openapi: 3.2.0 info: version: 2.0.0 title: Network Services IPsec Tunnels API description: These APIs are used for defining and managing network services configuration within Strata Cloud Manager. termsOfService: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf contact: email: support@paloaltonetworks.com name: Palo Alto Networks Technical Support url: https://support.paloaltonetworks.com license: name: MIT url: https://opensource.org/license/mit servers: - url: https://api.strata.paloaltonetworks.com/config/network/v1 description: Current - url: https://api.sase.paloaltonetworks.com/sse/config/v1 description: Legacy security: - scmToken: [] tags: - name: IP Sec Tunnels description: IPsec Tunnels paths: /ipsec-tunnels: get: tags: - IP Sec Tunnels summary: List IPsec tunnels description: Retrieve a list of IPsec tunnels. operationId: ListIPsecTunnels parameters: - $ref: '#/components/parameters/name' - $ref: '#/components/parameters/folder' - $ref: '#/components/parameters/snippet' - $ref: '#/components/parameters/device' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/limit' responses: '200': description: OK content: application/json: schema: type: object properties: data: allOf: - type: array items: $ref: '#/components/schemas/ipsec-tunnels' limit: type: integer default: 200 offset: type: integer default: 0 total: type: integer '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' default: $ref: '#/components/responses/default_errors' post: tags: - IP Sec Tunnels summary: Create an IPsec tunnel description: Create a new IPsec tunnel. operationId: CreateIPsecTunnels requestBody: description: Created content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' responses: '201': description: OK content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' '400': $ref: '#/components/responses/bad_request_errors_basic_with_body' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' servers: - url: https://api.sase.paloaltonetworks.com/sse/config/v1 description: Prisma Access SASE configuration API server. /ipsec-tunnels/{id}: get: tags: - IP Sec Tunnels summary: Get an IPsec tunnel description: Get an existing IPsec tunnel. operationId: GetIPsecTunnelsByID parameters: - $ref: '#/components/parameters/uuid' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' default: $ref: '#/components/responses/default_errors' put: tags: - IP Sec Tunnels summary: Update an IPsec tunnel description: Update an existing IPsec tunnel. operationId: UpdateIPsecTunnelsByID parameters: - $ref: '#/components/parameters/uuid' requestBody: description: OK content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' '400': $ref: '#/components/responses/bad_request_errors_basic_with_body' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' delete: tags: - IP Sec Tunnels summary: Delete an IPsec tunnel description: Delete an IPsec tunnel. operationId: DeleteIPsecTunnelsByID parameters: - $ref: '#/components/parameters/uuid' responses: '200': $ref: '#/components/responses/http_ok' '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' servers: - url: https://api.sase.paloaltonetworks.com/sse/config/v1 description: Prisma Access SASE configuration API server. /sse/config/v1/ipsec-tunnels: get: description: Retrieve IPSec tunnels. operationId: get-sse-config-v1-ipsec-tunnels parameters: - $ref: '#/components/parameters/limit-optional' - $ref: '#/components/parameters/offset-optional' - $ref: '#/components/parameters/name-optional' - $ref: '#/components/parameters/folder' responses: '200': content: application/json: schema: properties: data: allOf: - items: $ref: '#/components/schemas/ipsec-tunnels' type: array limit: default: 200 type: number offset: default: 0 type: number total: type: number type: object description: List of ipsec tunnels '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' default: $ref: '#/components/responses/default_errors' security: - Bearer: [] summary: List IPSec tunnels tags: - IP Sec Tunnels post: description: Create an IPSec tunnel. operationId: post-sse-config-v1-ipsec-tunnels parameters: - $ref: '#/components/parameters/folder' requestBody: content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' description: The ipsec tunnel you want to create responses: '201': $ref: '#/components/responses/http_created' '400': $ref: '#/components/responses/bad_request_errors_basic_with_body' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' security: - Bearer: [] summary: Create IPSec tunnels tags: - IP Sec Tunnels servers: - url: https://api.sase.paloaltonetworks.com /sse/config/v1/ipsec-tunnels/{id}: delete: description: Delete a ipsec tunnel. operationId: delete-sse-config-v1-ipsec-tunnels-id parameters: - $ref: '#/components/parameters/uuid-required' responses: '200': $ref: '#/components/responses/http_ok' '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' security: - Bearer: [] summary: Delete a ipsec tunnel tags: - IP Sec Tunnels get: description: Get an IPSec tunnel. operationId: get-sse-config-v1-ipsec-tunnels-id parameters: - $ref: '#/components/parameters/folder' - $ref: '#/components/parameters/uuid-required' responses: '200': content: application/json: schema: allOf: - items: $ref: '#/components/schemas/ipsec-tunnels' type: array description: Get the ipsec tunnel by id. '400': $ref: '#/components/responses/bad_request_errors_basic' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' default: $ref: '#/components/responses/default_errors' security: - Bearer: [] summary: Get an IPSec tunnel tags: - IP Sec Tunnels put: description: Modify a ipsec tunnel. operationId: put-sse-config-v1-ipsec-tunnels-id parameters: - $ref: '#/components/parameters/uuid-required' requestBody: content: application/json: schema: $ref: '#/components/schemas/ipsec-tunnels' description: The ipsec tunnel you want to edit responses: '200': $ref: '#/components/responses/http_ok' '400': $ref: '#/components/responses/bad_request_errors_basic_with_body' '401': $ref: '#/components/responses/auth_errors' '403': $ref: '#/components/responses/access_errors' '404': $ref: '#/components/responses/not_found' '409': $ref: '#/components/responses/conflict_errors' default: $ref: '#/components/responses/default_errors' security: - Bearer: [] summary: Edit a ipsec tunnel tags: - IP Sec Tunnels servers: - url: https://api.sase.paloaltonetworks.com components: responses: http_ok: description: OK not_found: description: Not Found content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: object_not_present: $ref: '#/components/examples/json_404_panui_mgmt_object_not_present' bad_request_errors_basic_with_body: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: input_format_mismatch: $ref: '#/components/examples/json_400_panui_restapi_input_format_mismatch' output_format_mismatch: $ref: '#/components/examples/json_400_panui_restapi_output_format_mismatch' missing_query_parameter: $ref: '#/components/examples/json_400_panui_restapi_missing_query_parameter' invalid_query_parameter: $ref: '#/components/examples/json_400_panui_restapi_invalid_query_parameter' missing_body: $ref: '#/components/examples/json_400_panui_restapi_missing_body' invalid_object: $ref: '#/components/examples/json_400_panui_mgmt_invalid_object' bad_request_errors_basic: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: input_format_mismatch: $ref: '#/components/examples/json_400_panui_restapi_input_format_mismatch' output_format_mismatch: $ref: '#/components/examples/json_400_panui_restapi_output_format_mismatch' missing_query_parameter: $ref: '#/components/examples/json_400_panui_restapi_missing_query_parameter' invalid_query_parameter: $ref: '#/components/examples/json_400_panui_restapi_invalid_query_parameter' conflict_errors: description: Conflict content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: object_not_unique: $ref: '#/components/examples/json_409_panui_mgmt_object_not_unique' name_not_unique: $ref: '#/components/examples/json_409_panui_mgmt_name_not_unique' reference_not_zero: $ref: '#/components/examples/json_409_panui_mgmt_reference_not_zero' default_errors: description: General Errors content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: version_not_supported: $ref: '#/components/examples/json_501_panui_restapi_version_not_supported' method_not_allowed: $ref: '#/components/examples/json_501_panui_restapi_method_not_supported' action_not_supported: $ref: '#/components/examples/json_405_panui_restapi_action_not_supported' bad_xpath: $ref: '#/components/examples/json_400_panui_mgmt_bad_xpath' invalid_command: $ref: '#/components/examples/json_400_panui_mgmt_invalid_command' malformed_command: $ref: '#/components/examples/json_400_panui_mgmt_malformed_command' session_timeout: $ref: '#/components/examples/json_504_panui_mgmt_session_timeout' auth_errors: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: auth_not_authenticated: $ref: '#/components/examples/json_401_panui_auth_not_authenticated' invalid_credential: $ref: '#/components/examples/json_401_panui_auth_invalid_credential' key_too_long: $ref: '#/components/examples/json_401_panui_auth_key_too_long' key_expired: $ref: '#/components/examples/json_401_panui_auth_key_expired' need_password_change: $ref: '#/components/examples/json_401_panui_auth_need_password_change' access_errors: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/generic_error' examples: auth_unauthorized: $ref: '#/components/examples/json_403_panui_auth_unauthorized' http_created: description: Created BadRequest: description: Invalid request parameters or body. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Unauthorized: description: Missing or invalid OAuth2 access token. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalServerError: description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' NotFound: description: The requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Forbidden: description: Insufficient permissions for this operation. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: json_400_panui_mgmt_invalid_object: summary: Invalid Object value: _errors: - code: E003 message: Invalid Object details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_501_panui_restapi_method_not_supported: summary: Method Not Supported value: _errors: - code: E012 message: Method Not Supported details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_405_panui_restapi_action_not_supported: summary: Action Not Supported value: _errors: - code: E012 message: 'Action Not Supported: move' details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_404_panui_mgmt_object_not_present: summary: Object Not Present value: _errors: - code: E005 message: Object Not Present details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_409_panui_mgmt_object_not_unique: summary: Object Not Unique value: _errors: - code: E016 message: Object Not Unique details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_mgmt_invalid_command: summary: Invalid Command value: _errors: - code: E003 message: Invalid Command details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_restapi_invalid_query_parameter: summary: Invalid Query Parameter value: _errors: - code: E003 message: 'Invalid Query Parameter: location=invalid' details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_409_panui_mgmt_name_not_unique: summary: Name Not Unique value: _errors: - code: E006 message: Name Not Unique details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_409_panui_mgmt_reference_not_zero: summary: Reference Not Zero value: _errors: - code: E009 message: Reference Not Zero details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_401_panui_auth_invalid_credential: summary: Invalid Credential value: _errors: - code: E016 message: Invalid Credential details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_401_panui_auth_key_expired: summary: Key Expired value: _errors: - code: E016 message: Key Expired details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_401_panui_auth_not_authenticated: summary: Not Authenticated value: _errors: - code: E016 message: Not Authenticated details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_401_panui_auth_key_too_long: summary: Key Too Long value: _errors: - code: E016 message: Key Too Long details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_restapi_missing_query_parameter: summary: Missing Query Parameter value: _errors: - code: E003 message: 'Missing Query Parameter: name' details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_mgmt_malformed_command: summary: Malformed Command value: _errors: - code: E003 message: Malformed Command details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_504_panui_mgmt_session_timeout: summary: Session Timeout value: _errors: - code: '4' message: Session Timeout details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_mgmt_bad_xpath: summary: Bad XPath value: _errors: - code: E013 message: Bad XPath details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_restapi_missing_body: summary: Missing Body value: _errors: - code: E003 message: Missing Body details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_501_panui_restapi_version_not_supported: summary: Version Not Supported value: _errors: - code: E012 message: Version Not Supported details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_restapi_output_format_mismatch: summary: Output Format Mismatch value: _errors: - code: E003 message: 'Output Format Mismatch: output-format=json Accept=xml' details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_401_panui_auth_need_password_change: summary: Need Password Change value: _errors: - code: E016 message: The password needs to be changed. details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_403_panui_auth_unauthorized: summary: Unauthorized value: _errors: - code: E007 message: Unauthorized details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 json_400_panui_restapi_input_format_mismatch: summary: Input Format Mismatch value: _errors: - code: E003 message: 'Input Format Mismatch: input-format=json' details: {} _request_id: 123e4567-e89b-12d3-a456-426655440000 schemas: error_detail_cause_info: type: object title: Cause Info properties: code: type: string message: type: string details: oneOf: - type: string - type: object help: type: string error_detail_cause_infos: type: array items: $ref: '#/components/schemas/error_detail_cause_info' x-examples: {} ipsec-tunnels: type: object properties: id: type: string description: UUID of the resource readOnly: true example: 123e4567-e89b-12d3-a456-426655440000 name: type: string description: 'Alphanumeric string begin with letter: [0-9a-zA-Z._-]' maxLength: 63 tunnel_interface: type: string description: Tunnel interface variable or hardcoded tunnel. Default will be tunnels. default: tunnel auto_key: type: object properties: ike_gateway: type: array items: type: object properties: name: type: string ipsec_crypto_profile: type: string proxy_id: type: array description: IPv4 type of proxy_id values items: type: object description: IPv4 type of proxy_id values for TCP protocol properties: name: type: string local: type: string remote: type: string protocol: type: object description: IPv4 type of proxy_id protocol values for TCP protocol oneOf: - type: object title: number properties: number: type: integer description: IP protocol number minimum: 1 maximum: 254 - type: object title: tcp properties: tcp: type: object description: IPv4 type of proxy_id protocol values for TCP protocol properties: local_port: type: integer minimum: 0 maximum: 65535 default: 0 remote_port: type: integer minimum: 0 maximum: 65535 default: 0 - type: object title: udp properties: udp: type: object description: IPv6 type of proxy_id protocol values for UDP protocol properties: local_port: type: integer minimum: 0 maximum: 65535 default: 0 remote_port: type: integer minimum: 0 maximum: 65535 default: 0 required: - name proxy_id_v6: type: array description: IPv6 type of proxy_id values items: type: object description: IPv6 type of proxy_id values for TCP protocol properties: name: type: string local: type: string remote: type: string protocol: type: object description: IPv6 type of proxy_id protocol values for protocol oneOf: - type: object title: number properties: number: type: integer description: IP protocol number minimum: 1 maximum: 254 - type: object title: tcp properties: tcp: type: object description: IPv6 type of proxy_id protocol values for TCP protocol properties: local_port: type: integer minimum: 0 maximum: 65535 default: 0 remote_port: type: integer minimum: 0 maximum: 65535 default: 0 - type: object title: udp properties: udp: type: object description: IPv6 type of proxy_id protocol values for UDP protocol properties: local_port: type: integer minimum: 0 maximum: 65535 default: 0 remote_port: type: integer minimum: 0 maximum: 65535 default: 0 required: - name required: - ike_gateway - ipsec_crypto_profile anti_replay: type: boolean description: Enable Anti-Replay check on this tunnel copy_tos: type: boolean description: Copy IP TOS bits from inner packet to IPSec packet (not recommended) default: false enable_gre_encapsulation: type: boolean description: allow GRE over IPSec default: false tunnel_monitor: type: object properties: enable: type: boolean description: Enable tunnel monitoring on this tunnel default: false destination_ip: type: string description: Destination IP to send ICMP probe proxy_id: type: string description: Which proxy-id (or proxy-id-v6) the monitoring traffic will use required: - destination_ip required: - name - auto_key oneOf: - type: object title: folder properties: folder: type: string pattern: ^[a-zA-Z\d\-_\. ]+$ maxLength: 64 description: The folder in which the resource is defined example: My Folder required: - folder - type: object title: snippet properties: snippet: type: string pattern: ^[a-zA-Z\d\-_\. ]+$ maxLength: 64 description: The snippet in which the resource is defined example: My Snippet required: - snippet - type: object title: device properties: device: type: string pattern: ^[a-zA-Z\d\-_\. ]+$ maxLength: 64 description: The device in which the resource is defined example: My Device required: - device generic_error: type: object properties: _errors: $ref: '#/components/schemas/error_detail_cause_infos' _request_id: type: string x-examples: {} ErrorResponse: type: object properties: _errors: type: array items: type: object properties: code: type: string example: example-code message: type: string example: Alert malware configured threat rule network malware configured on. details: type: object example: {} example: - code: example-code message: Threat configured alert firewall violation monitoring traffic activity. details: {} - code: example-code message: Blocked threat Security traffic firewall monitoring malware endpoint suspicious network. details: {} _request_id: type: string example: '980164' IPSecTunnel: type: object required: - name - auto_key properties: id: type: string description: Unique identifier for the IPSec tunnel. readOnly: true example: example-id name: type: string description: Name of the IPSec tunnel. example: Staging Firewall 42 auto_key: type: object description: Auto-key IKE configuration for the tunnel. properties: ike_gateway: type: array items: type: object properties: name: type: string description: Name of the IKE gateway to use. example: Production Agent 99 example: - name: Branch Agent 66 - name: Primary Agent 16 ipsec_crypto_profile: type: string description: IPSec crypto profile name. example: IP Camera example: ike_gateway: - name: Corporate Firewall 77 ipsec_crypto_profile: HVAC Controller tunnel_monitor: type: object properties: enable: type: boolean example: false destination_ip: type: string format: ipv4 example: 10.93.88.181 proxy_id: type: string example: '109061' example: enable: false destination_ip: 10.26.144.251 proxy_id: '408309' anti_replay: type: boolean default: true description: Whether anti-replay protection is enabled. example: true folder: type: string readOnly: true example: example-folder parameters: folder: name: folder in: query description: 'The folder in which the resource is defined ' required: false schema: type: string uuid: name: id in: path description: The UUID of the configuration resource required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426655440000 limit: name: limit in: query description: The maximum number of results per page required: false schema: type: integer default: 200 device: name: device in: query description: 'The device in which the resource is defined ' required: false schema: type: string snippet: name: snippet in: query description: 'The snippet in which the resource is defined ' required: false schema: type: string offset: name: offset in: query description: The offset into the list of results returned required: false schema: type: integer default: 0 name: name: name in: query description: The name of the configuration resource required: false schema: type: string uuid-required: description: 'The resource''s unique identifier. ' in: path name: id required: true schema: type: string offset-optional: description: 'The offset of the result entry. ' in: query name: offset required: false schema: type: number name-optional: description: 'The name of the entry. ' in: query name: name required: false schema: type: string limit-optional: description: 'The maximum number of result objects to return per page. ' in: query name: limit required: false schema: type: number securitySchemes: scmOAuth: type: oauth2 description: "Strata Cloud Manager APIs authenticate client requests using the \nOAuth 2.0 Client Credentials flow. Please use the `client_id`, \n`client_secret` values associated with an IAM service account along \nwith a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the \nTenant Service Group (TSG) ID. The resulting JWT access token should \nbe attached to all API calls as a `Bearer` token in the `Authorization` \nheader (ex. `Authorization: Bearer tokenstring`).\n" flows: clientCredentials: tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token scopes: tsg_id: Your tenant service group in the form `tsg_id:XXXXXXXXXX` scmToken: type: http description: "Strata Cloud Manager APIs authenticate client requests using the \nOAuth 2.0 Client Credentials flow. Please use the `client_id`, \n`client_secret` values associated with an IAM service account along \nwith a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the \nTenant Service Group (TSG) ID. The resulting JWT access token should \nbe attached to all API calls as a `Bearer` token in the `Authorization` \nheader (ex. `Authorization: Bearer tokenstring`).\n" scheme: bearer bearerFormat: JWT Bearer: scheme: bearer type: http oauth2: type: oauth2 description: OAuth 2.0 client credentials flow for obtaining an access token. Requires a client ID and client secret from the Palo Alto Networks SASE identity provider. flows: clientCredentials: tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token scopes: {} x-internal: false