster_ids:
description: To use Org mxedges when this WLAN does not use mxtunnel, specify their mxcluster_ids. Org mxedge(s) identified by mxcluster_ids
items:
examples:
- 572586b7-f97b-a22b-526c-8b97a3f609c4
format: uuid
type: string
type: array
tacacs:
additionalProperties: false
properties:
acct_servers:
$ref: '#/components/schemas/tacacs_acct_servers'
default_role:
$ref: '#/components/schemas/tacacs_default_role'
enabled:
type: boolean
network:
description: Which network the TACACS server resides
type: string
tacplus_servers:
$ref: '#/components/schemas/tacacs_auth_servers'
type: object
snmpv3_config_notify_filter_item_contents:
items:
$ref: '#/components/schemas/snmpv3_config_notify_filter_item_content'
type: array
bgp_config:
additionalProperties: false
description: BFD is enabled when either bfd_minimum_interval or bfd_multiplier is configured
properties:
auth_key:
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`
type: string
bfd_minimum_interval:
default: 350
description: "Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`, when bfd_multiplier is configured alone. Default:\n * 1000 if `type`==`external`\n * 350 `type`==`internal`"
maximum: 255000
minimum: 1
type:
- integer
- 'null'
bfd_multiplier:
default: 3
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`, when bfd_minimum_interval_is_configured alone
maximum: 255
minimum: 1
type:
- integer
- 'null'
disable_bfd:
default: false
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. BFD provides faster path failure detection and is enabled by default
type: boolean
export:
type: string
export_policy:
description: Default export policies if no per-neighbor policies defined
type: string
extended_v4_nexthop:
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. By default, either inet/net6 unicast depending on neighbor IP family (v4 or v6). For v6 neighbors, to exchange v4 nexthop, which allows dual-stack support, enable this
type: boolean
graceful_restart_time:
default: 0
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. `0` means disable
maximum: 4095
minimum: 0
type: integer
hold_time:
default: 90
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. Default is 90.
maximum: 65535
minimum: 0
type: integer
import:
type: string
import_policy:
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. Default import policies if no per-neighbor policies defined
type: string
local_as:
$ref: '#/components/schemas/bgp_local_as'
neighbor_as:
$ref: '#/components/schemas/bgp_as'
neighbors:
additionalProperties:
$ref: '#/components/schemas/bgp_config_neighbors'
description: Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. If per-neighbor as is desired. Property key is the neighbor address
type: object
networks:
$ref: '#/components/schemas/bgp_config_networks'
no_private_as:
default: false
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. If true, we will not advertise private ASNs (AS 64512-65534) to this neighbor
type: boolean
no_readvertise_to_overlay:
default: false
description: Optional if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. By default, we'll re-advertise all learned BGP routers toward overlay
type: boolean
tunnel_name:
description: Optional if `via`==`tunnel`
type: string
type:
$ref: '#/components/schemas/bgp_config_type'
via:
$ref: '#/components/schemas/bgp_config_via'
vpn_name:
description: Optional if `via`==`vpn`
type: string
wan_name:
description: Optional if `via`==`wan`
type: string
required:
- via
type: object
marvis:
additionalProperties: false
properties:
auto_operations:
$ref: '#/components/schemas/marvis_auto_operations'
type: object
switch_bgp_config_hold_time_integer:
maximum: 65535
minimum: 3
type: integer
network_multicast_group:
additionalProperties: false
properties:
rp_ip:
description: RP (rendezvous point) IP Address
type: string
type: object
site_auto_upgrade_version:
default: stable
description: 'desired version. enum: `beta`, `custom`, `stable`'
enum:
- beta
- custom
- stable
examples:
- beta
type: string
synthetictest_config_vlan_custom_test_urls:
deprecated: true
examples:
- - https://www.abc.com/
- https://10.3.5.1:8080/about
items:
type: string
type: array
service_policy_ewf_rule:
additionalProperties: false
properties:
alert_only:
type: boolean
block_message:
examples:
- Access to this URL Category has been blocked
type: string
enabled:
default: false
type: boolean
profile:
$ref: '#/components/schemas/service_policy_ewf_rule_profile'
type: object
evpn_options_routed_at:
default: edge
description: 'optional, where virtual-gateway should reside. enum: `core`, `distribution`, `edge`'
enum:
- core
- distribution
- edge
type: string
switch_port_usage_mode:
description: '`mode`==`dynamic` must only be used if the port usage name is `dynamic`. enum: `access`, `dynamic`, `inet`, `trunk`'
enum:
- access
- dynamic
- inet
- trunk
type: string
gateway_path_preferences:
additionalProperties: false
properties:
paths:
$ref: '#/components/schemas/gateway_path_preferences_paths'
strategy:
$ref: '#/components/schemas/gateway_path_strategy'
type: object
radsec_server:
additionalProperties: false
properties:
host:
examples:
- 1.1.1.1
type: string
port:
examples:
- 1812
maximum: 65535
minimum: 1
type: integer
type: object
vrf_extra_route6:
additionalProperties: false
properties:
via:
description: Next-hop address
format: ipv6
type: string
type: object
switch_port_usage_duplex:
default: auto
description: 'Only if `mode`!=`dynamic`. Link connection mode. enum: `auto`, `full`, `half`'
enum:
- auto
- full
- half
type: string
idp_profile_matching_severity_value:
description: 'enum: `critical`, `info`, `major`, `minor`'
enum:
- critical
- info
- major
- minor
examples:
- major
type: string
proxy:
additionalProperties: false
description: Proxy Configuration to talk to Mist
properties:
disabled:
default: false
examples:
- true
type: boolean
url:
examples:
- https://proxy.corp.com:8080/
type: string
type: object
site_setting_ntp_servers:
description: List of NTP servers
items:
type: string
type: array
ntp_servers:
description: List of NTP servers specific to this device. By default, those in Site Settings will be used
items:
type: string
type: array
site_mxtunnel_additional_mxtunnel_vlan_ids:
examples:
- - 300
- 310
- 320
items:
type: integer
type: array
switch_bgp_config_neighbors:
additionalProperties:
$ref: '#/components/schemas/switch_bgp_config_neighbor'
description: Property key is the BGP Neighbor IP Address.
type: object
response_http404:
additionalProperties: false
properties:
id:
type: string
type: object
snmp_config_trap_groups:
items:
$ref: '#/components/schemas/snmp_config_trap_group'
type: array
marvis_auto_operations:
additionalProperties: false
properties:
ap_insufficient_capacity:
default: false
type: boolean
ap_loop:
default: false
type: boolean
ap_non_compliant:
default: false
type: boolean
bounce_port_for_abnormal_poe_client:
default: false
type: boolean
disable_port_when_ddos_protocol_violation:
default: false
type: boolean
disable_port_when_rogue_dhcp_server_detected:
default: false
type: boolean
gateway_non_compliant:
default: false
type: boolean
switch_misconfigured_port:
default: false
type: boolean
switch_port_stuck:
default: false
type: boolean
type: object
dhcpd_config_vendor_option_type:
description: 'enum: `boolean`, `hex`, `int16`, `int32`, `ip`, `string`, `uint16`, `uint32`'
enum:
- boolean
- hex
- int16
- int32
- ip
- string
- uint16
- uint32
type: string
ospf_areas_network:
additionalProperties: false
description: Property key is the network name. Networks to participate in an OSPF area
properties:
auth_keys:
additionalProperties:
type: string
description: Required if `auth_type`==`md5`. Property key is the key number
examples:
- '1': auth-key-1
type: object
auth_password:
description: Required if `auth_type`==`password`, the password, max length is 8
examples:
- simple
type: string
auth_type:
$ref: '#/components/schemas/ospf_area_network_auth_type'
bfd_minimum_interval:
examples:
- 500
maximum: 255000
minimum: 1
type: integer
dead_interval:
examples:
- 40
maximum: 65535
minimum: 1
type: integer
export_policy:
examples:
- export_policy
type: string
hello_interval:
maximum: 255
minimum: 1
type: integer
import_policy:
examples:
- import_policy
type: string
interface_type:
$ref: '#/components/schemas/ospf_area_network_interface_type'
metric:
examples:
- 10000
maximum: 65535
minimum: 1
type:
- integer
- 'null'
no_readvertise_to_overlay:
default: false
description: By default, we'll re-advertise all learned OSPF routes toward overlay
type: boolean
passive:
default: false
description: Whether to send OSPF-Hello
type: boolean
type: object
dhcpd_config_vendor_option:
additionalProperties: false
properties:
type:
$ref: '#/components/schemas/dhcpd_config_vendor_option_type'
value:
type: string
type: object
mxtunnel_protocol:
default: udp
description: 'enum: `ip`, `udp`'
enum:
- ip
- udp
type: string
synthetictest_config_lan_network:
additionalProperties: false
description: configure minis probes to be tested on lan networks of gateways
properties:
networks:
$ref: '#/components/schemas/synthetictest_config_lan_networks_networks'
probes:
$ref: '#/components/schemas/synthetictest_config_probes'
type: object
site_setting:
description: Site Settings
properties:
acl_policies:
$ref: '#/components/schemas/acl_policies'
acl_tags:
$ref: '#/components/schemas/acl_tags'
additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
allow_mist:
default: false
description: whether to allow Mist to look at this org
type: boolean
analytic:
$ref: '#/components/schemas/site_setting_analytic'
ap_matching:
$ref: '#/components/schemas/site_setting_ap_matching'
ap_port_config:
$ref: '#/components/schemas/site_setting_ap_port_config'
ap_synthetic_test:
$ref: '#/components/schemas/site_setting_ap_synthetic_test'
ap_updown_threshold:
default: 0
description: Enable threshold-based device down delivery for AP devices only. When configured it takes effect for AP devices and `device_updown_threshold` is ignored.
examples:
- null
maximum: 240
minimum: 0
type:
- integer
- 'null'
auto_placement:
$ref: '#/components/schemas/site_setting_auto_placement'
auto_upgrade:
$ref: '#/components/schemas/site_setting_auto_upgrade'
auto_upgrade_esl:
$ref: '#/components/schemas/site_setting_auto_upgrade_esl'
auto_upgrade_linecard:
default: true
type: boolean
bgp_neighbor_updown_threshold:
description: enable threshold-based bgp neighbor down delivery.
examples:
- null
minimum: 0
type:
- integer
- 'null'
blacklist_url:
examples:
- https://papi.s3.amazonaws.com/blacklist/xxx...
readOnly: true
type: string
ble_config:
$ref: '#/components/schemas/ble_config'
config_auto_revert:
default: false
description: Whether to enable ap auto config revert
type: boolean
config_push_policy:
$ref: '#/components/schemas/site_setting_config_push_policy'
created_time:
$ref: '#/components/schemas/created_time'
critical_url_monitoring:
$ref: '#/components/schemas/site_setting_critical_url_monitoring'
device_updown_threshold:
default: 0
description: By default, device_updown_threshold, if set, will apply to all devices types if different values for specific device type is desired, use the following
examples:
- null
maximum: 240
minimum: 0
type:
- integer
- 'null'
dhcp_snooping:
$ref: '#/components/schemas/dhcp_snooping'
disabled_system_defined_port_usages:
$ref: '#/components/schemas/site_setting_disabled_system_defined_port_usages'
dns_servers:
$ref: '#/components/schemas/dns_servers'
dns_suffix:
$ref: '#/components/schemas/dns_suffix'
enable_unii_4:
default: false
type: boolean
engagement:
$ref: '#/components/schemas/site_engagement'
evpn_options:
$ref: '#/components/schemas/evpn_options'
extra_routes:
$ref: '#/components/schemas/extra_routes'
extra_routes6:
$ref: '#/components/schemas/extra_routes6'
flags:
$ref: '#/components/schemas/site_setting_flags'
for_site:
readOnly: true
type: boolean
gateway:
$ref: '#/components/schemas/gateway_template'
gateway_additional_config_cmds:
$ref: '#/components/schemas/additional_config_cmds'
gateway_mgmt:
$ref: '#/components/schemas/gateway_mgmt'
gateway_tunnel_updown_threshold:
description: enable threshold-based gateway tunnel (secure edge tunnels) up-down delivery.
examples:
- null
minimum: 0
type:
- integer
- 'null'
gateway_updown_threshold:
default: 0
description: Enable threshold-based device down delivery for Gateway devices only. When configured it takes effect for GW devices and `device_updown_threshold` is ignored.
examples:
- null
maximum: 240
minimum: 0
type:
- integer
- 'null'
id:
$ref: '#/components/schemas/id'
iotproxy:
$ref: '#/components/schemas/iotproxy'
juniper_srx:
$ref: '#/components/schemas/site_setting_juniper_srx'
led:
$ref: '#/components/schemas/ap_led'
marvis:
$ref: '#/components/schemas/marvis'
mist_nac:
$ref: '#/components/schemas/switch_mist_nac'
modified_time:
$ref: '#/components/schemas/modified_time'
mxedge:
$ref: '#/components/schemas/site_setting_mxedge'
mxedge_mgmt:
$ref: '#/components/schemas/mxedge_mgmt'
mxtunnels:
$ref: '#/components/schemas/site_mxtunnel'
networks:
$ref: '#/components/schemas/switch_networks'
ntp_servers:
$ref: '#/components/schemas/site_setting_ntp_servers'
occupancy:
$ref: '#/components/schemas/site_occupancy_analytics'
org_id:
$ref: '#/components/schemas/org_id'
ospf_areas:
$ref: '#/components/schemas/ospf_areas'
paloalto_networks:
$ref: '#/components/schemas/site_setting_paloalto_networks'
persist_config_on_device:
default: false
description: Whether to store the config on AP
type: boolean
port_mirroring:
$ref: '#/components/schemas/switch_port_mirroring'
port_usages:
$ref: '#/components/schemas/switch_port_usages'
proxy:
$ref: '#/components/schemas/proxy'
radio_config:
$ref: '#/components/schemas/ap_radio'
radius_config:
$ref: '#/components/schemas/switch_radius_config'
remote_syslog:
$ref: '#/components/schemas/remote_syslog'
remove_existing_configs:
default: false
description: By default, only the configuration generated by Mist is cleaned up during the configuration process. If `true`, all the existing configuration will be removed.
type: boolean
report_gatt:
default: false
description: Whether AP should periodically connect to BLE devices and report GATT device info (device name, manufacturer name, serial number, battery %, temperature, humidity)
type: boolean
rogue:
$ref: '#/components/schemas/site_rogue'
routing_policies:
$ref: '#/components/schemas/sw_routing_policies'
rtsa:
$ref: '#/components/schemas/site_setting_rtsa'
simple_alert:
$ref: '#/components/schemas/simple_alert'
site_id:
$ref: '#/components/schemas/site_id'
skyatp:
$ref: '#/components/schemas/site_setting_skyatp'
sle_thresholds:
$ref: '#/components/schemas/sle_thresholds'
snmp_config:
$ref: '#/components/schemas/snmp_config'
srx_app:
$ref: '#/components/schemas/site_setting_srx_app'
ssh_keys:
$ref: '#/components/schemas/site_setting_ssh_keys'
ssr:
$ref: '#/components/schemas/setting_ssr'
status_portal:
$ref: '#/components/schemas/site_setting_status_portal'
switch:
$ref: '#/components/schemas/site_setting_switch'
switch_matching:
$ref: '#/components/schemas/switch_matching'
switch_mgmt:
$ref: '#/components/schemas/switch_mgmt'
switch_updown_threshold:
default: 0
description: Enable threshold-based device down delivery for Switch devices only. When configured it takes effect for SW devices and `device_updown_threshold` is ignored.
examples:
- null
maximum: 240
minimum: 0
type:
- integer
- 'null'
synthetic_test:
$ref: '#/components/schemas/synthetictest_config'
track_anonymous_devices:
default: false
description: Whether to track anonymous BLE assets (requires ‘track_asset’ enabled)
type: boolean
tunterm_monitoring:
$ref: '#/components/schemas/tunterm_monitoring'
tunterm_monitoring_disabled:
default: false
type: boolean
tunterm_multicast_config:
$ref: '#/components/schemas/site_setting_tunterm_multicast_config'
uplink_port_config:
$ref: '#/components/schemas/ap_uplink_port_config'
uses_description_from_port_usage:
default: false
description: by default, we only honor description provided in port_config. This allows fallback to those defined in port_usages
type: boolean
vars:
$ref: '#/components/schemas/vars'
vars_annotations:
$ref: '#/components/schemas/vars_annotations'
vna:
$ref: '#/components/schemas/site_setting_vna'
vpn_path_updown_threshold:
description: enable threshold-based vpn path down delivery.
examples:
- null
minimum: 0
type:
- integer
- 'null'
vpn_peer_updown_threshold:
description: enable threshold-based vpn peer down delivery.
examples:
- null
minimum: 0
type:
- integer
- 'null'
vrf_config:
$ref: '#/components/schemas/vrf_config'
vrf_instances:
$ref: '#/components/schemas/switch_vrf_instances'
vrrp_groups:
$ref: '#/components/schemas/site_setting_vrrp_groups'
vs_instance:
$ref: '#/components/schemas/vs_instance'
wan_vna:
$ref: '#/components/schemas/site_setting_wan_vna'
watched_station_url:
examples:
- https://papi.s3.amazonaws.com/watched_station/xxx...
readOnly: true
type: string
whitelist_url:
examples:
- https://papi.s3.amazonaws.com/whitelist/xxx...
readOnly: true
type: string
wids:
$ref: '#/components/schemas/site_wids'
wifi:
$ref: '#/components/schemas/site_wifi'
wired_vna:
$ref: '#/components/schemas/site_setting_wired_vna'
zone_occupancy_alert:
$ref: '#/components/schemas/site_zone_occupancy_alert'
type: object
site_mxtunnel_radsec:
additionalProperties: false
properties:
acct_servers:
$ref: '#/components/schemas/site_mxtunnel_radsec_acct_servers'
auth_servers:
$ref: '#/components/schemas/site_mxtunnel_radsec_auth_servers'
enabled:
default: false
type: boolean
use_mxedge:
type: boolean
type: object
poe_priority:
description: 'PoE priority. enum: `low`, `high`'
enum:
- low
- high
type: string
vrrp_group:
additionalProperties: false
description: Junos VRRP group
properties:
auth_key:
description: If `auth_type`==`md5`
examples:
- auth-key-1
type: string
auth_password:
description: If `auth_type`==`simple`
format: password
type: string
auth_type:
$ref: '#/components/schemas/vrrp_group_auth_type'
networks:
$ref: '#/components/schemas/vrrp_group_networks'
type: object
gateway_wan_type6:
default: autoconf
description: 'enum: `autoconf`, `dhcp`, `static`'
enum:
- autoconf
- dhcp
- static
type: string
extra_route6_next_qualified_properties:
additionalProperties: false
properties:
metric:
type:
- integer
- 'null'
preference:
type:
- integer
- 'null'
type: object
sw_routing_policy:
additionalProperties: false
properties:
terms:
$ref: '#/components/schemas/sw_routing_policy_terms'
type: object
network:
description: Networks are usually subnets that have cross-site significance. `networks`in Org Settings will got merged into `networks`in Site Setting. For gateways, they can be used to define Service Routes.
properties:
created_time:
$ref: '#/components/schemas/created_time'
disallow_mist_services:
default: false
description: Whether to disallow Mist Devices in the network
type: boolean
gateway:
examples:
- 192.168.70.1
format: ipv4
type: string
gateway6:
examples:
- fdad:b0bc:f29e::1
format: ipv6
type: string
id:
$ref: '#/components/schemas/id'
internal_access:
$ref: '#/components/schemas/network_internal_access'
internet_access:
$ref: '#/components/schemas/network_internet_access'
isolation:
description: Whether to allow clients in the network to talk to each other
type: boolean
modified_time:
$ref: '#/components/schemas/modified_time'
multicast:
$ref: '#/components/schemas/network_multicast'
name:
type: string
org_id:
$ref: '#/components/schemas/org_id'
routed_for_networks:
$ref: '#/components/schemas/network_routed_for_networks'
subnet:
examples:
- 192.168.70.0/24
type: string
subnet6:
examples:
- fdad:b0bc:f29e::/32
type: string
tenants:
$ref: '#/components/schemas/network_tenants'
vlan_id:
$ref: '#/components/schemas/vlan_id_with_variable'
vpn_access:
$ref: '#/components/schemas/network_vpn_access'
required:
- name
type: object
oauth_account_errors:
examples:
- - OAuth token refresh failed, please re-link your account
- API daily rate limit reached for your account
items:
type: string
readOnly: true
type: array
bgp_config_type:
description: 'Required if `via`==`lan`, `via`==`tunnel` or `via`==`wan`. enum: `external`, `internal`'
enum:
- external
- internal
minLength: 1
type: string
synthetictest_config_custom_probe_type:
default: icmp
description: 'enum: `application`, `curl`, `icmp`, `reachability`, `tcp`'
enum:
- application
- curl
- icmp
- reachability
- tcp
type: string
push_policy_push_window:
additionalProperties: false
description: If enabled, new config will only be pushed to device within the specified time window
properties:
enabled:
default: false
type: boolean
hours:
$ref: '#/components/schemas/hours'
type: object
tunnel_config_dh_group:
default: '14'
description: "Only if `provider`==`custom-ipsec`. enum:\n * 1\n * 2 (1024-bit)\n * 5\n * 14 (default, 2048-bit)\n * 15 (3072-bit)\n * 16 (4096-bit)\n * 19 (256-bit ECP)\n * 20 (384-bit ECP)\n * 21 (521-bit ECP)\n * 24 (2048-bit ECP)"
enum:
- '1'
- '14'
- '15'
- '16'
- '19'
- '2'
- '20'
- '21'
- '24'
- '5'
type: string
routing_policy_term_action_community:
description: When used as export policy, optional
items:
examples:
- '3900190'
type: string
type: array
gateway_port_config_wan_networks:
description: Only if `usage`==`wan`. If some networks are connected to this WAN port, it can be added here so policies can be defined
items:
type: string
type: array
service_policy_skyatp_dns_dga_detection:
additionalProperties: false
properties:
enabled:
type: boolean
profile:
$ref: '#/components/schemas/service_policy_skyatp_dns_dga_detection_profile'
type: object
responses:
SiteSettings:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/SiteSettingsExample'
schema:
$ref: '#/components/schemas/site_setting'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/SiteSettingsExample'
schema:
$ref: '#/components/schemas/site_setting'
description: OK
OK:
description: OK
HTTP404:
content:
application/json:
schema:
$ref: '#/components/schemas/response_http404'
application/vnd.api+json:
schema:
$ref: '#/components/schemas/response_http404'
description: Not found. The API endpoint doesn’t exist or resource doesn’ t exist
SiteSettingsDerived:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/SiteSettingsDerivedExample'
schema:
$ref: '#/components/schemas/site_setting_derived'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/SiteSettingsDerivedExample'
schema:
$ref: '#/components/schemas/site_setting_derived'
description: OK
HTTP403:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP403Example'
schema:
$ref: '#/components/schemas/response_http403'
description: Permission Denied
HTTP401:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP401Example'
schema:
$ref: '#/components/schemas/response_http401'
description: Unauthorized
MacsArray:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/MacsArrayExample'
schema:
$ref: '#/components/schemas/mac_addresses'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/MacsArrayExample'
schema:
$ref: '#/components/schemas/mac_addresses'
description: OK
HTTP429:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP429Example'
schema:
$ref: '#/components/schemas/response_http429'
description: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
HTTP400:
content:
application/json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
application/vnd.api+json:
examples:
Example:
$ref: '#/components/examples/HTTP400Example'
schema:
$ref: '#/components/schemas/response_http400'
description: Bad Syntax
examples:
HTTP400Example:
value:
detail: 'JSON parse error - Expecting value: line 5 column 8 (char 56)'
HTTP401Example:
value:
detail: Authentication credentials were not provided.
SiteSettingsExample:
value:
additional_config_cmds:
- set snmp community public
analytic:
enabled: false
ap_matching:
enabled: true
rules:
- match_model: string
name: string
port_config:
eth1,eth2:
disabled: true
dynamic_vlan:
default_vlan_id: 999
enabled: true
port_vlan_id: 1
vlan_id: 9
vlan_ids: 1, 10, 50
ap_port_config:
model_specific:
AP32:
eth1,eth2:
port_vlan_id: 1
vlan_ids: 1, 10, 50
auto_placement:
orientation: 45
x: 30
y: 60
auto_upgrade:
custom_versions:
AP21: stable
AP41: 0.1.5135
AP61: 0.1.7215
day_of_week: sun
enabled: false
time_of_day: '12:00'
version: beta
blacklist_url: https://papi.s3.amazonaws.com/blacklist/xxx...
ble_config:
beacon_enabled: false
beacon_rate: 3
beacon_rate_mode: custom
beam_disabled:
- 1
- 3
- 6
custom_ble_packet_enabled: false
custom_ble_packet_frame: 0x........
custom_ble_packet_freq_msec: 300
eddystone_uid_adv_power: -65
eddystone_uid_beams: 2-4,7
eddystone_uid_enabled: false
eddystone_uid_freq_msec: 200
eddystone_uid_instance: 5c5b35000001
eddystone_uid_namespace: 2818e3868dec25629ede
eddystone_url_adv_power: -65
eddystone_url_beams: 2-4,7
eddystone_url_enabled: true
eddystone_url_freq_msec: 1000
eddystone_url_url: https://www.abc.com
ibeacon_adv_power: -65
ibeacon_beams: 2-4,7
ibeacon_enabled: false
ibeacon_freq_msec: 0
ibeacon_major: 13
ibeacon_minor: 138
ibeacon_uuid: f3f17139-704a-f03a-2786-0400279e37c3
power: 6
power_mode: custom
config_auto_revert: false
created_time: 0
device_updown_threshold: 0
dns_servers:
- string
dns_suffix:
- string
engagement:
dwell_tag_names:
bounce: Bounce
engaged: Engaged
passerby: Passer By
stationed: Stationed
dwell_tags:
bounce: null
engaged: 300-14400
passerby: null
stationed: 14400-43200
hours:
fri: 09:00-17:00
mon: 09:00-17:00
sat: 09:00-12:00
sun: 09:00-12:00
thu: 09:00-17:00
tue: 09:00-17:00
wed: 09:00-17:00
max_dwell: 43200
min_dwell: 0
evpn_options:
auto_loopback_subnet: 100.101.0.0/16
auto_router_id_subnet: 100.100.0.0/24
core_as_border: false
overlay:
as: 65000
per_vlan_vga_v4_mac: false
routed_at: edge
underlay:
as_base: 65001
routed_id_prefix: /24
subnet: 10.255.240.0/20
flags:
property1: string
property2: string
for_site: true
gateway_additional_config_cmds:
- set snmp community public
gateway_mgmt:
admin_sshkeys:
- string
app_probing:
apps:
- string
custom_apps:
- app_type: string
hostnames:
- string
name: string
protocol: http
enabled: true
app_usage: true
auto_signature_update:
day_of_week: mon
enable: true
time_of_day: string
config_revert_timer: 10
probe_hosts:
- string
root_password: string
security_log_source_address: 192.168.1.1
security_log_source_interface: string
id: 497f6eca-6276-4993-bfeb-53cbbbba6f09
led:
brightness: 255
enabled: true
modified_time: 0
mxedge:
mist_das:
coa_servers:
- disable_event_timestamp_check: false
enabled: true
host: string
port: 3799
secret: string
enabled: false
radsec:
acct_servers:
- host: string
port: 1813
secret: string
ssids:
- string
auth_servers:
- host: string
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: string
keywrap_mack: string
port: 1812
secret: string
ssids:
- string
enabled: true
match_ssid: true
proxy_hosts:
- string
server_selection: ordered
mxedge_mgmt:
mist_password: MIST_PASSWORD
root_password: ROOT_PASSWORD
ntp_servers:
- pool.ntp.org
occupancy:
assets_enabled: false
clients_enabled: true
min_duration: 3000
sdkclients_enabled: false
unconnected_clients_enabled: false
org_id: a40f5d1f-d889-42e9-94ea-b9b33585fc6b
ospf_areas:
property1:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
property2:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
persist_config_on_device: false
port_mirroring:
property1:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_network: analyze
output_port_id: ge-0/0/5
property2:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_network: analyze
output_port_id: ge-0/0/5
port_usages:
dynamic:
mode: dynamic
reset_default_when: link_down
rules:
- equals: string
equals_any:
- string
expression: string
src: lldp_chassis_id
usage: string
property1:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_auth: dot1x
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
property2:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
proxy:
url: http://proxy.internal:8080/
radius_config:
acct_interim_interval: 0
acct_servers:
- host: 1.2.3.4
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: '1122334455'
keywrap_mack: '1122334455'
port: 1813
secret: testing123
auth_servers:
- host: 1.2.3.4
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: '1122334455'
keywrap_mack: '1122334455'
port: 1812
secret: testing123
auth_servers_retries: 3
auth_servers_timeout: 5
coa_enabled: false
coa_port: 3799
network: string
source_ip: string
remote_syslog:
archive:
files: 20
size: 5m
console:
contents:
- facility: config
severity: warning
enabled: false
files:
- archive:
files: 10
size: 5m
contents:
- facility: config
severity: warning
explicit_priority: true
file: file-name
match: '!alarm|ntp|errors.crc_error[chan]'
structured_data: true
network: default
send_to_all_servers: false
servers:
- facility: config
host: syslogd.internal
port: 514
protocol: udp
severity: info
tag: ''
time_format: millisecond
users:
- contents:
- facility: config
severity: warning
match: '"!alarm|ntp|errors.crc_error[chan]"'
user: '*'
report_gatt: false
rogue:
enabled: false
honeypot_enabled: false
min_duration: 10
min_rssi: -80
whitelisted_bssids:
- NeighborSSID
whitelisted_ssids:
- cc:8e:6f:d4:bf:16
- cc-8e-6f-d4-bf-16
- cc-73-*
- cc:82:*
rtsa:
app_waking: false
disable_dead_reckoning: true
disable_pressure_sensor: false
enabled: true
track_asset: false
simple_alert:
arp_failure:
client_count: 10
duration: 20
incident_count: 10
dhcp_failure:
client_count: 10
duration: 10
incident_count: 20
dns_failure:
client_count: 20
duration: 10
incident_count: 30
site_id: 72771e6a-6f5e-4de4-a5b9-1266c4197811
skyatp:
enabled: true
send_ip_mac_mapping: true
srx_app:
enabled: false
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host
ssr:
conductor_hosts:
- '"1.1.1.1", "2.2.2.2"'
disable_stats: true
status_portal:
enabled: false
hostnames:
- my.misty.com
switch_mgmt:
ap_affinity_threshold: 10
config_revert_timer: 10
dhcp_option_fqdn: false
mxedge_proxy_host: string
mxedge_proxy_port: 2222
root_password: string
tacacs:
acct_servers:
- host: 198.51.100.1
port: '49'
secret: string
timeout: 10
enabled: true
network: string
tacplus_servers:
- host: 198.51.100.1
port: '49'
secret: string
timeout: 10
use_mxedge_proxy: true
vars:
RADIUS_IP1: 172.31.2.5
RADIUS_SECRET: 11s64632d
vna:
enabled: false
vrf_instances:
guest:
extra_routes:
0.0.0.0/0:
via: 192.168.31.1
networks:
- guest
vrrp_groups:
property1:
auth_key: auth-key-1
auth_password: string
auth_type: md5
networks:
data:
ip: 10.182.96.1
mgmt:
ip: 10.182.104.1
v10:
ip: 10.182.104.129
wap:
ip: 10.182.102.1
property2:
auth_key: auth-key-1
auth_password: string
auth_type: md5
networks:
data:
ip: 10.182.96.1
mgmt:
ip: 10.182.104.1
v10:
ip: 10.182.104.129
wap:
ip: 10.182.102.1
wan_vna:
enabled: false
watched_station_url: https://papi.s3.amazonaws.com/watched_station/xxx...
whitelist_url: https://papi.s3.amazonaws.com/whitelist/xxx...
wids:
repeated_auth_failures:
duration: 60
threshold: 0
wifi:
cisco_enabled: true
disable_11k: false
disable_radios_when_power_constrained: false
enable_arp_spoof_check: false
enable_shared_radio_scanning: true
enabled: true
locate_connected: true
locate_unconnected: false
mesh_allow_dfs: false
mesh_enable_crm: false
mesh_enabled: false
mesh_psk: string
mesh_ssid: string
proxy_arp: default
wired_vna:
enabled: false
zone_occupancy_alert:
email_notifiers:
- foo@juniper.net
- bar@juniper.net
enabled: false
threshold: 5
HTTP403Example:
value:
detail: You do not have permission to perform this action.
MacsArrayExample:
value:
macs:
- 18-65-90-de-f4-c6
- 84-89-ad-5d-69-0d
HTTP429Example:
value:
detail: Too Many Request. The API Token used for the request reached the 5000 API Calls per hour threshold
SiteSettingsDerivedExample:
value:
additional_config_cmds:
- set snmp community public
analytic:
enabled: false
ap_matching:
enabled: true
rules:
- match_model: string
name: string
port_config:
eth1,eth2:
disabled: true
dynamic_vlan:
default_vlan_id: 999
enabled: true
port_vlan_id: 1
vlan_id: 9
vlan_ids: 1, 10, 50
ap_port_config:
model_specific:
AP32:
eth1,eth2:
port_vlan_id: 1
vlan_ids: 1, 10, 50
auto_placement:
orientation: 45
x: 30
y: 60
auto_upgrade:
custom_versions:
AP21: stable
AP41: 0.1.5135
AP61: 0.1.7215
day_of_week: sun
enabled: false
time_of_day: '12:00'
version: beta
blacklist_url: https://papi.s3.amazonaws.com/blacklist/xxx...
ble_config:
beacon_enabled: false
beacon_rate: 3
beacon_rate_mode: custom
beam_disabled:
- 1
- 3
- 6
custom_ble_packet_enabled: false
custom_ble_packet_frame: 0x........
custom_ble_packet_freq_msec: 300
eddystone_uid_adv_power: -65
eddystone_uid_beams: 2-4,7
eddystone_uid_enabled: false
eddystone_uid_freq_msec: 200
eddystone_uid_instance: 5c5b35000001
eddystone_uid_namespace: 2818e3868dec25629ede
eddystone_url_adv_power: -65
eddystone_url_beams: 2-4,7
eddystone_url_enabled: true
eddystone_url_freq_msec: 1000
eddystone_url_url: https://www.abc.com
ibeacon_adv_power: -65
ibeacon_beams: 2-4,7
ibeacon_enabled: false
ibeacon_freq_msec: 0
ibeacon_major: 13
ibeacon_minor: 138
ibeacon_uuid: f3f17139-704a-f03a-2786-0400279e37c3
power: 6
power_mode: custom
config_auto_revert: false
created_time: 0
device_updown_threshold: 0
dns_servers:
- string
dns_suffix:
- string
engagement:
dwell_tag_names:
bounce: Bounce
engaged: Engaged
passerby: Passer By
stationed: Stationed
dwell_tags:
bounce: null
engaged: 300-14400
passerby: null
stationed: 14400-43200
hours:
fri: 09:00-17:00
mon: 09:00-17:00
sat: 09:00-12:00
sun: 09:00-12:00
thu: 09:00-17:00
tue: 09:00-17:00
wed: 09:00-17:00
max_dwell: 43200
min_dwell: 0
evpn_options:
auto_loopback_subnet: 100.101.0.0/16
auto_router_id_subnet: 100.100.0.0/24
core_as_border: false
overlay:
as: 65000
per_vlan_vga_v4_mac: false
routed_at: edge
underlay:
as_base: 65001
routed_id_prefix: /24
subnet: 10.255.240.0/20
flags:
property1: string
property2: string
for_site: true
gateway_additional_config_cmds:
- set snmp community public
gateway_mgmt:
admin_sshkeys:
- string
app_probing:
apps:
- string
custom_apps:
- app_type: string
hostnames:
- string
name: string
protocol: http
enabled: true
app_usage: true
auto_signature_update:
day_of_week: mon
enable: true
time_of_day: string
config_revert_timer: 10
probe_hosts:
- string
root_password: string
security_log_source_address: 192.168.1.1
security_log_source_interface: string
id: 497f6eca-6276-4993-bfeb-53cbbbba6f09
led:
brightness: 255
enabled: true
modified_time: 0
mxedge:
mist_das:
coa_servers:
- disable_event_timestamp_check: false
enabled: true
host: string
port: 3799
secret: string
enabled: false
radsec:
acct_servers:
- host: string
port: 1813
secret: string
ssids:
- string
auth_servers:
- host: string
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: string
keywrap_mack: string
port: 1812
secret: string
ssids:
- string
enabled: true
match_ssid: true
proxy_hosts:
- string
server_selection: ordered
mxedge_mgmt:
mist_password: MIST_PASSWORD
root_password: ROOT_PASSWORD
ntp_servers:
- pool.ntp.org
occupancy:
assets_enabled: false
clients_enabled: true
min_duration: 3000
sdkclients_enabled: false
unconnected_clients_enabled: false
org_id: a40f5d1f-d889-42e9-94ea-b9b33585fc6b
ospf_areas:
property1:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
property2:
include_loopback: false
networks:
corp:
auth_keys:
'1': auth-key-1
auth_type: md5
bfd_minimum_interval: 500
dead_interval: 40
hello_interval: 10
interface_type: nbma
metric: 10000
guest:
passive: true
type: default
persist_config_on_device: false
port_mirroring:
property1:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_port_id: ge-0/0/5
property2:
input_networks_ingress:
- corp
input_port_ids_egress:
- ge-0/0/3
input_port_ids_ingress:
- ge-0/0/3
output_network: analyze
port_usages:
dynamic:
mode: dynamic
reset_default_when: link_down
rules:
- equals: string
equals_any:
- string
expression: string
src: lldp_chassis_id
usage: string
property1:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_auth: dot1x
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
property2:
all_networks: false
allow_dhcpd: true
bypass_auth_when_server_down: true
description: string
disable_autoneg: false
disabled: false
duplex: auto
enable_mac_auth: true
enable_qos: true
guest_network: string
mac_auth_only: true
mac_auth_protocol: pap
mac_limit: 0
mode: access
networks:
- string
persist_mac: false
poe_disabled: false
port_network: string
server_reject_network: null
speed: auto
storm_control:
no_broadcast: false
no_multicast: false
no_registered_multicast: false
no_unknown_unicast: false
percentage: 80
stp_edge: true
voip_network: string
proxy:
url: http://proxy.internal:8080/
radius_config:
acct_interim_interval: 0
acct_servers:
- host: 1.2.3.4
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: '1122334455'
keywrap_mack: '1122334455'
port: 1813
secret: testing123
auth_servers:
- host: 1.2.3.4
keywrap_enabled: true
keywrap_format: hex
keywrap_kek: '1122334455'
keywrap_mack: '1122334455'
port: 1812
secret: testing123
auth_servers_retries: 3
auth_servers_timeout: 5
coa_enabled: false
coa_port: 3799
network: string
source_ip: string
remote_syslog:
archive:
files: 20
size: 5m
console:
contents:
- facility: config
severity: warning
enabled: false
files:
- archive:
files: 10
size: 5m
contents:
- facility: config
severity: warning
explicit_priority: true
file: file-name
match: '!alarm|ntp|errors.crc_error[chan]'
structured_data: true
network: default
send_to_all_servers: false
servers:
- facility: config
host: syslogd.internal
port: 514
protocol: udp
severity: info
tag: ''
time_format: millisecond
users:
- contents:
- facility: config
severity: warning
match: '"!alarm|ntp|errors.crc_error[chan]"'
user: '*'
report_gatt: false
rogue:
enabled: false
honeypot_enabled: false
min_duration: 10
min_rssi: -80
whitelisted_bssids:
- NeighborSSID
whitelisted_ssids:
- cc:8e:6f:d4:bf:16
- cc-8e-6f-d4-bf-16
- cc-73-*
- cc:82:*
rtsa:
app_waking: false
disable_dead_reckoning: true
disable_pressure_sensor: false
enabled: true
track_asset: false
simple_alert:
arp_failure:
client_count: 10
duration: 20
incident_count: 10
dhcp_failure:
client_count: 10
duration: 10
incident_count: 20
dns_failure:
client_count: 20
duration: 10
incident_count: 30
site_id: 72771e6a-6f5e-4de4-a5b9-1266c4197811
skyatp:
enabled: true
send_ip_mac_mapping: true
srx_app:
enabled: false
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAA...Wxa6p6UW0ZbcP john@host
ssr:
conductor_hosts:
- '"1.1.1.1", "2.2.2.2"'
disable_stats: true
status_portal:
enabled: false
hostnames:
- my.misty.com
switch_mgmt:
ap_affinity_threshold: 10
config_revert_timer: 10
dhcp_option_fqdn: false
mxedge_proxy_host: string
mxedge_proxy_port: 2222
root_password: string
tacacs:
acct_servers:
- host: 198.51.100.1
port: '49'
secret: string
timeout: 10
enabled: true
network: string
tacplus_servers:
- host: 198.51.100.1
port: '49'
secret: string
timeout: 10
use_mxedge_proxy: true
teams_accounts:
- account_id: aaaaaaaa-1bed-4a49-9fd6-123456789012
last_status: success
last_sync: 1738119600
vars:
RADIUS_IP1: 172.31.2.5
RADIUS_SECRET: 11s64632d
vna:
enabled: false
vrf_instances:
guest:
extra_routes:
0.0.0.0/0:
via: 192.168.31.1
networks:
- guest
vrrp_groups:
property1:
auth_key: auth-key-1
auth_password: string
auth_type: md5
networks:
data:
ip: 10.182.96.1
mgmt:
ip: 10.182.104.1
v10:
ip: 10.182.104.129
wap:
ip: 10.182.102.1
property2:
auth_key: auth-key-1
auth_password: string
auth_type: md5
networks:
data:
ip: 10.182.96.1
mgmt:
ip: 10.182.104.1
v10:
ip: 10.182.104.129
wap:
ip: 10.182.102.1
wan_vna:
enabled: false
watched_station_url: https://papi.s3.amazonaws.com/watched_station/xxx...
whitelist_url: https://papi.s3.amazonaws.com/whitelist/xxx...
wids:
repeated_auth_failures:
duration: 60
threshold: 0
wifi:
cisco_enabled: true
disable_11k: false
disable_radios_when_power_constrained: false
enable_arp_spoof_check: false
enable_shared_radio_scanning: true
enabled: true
locate_connected: true
locate_unconnected: false
mesh_allow_dfs: false
mesh_enable_crm: false
mesh_enabled: false
mesh_psk: string
mesh_ssid: string
proxy_arp: default
wired_vna:
enabled: false
zone_occupancy_alert:
email_notifiers:
- foo@juniper.net
- bar@juniper.net
enabled: false
threshold: 5
zoom_accounts:
- account_id: '123451111'
errors:
- OAuth token refresh failed, please re-link your account
last_status: failed
last_sync: 1738119600
parameters:
site_id:
in: path
name: site_id
required: true
schema:
examples:
- 000000ab-00ab-00ab-00ab-0000000000ab
format: uuid
type: string
securitySchemes:
apiToken:
description: "Like many other API providers, it’s also possible to generate API Tokens to be used (in HTTP Header) for authentication. An API token ties to a Admin with equal or less privileges.\n\n**Format**:\n API Token value format is `Token {apitoken}`\n\n**Notes**:\n* an API token generated for a specific admin has the same privilege as the user\n* an API token will be automatically removed if not used for > 90 days\n* SSO admins cannot generate these API tokens. Refer Org level API tokens which can have privileges of a specific Org/Site for more information."
in: header
name: Authorization
type: apiKey
basicAuth:
description: While our current UI uses Session / Cookie-based authentication, it’s also possible to do Basic Auth.
scheme: basic
type: http
csrfToken:
description: "This protects the website against [Cross Site Request Forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery), all the POST / PUT / DELETE APIs needs to have CSRF token in the AJAX Request header when using Login/Password authentication (with or without MFA)\n\n\nThe CSRF Token is sent back by Mist in the Cookies from the Login Response API Call:\n`cookies[csrftoken]` \n\nThe CSRF Token must be added in the HTTP Request Headers:\n```\nX-CSRFToken: vwvBuq9qkqaKh7lu8tNc0gkvBfEaLAmx\n```"
in: header
name: X-CSRFToken
type: apiKey