> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vmarea.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add a rule to a firewall

> Creates a rule and re-syncs the security group. The rule is rolled back if the upstream sync fails.



## OpenAPI

````yaml https://api.vmarea.com/api/public/v1/openapi.json post /api/public/v1/firewalls/{id}/rules
openapi: 3.1.0
info:
  title: VMArea Public API
  version: 1.0.0
  description: >-
    The VMArea Public API lets you provision and manage VMs, networks,
    firewalls, SSH keys, backups, and webhooks programmatically. Authenticate
    every request with an API token (`x-api-key` header) created in the
    dashboard. Tokens carry coarse scopes (e.g. `vms:write`); endpoints reject
    calls that lack the scope they require.
  contact:
    name: VMArea Support
    url: https://vmarea.com/support
servers:
  - url: https://api.vmarea.com/api/v1
    description: Production
security:
  - ApiKey: []
paths:
  /api/public/v1/firewalls/{id}/rules:
    post:
      tags:
        - Firewalls
      summary: Add a rule to a firewall
      description: >-
        Creates a rule and re-syncs the security group. The rule is rolled back
        if the upstream sync fails.
      operationId: createFirewallRule
      parameters:
        - schema:
            type: string
          in: path
          name: id
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                position:
                  type: integer
                  minimum: 0
                  maximum: 1000
                direction:
                  type: string
                  enum:
                    - IN
                    - OUT
                action:
                  type: string
                  enum:
                    - ACCEPT
                    - DROP
                    - REJECT
                  default: ACCEPT
                protocol:
                  type: string
                  enum:
                    - TCP
                    - UDP
                    - ICMP
                    - ESP
                    - GRE
                    - ANY
                  default: TCP
                port:
                  type: string
                  maxLength: 64
                  nullable: true
                sourceIps:
                  type: array
                  items:
                    type: string
                    maxLength: 64
                  maxItems: 50
                  default: []
                destIps:
                  type: array
                  items:
                    type: string
                    maxLength: 64
                  maxItems: 50
                  default: []
                description:
                  type: string
                  maxLength: 255
                  nullable: true
              required:
                - position
                - direction
              additionalProperties: false
      responses:
        '201':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                      firewallId:
                        type: string
                      position:
                        type: integer
                      direction:
                        type: string
                        enum:
                          - IN
                          - OUT
                      action:
                        type: string
                        enum:
                          - ACCEPT
                          - DROP
                          - REJECT
                      protocol:
                        type: string
                        enum:
                          - TCP
                          - UDP
                          - ICMP
                          - ESP
                          - GRE
                          - ANY
                      port:
                        type: string
                        nullable: true
                      sourceIps:
                        type: array
                        items:
                          type: string
                      destIps:
                        type: array
                        items:
                          type: string
                      description:
                        type: string
                        nullable: true
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                    required:
                      - id
                      - firewallId
                      - position
                      - direction
                      - action
                      - protocol
                      - port
                      - sourceIps
                      - destIps
                      - description
                      - createdAt
                      - updatedAt
                    additionalProperties: false
                required:
                  - success
                  - data
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  error:
                    type: string
                required:
                  - success
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  error:
                    type: string
                required:
                  - success
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  error:
                    type: string
                required:
                  - success
                  - error
                additionalProperties: false
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  error:
                    type: string
                required:
                  - success
                  - error
                additionalProperties: false
      security:
        - ApiKey: []
components:
  securitySchemes:
    ApiKey:
      type: apiKey
      name: x-api-key
      in: header
      description: >-
        Long-lived API token created at
        https://vmarea.com/dashboard/settings/api-keys. Tokens are
        scope-restricted; this spec lists the scope each endpoint requires.

````