End of support notice: On October 7, 2026, AWS will end support for Amazon FinSpace. After October 7, 2026, you will no longer be able to access the FinSpace console or FinSpace resources. For more information, see Amazon FinSpace end of support.
After careful consideration, we decided to end support for Amazon FinSpace, effective October 7, 2026. Amazon FinSpace will no longer accept new customers beginning October 7, 2025. As an existing customer with an Amazon FinSpace environment created before October 7, 2025, you can continue to use the service as normal. After October 7, 2026, you will no longer be able to use Amazon FinSpace. For more information, see Amazon FinSpace end of support.
NetworkACLEntry
The network access control list (ACL) is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. The entry is a set of numbered ingress and egress rules that determine whether a packet should be allowed in or out of a subnet associated with the ACL. We process the entries in the ACL according to the rule numbers, in ascending order.
Contents
Note
In the following list, the required parameters are described first.
- cidrBlock
-
The IPv4 network range to allow or deny, in CIDR notation. For example,
172.16.0.0/24
. We modify the specified CIDR block to its canonical form. For example, if you specify100.68.0.18/18
, we modify it to100.68.0.0/18
.Type: String
Length Constraints: Minimum length of 1. Maximum length of 18.
Pattern:
^(?:\d{1,3}\.){3}\d{1,3}(?:\/(?:3[0-2]|[12]\d|\d))$
Required: Yes
- protocol
-
The protocol number. A value of -1 means all the protocols.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 5.
Pattern:
^-1|[0-9]+$
Required: Yes
- ruleAction
-
Indicates whether to allow or deny the traffic that matches the rule.
Type: String
Valid Values:
allow | deny
Required: Yes
- ruleNumber
-
The rule number for the entry. For example 100. All the network ACL entries are processed in ascending order by rule number.
Type: Integer
Valid Range: Minimum value of 1. Maximum value of 32766.
Required: Yes
- icmpTypeCode
-
Defines the ICMP protocol that consists of the ICMP type and code.
Type: IcmpTypeCode object
Required: No
- portRange
-
The range of ports the rule applies to.
Type: PortRange object
Required: No
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: