The identity and technical contract details declared by the specification.
protect_re_custom_protocol
string
enum: any, icmp, tcp, udp
gw_routing_policy_term_matching_protocol
array
gateway_port_reth_nodes
array
SSR only - supporting vlan-based redundancy (matching the size of networks)
tunnel_config_ipsec_proposal
object
3 properties
tunnel_config_node_internal_ips
array
Only if provider==zscaler-gre, provider==jse-ipsec, provider==custom-ipsec or provider==custom-gre
service_policy_ewf_rule_profile
string
enum: critical, standard, strict
day_of_week
string
enum: any, fri, mon, sat, sun, thu, tue, wed
gateway_port_wan_arp_policer
string
Only when wantype==broadband. enum: default, max, recommended
gateway_oob_ip_config
object
Out-of-band (vme/em0/fxp0) IP config
8 properties
service_policy_skyatp_dns_dga_detection_profile
string
enum: default, standard, strict
gateway_port_config
object
Gateway port config
48 properties
1 required
service_policy
object
15 properties
routing_policy_term_matching_community
array
network_internal_access
object
1 property
app_probing_apps
array
APp-keys from [List Applications](/operations/listApplications)
tunnel_config_node
object
Only if provider==zscaler-ipsec, provider==jse-ipsec or provider==custom-ipsec
5 properties
2 required
app_probing_custom_app
object
10 properties
tunnel_config_dh_group
string
Only if provider==custom-ipsec. enum: 1 2 (1024-bit) 5 14 (default, 2048-bit) 15 (3072-bit) 16 (4096-bit) 19 (256-bit ECP) 20 (384-bit ECP) 21 (521-bit ECP) 24…
gateway_mgmt_probe_hosts
array
gateway_port_vpn_path
object
5 properties
tunnel_config_node_remote_ids
array
Only if provider==jse-ipsec or provider==custom-ipsec
network_internet_access
object
Whether this network has direct internet access
5 properties
gateway_wan_probe_override_probe_profile
string
enum: broadband, lte
gw_routing_policy_term
object
2 properties
gateway_extra_route6
object
1 property
gateway_ip_config_dns_suffix
array
Except for out-ofband interface (vme/em0/fxp0)
service_policy_secintel_profile
string
enum: default, standard, strict
tunnel_config_node_hosts
array
tunnel_config_local_subnets
array
List of Local protected subnet for policy-based IPSec negotiation
gateway_port_usage
string
port usage name. enum: hacontrol, hadata, lan, wan
gateway_mgmt_auto_signature_update
object
3 properties
dhcpd_config_fixed_bindings
object
If type==local or type6==local. Property key is the MAC Address. Format is [0-9a-f]{12} (e.g. "5684dae9ac8b")
tunnel_config
object
18 properties
dhcpd_config_type
string
enum: local (DHCP Server), none, relay (DHCP Relay)
tunnel_provider_options_prisma
object
1 property
gw_routing_policy_term_action
object
When used as import policy
9 properties
protect_re_custom_subnet
array
app_probing_custom_app_protocol
string
enum: http, icmp
gateway_path_preferences_paths
array
gw_routing_policy_terms
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
tunnel_config_tunnel_mode
string
Required if provider==zscaler-gre, provider==jse-ipsec. enum: active-active, active-standby
gateway_port_dsl_type
string
if wantype==dsl. enum: adsl, vdsl
service_policy_skyatp_dns_tunnel_detection
object
2 properties
routing_policy_local_preference
Optional, for an import policy, localpreference can be changed, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}})
network_internet_access_destination_nat_property
object
4 properties
gateway_ip_configs
object
Property key is the network name
gateway_path_type
string
enum: local, tunnel, vpn, wan
gateway_port_config_ip_config
object
Junos IP Config
14 properties
gateway_wan_probe_override
object
Only if usage==wan
3 properties
tunnel_config_remote_subnets
array
List of Remote protected subnet for policy-based IPSec negotiation
app_probing_custom_app_hostname
array
If protocol==http
network_vpn_access_config_other_vrfs
array
By default, the routes are only readvertised toward the same vrf on spoke. To allow it to be leaked to other vrfs
service_policy_antivirus
object
For SRX-only
3 properties
gateway_port_lte_auth
string
if wantype==lte. enum: chap, none, pap
gw_routing_policy_term_action_add_community
array
tunnel_provider_options_zscaler_sub_location
object
14 properties
gateway_port_vlan_id_with_variable
If WAN interface is on a VLAN. Can be the VLAN ID (i.e. "10") or a Variable (i.e. "{{myvar}}")
wan_extra_routes6
object
1 property
routing_policy_term_matching_as_path
array
routing_policy_term_action_prepend_as_path
array
When used as export policy, optional. By default, the local AS will be prepended, to change it. Can be a Variable (e.g. {{aspath}})
tunnel_config_auto_provision_provider
string
enum: jse-ipsec, zscaler-ipsec
tunnel_provider_options
object
3 properties
gateway_mgmt_probe_hostsv6
array
response_http401
object
1 property
network_internet_access_static_nat
object
Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
additional_config_cmds
array
additional CLI commands to append to the generated Junos config. Note: no check is done
gateway_ip_config_property
object
7 properties
gateway_mgmt_admin_sshkeys
array
For SSR only, as direct root access is not allowed
gateway_port_config_wan_speedtest_mode
string
Controls whether Marvis/scheduler can run speedtest on this port. enum: auto, enabled, disabled
gateway_path_strategy
string
enum: ecmp, ordered, weighted
idp_profile
object
7 properties
gateway_wan_ppoe_auth
string
if type==pppoe. enum: chap, none, pap
idp_config
object
4 properties
network_source_nat
object
If routed==false (usually at Spoke), but some hosts needs to be reachable from Hub
1 property
network_tenant_addresses
array
tunnel_config_auth_algo
string
enum: md5, sha1, sha2
gateway_traffic_shaping
object
3 properties
gateway_template_type
string
enum: spoke, standalone
gateway_ip_config_property_second_ips
array
Optional list of secondary IPs in CIDR format
app_probing
object
3 properties
zscaler_sub_locations
array
sub-locations can be used for specific uses cases to define different configuration based on the user network
tunnel_config_auto_provision_node_wan_names
array
Optional, only needed if varsonly==false
network_vpn_access_static_nat_property
object
2 properties
dns_suffix
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
tunnel_config_ike_mode
string
Only if provider==custom-ipsec. enum: aggressive, main
tunnel_config_auto_provision_node
object
2 properties
dns_servers
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
gateway_template
object
Gateway Template is applied to a site for gateway(s) in a site.
32 properties
1 required
tunnel_config_auto_provision_lat_lng
object
API override for POP selection
2 properties
2 required
network_vpn_access_config
object
14 properties
idp_profile_overwrites
array
network_vpn_access
object
Property key is the VPN name. Whether this network can be accessed from vpn
network_routed_for_networks
array
For a Network (usually LAN), it can be routable to other networks (e.g. OSPF)
network_vpn_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
dhcpd_config_type6
string
enum: local (DHCP Server), none, relay (DHCP Relay)
allow_deny
string
enum: allow, deny
dhcpd_config_property
object
16 properties
idp_profile_overwrite
object
3 properties
tunnel_config_auto_provision
object
Auto Provisioning configuration for the tunne. This takes precedence over the primary and secondary nodes.
7 properties
1 required
service_policy_syslog
object
Required for syslog logging
2 properties
tunnel_config_probe_type
string
enum: http, icmp
gateway_path_preferences_path_networks
array
Required when type==local
ssl_proxy_ciphers_category
string
enum: medium, strong, weak
gateway_extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64"), the destination Network name or a variable (e.g. "{{myvar}}")
idp_profile_matching_attack_name
array
dhcpd_config_dns_servers
array
If type==local or type6==local - optional, if not defined, system one will be used
dhcpd_config_servers
array
If type==relay
gateway_matching
object
Gateway matching
2 properties
network_multicast
object
Whether to enable multicast support (only PIM-sparse mode is supported)
3 properties
service_policy_skyatp_http_inspection_profile
string
enum: standard, strict
gw_routing_policy_term_action_export_communities
array
When used as export policy, optional
gateway_port_vpn_path_role
string
If the VPN type==hubspoke, enum: hub, spoke. If the VPN type==mesh, enum: mesh
protect_re_allowed_service
string
enum: icmp, ssh
app_probing_custom_apps
array
gw_routing_policy_term_matching_route_exists
object
2 properties
gateway_extra_route
object
1 property
created_time
number
When the object has been created, in epoch
tunnel_provider_options_jse
object
For jse-ipsec, this allows provisioning of adequate resource on JSE. Make sure adequate licenses are added
2 properties
network_vpn_access_destination_nat_property
object
3 properties
dhcpd_config_dns_suffix
array
If type==local or type6==local - optional, if not defined, system one will be used
gateway_port_duplex
string
enum: auto, full, half
gateway_vrf_instance
object
1 property
protect_re_allowed_services
array
Optionally, services we'll allow
gateway_oob_ip_config_node1
object
For HA Cluster, node1 can have different IP Config
7 properties
dhcpd_config_servers6
array
If type6==relay
network_tenant
object
1 property
gw_routing_policy_term_matching_vpn_path_sla
object
3 properties
tunnel_config_protocol
string
Only if provider==custom-ipsec. enum: gre, ipsec
gateway_path_preferences_path_target_ips
array
If type==local, if destination IP is to be replaced
service_policy_skyatp
object
SRX only
4 properties
dhcpd_config_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
tunnel_via
string
If via==tunnel, specifies which tunnel (primary/secondary) this neighbor is associated with. enum: primary, secondary
tunnel_config_ike_proposals
array
If provider==custom-ipsec
vrf_config
object
1 property
tunnel_config_node_wan_names
array
gw_routing_policy_term_matching
object
zero or more criteria/filter can be specified to match the term, all criteria have to be met
9 properties
bgp_as
BGP AS, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}} )
protect_re_custom
object
Custom acls
3 properties
gw_routing_policy
object
1 property
service_policy_ssl_proxy
object
For SRX-only
2 properties
service_policy_skyatp_http_inspection
object
2 properties
gateway_port_vpn_path_bfd_profile
string
Only if the VPN type==hubspoke. enum: broadband, lte
bgp_local_as
Required if via==lan, via==tunnel or via==wan. BGP AS, value in range 1-4294967295
dhcpd_config
object
1 property
dhcpd_config_options
object
If type==local or type6==local. Property key is the DHCP option number
bgp_config_networks
array
Optional if via==lan. List of networks where we expect BGP neighbor to connect to/from
bgp_config_neighbors
object
7 properties
1 required
gateway_port_config_reth_idx
For SRX only and if HA Mode. -1 means it will be managed by the device. Use = 0 values to manage it manually. Ensure no conflicting values are assigned across…
gateway_traffic_shaping_class_percentages
array
percentages for different class of traffic: high / medium / low / best-effort. Sum must be equal to 100
gateway_vrf_instances
object
Property key is the network name
tunnel_config_ike_proposal
object
3 properties
idp_profile_action
string
enum: alert (default) drop: silently dropping packets close: notify client/server to close connection
response_http429
object
1 property
network_tenants
object
Property key must be the user/tenant name (i.e. "printer-1") or a Variable (i.e. "{{myvar}}")
tunnel_config_enc_algo
stringnull
enum: 3des, aes128, aes256, aesgcm128, aesgcm256
gw_routing_policy_term_matching_protocol_enum
string
enum: aggregate, bgp, direct, ospf, static (SRX Only)
gateway_ip_config_dns_servers
array
Except for out-ofband interface (vme/em0/fxp0)
gateway_extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8"), the destination Network name or a variable (e.g. "{{myvar}}")
wan_extra_routes
object
1 property
protect_re
object
Restrict inbound-traffic to host when enabled, all traffic that is not essential to our operation will be dropped e.g. ntp / dns / traffic to mist will be allo…
5 properties
service_policy_secintel
object
SRX only
3 properties
tunnel_config_probe
object
Only if provider==custom-ipsec
4 properties
gw_routing_policy_term_action_exclude_as_path
array
When used as export policy, optional. To exclude certain AS
gateway_idp_profiles
object
Property key is the profile name
idp_profile_matching_severity
array
ip_type6
string
enum: autoconf, dhcp, disabled, static
tunnel_config_provider
string
Only if autoprovision.enabled==false. enum: custom-ipsec, custom-gre, jse-ipsec, prisma-ipsec, zscaler-gre, zscaler-ipsec
gateway_mgmt
object
Gateway Management settings
15 properties
service_policy_appqoe
object
SRX only
1 property
routing_policy_term_matching_prefix
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
protect_re_trusted_hosts
array
host/subnets we'll allow traffic to/from
gateway_port_wan_source_nat
object
Only if usage==wan, optional. By default, source-NAT is performed on all WAN Ports using the interface-ip
3 properties
gateway_port_vpn_paths
object
Property key is the VPN name
network_internet_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
id
string
Unique ID of the object instance in the Mist Organization
tunnel_provider_options_zscaler
object
For zscaler-ipsec and zscaler-gre
15 properties
gateway_matching_rule
object
3 properties
bgp_config
object
BFD is enabled when either bfdminimuminterval or bfdmultiplier is configured
22 properties
1 required
gateway_matching_rules
array
gateway_port_networks
array
If usage==lan, name of the [networks]($h/Orgs%20Networks/overview) to attach to the interface
gateway_wan_type
string
enum: dhcp, pppoe, static
gw_routing_policy_term_matching_vpn_path
array
overlay-facing criteria (used for bgpconfig where via=vpn). ordered-
network_multicast_group
object
1 property
service_policy_ewf_rule
object
4 properties
idp_profile_matching_dst_subnet
array
response_http403
object
1 property
gateway_path_preferences
object
2 properties
ip_type
string
enum: dhcp, static
network_multicast_groups
object
Group address to RP (rendezvous point) mapping. Property Key is the CIDR (example "225.1.0.3/32")
idp_profile_matching_severity_value
string
enum: critical, info, major, minor
gateway_port_wan_type
string
Only if usage==wan. enum: broadband, dsl, lte
ntp_servers
array
List of NTP servers specific to this device. By default, those in Site Settings will be used
tunnel_config_ike_dh_group
string
enum: 1 2 (1024-bit) 5 14 (default, 2048-bit) 15 (3072-bit) 16 (4096-bit) 19 (256-bit ECP) 20 (384-bit ECP) 21 (521-bit ECP) 24 (2048-bit ECP)
dhcpd_config_fixed_binding
object
3 properties
idp_profile_base_profile
string
enum: critical, standard, strict
response_http404
object
1 property
dhcpd_config_option
object
2 properties
gw_routing_policy_term_matching_vpn_neighbor_mac
array
overlay-facing criteria (used for bgpconfig where via=vpn)
gateway_path_preferences_path
object
9 properties
1 required
dhcpd_config_vendor_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
idp_profile_matching
object
3 properties
service_policy_skyatp_iot_device_policy
object
1 property
response_http400
object
1 property
network_vpn_access_static_nat
object
Property key may be an External IP Address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
dhcpd_config_vendor_option
object
2 properties
gw_routing_policy_term_action_exclude_community
array
service_policy_skyatp_dns_tunnel_detection_profile
string
enum: default, standard, strict
tunnel_config_networks
array
If provider==custom-ipsec or provider==prisma-ipsec, networks reachable via this tunnel
gateway_wan_type6
string
enum: autoconf, dhcp, static
gw_routing_policies
object
Property key is the routing policy name
bgp_config_via
string
enum: lan, tunnel, vpn, wan
gw_routing_policy_term_action_add_target_vrfs
array
For SSR, hub decides how VRF routes are leaked on spoke
network
object
Networks are usually subnets that have cross-site significance. networksin Org Settings will got merged into networksin Site Setting. For gateways, they can be…
18 properties
1 required
bgp_config_type
string
Required if via==lan, via==tunnel or via==wan. enum: external, internal
tunnel_config_version
string
Only if provider==custom-gre or provider==custom-ipsec. enum: 1, 2
tunnel_config_ipsec_proposals
array
Only if provider==custom-ipsec
modified_time
number
When the object has been modified for the last time, in epoch
dhcpd_config_vendor_options
object
If type==local or type6==local. Property key is : , with enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers) su…
routing_policy_term_action_community
array
When used as export policy, optional
gateway_port_config_wan_networks
array
Only if usage==wan. If some networks are connected to this WAN port, it can be added here so policies can be defined
service_policy_skyatp_dns_dga_detection
object
2 properties
network_internet_access_static_nat_property
object
3 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Juniper Mist AI publishes across the network.