Is there any way to use the nebula OpenAPI to query info on USG60AX?
Freshman Member
I get a 404 error when tring to get resource-load, NAT rules and iterfaces and settings. Also there doesnt seem to be an option to get the WAN address of the device.
There is very little information about these SCR type devices and at this time i only have an SCR to develop for, but point is to be able to monitor WWAN, GW and SCR device as minimum capability. I have cloud-online status and VPN count working. Name of org,site and device are also in good order.
I hope this is possible for SCR without breaking the code which should also work for USG Flex and possibly USG Flex H
Comments
-
Hi @Atmosphere,
Welcome to the Zyxel Community!
Thank you for sharing your use case. We've moved this post to the Nebula Ideas section for better tracking, so it can be part of our evaluation process.
To help us better understand your needs, could you list the specific APIs you would like to have available for your USG LITE 60AX? The more details you can provide, the better we can evaluate the request.
Zyxel Tina
1 -
Hi, thanks for your time!.
And ofcourse the anwser is just about everything as for monitoring. But in the short term as i bought a pro license to test and try the requirements are a bit less ;)
Most important for is me (and my project) is the nebula online status, Wan IP with which it is connected to nebula, And resource usages as well as wan traffic (prefered would in both directions seperate but a total will give a good indication.) It show VPN count as 0 which is good (as it doesnt result in a 404 error). Goal is to have an option to increase monitoring resolution and offer a actual dashboard to our service desk (as well as myself btw) and allow me (the user) to perform some basic tests to check for connectivity issues beyond the router.
As i got allowed to add a api key of a more "populated" account i now have also access to a USG, USG-H, WWAN, AP and SW. But i was rather suprised to notice that the USG and USG-H are reporting type GW and GWH. AP en SW online-works, but query system-usage doesnt return CPU or mem load ( which would be nice for switches for instance)
I was reading the API documentation and is very well formatted but, it would be amazing if there was a reference of supported API-calls per device type. I see a lot of 404 coming back while i do see those option in th OpenAPI docs.
And well now having the oppertunity, i love that i should be to create rules and more, but that made me wonder if it is posibble to create a nebula account which can generate an API key, but everything else should be only read-only for that account.
Also a API-endpoint, combined with login on org-basis to allow cycling the API-keys of sites in that ORG.
I also did notice i hace a API key for one site, but all other sites get reported back (but that might be because of the MSP enablement)
Also i noticed that the Online status of the USG's goes to UNKNOWN, but is showing actual CPU and memory usage.
[edit: there is an api, so added '-endpoint' :) ]0 -
Ok, just build a OpenAPI.json explorer,..
- really missing PPPoE- and vlan-interfaces (or ID) on USG(H) and SCR.
- would be so nice if system status would also return NCC-connected status.
Wanted to be sure, as a lot of interfaces return no IP, and traced it to missing VLAN-IF's and PPPoE is often the SUB-IF that has a wan/remote-link.
also typo in the OpenAPI.json:
around line 9089 → "cleints": { "anyOf": [ {0 -
Without changing a single line of code today i was happly surprised with all devices suddenly showing PPPoE adapters.. that is awesome. I can now back off hammering the API side to check a device more closely based on the WAN IP from nebula! I dont know if i had 3 days of buggy queries .. but the code was sane, as are the result right!! So i gues: thank so much, already
0 -
Hi @Atmosphere
Thanks for your input. I summary some specific part in below:
Security router hope to have API> We will evaluate this idea.AP SW hope to have CPU & memory usage> We will evaluate this idea. Additionally, which model of AP and switch are you using?Create an admin with read-only privilege to create an API key?> Yes, the API key generation is under my device & services page, which is not limited by organization privilege. And please note that the API key is by account, not by organization. This allows user to access all organization that she/he has access privilege by one API key. Additionally, if the organization privilege of the account/admin is not full(means read-only), he may not setAlso a API-endpoint, combined with login on org-basis to allow cycling the API-keys of sites in that ORG.> I'm not sure what your purpose and scenario are in here. One API key can check all the sites in an organization.
I also did notice i hace a API key for one site, but all other sites get reported back (but that might be because of the MSP enablement)i noticed that the Online status of the USG's goes to UNKNOWN> Is the status still unknown? If so, open support for us to check.typo in the OpenAPI.json:> Thanks for the reporting, but consider the API has been published for a while, to avoid the current users having services issue, we won't change the typo. And will take care more in the future API release.
around line 9089 → "cleints": { "anyOf": [ {
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 239 Nebula Ideas
- 6.8K Security
- 754 USG FLEX H Series
- 377 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 320 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 90 About Community
- 119 Security Highlight
Zyxel Employee