| Column Name | Column Data Type |
tls_inspection_configuration_arn Input Column
The Amazon Resource Name (ARN) of the TLS inspection configuration. You must specify the ARN or the name, and you can specify both. | VARCHAR |
tls_inspection_configuration_name Input Column
The descriptive name of the TLS inspection configuration. You can't change the name of a TLS inspection configuration after you create it. You must specify the ARN or the name, and you can specify both. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_aws_region Input Column
The AWS region to use. | VARCHAR |
tls_inspection_configuration
The object that defines a TLS inspection configuration. This, along with TLSInspectionConfigurationResponse, define the TLS inspection configuration. You can retrieve all objects for a TLS inspection configuration by calling DescribeTLSInspectionConfiguration. Network Firewall uses a TLS inspection configuration to decrypt traffic. Network Firewall re-encrypts the traffic before sending it to its destination. To use a TLS inspection configuration, you add it to a new Network Firewall firewall policy, then you apply the firewall policy to a firewall. Network Firewall acts as a proxy service to decrypt and inspect the traffic traveling through your firewalls. You can reference a TLS inspection configuration from more than one firewall policy, and you can use a firewall policy in more than one firewall. For more information about using TLS inspection configurations, see Inspecting SSL/TLS traffic with TLS inspection configurations in the Network Firewall Developer Guide. | STRUCT( "server_certificate_configurations" STRUCT( "server_certificates" STRUCT( "resource_arn" VARCHAR )[], "scopes" STRUCT( "sources" STRUCT( "address_definition" VARCHAR )[], "destinations" STRUCT( "address_definition" VARCHAR )[], "source_ports" STRUCT( "from_port" BIGINT, "to_port" BIGINT )[], "destination_ports" STRUCT( "from_port" BIGINT, "to_port" BIGINT )[], "protocols" BIGINT[] )[], "certificate_authority_arn" VARCHAR, "check_certificate_revocation_status" STRUCT( "revoked_status_action" VARCHAR, "unknown_status_action" VARCHAR ) )[] ) |
Show child fields- tls_inspection_configuration.server_certificate_configurations[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].certificate_authority_arn
The Amazon Resource Name (ARN) of the imported certificate authority (CA) certificate within Certificate Manager (ACM) to use for outbound SSL/TLS inspection. The following limitations apply: -
You can use CA certificates that you imported into ACM, but you can't generate CA certificates with ACM. -
You can't use certificates issued by Private Certificate Authority. For more information about configuring certificates for outbound inspection, see Using SSL/TLS certificates with certificates with TLS inspection configurations in the Network Firewall Developer Guide. For information about working with certificates in ACM, see Importing certificates in the Certificate Manager User Guide.
- tls_inspection_configuration.server_certificate_configurations[].check_certificate_revocation_status
When enabled, Network Firewall checks if the server certificate presented by the server in the SSL/TLS connection has a revoked or unkown status. If the certificate has an unknown or revoked status, you must specify the actions that Network Firewall takes on outbound traffic. To check the certificate revocation status, you must also specify a CertificateAuthorityArn in ServerCertificateConfiguration. Show child fields- tls_inspection_configuration.server_certificate_configurations[].check_certificate_revocation_status.revoked_status_action
Configures how Network Firewall processes traffic when it determines that the certificate presented by the server in the SSL/TLS connection has a revoked status. -
PASS - Allow the connection to continue, and pass subsequent packets to the stateful engine for inspection. -
DROP - Network Firewall closes the connection and drops subsequent packets for that connection. -
REJECT - Network Firewall sends a TCP reject packet back to your client. The service closes the connection and drops subsequent packets for that connection. REJECT is available only for TCP traffic.
- tls_inspection_configuration.server_certificate_configurations[].check_certificate_revocation_status.unknown_status_action
Configures how Network Firewall processes traffic when it determines that the certificate presented by the server in the SSL/TLS connection has an unknown status, or a status that cannot be determined for any other reason, including when the service is unable to connect to the OCSP and CRL endpoints for the certificate. -
PASS - Allow the connection to continue, and pass subsequent packets to the stateful engine for inspection. -
DROP - Network Firewall closes the connection and drops subsequent packets for that connection. -
REJECT - Network Firewall sends a TCP reject packet back to your client. The service closes the connection and drops subsequent packets for that connection. REJECT is available only for TCP traffic.
- tls_inspection_configuration.server_certificate_configurations[].scopes[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].scopes[].destination_ports[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].scopes[].destination_ports[].from_port
The lower limit of the port range. This must be less than or equal to the ToPort specification.
- tls_inspection_configuration.server_certificate_configurations[].scopes[].destination_ports[].to_port
The upper limit of the port range. This must be greater than or equal to the FromPort specification.
- tls_inspection_configuration.server_certificate_configurations[].scopes[].destinations[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].scopes[].destinations[].address_definition
Specify an IP address or a block of IP addresses in Classless Inter-Domain Routing (CIDR) notation. Network Firewall supports all address ranges for IPv4 and IPv6. Examples: -
To configure Network Firewall to inspect for the IP address 192.0.2.44, specify 192.0.2.44/32. -
To configure Network Firewall to inspect for IP addresses from 192.0.2.0 to 192.0.2.255, specify 192.0.2.0/24. -
To configure Network Firewall to inspect for the IP address 1111:0000:0000:0000:0000:0000:0000:0111, specify 1111:0000:0000:0000:0000:0000:0000:0111/128. -
To configure Network Firewall to inspect for IP addresses from 1111:0000:0000:0000:0000:0000:0000:0000 to 1111:0000:0000:0000:ffff:ffff:ffff:ffff, specify 1111:0000:0000:0000:0000:0000:0000:0000/64. For more information about CIDR notation, see the Wikipedia entry Classless Inter-Domain Routing.
- tls_inspection_configuration.server_certificate_configurations[].scopes[].protocols[]
- tls_inspection_configuration.server_certificate_configurations[].scopes[].source_ports[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].scopes[].source_ports[].from_port
The lower limit of the port range. This must be less than or equal to the ToPort specification.
- tls_inspection_configuration.server_certificate_configurations[].scopes[].source_ports[].to_port
The upper limit of the port range. This must be greater than or equal to the FromPort specification.
- tls_inspection_configuration.server_certificate_configurations[].scopes[].sources[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].scopes[].sources[].address_definition
Specify an IP address or a block of IP addresses in Classless Inter-Domain Routing (CIDR) notation. Network Firewall supports all address ranges for IPv4 and IPv6. Examples: -
To configure Network Firewall to inspect for the IP address 192.0.2.44, specify 192.0.2.44/32. -
To configure Network Firewall to inspect for IP addresses from 192.0.2.0 to 192.0.2.255, specify 192.0.2.0/24. -
To configure Network Firewall to inspect for the IP address 1111:0000:0000:0000:0000:0000:0000:0111, specify 1111:0000:0000:0000:0000:0000:0000:0111/128. -
To configure Network Firewall to inspect for IP addresses from 1111:0000:0000:0000:0000:0000:0000:0000 to 1111:0000:0000:0000:ffff:ffff:ffff:ffff, specify 1111:0000:0000:0000:0000:0000:0000:0000/64. For more information about CIDR notation, see the Wikipedia entry Classless Inter-Domain Routing.
- tls_inspection_configuration.server_certificate_configurations[].server_certificates[]
Show child fields- tls_inspection_configuration.server_certificate_configurations[].server_certificates[].resource_arn
The Amazon Resource Name (ARN) of the Certificate Manager SSL/TLS server certificate that's used for inbound SSL/TLS inspection.
|
tls_inspection_configuration_response
The high-level properties of a TLS inspection configuration. This, along with the TLSInspectionConfiguration, define the TLS inspection configuration. You can retrieve all objects for a TLS inspection configuration by calling DescribeTLSInspectionConfiguration. | STRUCT( "tls_inspection_configuration_arn" VARCHAR, "tls_inspection_configuration_name" VARCHAR, "tls_inspection_configuration_id" VARCHAR, "tls_inspection_configuration_status" VARCHAR, "description" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "last_modified_time" TIMESTAMP_S, "number_of_associations" BIGINT, "encryption_configuration" STRUCT( "key_id" VARCHAR, "type" VARCHAR ), "certificates" STRUCT( "certificate_arn" VARCHAR, "certificate_serial" VARCHAR, "status" VARCHAR, "status_message" VARCHAR )[], "certificate_authority" STRUCT( "certificate_arn" VARCHAR, "certificate_serial" VARCHAR, "status" VARCHAR, "status_message" VARCHAR ) ) |
Show child fields- tls_inspection_configuration_response.certificate_authority
Contains metadata about an Certificate Manager certificate. Show child fields- tls_inspection_configuration_response.certificate_authority.certificate_arn
The Amazon Resource Name (ARN) of the certificate.
- tls_inspection_configuration_response.certificate_authority.certificate_serial
The serial number of the certificate.
- tls_inspection_configuration_response.certificate_authority.status
The status of the certificate.
- tls_inspection_configuration_response.certificate_authority.status_message
Contains details about the certificate status, including information about certificate errors.
- tls_inspection_configuration_response.certificates[]
Show child fields- tls_inspection_configuration_response.certificates[].certificate_arn
The Amazon Resource Name (ARN) of the certificate.
- tls_inspection_configuration_response.certificates[].certificate_serial
The serial number of the certificate.
- tls_inspection_configuration_response.certificates[].status
The status of the certificate.
- tls_inspection_configuration_response.certificates[].status_message
Contains details about the certificate status, including information about certificate errors.
- tls_inspection_configuration_response.description
A description of the TLS inspection configuration.
- tls_inspection_configuration_response.encryption_configuration
A complex type that contains the Amazon Web Services KMS encryption configuration settings for your TLS inspection configuration. Show child fields- tls_inspection_configuration_response.encryption_configuration.key_id
The ID of the Amazon Web Services Key Management Service (KMS) customer managed key. You can use any of the key identifiers that KMS supports, unless you're using a key that's managed by another account. If you're using a key managed by another account, then specify the key ARN. For more information, see Key ID in the Amazon Web Services KMS Developer Guide.
- tls_inspection_configuration_response.encryption_configuration.type
The type of Amazon Web Services KMS key to use for encryption of your Network Firewall resources.
- tls_inspection_configuration_response.last_modified_time
The last time that the TLS inspection configuration was changed.
- tls_inspection_configuration_response.number_of_associations
The number of firewall policies that use this TLS inspection configuration.
- tls_inspection_configuration_response.tags[]
Show child fields- tls_inspection_configuration_response.tags[].key
The part of the key:value pair that defines a tag. You can use a tag key to describe a category of information, such as "customer." Tag keys are case-sensitive.
- tls_inspection_configuration_response.tags[].value
The part of the key:value pair that defines a tag. You can use a tag value to describe a specific value within a category, such as "companyA" or "companyB." Tag values are case-sensitive.
- tls_inspection_configuration_response.tls_inspection_configuration_arn
The Amazon Resource Name (ARN) of the TLS inspection configuration.
- tls_inspection_configuration_response.tls_inspection_configuration_id
A unique identifier for the TLS inspection configuration. This ID is returned in the responses to create and list commands. You provide it to operations such as update and delete.
- tls_inspection_configuration_response.tls_inspection_configuration_name
The descriptive name of the TLS inspection configuration. You can't change the name of a TLS inspection configuration after you create it.
- tls_inspection_configuration_response.tls_inspection_configuration_status
Detailed information about the current status of a TLSInspectionConfiguration. You can retrieve this for a TLS inspection configuration by calling DescribeTLSInspectionConfiguration and providing the TLS inspection configuration name and ARN.
|
update_token
A token used for optimistic locking. Network Firewall returns a token to your requests that access the TLS inspection configuration. The token marks the state of the TLS inspection configuration resource at the time of the request. To make changes to the TLS inspection configuration, you provide the token in your request. Network Firewall uses the token to ensure that the TLS inspection configuration hasn't changed since you last retrieved it. If it has changed, the operation fails with an InvalidTokenException. If this happens, retrieve the TLS inspection configuration again to get a current copy of it with a current token. Reapply your changes as needed, then try the operation again using the new token. | VARCHAR |