Firewall Management
Searching and managing firewall rules and rule groups
API Scopes
Section titled “API Scopes”- Firewall Management: READ
- Firewall Management: WRITE
falcon_create_firewall_rule_group
Section titled “falcon_create_firewall_rule_group”Required scopes: Firewall Management: WRITE
Create a firewall rule group.
Provide a name, platform, and either rules or a clone_id. Returns a list containing the created rule group object.
Example prompts:
- “Create a Windows firewall rule group named ‘Prod Outbound‘“
falcon_delete_firewall_rule_groups
Section titled “falcon_delete_firewall_rule_groups”Required scopes: Firewall Management: WRITE
Delete firewall rule groups by ID.
Permanently removes the specified rule groups and all rules within them. Returns an empty list on success.
Example prompts:
- “Delete firewall rule group abc123”
falcon_search_firewall_policy_rules
Section titled “falcon_search_firewall_policy_rules”Required scopes: Firewall Management: READ
Search firewall rules within a specific policy container.
Use this when you need rules scoped to a particular policy. Consult
falcon://firewall/rules/fql-guide before constructing filter expressions.
Returns full rule details for the specified policy.
Responses include pagination.total (the total number of records matching the filter, or null when the API does not report a count) — use it to answer “how many” questions.
Example prompts:
- “Show me all rules in firewall policy abc123”
falcon_search_firewall_rule_groups
Section titled “falcon_search_firewall_rule_groups”Required scopes: Firewall Management: READ
Search firewall rule groups and return full rule group details.
Use this to find rule groups by name, platform, or enabled state. Consult
falcon://firewall/rules/fql-guide before constructing filter expressions.
Returns rule group objects including their contained rules.
Responses include pagination.total (the total number of records matching the filter, or null when the API does not report a count) — use it to answer “how many” questions. For cursor-based paging, use pagination.next as the after parameter on the next call.
Example prompts:
- “Find all enabled firewall rule groups for Windows”
falcon_search_firewall_rules
Section titled “falcon_search_firewall_rules”Required scopes: Firewall Management: READ
Search firewall rules and return full rule details.
Use this to find firewall rules by name, platform, or enabled state. Consult
falcon://firewall/rules/fql-guide before constructing filter expressions.
Returns complete rule objects including conditions and actions.
Responses include pagination.total (the total number of records matching the filter, or null when the API does not report a count) — use it to answer “how many” questions. For cursor-based paging, use pagination.next as the after parameter on the next call.
Example prompts:
- “Show me all enabled Windows firewall rules”
- “Find firewall rules matching ‘outbound‘“
Resources
Section titled “Resources”falcon://firewall/rules/fql-guide: Contains the guide for thefilterparam of firewall search tools.