<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Rest APIs - Access Control Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4953010#M477</link>
    <description>&lt;P&gt;This is pretty detailed!&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2023 05:18:47 GMT</pubDate>
    <dc:creator>divitgupta</dc:creator>
    <dc:date>2023-11-03T05:18:47Z</dc:date>
    <item>
      <title>Firepower Rest APIs - Access Control Rules</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4938166#M474</link>
      <description>&lt;P&gt;I'm attempting to pull our access policy rules and get the allowed networks and port numbers using REST API. When trying to run the GET request&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN&gt;{{baseURL}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;/api/fmc_config/v1/domain/&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;{{domainUUID}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;/policy/accesspolicies/&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;{{???}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;/accessrules I keep getting a&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"No&amp;nbsp;data&amp;nbsp;found&amp;nbsp;for: " 404 error. I have tried HA pair and individual device UUIDs with no luck. Does anyone know what Container UUID the request needs to get the information requested?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Oct 2023 15:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4938166#M474</guid>
      <dc:creator>jaismith</dc:creator>
      <dc:date>2023-10-11T15:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Rest APIs - Access Control Rules</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4952380#M476</link>
      <description>&lt;P&gt;Rest API document: &lt;SPAN class="resolvedVariable" data-testid="resolvedVariable"&gt;&lt;SPAN data-offset-key="8rkjm-0-0"&gt;{{protocol}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-offset-key="8rkjm-1-0"&gt;://&lt;/SPAN&gt;&lt;SPAN class="resolvedVariable" data-testid="resolvedVariable"&gt;&lt;SPAN data-offset-key="8rkjm-2-0"&gt;{{hostname}}&lt;/SPAN&gt;&lt;/SPAN&gt;/api/api-explorer/&lt;/P&gt;
&lt;P&gt;For example:&lt;A href="https://1.2.3.4/api/api-explorer/" target="_blank" rel="noopener"&gt;https://1.2.3.4/api/api-explorer/&lt;/A&gt; (1.2.3.4 is FMC IP address or you can input FMC hostname here)&lt;/P&gt;
&lt;P&gt;--------------------------&lt;/P&gt;
&lt;P&gt;Device_id is FMC ID which can be found in the browser address after you access 'System&amp;gt;Health&amp;gt;Monitor&amp;gt;FMC'.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_7-1698903624141.png" style="width: 770px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201431iE4DF4D09B1E20F31/image-dimensions/770x260?v=v2" width="770" height="260" role="button" title="betliu_7-1698903624141.png" alt="betliu_7-1698903624141.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Container_uuid is the access control policy id which can be found in the browser address after you access 'Policies&amp;gt;Access Control&amp;gt;click one of your policies'.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_8-1698903949425.png" style="width: 750px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201432iE8C16029DA238450/image-dimensions/750x243?v=v2" width="750" height="243" role="button" title="betliu_8-1698903949425.png" alt="betliu_8-1698903949425.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I tested in lab to retrieve access control rules and took screenshots for your reference.&lt;/P&gt;
&lt;P&gt;Step1: Generate Token&lt;/P&gt;
&lt;P&gt;{{protocol}}://{{hostname}}/api/fmc_platform/v1/auth/generatetoken&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_0-1698903493989.png" style="width: 748px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201426iCD0012F6A1FA63A4/image-dimensions/748x242?v=v2" width="748" height="242" role="button" title="betliu_0-1698903493989.png" alt="betliu_0-1698903493989.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then you can find ‘token’ and ‘DOMAIN_UUI’ in headers after you click button ‘Send’&lt;/P&gt;
&lt;P&gt;‘token’ and ‘DOMAIN_UUI’ will be used in next step.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_1-1698903493999.png" style="width: 740px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201425i2647BB9DB04B450C/image-dimensions/740x345?v=v2" width="740" height="345" role="button" title="betliu_1-1698903493999.png" alt="betliu_1-1698903493999.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Step2: Get Access Policy ID which is ‘Container ID’ .&lt;/P&gt;
&lt;P&gt;option1: operate in FMC GUI directly&lt;/P&gt;
&lt;P&gt;Container_uuid is the access control policy id which can be found in the browser address after you access 'Policies&amp;gt;Access Control&amp;gt;click one of your policies'.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_8-1698903949425.png" style="width: 741px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201432iE8C16029DA238450/image-dimensions/741x240?v=v2" width="741" height="240" role="button" title="betliu_8-1698903949425.png" alt="betliu_8-1698903949425.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;option2: operate in postman&lt;/P&gt;
&lt;P&gt;{{protocol}}://{{hostname}}/api/fmc_config/v1/domain/{{domain_id}}/policy/accesspolicies?limit=1000&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_2-1698903494008.png" style="width: 753px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201424iAF2735434137CE95/image-dimensions/753x274?v=v2" width="753" height="274" role="button" title="betliu_2-1698903494008.png" alt="betliu_2-1698903494008.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Input the DOMAIN_UUID generated in last step and other required information in the screenshot, click ‘Send’ button, then we can get ‘id’ which is ‘policy id’ and we also call it ‘Container ID’ in the response body.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_3-1698903494024.png" style="width: 762px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201429iA15C9B880CA8D34E/image-dimensions/762x329?v=v2" width="762" height="329" role="button" title="betliu_3-1698903494024.png" alt="betliu_3-1698903494024.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Step3: get access control rules&lt;/P&gt;
&lt;P&gt;{{protocol}}://{{hostname}}/api/fmc_config/v1/domain/{{domain_id}}/policy/accesspolicies/{{accesspolicy_id}}/accessrules&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_5-1698903494049.png" style="width: 756px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201427i48F1CF7E25CA7B10/image-dimensions/756x289?v=v2" width="756" height="289" role="button" title="betliu_5-1698903494049.png" alt="betliu_5-1698903494049.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Input ‘Domian_id’ which was generated in step1 and ‘accesspolicy_id’ (‘Container_uuid’) which was generated in step2, along with authentication and token information, click ‘Try’ button.&lt;/P&gt;
&lt;P&gt;Then we can get Access Control Rules information in response body.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="betliu_6-1698903494064.png" style="width: 816px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201430i3BE6D8ED43400003/image-dimensions/816x359?v=v2" width="816" height="359" role="button" title="betliu_6-1698903494064.png" alt="betliu_6-1698903494064.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 06:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4952380#M476</guid>
      <dc:creator>betliu</dc:creator>
      <dc:date>2023-11-03T06:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Rest APIs - Access Control Rules</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4953010#M477</link>
      <description>&lt;P&gt;This is pretty detailed!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 05:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4953010#M477</guid>
      <dc:creator>divitgupta</dc:creator>
      <dc:date>2023-11-03T05:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Rest APIs - Access Control Rules</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4971121#M484</link>
      <description>&lt;P&gt;I'm going to try this in my lab. Will update.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 17:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rest-apis-access-control-rules/m-p/4971121#M484</guid>
      <dc:creator>asadabbasawan</dc:creator>
      <dc:date>2023-12-04T17:42:46Z</dc:date>
    </item>
  </channel>
</rss>

