The identity and technical contract details declared by the specification.
switch_port_usage_dynamic_rule
object
Dynamic port usage rule evaluated against LLDP, RADIUS, or peer MAC attributes
6 properties
1 required
switch_mist_nac
object
Mist NAC RadSec settings for a switch
2 properties
gateway_mgmt
object
Gateway management-plane and access settings
15 properties
switch_dhcpd_config_property
object
DHCP server or relay configuration for one switch network. The property key is the network name. In case of DHCP relay, it's common for many networks to use th…
16 properties
service_policy_skyatp_dns_tunnel_detection_profile
string
enum: default, standard, strict
dhcpd_config_property
object
DHCP server or relay configuration for one network
16 properties
radius_acct_server
object
RADIUS accounting server settings
7 properties
2 required
ntp_servers
array
List of NTP servers specific to this device. By default, those in Site Settings will be used
junos_port_config
object
Junos switch port configuration
19 properties
1 required
vrf_extra_route6
object
Additional IPv6 static route for a VRF instance
1 property
gateway_ip_configs
object
Property key is the network name
remote_syslog_server_protocol
string
Transport protocol used for this remote syslog server. enum: tcp, udp
ospf_area
object
Property key is the OSPF Area (Area should be a number (0-255) / IP address)
3 properties
tunnel_config
object
Gateway tunnel configuration for provider-managed or custom tunnels
18 properties
network_multicast_groups
object
Group address to RP (rendezvous point) mapping. Property Key is the CIDR (example "225.1.0.3/32")
strings
array
Unique string values returned or accepted by this schema
network_source_nat
object
If routed==false (usually at Spoke), but some hosts needs to be reachable from Hub
1 property
sw_routing_policy_term_action
object
Actions applied to routes matched by a switch routing policy term
4 properties
tunnel_config_probe_type
string
Protocol used by the custom IPsec tunnel health probe. enum: http, icmp
switch_bgp_config_hold_time_zero
integer
BGP hold time value of 0
radsec
object
RadSec settings for sending RADIUS traffic over TLS
9 properties
const_device_type_switch
string
Device Type. enum: switch
vrrp_config_groups
object
Property key is the VRRP name
routing_policy_term_matching_prefix
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
gateway_ip_config_property
object
Gateway network interface IP configuration
7 properties
ap_mesh
object
Wireless mesh settings for an access point
5 properties
ap_search_wlan
object
WLAN summary included in an AP search result
2 properties
remote_syslog_users
array
User-specific syslog logging rules
switch_bgp_config_neighbors
object
Switch BGP neighbor settings keyed by neighbor IP address
idp_profile_matching
object
Criteria that select IDP signatures for an overwrite rule
3 properties
switch_radius_config
object
Switch RADIUS authentication and accounting configuration
12 properties
dhcpd_config_vendor_option
object
Vendor-encapsulated DHCP option value
2 properties
ospf_area_type
string
OSPF type. enum: default, nssa, stub
service_policy_skyatp_iot_device_policy
object
Sky ATP IoT device policy settings
1 property
routing_policy_term_action_prepend_as_path
array
When used as export policy, optional. By default, the local AS will be prepended, to change it. Can be a Variable (e.g. {{aspath}})
ip_type6
string
enum: autoconf, dhcp, disabled, static
vrf_extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8")
gateway_port_config
object
Gateway port configuration for LAN, WAN, tunnel, and HA interfaces
48 properties
1 required
network_tenants
object
Property key must be the user/tenant name (i.e. "printer-1") or a Variable (i.e. "{{myvar}}")
switch_bgp_config_neighbor
object
Per-neighbor switch BGP session settings
5 properties
1 required
ospf_area_network_interface_type
string
interface type (nbma = non-broadcast multi-access). enum: broadcast, nbma, p2mp, p2p
snmp_config_client_list
object
SNMP client allowlist definition
2 properties
ibeacon_minor
integernull
Minor number for iBeacon
gateway_path_preferences
object
Gateway path preference that selects among one or more local, WAN, VPN, or tunnel paths
2 properties
switch_mgmt_mxedge_proxy_port
Mist Edge port used to proxy the switch management traffic to the Mist Cloud. Value in range 1-65535
aggregate_route
object
Aggregate route configuration for a network or routing instance
3 properties
switch_search
object
Switch record returned by device search endpoints
24 properties
1 required
switch_port_local_usage_mode
string
enum: access, inet, trunk
gateway_extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64"), the destination Network name or a variable (e.g. "{{myvar}}")
dhcp_snooping
object
DHCP snooping security settings
5 properties
ap_mqtt
object
MQTT broker publishing settings for an AP; use mqtttopic on individual AssetFilter entries to specify which MQTT topic each matching BLE advertisement is forwa…
7 properties
tunnel_config_provider
string
Only if autoprovision.enabled==false. enum: custom-ipsec, custom-gre, jse-ipsec, prisma-ipsec, zscaler-gre, zscaler-ipsec
gateway_ip_config_property_second_ips
array
Optional list of secondary IPs in CIDR format
dot11_bandwidth24
integer
channel width for the 2.4GHz band. enum: 0(disabled, response only), 20, 40
remote_syslog_servers
array
Remote syslog server destination list
sw_routing_policy_term_matching_protocol_enum
string
enum: bgp, direct, evpn, ospf, static
network_internet_access_static_nat
object
Property key may be an External IP address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
idp_profile_matching_severity
array
Severity levels matched by an IDP profile overwrite
tunnel_config_ipsec_proposals
array
Only if provider==custom-ipsec. IPsec proposals used for custom IPsec negotiation
site_device_events_count_distinct
string
enum: mac, model, type, typecode
ap_airista
object
Airista RTLS integration settings for an AP
3 properties
snmp_config_engine_id_type
string
Method used to derive the SNMP engine ID. enum: local, usemacaddress
gateway_mgmt_probe_hostsv6
array
IPv6 probe hosts used for gateway connectivity checks
switch_port_local_usage_storm_control
object
Storm-control settings for this local port configuration
6 properties
switch_port_usage_dynamic_rule_src
string
enum: linkpeermac, lldpchassisid, lldphardwarerevision, lldpmanufacturername, lldpoui, lldpserialnumber, lldpsystemdescription, lldpsystemname, radiusdynamicfi…
snmp_config_trap_groups
array
SNMP trap group definitions
snmp_vacm_access_item_type
string
VACM context matching type for this access rule. enum: contextprefix, defaultcontextprefix
snmpv3_config_notify_items
object
SNMPv3 notification definition for traps or informs
3 properties
switch_bgp_config
object
Switch BGP configuration for a routing instance
9 properties
2 required
snmp_vacm_access_item
object
VACM access rule for an SNMP group
2 properties
idp_profile_action
string
IDP profile action. enum: alert, close, drop. alert is the default, drop silently drops packets, and close asks the client/server to close the connection
day_of_week
string
enum: any, fri, mon, sat, sun, thu, tue, wed
idp_profile_matching_dst_subnet
array
Destination CIDR subnets matched by an IDP profile overwrite
switch_port_local_usage_dynamic_vlan_networks
array
Only if portauth==dot1x, if dynamic vlan is used, specify the possible networks/vlans RADIUS can return
switch_dhcpd_config_dns_suffix
array
If type==server or type6==server - optional, if not defined, system one will be used
extra_route
object
IPv4 static route settings for a destination prefix
6 properties
response_config_history_search_results
array
Device config history entries returned by a search response
wan_extra_routes
object
Additional IPv4 route for a WAN interface
1 property
gateway_idp_profiles
object
Property key is the profile name
config_switch_local_accounts
object
Property key is the user name. For Local user authentication
tunnel_config_tunnel_mode
string
Required if provider==zscaler-gre, provider==jse-ipsec. enum: active-active, active-standby
snmpv3_config_target_param_security_level
string
enum: authentication, none, privacy
snmp_config_client_list_clients
array
SNMP client IP addresses or CIDR ranges allowed by a client list
protect_re_trusted_hosts
array
Host or subnet entries allowed by the Protect RE policy
gw_routing_policy_term_action
object
Actions applied to routes matched by a gateway routing policy term
9 properties
switch_dhcpd_config_type6
string
enum: none, relay (DHCP Relay), server (DHCP Server)
vrf_extra_route
object
Additional IPv4 static route for a VRF instance
1 property
ap_led
object
Indicator light settings for an access point
2 properties
junos_local_port_config
object
Per-port Switch Port Operator (SPO) override configuration used in localportconfig to customize settings inherited from portconfig
37 properties
1 required
snmp_usm_engine_type
string
SNMP engine type used for this USM configuration. enum: localengine, remoteengine
gw_routing_policy
object
Gateway routing policy made of ordered match-action terms
1 property
gw_routing_policy_term_matching_route_exists
object
Route-existence match condition for a gateway routing policy term
2 properties
gateway_path_preferences_paths
array
Candidate paths evaluated by a gateway path preference
ap_radio_antenna_mode
string
enum: 1x1, 2x2, 3x3, 4x4, default
tunnel_config_auth_algo
string
enum: md5, sha1, sha2
dhcpd_config_options
object
If type==local or type6==local. Property key is the DHCP option number
acl_tag_ether_types
array
ARP / IPv6. Default is any
remote_syslog_time_format
string
enum: millisecond, year, year millisecond
ap_radio_band6
object
6 GHz radio settings for an access point
13 properties
switch_port_usage_dot1x
stringnull
Only if mode!=dynamic. If dot1x is desired, set to dot1x. enum: dot1x
network_vpn_access_static_nat_property
object
VPN access static NAT rule target settings
2 properties
service_policy_secintel_profile
string
enum: default, standard, strict
response_events_devices
object
Paginated response for site device event search results
6 properties
5 required
site_device_last_config_count_distinct
string
enum: mac, name, siteid, version
switch_port_usage_reauth_interval
Only if mode!=dynamic and portauth=dot1x reauthentication interval range (min: 10, max: 65535, default: 3600). Set to 0 to disable reauthentication (no-reauthe…
ssl_proxy_ciphers_category
string
enum: medium, strong, weak
gateway_port_mirroring
object
Port mirroring settings for a gateway interface
1 property
snmp_vacm_access_item_prefix_list_item
object
Context prefix rule for a VACM access entry
7 properties
gateway_port_mirroring_ingress_port_ids
array
Gateway port IDs used as ingress sources for mirrored traffic
gateway_wan_type
string
enum: dhcp, pppoe, static
vrrp_config
object
Junos VRRP configuration applied to a switch or switch profile
2 properties
ap_port_config_forwarding
string
enum: all: local breakout, All VLANs limited: local breakout, only the VLANs configured in portvlanid and vlanids mxtunnel: central breakout to an Org Mist Edg…
device_search_radius_stats
object
Property key is the RADIUS server IP address
local_port_config
object
Per-port Switch Port Operator (SPO) override, overriding the port configuration from portconfig. Property key is the port name or range (e.g. "ge-0/0/0-10")
ap_search_wlans
array
WLAN summaries included in an AP search result
response_config_history_search
object
Paginated device config history search response
6 properties
5 required
search_site_devices_sort
string
enum: mac, model, sku, timestamp
extra_route6_next_qualified_properties
object
Qualified next-hop attributes for an IPv6 static route
2 properties
extra_route6
object
IPv6 static route settings for a destination prefix
6 properties
snmpv3_config_target_param_security_model
string
enum: usm, v1, v2c
network_internet_access_destination_nat_property
object
Direct-internet destination NAT rule target settings
4 properties
routing_policy_term_action_community
array
When used as export policy, optional
count_result
object
Count result row with the matching distinct field values
1 property
1 required
switch_port_usage
object
Junos switch port usage template and authentication settings
46 properties
ap_zigbee_allow_join
string
Controls whether new Zigbee devices are allowed to join the network. enum: always, manual
service_policy_syslog
object
Syslog logging settings for a service policy
2 properties
service_policy_skyatp_dns_dga_detection_profile
string
enum: default, standard, strict
switch_port_usage_mac_limit_overwrite
Max number of MAC addresses, default is 0 for unlimited, otherwise range is 1 to 16383 (upper bound constrained by platform)
idp_profile_overwrite
object
Override rule that changes the IDP action for matching signatures
3 properties
service_policy_skyatp_dns_tunnel_detection
object
Sky ATP DNS tunneling detection settings
2 properties
service_policy_ewf_rule_profile
string
enum: critical, standard, strict
snmp_config_trap_group_categories
array
Trap categories included in an SNMP trap group
switch_port_usages
object
Property key is the port usage name. Defines the profiles of port configuration configured on the switch
tunnel_provider_options_zscaler
object
For zscaler-ipsec and zscaler-gre
15 properties
tunnel_provider_options_jse
object
For jse-ipsec, this allows provisioning of adequate resource on JSE. Make sure adequate licenses are added
2 properties
response_device_search_results_items
Device search record for an AP, switch, or gateway
junos_port_config_duplex
string
enum: auto, full, half
ap_client_bridge
object
AP client bridge mode configuration
3 properties
org_id
string
Unique identifier of a Mist organization
tacacs_auth_server
object
TACACS+ authentication server settings
4 properties
switch_radius_config_auth_server_selection
string
Selection strategy for RADIUS authentication servers. enum: ordered, unordered
switch_bgp_config_hold_time
Hold time is three times the interval at which keepalive messages are sent. It indicates to the peer the length of time that it should consider the sender vali…
ap_centrak
object
CenTrak integration settings for an AP
1 property
aggregate_routes
object
Property key is the destination subnet (e.g. "172.16.3.0/24")
bgp_config
object
BGP session configuration. BFD is enabled when either bfdminimuminterval or bfdmultiplier is configured
22 properties
1 required
gateway_port_reth_nodes
array
SSR only - supporting vlan-based redundancy (matching the size of networks)
snmpv3_config_notify_filter
array
SNMPv3 notification filter profiles
extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8")
ap_search
object
Access point record returned by device search endpoints
36 properties
4 required
binary_stream
object
Binary file upload payload
1 property
1 required
gateway_vrf_instance
object
Gateway VRF instance and its member networks
1 property
switch_port_usage_storm_control
object
Switch storm control. Only if mode!=dynamic
6 properties
msp_id
string
Managed service provider identifier
switch_port_usage_duplex_overwrite
string
Link connection mode. enum: auto, full, half
device_search_radius_stat
object
RADIUS authentication counters and server status for a device search result
4 properties
mist_device
Mist-managed device object for an AP, switch, or gateway
gateway_path_preferences_path_networks
array
Network names used by a local path; required when type==local
switch_port_usage_mac_limit
Only if mode!=dynamic, max number of MAC addresses, default is 0 for unlimited, otherwise range is 1 to 16383 (upper bound constrained by platform)
switch_stp_config
object
Switch spanning-tree protocol configuration
1 property
routing_policy_term_matching_community
array
BGP community values used as routing-policy match criteria
extra_route_next_qualified_properties
object
Qualified next-hop attributes for an IPv4 static route
2 properties
switch_radius
object
Switch RADIUS override settings. By default, the switch radiusconfig is used; set usedifferentradius to use alternate RADIUS settings.
3 properties
switch_port_mirroring_property
object
Input and output settings for one switch port mirroring session
6 properties
switch_mgmt
object
Switch management-plane access and proxy settings
16 properties
response_config_history_search_item
object
Device config history entry
11 properties
5 required
ap_port_config
object
Ethernet port behavior settings for an access point
17 properties
snmp_vacm_access
array
VACM access rules for SNMPv3
service_policy_secintel
object
SRX SecIntel settings for a service policy
3 properties
snmp_config_trap_group
object
SNMP trap group definition
4 properties
network_internet_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
network_multicast_group
object
Multicast group rendezvous point mapping
1 property
remote_syslog
object
Remote syslog forwarding settings
10 properties
snmpv3_config_target_address_item
object
SNMPv3 notification target address entry
6 properties
gateway_port_duplex
string
enum: auto, full, half
tunnel_config_remote_subnets
array
List of Remote protected subnet for policy-based IPSec negotiation
routing_policy_term_matching_as_path
array
BGP AS path values used as routing-policy match criteria
gateway_extra_route6
object
Gateway IPv6 extra route next-hop settings
1 property
response_http403
object
Standard HTTP 403 permission error response
1 property
gw_routing_policy_terms
array
zero or more criteria/filter can be specified to match the term, all criteria have to be met
tunnel_config_node_hosts
array
Remote gateway host addresses for a tunnel node
service_policy
object
Site-level service policy that allows or denies traffic for tenants and services
15 properties
gateway_port_networks
array
If usage==lan, name of the [networks]($h/Orgs%20Networks/overview) to attach to the interface
service_policy_skyatp
object
SRX Sky ATP threat inspection settings for a service policy
4 properties
snmp_vacm_security_model
string
enum: usm, v1, v2c
radio_band_24_usage
string
enum: 24, 5, 6, auto
gateway_port_vpn_path
object
VPN path settings for traffic that uses a gateway port
5 properties
radsec_mxcluster_ids
array
To use Org Mist Edges when this WLAN does not use mxtunnel, specify their mxclusterids. Org Mist Edge(s) identified by mxclusterids
dhcpd_config_option
object
Custom DHCP option value
2 properties
mac_addresses_macs
array
Unique MAC addresses included in a request
gateway_traffic_shaping
object
Traffic shaping settings for a gateway interface or VPN path
3 properties
radio_band_antenna_mode
string
enum: 1x1, 2x2, 3x3, 4x4, default
service_policy_appqoe
object
SRX application QoE settings for a service policy
1 property
gateway_path_preferences_path
object
Candidate path within a gateway path preference
9 properties
1 required
remote_syslog_server_port
Syslog Service Port, value from 1 to 65535
ap_usb
object
Legacy USB integration settings for an access point - Note: if native imagotag is enabled, BLE will be disabled automatically - Note: legacy, new config moved…
8 properties
gateway_extra_route
object
Gateway IPv4 extra route next-hop settings
1 property
acl_policies
array
List of ACL policy definitions
snmp_vacm
object
SNMPv3 View-based Access Control Model configuration
2 properties
gateway_extra_routes
object
Property key is the destination CIDR (e.g. "10.0.0.0/8"), the destination Network name or a variable (e.g. "{{myvar}}")
tunnel_config_version
string
Only if provider==custom-gre or provider==custom-ipsec. enum: 1, 2
ap_ip_config_dns
array
If type==static. DNS server IP addresses for AP management traffic
switch_port_mirroring_ingress_port_ids
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
switch_dhcpd_config_options
object
If type==server or type6==server. Property key is the DHCP option number
radio_band_preamble
string
enum: auto, long, short
network_vpn_access_config
object
VPN access settings for a network and VPN pair
14 properties
gateway_mgmt_auto_signature_update
object
Automatic security signature update schedule
3 properties
ip_type
string
IP address assignment mode, either DHCP or static. enum: dhcp, static
created_time
number
When the object has been created, in epoch
snmp_usm_user
object
SNMPv3 USM user definition
5 properties
remote_syslog_facility
string
enum: any, authorization, change-log, config, conflict-log, daemon, dfc, external, firewall, ftp, interactive-commands, kernel, ntp, pfe, security, user
snmp_config_v2c_configs
array
SNMPv2c community configuration entries for this SNMP profile
tunnel_via
string
If via==tunnel, specifies which tunnel (primary/secondary) this neighbor is associated with. enum: primary, secondary
ap_radio_band24
object
2.4 GHz radio settings for an access point
11 properties
vrf_extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
bgp_config_neighbors
object
Per-neighbor BGP session settings
7 properties
1 required
radius_auth_port
RADIUS Auth Port, value from 1 to 65535, default is 1812
search_site_devices_desc_sort
string
enum: mac, model, sku, timestamp
tunnel_config_auto_provision_node_wan_names
array
Optional, only needed if varsonly==false
gateway_port_config_wan_speedtest_mode
string
Controls whether Marvis/scheduler can run speedtest on this port. enum: auto, enabled, disabled
gateway_oob_ip_config
object
Out-of-band management IP configuration for gateway interfaces such as vme, em0, or fxp0
8 properties
switch_port_usage_mac_auth_protocol
string
Only if mode!=dynamic and enablemacauth ==true. This type is ignored if mistnac is enabled. enum: eap-md5, eap-peap, pap
switch_bgp_config_type
string
BGP session type for this switch BGP configuration. enum: external, internal
app_probing
object
Application reachability probing settings for gateway management
3 properties
network_tenant
object
Tenant address entry for a network
1 property
idp_profile_base_profile
string
enum: critical, standard, strict
remote_syslog_content
object
Syslog message content selector for remote logging
2 properties
snmp_config_view
object
SNMP MIB view definition
3 properties
response_count
object
Distinct count response for time-bounded search results
6 properties
6 required
idp_profile_matching_severity_value
string
enum: critical, info, major, minor
switch_dhcpd_config_type
string
enum: none, relay (DHCP Relay), server (DHCP Server)
radsec_server
object
External RadSec server settings
2 properties
switch_port_local_usage_duplex
string
link connection mode. enum: auto, full, half
response_config_history_search_item_radios
array
Radio config history details
gateway_port_wan_source_nat
object
Only if usage==wan, optional. By default, source-NAT is performed on all WAN Ports using the interface-ip
3 properties
radius_auth_server
object
RADIUS authentication server settings
8 properties
2 required
switch_oob_ip_config
object
Switch OOB IP Config: - If HA configuration: key parameter will be nodeX (eg: node1) - If there are 2 routing engines, re1 mgmt IP has to be set separately (if…
7 properties
switch_port_usage_dynamic_rules
array
Only if mode==dynamic. Dynamic matching rules that select the port usage to apply
service_policy_antivirus
object
SRX antivirus inspection settings for a service policy
3 properties
timestamp
number
Epoch timestamp, in seconds
acl_tag_macs
array
Required if - type==mac - type==staticgbp if from matching mac
protect_re_custom_subnet
array
Source subnets matched by a custom Protect RE ACL
switch_dhcpd_config_dns_servers
array
If type==server or type6==server - optional, if not defined, system one will be used
snmp_usm_user_authentication_type
string
sha224, sha256, sha384, sha512 are supported in 21.1 and newer release. enum: authentication-md5, authentication-none, authentication-sha, authentication-sha22…
snmp_vacm_security_to_group
object
VACM security-name to group mapping configuration
2 properties
switch_iot_port_input_src
string
Only for "OUT" ports, input source for the switch iot port out. enum: IN0, IN1
dhcpd_config_vendor_options
object
If type==local or type6==local. Property key is : , with enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers) su…
switch_port_usage_duplex
string
Only if mode!=dynamic. Link connection mode. enum: auto, full, half
ha_cluster_node_enum
string
HA cluster node selector. enum: node0, node1
ap_radio_band5
object
5 GHz radio settings for an access point
12 properties
switch_port_local_usage_mac_auth_protocol
string
Only if enablemacauth ==true. This type is ignored if mistnac is enabled. enum: eap-md5, eap-peap, pap
ospf_areas
object
Junos OSPF areas. Property key is the OSPF Area (Area should be a number (0-255) / IP address)
switch_iot_port
object
Switch IOT port configuration
4 properties
gw_routing_policy_term_action_export_communities
array
Optional when used as an export policy. BGP communities that may be exported
remote_syslog_archive_files
Number of archived syslog files to retain
dhcpd_config_fixed_bindings
object
If type==local or type6==local. Property key is the client MAC address. Format is [0-9a-f]{12} (e.g. "5684dae9ac8b")
snmp_vacm_access_item_prefix_list_item_level
string
enum: authentication, none, privacy
switch_networks
object
Property key is network name
tunnel_config_enc_algo
stringnull
enum: 3des, aes128, aes256, aesgcm128, aesgcm256
last_config_device_type
string
enum: ap, gateway, mxedge, switch
snmp_vacm_access_item_prefix_list
array
Context prefix rules for a VACM access entry
ap_port_config_dynamic_vlan
object
Dynamic VLAN assignment settings for AP port authentication
4 properties
gateway_port_vlan_id_with_variable
If WAN interface is on a VLAN. Can be the VLAN ID (i.e. "10") or a Variable (i.e. "{{myvar}}")
sw_routing_policy
object
Switch routing policy made of ordered match-action terms
1 property
gateway_port_config_ip_config
object
Junos IP configuration for a gateway port interface
14 properties
switch_port_mirroring_egress_port_ids
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
dhcpd_config_dns_servers
array
If type==local or type6==local - optional, if not defined, system one will be used
device_ap_lacp_config
object
LACP settings for supported AP Ethernet uplinks
1 property
snmpv3_config
object
SNMPv3 notification, target, USM, and VACM configuration
6 properties
routing_policy_local_preference
Optional, for an import policy, localpreference can be changed, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}})
switch_iot_config
object
Property Key is the IOT port name, e.g.: IN0 or IN1 for the FPC0 input port with 5V triggered inputs OUT1 for the FPC0 output port (can only be triggered by ei…
snmpv3_config_target_address
array
SNMPv3 notification target addresses
bgp_local_as
Required if via==lan, via==tunnel or via==wan. BGP AS, value in range 1-4294967295
gateway_wan_ppoe_auth
string
if type==pppoe. enum: chap, none, pap
protect_re_allowed_service
string
Services allowed through protect-RE filters. enum: icmp, ssh
switch_port_mirroring_ingress_networks
array
At least one of the inputportidsingress, inputportidsegress or inputnetworksingress should be specified
ospf_area_network_auth_type
string
auth type. enum: md5, none, password
config_devices
array
List of device configuration objects
acl_policy
object
ACL Policy: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source or destinatio…
3 properties
ap_radio
object
Radio configuration settings for an access point
15 properties
radio_band_channels
arraynull
For RFTemplates. List of channels, null or empty array means auto
tunnel_config_auto_provision_lat_lng
object
Geographic coordinate override for tunnel POP selection
2 properties
2 required
bgp_config_via
string
enum: lan, tunnel, vpn, wan
app_probing_custom_app_hostname
array
If protocol==http. HTTP hostnames or URLs probed by the custom app
service_policies
array
Service policies returned by derived site configuration
snmp_config_trap_group_targets
array
Trap target addresses for an SNMP trap group
snmpv3_config_notify_filter_item_contents
array
OID filter rules in an SNMPv3 notification filter profile
network_internet_access
object
Direct internet access settings for an organization network
5 properties
app_probing_custom_app
object
User-defined application probe definition
10 properties
modified_time
number
When the object has been modified for the last time, in epoch
vars
object
Dictionary of name-value, the vars can then be used in Wlans. This can overwrite those from Site Vars
idp_config
object
Intrusion detection and prevention settings for a service policy
4 properties
gateway_search
object
Gateway record returned by device search endpoints
27 properties
1 required
remote_syslog_archive
object
Syslog file archive retention settings
2 properties
tunnel_config_ike_proposals
array
If provider==custom-ipsec, IKE proposals used for custom IPsec negotiation
dhcp_snooping_networks
array
If allnetworks==false, list of network with DHCP snooping enabled
switch_bgp_config_hold_time_integer
integer
BGP hold time value from 3 to 65535 seconds
snmpv3_config_notify_type
string
Delivery mode for this SNMPv3 notification, such as trap or inform. enum: inform, trap
snmp_config_views
array
SNMP MIB view definitions
gw_routing_policy_term_action_exclude_community
array
BGP communities excluded by a gateway routing policy term
snmpv3_config_target_param
object
SNMPv3 target parameter profile
6 properties
device_search_radius_filter_status
string
Status of the device search RADIUS filter. enum: up, down, unreachable
image_import
object
Multipart image upload payload
2 properties
1 required
gateway_port_vpn_path_role
string
If the VPN type==hubspoke, enum: hub, spoke. If the VPN type==mesh, enum: mesh
snmp_usms
array
SNMPv3 USM engine configurations
radio_band_antenna_beam_pattern
string
enum: narrow, medium, wide
poe_priority
string
PoE priority. enum: low, high
tunnel_config_ike_dh_group
string
Diffie-Hellman group for IKE phase 1. enum: 1, 14, 15, 16, 19, 2, 20, 21, 24, 5. 14 is the default 2048-bit group; 19, 20, 21, and 24 are ECP groups
ble_config_power_mode
string
Transmit power mode for BLE beacons; use custom to set explicit power. enum: custom, default
dhcpd_config_servers
array
If type==relay, upstream IPv4 DHCP servers
wan_extra_routes6
object
Additional IPv6 route for a WAN interface
1 property
snmp_usm
object
SNMPv3 User-based Security Model configuration
3 properties
tunnel_config_node_remote_ids
array
Only if provider==jse-ipsec or provider==custom-ipsec
ap_aeroscout
object
AeroScout location integration settings applied to an AP or AP profile
4 properties
sw_routing_policies
object
Switch routing policies keyed by routing policy name
switch_port_usage_dynamic_vlan_networks
array
Only if mode!=dynamic and portauth==dot1x, if dynamic vlan is used, specify the possible networks/vlans RADIUS can return
gateway_path_strategy
string
enum: ecmp, ordered, weighted
response_device_search_results
array
Device search records for APs, switches, or gateways
extra_routes6
object
Property key is the destination CIDR (e.g. "2a02:1234:420a:10c9::/64")
snmp_vacm_security_to_group_content
array
VACM security-name to group mapping entries
gateway_vrf_instances
object
Property key is the VRF instance name
ap_pwr_config
object
Power negotiation and peripheral power settings for an AP or AP profile
2 properties
switch_port_usage_speed_overwrite
string
Port Speed, default is auto to automatically negotiate speed enum: 100m, 10m, 1g, 2.5g, 5g, 10g, 25g, 40g, 100g,auto
network_tenant_addresses
array
IP addresses or subnets assigned to a network tenant
response_config_history_search_item_wlan
object
WLAN config history detail
5 properties
3 required
dot11_bandwidth5
integer
channel width for the 5GHz band. enum: 0(disabled, response only), 20, 40, 80
idp_profile_overwrites
array
IDP profile overwrite rules applied to the base profile
allow_deny
string
Policy action value that either allows or denies matching traffic. enum: allow, deny
radsec_proxy_hosts
array
Default is site.mxedge.radsec.proxyhosts which must be a superset of all wlans[].radsec.proxyhosts. When radsec.proxyhosts are not used, tunnel peers (org or s…
wired_port_config
object
Property key is the port name or range (e.g. "ge-0/0/0-10")
tunnel_config_ike_proposal
object
IKE proposal settings for custom IPsec tunnels
3 properties
radsec_servers
array
External RadSec servers. Only if not Mist Edge.
junos_other_ip_config
object
Optional switch L3 presence on an additional network or VLAN
7 properties
switch_network
object
A network represents a network segment. It can either represent a VLAN (then usually ties to a L3 subnet), optionally associate it with a subnet which can late…
7 properties
1 required
gateway_port_lte_auth
string
if wantype==lte. enum: chap, none, pap
gw_routing_policy_term
object
Gateway routing policy term with match criteria and actions
2 properties
gw_routing_policy_term_matching
object
Route match criteria for a gateway routing policy term; all specified criteria must match
9 properties
dot11_band
string
enum: 24, 5, 5-dedicated, 5-selectable, 6, 6-dedicated, 6-selectable
dhcpd_config_type6
string
enum: local (DHCP Server), none, relay (DHCP Relay)
tunnel_provider_options_zscaler_sub_location
object
Zscaler sub-location settings for a specific network
14 properties
junos_ip_config
object
Junos management IP configuration
7 properties
ibeacon_major
integernull
Major number for iBeacon
gateway_wan_probe_override
object
Only if usage==wan. WAN health probe override for this gateway port
3 properties
gateway_path_preferences_path_target_ips
array
Destination IP addresses to replace when type==local
ap_zigbee
object
Zigbee radio and network settings applied to an AP or AP profile
5 properties
device_event
object
Device event payload returned by search and webhook APIs
30 properties
3 required
device_type
string
enum: ap, gateway, switch
remote_syslog_user
object
User-specific syslog logging rule
3 properties
dhcpd_config_fixed_binding
object
Static DHCP binding for a client MAC address
3 properties
device_switch
object
You can configure portusages and networks settings at the device level, but most of the time it's better use the Site Setting to achieve better consistency and…
63 properties
1 required
acl_tag_specs
array
If type==resource, type==radiusgroup, type==portusage or type==gbpresource. Empty means unrestricted, i.e. any
sw_routing_policy_term_matching_protocol
array
Routing protocols that can match a switch routing policy term
remote_syslog_severity
string
enum: alert, any, critical, emergency, error, info, notice, warning
switch_dhcpd_config_vendor_options
object
If type==server or type6==server. Property key is : , with enterprise number: 1-65535 (https://www.iana.org/assignments/enterprise-numbers/enterprise-numbers)…
snmp_usm_user_encryption_type
string
enum: privacy-3des, privacy-aes128, privacy-des, privacy-none
junos_port_config_speed
string
enum: 100m, 10m, 1g, 2.5g, 5g, 10g, 25g, 40g, 100g,auto
switch_iot_port_alarm_class
string
Alarm class for the switch iot port in. enum: minor, major
tacacs_acct_server
object
TACACS+ accounting server settings
4 properties
switch_port_mirroring
object
Property key is the port mirroring instance name. portmirroring can be added under device/site settings. It takes interface and ports as input for ingress, int…
ap_iot_output
object
IoT output AP settings
5 properties
app_probing_custom_app_protocol
string
Probe protocol for a custom application. enum: http, icmp
vrf_config
object
VRF enablement settings applied when supported on the device
1 property
tacacs_acct_servers
array
List of TACACS+ accounting servers
ap_iot
object
Digital and analog IoT port settings applied to an AP or AP profile
7 properties
zscaler_sub_locations
array
sub-locations can be used for specific uses cases to define different configuration based on the user network
tunnel_config_node_internal_ips
array
Only if provider==zscaler-gre, provider==jse-ipsec, provider==custom-ipsec or provider==custom-gre
ap_port_config_mac_auth_protocol
string
if enablemacauth==true, allows user to select an authentication protocol. enum: eap-md5, eap-peap, pap
switch_dhcpd_config
object
Switch DHCP server or relay configuration keyed by network name
1 property
network
object
Organization-level Layer 3 network definition that can be merged into site settings and used for service routes. Networks are used to define the service routes…
18 properties
1 required
ap_ip_config
object
Management IP addressing settings for an access point
12 properties
idp_profile_matching_attack_name
array
IDP attack signature names matched by an overwrite rule
snmp_config_client_lists
array
SNMP client allowlists that can be referenced by communities
switch_virtual_chassis_member
object
Virtual Chassis member identified by MAC address and role
3 properties
3 required
tunnel_config_auto_provision
object
Auto-provisioning configuration for the tunnel. This takes precedence over the primary and secondary nodes.
7 properties
1 required
gateway_wan_probe_override_probe_profile
string
WAN probe profile used for health checks on this port. enum: broadband, lte
tacacs_default_role
string
enum: admin, helpdesk, none, read
snmp_config
object
SNMP configuration for managed network devices
13 properties
dhcpd_config
object
DHCP server configuration map with a global enable flag
1 property
sw_routing_policy_term_matching
object
Route match criteria for a switch routing policy term; all specified criteria must match
4 properties
dhcpd_config_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
snmp_config_v2c_config
object
SNMPv2c community configuration entry
4 properties
vlan_id_with_variable
VLAN ID, either numeric or expressed as a template variable string
gateway_port_mirroring_port_mirror
object
Gateway port mirroring rule
5 properties
tunnel_config_node
object
Only if provider==zscaler-ipsec, provider==jse-ipsec or provider==custom-ipsec
5 properties
2 required
ble_config_beacon_rate_mode
string
Beacon rate mode for Mist BLE beacons; use custom to set beaconrate. enum: custom, default
network_multicast
object
Whether to enable multicast support (only PIM-sparse mode is supported)
3 properties
ap_ip_config_dns_suffix
array
Required if type==static; DNS search suffixes applied to AP management lookups
ap_search_hostnames
array
List of hostnames detected for the AP
gateway_port_vpn_paths
object
Property key is the VPN name
snmp_config_engine_id
string
SNMP engine ID value used for SNMPv3
response_http429
object
Standard HTTP 429 rate limit error response
1 property
dns_servers
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
id
string
Unique ID of the object instance in the Mist Organization
snmpv3_config_notify_filter_item_content
object
OID filter rule for an SNMPv3 notification profile
2 properties
ap_mesh_bands
array
List of bands that mesh should use. For relay, the first viable one will be picked. enum: 24, 5, 6
ap_port_config_dynamic_vlan_type
string
Mapping mode for interpreting dynamic VLAN attributes returned by RADIUS.\ \ enum: airespace-interface-name, where the VLAN is determined by parsing\ \ the RAD…
protect_re
object
Restrict inbound-traffic to host when enabled, all traffic that is not essential to our operation will be dropped e.g. ntp / dns / traffic to mist will be allo…
5 properties
remote_syslog_cacerts
array
CA certificates used to verify TLS syslog servers
network_internal_access
object
Internal access settings for an organization network
1 property
service_policy_ssl_proxy
object
SRX SSL proxy inspection settings for a service policy
2 properties
device_type_switch
string
Device Type. enum: switch
response_http400
object
Standard HTTP 400 bad request error response
1 property
dhcpd_config_vendor_option_type
string
enum: boolean, hex, int16, int32, ip, string, uint16, uint32
gateway_wan_type6
string
enum: autoconf, dhcp, static
gw_routing_policy_term_action_add_target_vrfs
array
For SSR, target VRFs used by a hub when leaking VRF routes to spokes
switch_port_usage_dynamic_rule_equals_any
array
Use equalsany to match any item in a list
dhcpd_config_servers6
array
If type6==relay, upstream IPv6 DHCP servers
snmpv3_config_notify_filter_item
object
SNMPv3 notification filter profile
2 properties
gateway_port_usage
string
port usage name. enum: hacontrol, hadata, lan, wan
device_ap
object
Access point configuration and placement data
48 properties
1 required
switch_port_usage_mode
string
mode==dynamic must only be used if the port usage name is dynamic. enum: access, dynamic, inet, trunk
switch_port_usage_networks
array
Only if mode==trunk, the list of network/vlans
network_vpn_access_static_nat
object
Property key may be an External IP address (i.e. "63.16.0.3"), a CIDR (i.e. "63.16.0.12/20") or a Variable (i.e. "{{myvar}}")
tunnel_config_networks
array
If provider==custom-ipsec or provider==prisma-ipsec, networks reachable via this tunnel
gateway_mgmt_probe_hosts
array
IPv4 probe hosts used for gateway connectivity checks
remote_syslog_contents
array
List of syslog content selectors
response_http404
object
Standard HTTP 404 not found error response
1 property
next_hop_via
Next-hop IP address. Can be a single IP address or an array of IP addresses for ECMP (Equal-Cost Multi-Path) load balancing across multiple next-hops.
gateway_ip_config_dns_servers
array
Except for out-ofband interface (vme/em0/fxp0)
ap_uplink_port_config
object
AP Uplink port configuration
2 properties
gateway_port_config_reth_idx
For SRX only and if HA Mode. -1 means it will be managed by the device. Use = 0 values to manage it manually. Ensure no conflicting values are assigned across…
service_policy_ewf
array
Enhanced web filtering rules applied by a service policy
switch_port_usage_dynamic_reset_default_when
string
Only if mode==dynamic Control when the DPC port should be changed to the default port usage. enum: linkdown, none (let the DPC port keep at the current port us…
dhcpd_config_dns_suffix
array
If type==local or type6==local - optional, if not defined, system one will be used
gw_routing_policies
object
Property key is the routing policy name
network_vpn_access_destination_nat_property
object
VPN access destination NAT rule target settings
3 properties
network_routed_for_networks
array
For a Network (usually LAN), it can be routable to other networks (e.g. OSPF)
gw_routing_policy_term_matching_protocol
array
Routing protocols that can match a gateway routing policy term
dhcpd_config_type
string
enum: local (DHCP Server), none, relay (DHCP Relay)
device_type_default_ap
string
enum: ap, gateway, switch
snmp_vacm_security_to_group_content_item
object
VACM security-name to group mapping entry
2 properties
radius_acct_port
RADIUS Auth Port, value from 1 to 65535, default is 1813
switch_vrf_instances
object
Property key is the network name
evpn_config_role
string
enum: access, border, collapsed-core, core, distribution, esilag-access, none
ap_iot_input
object
IoT Input AP settings
3 properties
ap_esl_config
object
Electronic shelf label integration settings for an AP
8 properties
device_events
array
List of device event payloads
acl_tag_spec
object
Layer 4 protocol and destination-port match constraint for an ACL tag
2 properties
radius_coa_port
RADIUS CoA Port, value from 1 to 65535, default is 3799
search_site_devices_mxtunnel_status
string
Mist Tunnel status filter for site device search. enum: down, up
gw_routing_policy_term_matching_vpn_neighbor_mac
array
Overlay neighbor MAC addresses used for bgpconfig where via==vpn
vrrp_config_group
object
VRRP group behavior settings
2 properties
ap_esl_type
string
note: bleconfig will be ignored if eslconfig is enabled and with native mode. enum: hanshow, imagotag, native, solum
ospf_areas_network
object
Property key is the network name. Networks to participate in an OSPF area
12 properties
count_results
array
List of count result rows
ap_mqtt_broker_proto
string
MQTT broker transport protocol. enum: ssl, tcp
tunnel_provider_options
object
Provider-specific options for gateway tunnel auto provisioning
3 properties
gw_routing_policy_term_matching_protocol_enum
string
enum: aggregate, bgp, direct, ospf, static (SRX Only)
gateway_port_vpn_path_bfd_profile
string
Only if the VPN type==hubspoke. enum: broadband, lte
radsec_idle_timeout
RadSec idle timeout in seconds. Default is 60
acl_tag_subnets
array
If - type==subnet - type==resource (optional. default is any) - type==staticgbp if from matching subnet
gateway_path_type
string
enum: local, tunnel, vpn, wan
switch_ospf_config_area
object
Settings for a single OSPF area on a switch
1 property
tunnel_config_probe
object
Tunnel health probe settings
4 properties
tunnel_config_protocol
string
Only if provider==custom-ipsec. enum: gre, ipsec
bgp_config_networks
array
Optional if via==lan. List of networks where we expect BGP neighbor to connect to/from
switch_dhcpd_config_fixed_bindings
object
If type==server or type6==server. Property key is the MAC address. Format is [0-9a-f]{12} (e.g. "5684dae9ac8b")
acl_tags
object
ACL Tags to identify traffic source or destination. Key name is the tag name
dns_suffix
array
Global dns settings. To keep compatibility, dns settings in ipconfig and oobipconfig will overwrite this setting
response_config_history_search_item_wlans
array
WLAN config history details
gateway_oob_ip_config_node1
object
Node1-specific out-of-band management IP configuration for HA clusters
7 properties
config_switch_local_accounts_user_role
string
enum: admin, helpdesk, none, read
response_device_search
object
Paginated response for organization or site device search results
6 properties
5 required
service_policy_skyatp_http_inspection_profile
string
Sky ATP HTTP inspection profile to apply. enum: standard, strict
tacacs_auth_servers
array
List of TACACS+ authentication servers
tunnel_config_auto_provision_provider
string
Tunnel provider used for automatic endpoint provisioning. enum: jse-ipsec, zscaler-ipsec
response_config_history_search_item_radio
object
Radio config history detail
2 properties
2 required
switch_virtual_chassis_members
array
List of Virtual Chassis members
ap_client_bridge_auth
object
Authentication settings for the AP client bridge uplink
2 properties
network_vpn_access_destination_nat
object
Property key can be an External IP (i.e. "63.16.0.3"), an External IP:Port (i.e. "63.16.0.3:443"), an External Port (i.e. ":443"), an External CIDR (i.e. "63.1…
gw_routing_policy_term_action_add_community
array
BGP communities added to routes matched by a gateway routing policy term
config_device
Device configuration object for an AP, switch, or gateway
remote_syslog_server
object
Remote syslog server destination settings
13 properties
ap_port_config_port_auth
string
When doing port auth. enum: dot1x, none
gw_routing_policy_term_matching_vpn_path
array
Overlay path names used for bgpconfig where via==vpn; order is significant
tunnel_config_node_wan_names
array
Interface names that source tunnel traffic for a tunnel node
switch_ospf_config
object
OSPF routing configuration for a Junos switch
5 properties
network_vpn_access_config_other_vrfs
array
By default, the routes are only readvertised toward the same vrf on spoke. To allow it to be leaked to other vrfs
acl_policy_actions
array
ACL Policy Actions: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source or de…
config_switch_local_accounts_user
object
Local switch user account credentials and access role
2 properties
sw_routing_policy_term
object
Switch routing policy term with match criteria and actions
3 properties
1 required
gateway_port_config_wan_networks
array
Only if usage==wan. If some networks are connected to this WAN port, it can be added here so policies can be defined
switch_virtual_chassis_member_vc_role
string
Both vcrole master and backup will be matched to routing-engine role in Junos preprovisioned VC config. enum: backup, linecard, master
ap_search_inactive_wired_vlans
array
Inactive wired VLAN IDs reported for an AP
switch_port_usage_speed
string
Only if mode!=dynamic, Port speed, default is auto to automatically negotiate speed enum: 100m, 10m, 1g, 2.5g, 5g, 10g, 25g, 40g, 100g,auto
switch_ospf_config_areas
object
Property key is the area name. Defines the OSPF areas configured on the switch.
protect_re_allowed_services
array
Built-in services explicitly allowed by the Protect RE policy
snmpv3_config_target_params
array
SNMPv3 target parameter profiles
switch_port_usage_mtu
Only if mode!=dynamic media maximum transmission unit (MTU) is the largest data unit that can be forwarded without fragmentation. The default value is 1514.
ap_iot_pullup
string
the type of pull-up the pin uses. enum: external, internal, none
aggregate_routes6
object
Property key is the destination subnet (e.g. "2a02:1234:420a:10c9::/64")
acl_policy_action
object
Action applied to traffic that matches a destination ACL tag
2 properties
1 required
bgp_config_type
string
Required if via==lan, via==tunnel or via==wan. enum: external, internal
acl_tag_type
string
enum: any: matching anything not identified dynamicgbp: from the gbptag received from RADIUS gbpresource: can only be used in dsttags mac network portusage rad…
tunnel_config_dh_group
string
Only if provider==custom-ipsec. Diffie-Hellman group for IPsec phase 2. enum: 1, 14, 15, 16, 19, 2, 20, 21, 24, 5. 14 is the default 2048-bit group; 19, 20, 21…
ap_client_bridge_auth_type
string
wpa2-AES/CCMPp is assumed when type==psk. enum: open, psk
gateway_port_dsl_type
string
if wantype==dsl. enum: adsl, vdsl
gateway_mgmt_admin_sshkeys
array
For SSR only, as direct root access is not allowed
bgp_as
BGP AS, value in range 1-4294967294. Can be a Variable (e.g. {{bgpas}} )
radius_config
object
Junos RADIUS authentication and accounting configuration
9 properties
tunnel_config_ipsec_proposal
object
IPsec proposal settings for custom IPsec tunnels
3 properties
ap_import_json
array
AP device records supplied in a JSON import payload
wlan_mist_nac
object
Mist NAC RADIUS settings for a WLAN
9 properties
tunnel_config_auto_provision_node
object
Auto-provisioned tunnel endpoint settings
2 properties
snmp_config_trap_version
string
enum: all, v1, v2
tunnel_config_ike_mode
string
Only if provider==custom-ipsec. enum: aggressive, main
service_policy_ewf_rule
object
Enhanced web filtering rule applied by a service policy
4 properties
radius_auth_servers
array
List of RADIUS authentication servers
sw_routing_policy_terms
array
Ordered switch routing policy terms; at least one term is required
gateway_port_wan_arp_policer
string
Only when wantype==broadband. enum: default, max, recommended
additional_config_cmds
array
additional CLI commands to append to the generated Junos config. Note: no check is done
remote_syslog_console
object
Console log forwarding filters for remote syslog
1 property
service_policy_skyatp_dns_dga_detection
object
Sky ATP DNS DGA detection settings
2 properties
switch_ospf_config_reference_bandwidth
Reference bandwidth. Integer(100000) or String (10g)
network_internet_access_static_nat_property
object
Direct-internet static NAT rule target settings
3 properties
remote_syslog_file_config
object
Generated syslog file output settings
7 properties
network_vpn_access
object
Property key is the VPN name. Whether this network can be accessed from vpn
snmp_vacm_access_item_prefix_list_item_model
string
enum: any, usm, v1, v2c
snmpv3_config_notify
array
SNMPv3 notification definitions used for traps and informs
device_type_gateway
string
Device Type. enum: gateway
response_http401
object
Standard HTTP 401 authentication error response
1 property
tacacs
object
TACACS+ settings for switch management authentication and accounting
5 properties
service_policy_skyatp_http_inspection
object
Sky ATP HTTP inspection settings
2 properties
switch_port_config_overwrites
object
Property key is the port name or range (e.g. "ge-0/0/0-10"). This can be used to override some attributes of the portusage without having to create a new portu…
remote_syslog_files
array
Generated syslog file output definitions
switch_virtual_chassis
object
Required for preprovisioned Virtual Chassis
2 properties
device_gateway
object
Gateway configuration and placement data
47 properties
1 required
device_type_with_all
string
ap, switch, gateway, router, all, default is ap. Supports comma-separated values for multiple types (e.g., type=switch,gateway)
idp_profile
object
Organization IDP profile with a base profile and targeted overwrite rules
7 properties
dot11_bandwidth6
integer
channel width for the 6GHz band. enum: 0(disabled, response only), 20, 40, 80, 160
snmpv3_config_target_param_mess_process_model
string
enum: v1, v2c, v3
evpn_config
object
EVPN configuration settings applied to a Junos switch
2 properties
gateway_traffic_shaping_class_percentages
array
percentages for different class of traffic: high / medium / low / best-effort. Sum must be equal to 100
radius_acct_servers
array
List of RADIUS accounting servers
switch_bgp_config_networks
array
List of network names for BGP configuration. When a network is specified, a BGP group will be added to the VRF that network is part of.
ap_mesh_role
string
Mesh role for this AP, either base or remote. enum: base, remote
gateway_port_wan_type
string
Only if usage==wan. enum: broadband, dsl, lte
gw_routing_policy_term_action_exclude_as_path
array
Optional when used as an export policy. AS path values to exclude
site_devices_count_distinct
string
enum: hostname, lldpmgmtaddr, lldpportid, lldpsystemdesc, lldpsystemname, mapid, model, mxedgeid, mxtunnelstatus, version
app_probing_custom_apps
array
User-defined application probe definitions
ble_config_beam_disabled
array
List of AP BLE location beam numbers (1-8) which should be disabled at the AP and not transmit location information (where beam 1 is oriented at the top the AP…
acl_policy_src_tags
array
ACL Policy Source Tags: - for GBP-based policy, all srctags and dsttags have to be gbp-based - for ACL-based policy, network is required in either the source o…
tunnel_config_local_subnets
array
List of Local protected subnet for policy-based IPSec negotiation
snmp_usm_users
array
SNMPv3 USM user definitions
protect_re_customs
array
Custom Protect RE ACL entries
switch_vrf_instance
object
Switch VRF instance routing and network membership settings
7 properties
switch_port_config_overwrite
object
Switch port configuration overrides
8 properties
antenna_select
string
Antenna Mode for AP which supports selectable antennas. enum: "" (default), external, internal
radius_keywrap_format
string
Encoding format for RADIUS keywrap KEK and MACK values. enum: ascii, hex
protect_re_custom_protocol
string
enum: any, icmp, tcp, udp
const_device_type_ap
string
Device Type. enum: ap
ap_mqtt_format
string
Payload format for MQTT published messages. enum: json, raw
ble_config
object
Bluetooth Low Energy beacon and asset advertising settings for an AP
27 properties
const_device_type_gateway
string
Device Type. enum: gateway
tunnel_provider_options_prisma
object
Prisma Access provider options for tunnel auto provisioning
1 property
acl_tag
object
Resource tags (type==resource or type==gbpresource) can only be used in dsttags
9 properties
1 required
devices_gbp_tag
object
Request body for assigning a GBP tag to multiple devices
2 properties
2 required
app_probing_apps
array
Application keys from [List Applications](/operations/listApplications)
switch_port_local_usage_dot1x
stringnull
if dot1x is desired, set to dot1x. enum: dot1x
site_id
string
Unique identifier of a Mist site
ap_usb_type
string
usb config type. enum: hanshow, imagotag, solum
networks
array
List of organization network definitions
protect_re_custom
object
Custom Protect RE ACL entry
3 properties
webhook_device_events_event_ev_type
string
(optional) event advisory. enum: notice, warn
gateway_ip_config_dns_suffix
array
Except for out-ofband interface (vme/em0/fxp0)
gw_routing_policy_term_matching_vpn_path_sla
object
SLA thresholds used when matching VPN paths
3 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Mist publishes across the network.