Skip to content

Intrusion Prevention

POST/settings/exclusions/intrusion-prevention

Endpoint API · Intrusion Prevention

Add a new Intrusion Prevention exclusion.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

localPortsarray of integer
Local protected ports.
Must contain exactly 1 item. Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote protected ports.
Must contain exactly 1 item. Each item must be ≥ 1 and ≤ 65535.
directionstringrequired
Direction property of the intrusion prevention exclusion.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Array of remote addresses for the intrusion prevention exclusion.
Must contain exactly 1 item.
commentstring
Comment given to the exclusion at the time of creation.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"localPorts\": [
    65232
  ],
  \"remotePorts\": [
    65232
  ],
  \"direction\": \"inbound\",
  \"remoteAddresses\": [
    \"http://10.50.100.100\"
  ],
  \"comment\": \"Item is a Malware\"
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'localPorts': [65232],
    'remotePorts': [65232],
    'direction': 'inbound',
    'remoteAddresses': ['http://10.50.100.100'],
    'comment': 'Item is a Malware'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "localPorts": [
    65232
  ],
  "remotePorts": [
    65232
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention", strings.NewReader(`{
  "localPorts": [
    65232
  ],
  "remotePorts": [
    65232
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/intrusion-prevention", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "localPorts": [
    65232
  ],
  "remotePorts": [
    65232
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}),
});
const data = await response.json();
console.log(data);

Responses

201 — Intrusion Prevention exclusion created.

Response fields

idstringrequired
Exclusion ID.
Must match the pattern [a-f0-9]{64}.
typestringrequired
Exclusion type. This is always intrusionPrevention.
Must be one of: intrusionPrevention.
localPortsarray of integer
Local allowed ports.
Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote allowed ports.
Each item must be ≥ 1 and ≤ 65535.
directionstringrequired
Direction property of the intrusion prevention exclusion.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Remote addresses to exempt from Intrusion Prevention checks.
commentstringrequired
Exclusion comment.

Errors

Status Meaning
400 Bad request.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "string",
  "type": "intrusionPrevention",
  "localPorts": [
    0
  ],
  "remotePorts": [
    0
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "string"
  ],
  "comment": "string"
}

See the guide for a narrative walkthrough of this API.