The identity and technical contract details declared by the specification.
protect_re_custom_protocol
string
enum: any, icmp, tcp, udp
service_policy_ewf_rule_profile
string
enum: critical, standard, strict
network_internal_access
object
1 property
tunnel_config_node_remote_ids
array
Only if provider==jse-ipsec or provider==custom-ipsec
service_policy_secintel_profile
string
enum: default, standard, strict
network_internet_access
object
Whether this network has direct internet access
5 properties
gw_routing_policy_term
object
2 properties
gateway_extra_route6
object
1 property
tunnel_config
object
18 properties
sw_routing_policy_term_matching
object
zero or more criteria/filter can be specified to match the term, all criteria have to be met
4 properties
tunnel_config_tunnel_mode
string
Required if provider==zscaler-gre, provider==jse-ipsec. enum: active-active, active-standby
gw_routing_policy_terms
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
gateway_port_dsl_type
string
if wantype==dsl. enum: adsl, vdsl
acl_policy_src_tags
array
ACL Policy Source Tags: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source o…
snmpv3_config_target_address
array
acl_tags
object
ACL Tags to identify traffic source or destination. Key name is the tag name
tacacs_default_role
string
enum: admin, helpdesk, none, read
switch_port_usage_mac_auth_protocol
string
Only if mode!=dynamic and enablemacauth ==true. This type is ignored if mistnac is enabled. enum: eap-md5, eap-peap, pap
gateway_port_config_ip_config
object
Junos IP Config
14 properties
gateway_wan_probe_override
object
Only if usage==wan
3 properties
snmp_vacm_access_item_prefix_list_item_level
string
enum: authentication, none, privacy
radsec_servers
array
List of RadSec Servers. Only if not Mist Edge.
extra_route
object
6 properties
gateway_port_lte_auth
string
if wantype==lte. enum: chap, none, pap
gw_routing_policy_term_action_add_community
array
snmp_usm_user
object
5 properties
routing_policy_term_matching_as_path
array
tunnel_provider_options
object
3 properties
radius_acct_server
object
7 properties
2 required
network_internet_access_static_nat
object
Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
idp_profile
object
7 properties
remote_syslog
object
10 properties
switch_port_usage_dynamic_rule_equals_any
array
Use equalsany to match any item in a list
gateway_wan_ppoe_auth
string
if type==pppoe. enum: chap, none, pap
snmp_config_trap_group_targets
array
network_source_nat
object
If routed==false (usually at Spoke), but some hosts needs to be reachable from Hub
1 property
network_tenant_addresses
array
snmpv3_config_target_param
object
6 properties
gateway_ip_config_property_second_ips
array
Optional list of secondary IPs in CIDR format
ap_switch_setting_port_vlan_id
Native VLAN id, optional
junos_port_config
object
Switch port config
18 properties
1 required
tunnel_config_ike_mode
string
Only if provider==custom-ipsec. enum: aggressive, main
tunnel_config_auto_provision_lat_lng
object
API override for POP selection
2 properties
2 required
sw_routing_policy_term
object
3 properties
1 required
snmpv3_config
object
6 properties
dhcpd_config_type6
string
enum: local (DHCP Server), none, relay (DHCP Relay)
ap_radio_band24
object
Radio Band AP settings
11 properties
radius_config
object
Junos Radius config
9 properties
switch_port_mirroring_ingress_port_ids
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
gateway_extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64"), the destination Network name or a variable (e.g. "{{myvar}}")
dhcpd_config_dns_servers
array
If type==local or type6==local - optional, if not defined, system one will be used
ap_led
object
LED AP settings
2 properties
remote_syslog_cacerts
array
gateway_port_vpn_path_role
string
If the VPN type==hubspoke, enum: hub, spoke. If the VPN type==mesh, enum: mesh
ospf_area_network_auth_type
string
auth type. enum: md5, none, password
gateway_extra_route
object
1 property
snmp_vacm_security_to_group
object
2 properties
dot11_bandwidth5
integer
channel width for the 5GHz band. enum: 0(disabled, response only), 20, 40, 80
tunnel_provider_options_jse
object
For jse-ipsec, this allows provisioning of adequate resource on JSE. Make sure adequate licenses are added
2 properties
network_vpn_access_destination_nat_property
object
3 properties
tacacs_acct_servers
array
protect_re_allowed_services
array
Optionally, services we'll allow
dhcpd_config_servers6
array
If type6==relay
switch_dhcpd_config_options
object
If type==server or type6==server. Property key is the DHCP option number
ap_ip_config_dns
array
If type==static
snmp_vacm_access_item_prefix_list_item
object
7 properties
switch_port_usage_dynamic_vlan_networks
array
Only if mode!=dynamic and portauth==dot1x, if dynamic vlan is used, specify the possible networks/vlans RADIUS can return
ap_ip_config_dns_suffix
array
Required if type==static
next_hop_via
Next-hop IP Address. Can be a single IP address or an array of IP addresses for ECMP (Equal-Cost Multi-Path) load balancing across multiple next-hops.
antenna_select
string
Antenna Mode for AP which supports selectable antennas. enum: "" (default), external, internal
protect_re_custom
object
Custom acls
3 properties
gateway_port_vpn_path_bfd_profile
string
Only if the VPN type==hubspoke. enum: broadband, lte
radio_band_preamble
string
enum: auto, long, short
config_switch_local_accounts
object
Property key is the user name. For Local user authentication
snmpv3_config_notify_filter_item_content
object
2 properties
ap_mesh_role
string
enum: base, remote
tunnel_config_ike_proposal
object
3 properties
ap_zigbee_allow_join
string
Controls whether new Zigbee devices are allowed to join the network. enum: always, manual
sw_routing_policy_term_matching_protocol_enum
string
enum: bgp, direct, evpn, ospf, static
gateway_ip_config_dns_servers
array
Except for out-ofband interface (vme/em0/fxp0)
snmp_config_trap_group_categories
array
remote_syslog_contents
array
remote_syslog_user
object
3 properties
ap_pwr_config
object
Power related configs
2 properties
switch_dhcpd_config_dns_suffix
array
If type==server or type6==server - optional, if not defined, system one will be used
protect_re
object
Restrict inbound-traffic to host when enabled, all traffic that is not essential to our operation will be dropped e.g. ntp / dns / traffic to mist will be allo…
5 properties
tunnel_config_probe
object
Only if provider==custom-ipsec
4 properties
device_ap_lacp_config
object
1 property
vrrp_config_group
object
2 properties
snmp_config_v2c_config
object
4 properties
protect_re_trusted_hosts
array
host/subnets we'll allow traffic to/from
sw_routing_policy_term_action
object
When used as import policy
4 properties
snmp_config_engine_id_type
string
enum: local, usemacaddress
gateway_matching_rule
object
3 properties
gateway_port_networks
array
If usage==lan, name of the [networks]($h/Orgs%20Networks/overview) to attach to the interface
remote_syslog_file_config
object
7 properties
ap_uplink_port_config
object
AP Uplink port configuration
2 properties
ip_type
string
enum: dhcp, static
dhcp_snooping_networks
array
If allnetworks==false, list of network with DHCP snooping enabled
network_multicast_groups
object
Group address to RP (rendezvous point) mapping. Property Key is the CIDR (example "225.1.0.3/32")
vars
object
Dictionary of name-value, the vars can then be used in Wlans. This can overwrite those from Site Vars
gateway_port_wan_type
string
Only if usage==wan. enum: broadband, dsl, lte
ap_radio_band6
object
Radio Band AP settings
13 properties
dhcpd_config_fixed_binding
object
3 properties
dhcpd_config_option
object
2 properties
switch_networks
object
Property key is network name
ospf_area_network_interface_type
string
interface type (nbma = non-broadcast multi-access). enum: broadcast, nbma, p2mp, p2p
ble_config_beam_disabled
array
List of AP BLE location beam numbers (1-8) which should be disabled at the AP and not transmit location information (where beam 1 is oriented at the top the AP…
idp_profile_matching
object
3 properties
switch_port_mirroring
object
Property key is the port mirroring instance name. portmirroring can be added under device/site settings. It takes interface and ports as input for ingress, int…
network_vpn_access_static_nat
object
Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
radius_acct_servers
array
gw_routing_policy_term_action_exclude_community
array
config_switch_local_accounts_user_role
string
enum: admin, helpdesk, none, read
ap_switch_setting
object
3 properties
switch_port_usage_dot1x
stringnull
Only if mode!=dynamic. If dot1x is desired, set to dot1x. enum: dot1x
snmpv3_config_notify_filter
array
remote_syslog_facility
string
enum: any, authorization, change-log, config, conflict-log, daemon, dfc, external, firewall, ftp, interactive-commands, kernel, ntp, pfe, security, user
remote_syslog_server_port
Syslog Service Port, value from 1 to 65535
switch_vrf_instance
object
7 properties
remote_syslog_server
object
13 properties
service_policy_skyatp_dns_dga_detection_profile
string
enum: default, standard, strict
gateway_port_config
object
Gateway port config
48 properties
1 required
service_policy
object
15 properties
snmpv3_config_notify_type
string
enum: inform, trap
gateway_wan_probe_override_probe_profile
string
enum: broadband, lte
tunnel_config_local_subnets
array
List of Local protected subnet for policy-based IPSec negotiation
gateway_port_usage
string
port usage name. enum: hacontrol, hadata, lan, wan
tacacs_acct_server
object
4 properties
dhcpd_config_type
string
enum: local (DHCP Server), none, relay (DHCP Relay)
switch_port_usage_networks
array
Only if mode==trunk, the list of network/vlans
protect_re_custom_subnet
array
gw_routing_policy_term_action
object
When used as import policy
9 properties
switch_iot_port_input_src
string
Only for "OUT" ports, input source for the switch iot port out. enum: IN0, IN1
ap_airista
object
3 properties
switch_port_mirroring_egress_port_ids
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
gateway_ip_configs
object
Property key is the network name
gateway_path_type
string
enum: local, tunnel, vpn, wan
tunnel_config_remote_subnets
array
List of Remote protected subnet for policy-based IPSec negotiation
response_assign_success
object
1 property
1 required
snmp_vacm_security_to_group_content_item
object
2 properties
tunnel_provider_options_zscaler_sub_location
object
14 properties
snmpv3_config_notify_items
object
3 properties
gateway_ip_config_property
object
7 properties
switch_radius
object
By default, radiusconfig will be used. if a different one has to be used set usedifferentradius
3 properties
acl_tag_type
string
enum: any: matching anything not identified dynamicgbp: from the gbptag received from RADIUS gbpresource: can only be used in dsttags mac network portusage rad…
radio_band_antenna_beam_pattern
string
enum: narrow, medium, wide
vrrp_config_groups
object
Property key is the VRRP name
ospf_area_type
string
OSPF type. enum: default, nssa, stub
ap_switch
object
For people who want to fully control the vlans (advanced)
7 properties
tunnel_config_auto_provision_node
object
2 properties
idp_profile_overwrites
array
network_vpn_access
object
Property key is the VPN name. Whether this network can be accessed from vpn
network_vpn_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
acl_tag_spec
object
2 properties
dhcpd_config_property
object
16 properties
sw_routing_policy_terms
array
at least criteria/filter must be specified to match the term, all criteria have to be met
service_policy_syslog
object
Required for syslog logging
2 properties
switch_iot_port_alarm_class
string
Alarm class for the switch iot port in. enum: minor, major
gateway_path_preferences_path_networks
array
Required when type==local
ssl_proxy_ciphers_category
string
enum: medium, strong, weak
switch_stp_config
object
1 property
gw_routing_policy_term_action_export_communities
array
When used as export policy, optional
switch_port_usage_dynamic_rule
object
6 properties
1 required
remote_syslog_users
array
gw_routing_policy_term_matching_route_exists
object
2 properties
created_time
number
When the object has been created, in epoch
ap_usb
object
USB AP settings - Note: if native imagotag is enabled, BLE will be disabled automatically - Note: legacy, new config moved to ESL Config.
8 properties
switch_port_usage
object
Junos port usages
45 properties
aggregate_routes
object
Property key is the destination subnet (e.g. "172.16.3.0/24")
snmp_usm_user_encryption_type
string
enum: privacy-3des, privacy-aes128, privacy-des, privacy-none
remote_syslog_content
object
2 properties
gateway_vrf_instance
object
1 property
network_tenant
object
1 property
service_policy_skyatp
object
SRX only
4 properties
ospf_area
object
Property key is the OSPF Area (Area should be a number (0-255) / IP address)
3 properties
ble_config
object
BLE AP settings
27 properties
switch_port_usage_dynamic_rule_src
string
enum: linkpeermac, lldpchassisid, lldphardwarerevision, lldpmanufacturername, lldpoui, lldpserialnumber, lldpsystemdescription, lldpsystemname, radiusdynamicfi…
dhcpd_config_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
ap_iot_input
object
IoT Input AP settings
3 properties
tunnel_via
string
If via==tunnel, specifies which tunnel (primary/secondary) this neighbor is associated with. enum: primary, secondary
tunnel_config_node_wan_names
array
mac_addresses
object
1 property
1 required
wired_port_config
object
Property key is the port name or range (e.g. "ge-0/0/0-10")
bgp_as
BGP AS, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}} )
gw_routing_policy_term_matching
object
zero or more criteria/filter can be specified to match the term, all criteria have to be met
9 properties
ap_port_config
object
17 properties
gw_routing_policy
object
1 property
switch_mgmt_mxedge_proxy_port
Mist Edge port used to proxy the switch management traffic to the Mist Cloud. Value in range 1-65535
remote_syslog_files
array
snmp_config_view
object
3 properties
response_http429
object
1 property
ap_port_config_dynamic_vlan
object
Optional dynamic vlan
4 properties
idp_profile_action
string
enum: alert (default) drop: silently dropping packets close: notify client/server to close connection
gateway_vrf_instances
object
Property key is the network name
gateway_traffic_shaping_class_percentages
array
percentages for different class of traffic: high / medium / low / best-effort. Sum must be equal to 100
vrrp_config
object
Junos VRRP config
2 properties
ap_iot_pullup
string
the type of pull-up the pin uses. enum: external, internal, none
junos_other_ip_config
object
Optional, if it's required to have switch's L3 presence on a network/vlan
7 properties
routing_policy_term_action_community
array
When used as export policy, optional
ap_iot
object
IoT AP settings
7 properties
acl_policy
object
ACL Policy: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source or destinatio…
3 properties
wan_extra_routes
object
1 property
service_policy_secintel
object
SRX only
3 properties
gw_routing_policy_term_action_exclude_as_path
array
When used as export policy, optional. To exclude certain AS
switch_mgmt
object
Switch Management settings
16 properties
ip_type6
string
enum: autoconf, dhcp, disabled, static
gateway_port_wan_source_nat
object
Only if usage==wan, optional. By default, source-NAT is performed on all WAN Ports using the interface-ip
3 properties
gateway_port_vpn_paths
object
Property key is the VPN name
network_internet_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
snmpv3_config_target_param_security_level
string
enum: authentication, none, privacy
device_type_ap
string
Device Type. enum: ap
ap_esl_type
string
note: bleconfig will be ignored if eslconfig is enabled and with native mode. enum: hanshow, imagotag, native, solum
switch_port_usage_dynamic_reset_default_when
string
Only if mode==dynamic Control when the DPC port should be changed to the default port usage. enum: linkdown, none (let the DPC port keep at the current port us…
tunnel_provider_options_zscaler
object
For zscaler-ipsec and zscaler-gre
15 properties
idp_profile_matching_dst_subnet
array
response_http403
object
1 property
gateway_wan_type
string
enum: dhcp, pppoe, static
aggregate_routes6
object
Property key is the destination subnet (e.g. "2a02:1234:420a:10c9::/64")
snmp_vacm_security_model
string
enum: usm, v1, v2c
switch_port_mirroring_property
object
6 properties
snmp_vacm_access_item_prefix_list_item_model
string
enum: any, usm, v1, v2c
snmp_vacm_access_item
object
2 properties
idp_profile_base_profile
string
enum: critical, standard, strict
gw_routing_policy_term_matching_vpn_neighbor_mac
array
overlay-facing criteria (used for bgpconfig where via=vpn)
switch_network
object
A network represents a network segment. It can either represent a VLAN (then usually ties to a L3 subnet), optionally associate it with a subnet which can late…
7 properties
1 required
snmpv3_config_target_param_mess_process_model
string
enum: v1, v2c, v3
response_http400
object
1 property
extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8")
extra_route_next_qualified_properties
object
2 properties
vrf_extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8")
dot11_bandwidth6
integer
channel width for the 6GHz band. enum: 0(disabled, response only), 20, 40, 80, 160
tunnel_config_networks
array
If provider==custom-ipsec or provider==prisma-ipsec, networks reachable via this tunnel
ap_switch_setting_vlan_ids
array
List of VLAN ids
switch_dhcpd_config_type6
string
enum: none, relay (DHCP Relay), server (DHCP Server)
radio_band_channels
arraynull
For RFTemplates. List of channels, null or empty array means auto
snmpv3_config_notify_filter_item
object
2 properties
bgp_config_via
string
enum: lan, tunnel, vpn, wan
dot11_band
string
enum: 24, 5, 5-dedicated, 5-selectable, 6, 6-dedicated, 6-selectable
remote_syslog_time_format
string
enum: millisecond, year, year millisecond
deviceprofile_gateway
object
Gateway Template is applied to a site for gateway(s) in a site.
31 properties
2 required
tacacs_auth_server
object
4 properties
tunnel_config_version
string
Only if provider==custom-gre or provider==custom-ipsec. enum: 1, 2
tunnel_config_ipsec_proposals
array
Only if provider==custom-ipsec
switch_port_mirroring_ingress_networks
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
modified_time
number
When the object has been modified for the last time, in epoch
acl_policy_actions
array
ACL Policy Actions: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source or de…
tunnel_config_ipsec_proposal
object
3 properties
gw_routing_policy_term_matching_protocol
array
acl_tag_macs
array
Required if - type==mac - type==staticgbp if from matching mac
gateway_oob_ip_config
object
Out-of-band (vme/em0/fxp0) IP config
8 properties
routing_policy_term_matching_community
array
tunnel_config_node
object
Only if provider==zscaler-ipsec, provider==jse-ipsec or provider==custom-ipsec
5 properties
2 required
deviceprofile_ap
object
Device Profile
31 properties
1 required
switch_port_usage_mtu
Only if mode!=dynamic media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation. The default value is 1514.
tunnel_config_node_hosts
array
radius_acct_port
Radius Auth Port, value from 1 to 65535, default is 1813
gateway_ip_config_dns_suffix
array
Except for out-ofband interface (vme/em0/fxp0)
dhcpd_config_fixed_bindings
object
If type==local or type6==local. Property key is the MAC Address. Format is [0-9a-f]{12} (e.g. "5684dae9ac8b")
ap_radio_band5
object
Radio Band AP settings
12 properties
tunnel_provider_options_prisma
object
1 property
gateway_path_preferences_paths
array
ap_aeroscout
object
Aeroscout AP settings
4 properties
network_internet_access_destination_nat_property
object
4 properties
acl_tag
object
Resource tags (type==resource or type==gbpresource) can only be used in dsttags
9 properties
1 required
snmp_usm_engine_type
string
enum: localengine, remoteengine
snmp_config_trap_version
string
enum: all, v1, v2
ap_radio
object
Radio AP settings
15 properties
snmp_config_client_list_clients
array
ap_port_config_forwarding
string
enum: all: local breakout, All VLANs limited: local breakout, only the VLANs configured in portvlanid and vlanids mxtunnel: central breakout to an Org Mist Edg…
service_policy_antivirus
object
For SRX-only
3 properties
gateway_port_vlan_id_with_variable
If WAN interface is on a VLAN. Can be the VLAN ID (i.e. "10") or a Variable (i.e. "{{myvar}}")
routing_policy_term_action_prepend_as_path
array
When used as export policy, optional. By default, the local AS will be prepended, to change it. Can be a Variable (e.g. {{aspath}})
tunnel_config_auto_provision_provider
string
enum: jse-ipsec, zscaler-ipsec
ap_mesh_bands
array
List of bands that the mesh should apply to. For relay, the first viable one will be picked. For relay, the first viable one will be picked. enum: 24, 5, 6
switch_dhcpd_config_fixed_bindings
object
If type==server or type6==server. Property key is the MAC Address. Format is [0-9a-f]{12} (e.g. "5684dae9ac8b")
gateway_port_config_wan_speedtest_mode
string
Controls whether Marvis/scheduler can run speedtest on this port. enum: auto, enabled, disabled
idp_config
object
4 properties
tunnel_config_auth_algo
string
enum: md5, sha1, sha2
radsec_proxy_hosts
array
Default is site.mxedge.radsec.proxyhosts which must be a superset of all wlans[].radsec.proxyhosts. When radsec.proxyhosts are not used, tunnel peers (org or s…
snmp_vacm_access_item_prefix_list
array
radius_auth_server
object
Authentication Server
8 properties
2 required
extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
tunnel_config_auto_provision_node_wan_names
array
Optional, only needed if varsonly==false
snmp_config_engine_id
string
dns_suffix
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
dns_servers
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
config_switch_local_accounts_user
object
2 properties
radius_auth_servers
array
network_routed_for_networks
array
For a Network (usually LAN), it can be routable to other networks (e.g. OSPF)
allow_deny
string
enum: allow, deny
idp_profile_overwrite
object
3 properties
tunnel_config_probe_type
string
enum: http, icmp
vrf_extra_route
object
1 property
ap_port_config_mac_auth_protocol
string
if enablemacauth==true, allows user to select an authentication protocol. enum: eap-md5, eap-peap, pap
switch_dhcpd_config_dns_servers
array
If type==server or type6==server - optional, if not defined, system one will be used
switch_iot_port
object
Switch IOT port configuration
4 properties
dhcpd_config_servers
array
If type==relay
service_policy_skyatp_http_inspection_profile
string
enum: standard, strict
gateway_matching
object
Gateway matching
2 properties
ibeacon_minor
integernull
Minor number for iBeacon
protect_re_allowed_service
string
enum: icmp, ssh
switch_iot_config
object
Property Key is the IOT port name, e.g.: IN0 or IN1 for the FPC0 input port with 5V triggered inputs OUT1 for the FPC0 output port (can only be triggered by ei…
ap_zigbee
object
Zigbee AP settings
5 properties
dhcpd_config_dns_suffix
array
If type==local or type6==local - optional, if not defined, system one will be used
gateway_port_duplex
string
enum: auto, full, half
tunnel_config_protocol
string
Only if provider==custom-ipsec. enum: gre, ipsec
const_device_type_switch
string
Device Type. enum: switch
tunnel_config_ike_proposals
array
If provider==custom-ipsec
service_policy_ssl_proxy
object
For SRX-only
2 properties
switch_port_usages
object
Property key is the port usage name. Defines the profiles of port configuration configured on the switch
ap_esl_config
object
8 properties
sw_routing_policy_term_matching_protocol
array
dhcpd_config_options
object
If type==local or type6==local. Property key is the DHCP option number
switch_oob_ip_config
object
Switch OOB IP Config: - If HA configuration: key parameter will be nodeX (eg: node1) - If there are 2 routing engines, re1 mgmt IP has to be set separately (if…
7 properties
gateway_port_config_reth_idx
For SRX only and if HA Mode. -1 means it will be managed by the device. Use = 0 values to manage it manually. Ensure no conflicting values are assigned across…
dhcp_snooping
object
5 properties
ble_config_power_mode
string
enum: custom, default
remote_syslog_server_protocol
string
enum: tcp, udp
idp_profile_matching_severity
array
routing_policy_term_matching_prefix
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
aggregate_route
object
3 properties
remote_syslog_servers
array
snmp_config_client_lists
array
gateway_matching_rules
array
gw_routing_policy_term_matching_vpn_path
array
overlay-facing criteria (used for bgpconfig where via=vpn). ordered-
radsec
object
RadSec settings
9 properties
radio_band_24_usage
string
enum: 24, 5, 6, auto
tunnel_config_ike_dh_group
string
enum: 1 2 (1024-bit) 5 14 (default, 2048-bit) 15 (3072-bit) 16 (4096-bit) 19 (256-bit ECP) 20 (384-bit ECP) 21 (521-bit ECP) 24 (2048-bit ECP)
gateway_path_preferences_path
object
9 properties
1 required
service_policy_skyatp_iot_device_policy
object
1 property
switch_port_usage_storm_control
object
Switch storm control. Only if mode!=dynamic
6 properties
service_policy_skyatp_dns_tunnel_detection_profile
string
enum: default, standard, strict
ap_port_config_port_auth
string
When doing port auth. enum: dot1x, none
switch_vrf_instances
object
Property key is the network name
snmp_vacm
object
2 properties
gw_routing_policies
object
Property key is the routing policy name
radio_band_antenna_mode
string
enum: 1x1, 2x2, 3x3, 4x4, default
gw_routing_policy_term_action_add_target_vrfs
array
For SSR, hub decides how VRF routes are leaked on spoke
ibeacon_major
integernull
Major number for iBeacon
dhcpd_config_vendor_options
object
If type==local or type6==local. Property key is : , with enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers) su…
network_internet_access_static_nat_property
object
3 properties
tacacs_auth_servers
array
gateway_port_reth_nodes
array
SSR only - supporting vlan-based redundancy (matching the size of networks)
tunnel_config_node_internal_ips
array
Only if provider==zscaler-gre, provider==jse-ipsec, provider==custom-ipsec or provider==custom-gre
switch_port_usage_reauth_interval
Only if mode!=dynamic and portauth=dot1x reauthentication interval range (min: 10, max: 65535, default: 3600). Set to 0 to disable reauthentication (no-reauthe…
gateway_port_wan_arp_policer
string
Only when wantype==broadband. enum: default, max, recommended
snmp_vacm_access_item_type
string
enum: contextprefix, defaultcontextprefix
remote_syslog_archive
object
2 properties
junos_port_config_duplex
string
enum: auto, full, half
ble_config_beacon_rate_mode
string
enum: custom, default
gateway_idp_profiles
object
Property key is the profile name
gateway_port_vpn_path
object
5 properties
radsec_idle_timeout
Radsec Idle Timeout in seconds. Default is 60
remote_syslog_severity
string
enum: alert, any, critical, emergency, error, info, notice, warning
radius_coa_port
Radius CoA Port, value from 1 to 65535, default is 3799
ap_iot_output
object
IoT output AP settings
5 properties
service_policy_skyatp_dns_tunnel_detection
object
2 properties
routing_policy_local_preference
Optional, for an import policy, localpreference can be changed, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}})
acl_policy_action
object
2 properties
1 required
network_vpn_access_config_other_vrfs
array
By default, the routes are only readvertised toward the same vrf on spoke. To allow it to be leaked to other vrfs
switch_mist_nac
object
Enable mistnac to use RadSec
2 properties
evpn_config_role
string
enum: access, border, collapsed-core, core, distribution, esilag-access, none
response_http401
object
1 property
wan_extra_routes6
object
1 property
snmpv3_config_target_param_security_model
string
enum: usm, v1, v2c
snmp_usm_user_authentication_type
string
sha224, sha256, sha384, sha512 are supported in 21.1 and newer release. enum: authentication-md5, authentication-none, authentication-sha, authentication-sha22…
acl_tag_subnets
array
If - type==subnet - type==resource (optional. default is any) - type==staticgbp if from matching subnet
radius_auth_port
Radius Auth Port, value from 1 to 65535, default is 1812
additional_config_cmds
array
additional CLI commands to append to the generated Junos config. Note: no check is done
gateway_path_strategy
string
enum: ecmp, ordered, weighted
switch_dhcpd_config_property
object
the Property key is the network name. In case of DHCP relay, it's common for many networks to use the same dhcp relay, comma-separated network names can be use…
16 properties
snmp_config
object
13 properties
remote_syslog_archive_files
gateway_traffic_shaping
object
3 properties
switch_radius_config
object
Junos Radius config
12 properties
zscaler_sub_locations
array
sub-locations can be used for specific uses cases to define different configuration based on the user network
snmpv3_config_target_address_item
object
6 properties
network_vpn_access_static_nat_property
object
2 properties
ospf_areas
object
Junos OSPF areas. Property key is the OSPF Area (Area should be a number (0-255) / IP address)
snmp_vacm_security_to_group_content
array
snmp_usm
object
3 properties
network_vpn_access_config
object
14 properties
dot11_bandwidth24
integer
channel width for the 2.4GHz band. enum: 0(disabled, response only), 20, 40
evpn_config
object
EVPN Junos settings
2 properties
tunnel_config_auto_provision
object
Auto Provisioning configuration for the tunne. This takes precedence over the primary and secondary nodes.
7 properties
1 required
vrf_extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
switch_port_usage_dynamic_rules
array
Only if mode==dynamic
ap_radio_antenna_mode
string
enum: 1x1, 2x2, 3x3, 4x4, default
junos_port_config_speed
string
enum: 100m, 10m, 1g, 2.5g, 5g, 10g, 25g, 40g, 100g,auto
idp_profile_matching_attack_name
array
snmp_config_client_list
object
2 properties
junos_ip_config
object
Junos IP Config
7 properties
network_multicast
object
Whether to enable multicast support (only PIM-sparse mode is supported)
3 properties
switch_port_usage_mac_limit
Only if mode!=dynamic, max number of mac addresses, default is 0 for unlimited, otherwise range is 1 to 16383 (upper bound constrained by platform)
switch_port_usage_speed
string
Only if mode!=dynamic, Port speed, default is auto to automatically negotiate speed enum: 100m, 10m, 1g, 2.5g, 5g, 10g, 25g, 40g, 100g,auto
switch_dhcpd_config
object
1 property
sw_routing_policies
object
Property key is the routing policy name
gateway_oob_ip_config_node1
object
For HA Cluster, node1 can have different IP Config
7 properties
switch_dhcpd_config_type
string
enum: none, relay (DHCP Relay), server (DHCP Server)
switch_radius_config_auth_server_selection
string
enum: ordered, unordered
gw_routing_policy_term_matching_vpn_path_sla
object
3 properties
gateway_path_preferences_path_target_ips
array
If type==local, if destination IP is to be replaced
acl_tag_ether_types
array
ARP / IPv6. Default is any
snmp_config_v2c_configs
array
snmpv3_config_notify
array
vrf_config
object
1 property
ap_ip_config
object
IP AP settings
12 properties
radius_keywrap_format
string
enum: ascii, hex
ap_mesh
object
Mesh AP settings
5 properties
service_policy_skyatp_http_inspection
object
2 properties
remote_syslog_console
object
1 property
acl_tag_specs
array
If type==resource, type==radiusgroup, type==portusage or type==gbpresource. Empty means unrestricted, i.e. any
bgp_local_as
Required if via==lan, via==tunnel or via==wan. BGP AS, value in range 1-4294967295
wlan_mist_nac
object
9 properties
ap_usb_type
string
usb config type. enum: hanshow, imagotag, solum
extra_route6
object
6 properties
dhcpd_config
object
1 property
bgp_config_networks
array
Optional if via==lan. List of networks where we expect BGP neighbor to connect to/from
snmp_config_trap_group
object
4 properties
bgp_config_neighbors
object
7 properties
1 required
snmpv3_config_target_params
array
network_tenants
object
Property key must be the user/tenant name (i.e. "printer-1") or a Variable (i.e. "{{myvar}}")
tunnel_config_enc_algo
stringnull
enum: 3des, aes128, aes256, aesgcm128, aesgcm256
gw_routing_policy_term_matching_protocol_enum
string
enum: aggregate, bgp, direct, ospf, static (SRX Only)
gateway_extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8"), the destination Network name or a variable (e.g. "{{myvar}}")
tunnel_config_provider
string
Only if autoprovision.enabled==false. enum: custom-ipsec, custom-gre, jse-ipsec, prisma-ipsec, zscaler-gre, zscaler-ipsec
service_policy_appqoe
object
SRX only
1 property
id
string
Unique ID of the object instance in the Mist Organization
radsec_mxcluster_ids
array
To use Org mxedges when this WLAN does not use mxtunnel, specify their mxclusterids. Org mxedge(s) identified by mxclusterids
tacacs
object
5 properties
snmpv3_config_notify_filter_item_contents
array
bgp_config
object
BFD is enabled when either bfdminimuminterval or bfdmultiplier is configured
22 properties
1 required
network_multicast_group
object
1 property
service_policy_ewf_rule
object
4 properties
switch_port_usage_mode
string
mode==dynamic must only be used if the port usage name is dynamic. enum: access, dynamic, inet, trunk
gateway_path_preferences
object
2 properties
radsec_server
object
2 properties
vrf_extra_route6
object
1 property
switch_port_usage_duplex
string
Only if mode!=dynamic. Link connection mode. enum: auto, full, half
idp_profile_matching_severity_value
string
enum: critical, info, major, minor
ntp_servers
array
List of NTP servers specific to this device. By default, those in Site Settings will be used
response_http404
object
1 property
snmp_config_trap_groups
array
dhcpd_config_vendor_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
ospf_areas_network
object
Property key is the network name. Networks to participate in an OSPF area
12 properties
device_type_default_ap
string
enum: ap, gateway, switch
switch_dhcpd_config_vendor_options
object
If type==server or type6==server. Property key is : , with enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers)…
dhcpd_config_vendor_option
object
2 properties
poe_priority
string
PoE priority. enum: low, high
gateway_wan_type6
string
enum: autoconf, dhcp, static
extra_route6_next_qualified_properties
object
2 properties
deviceprofile_switch
object
Switch Device Profiles can be applied to one or multiple switches. The settings from the Device Profile will override the settings from the Switch Template and…
40 properties
2 required
sw_routing_policy
object
1 property
network
object
Networks are usually subnets that have cross-site significance. networksin Org Settings will got merged into networksin Site Setting. For gateways, they can be…
18 properties
1 required
bgp_config_type
string
Required if via==lan, via==tunnel or via==wan. enum: external, internal
tunnel_config_dh_group
string
Only if provider==custom-ipsec. enum: 1 2 (1024-bit) 5 14 (default, 2048-bit) 15 (3072-bit) 16 (4096-bit) 19 (256-bit ECP) 20 (384-bit ECP) 21 (521-bit ECP) 24…
device_type_gateway
string
Device Type. enum: gateway
gateway_port_config_wan_networks
array
Only if usage==wan. If some networks are connected to this WAN port, it can be added here so policies can be defined
service_policy_skyatp_dns_dga_detection
object
2 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Juniper Mist AI publishes across the network.