curl --request POST \
--url https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"protocol": "TCP",
"minDstPort": 22,
"maxDstPort": 22,
"notes": "Sector C maintenance shell",
"presetId": "ce736ad0-0ad7-4b43-95b8-1156cccdf2be"
}
'import requests
url = "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles"
payload = {
"protocol": "TCP",
"minDstPort": 22,
"maxDstPort": 22,
"notes": "Sector C maintenance shell",
"presetId": "ce736ad0-0ad7-4b43-95b8-1156cccdf2be"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
protocol: 'TCP',
minDstPort: 22,
maxDstPort: 22,
notes: 'Sector C maintenance shell',
presetId: 'ce736ad0-0ad7-4b43-95b8-1156cccdf2be'
})
};
fetch('https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'protocol' => 'TCP',
'minDstPort' => 22,
'maxDstPort' => 22,
'notes' => 'Sector C maintenance shell',
'presetId' => 'ce736ad0-0ad7-4b43-95b8-1156cccdf2be'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles"
payload := strings.NewReader("{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}"
response = http.request(request)
puts response.read_body{
"id": "a45afea6-a83e-4685-b7d5-029d0a91e81e",
"protocol": "TCP",
"minDstPort": 443,
"maxDstPort": 443,
"preset": {
"id": "19cfb2ea-daa8-4693-ad63-9d147b00b8f7",
"name": "HTTPS",
"protocol": "TCP"
},
"notes": "Black Mesa announcement system",
"createdAt": "2026-03-04T10:22:51Z",
"updatedAt": "2026-03-04T10:22:51Z"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Add a DDoS filtering rule to an IP address
Overview
Creates a filtering rule that applies immediately. Send presetId and protocol (TCP, UDP, ICMP, IPIP, GRE, ESP or AH). TCP and UDP require minDstPort; add maxDstPort for a range. notes is optional. Returns 422 if the protection service rejects the rule.
Permissions
Requires the network.update (Change networking) permission for the selected team. Resources outside that team return 404.
curl --request POST \
--url https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"protocol": "TCP",
"minDstPort": 22,
"maxDstPort": 22,
"notes": "Sector C maintenance shell",
"presetId": "ce736ad0-0ad7-4b43-95b8-1156cccdf2be"
}
'import requests
url = "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles"
payload = {
"protocol": "TCP",
"minDstPort": 22,
"maxDstPort": 22,
"notes": "Sector C maintenance shell",
"presetId": "ce736ad0-0ad7-4b43-95b8-1156cccdf2be"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
protocol: 'TCP',
minDstPort: 22,
maxDstPort: 22,
notes: 'Sector C maintenance shell',
presetId: 'ce736ad0-0ad7-4b43-95b8-1156cccdf2be'
})
};
fetch('https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'protocol' => 'TCP',
'minDstPort' => 22,
'maxDstPort' => 22,
'notes' => 'Sector C maintenance shell',
'presetId' => 'ce736ad0-0ad7-4b43-95b8-1156cccdf2be'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles"
payload := strings.NewReader("{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/servers/{server}/ddos-protection/ip/{ip}/profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"protocol\": \"TCP\",\n \"minDstPort\": 22,\n \"maxDstPort\": 22,\n \"notes\": \"Sector C maintenance shell\",\n \"presetId\": \"ce736ad0-0ad7-4b43-95b8-1156cccdf2be\"\n}"
response = http.request(request)
puts response.read_body{
"id": "a45afea6-a83e-4685-b7d5-029d0a91e81e",
"protocol": "TCP",
"minDstPort": 443,
"maxDstPort": 443,
"preset": {
"id": "19cfb2ea-daa8-4693-ad63-9d147b00b8f7",
"name": "HTTPS",
"protocol": "TCP"
},
"notes": "Black Mesa announcement system",
"createdAt": "2026-03-04T10:22:51Z",
"updatedAt": "2026-03-04T10:22:51Z"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Authorizations
Your API key, sent as a bearer token. Create one in the control panel under API Keys, give it only the permissions the integration needs, and copy it when it is created. It cannot be shown again. Each key is restricted to one owned team. The key determines the team for every request.
Path Parameters
The server UUID
"ecc6f4f1"
The ip ID.
"203.0.113.24"
Body
Send a JSON object containing the fields below. Required fields are marked in the schema.
The value of protocol.
TCP, UDP, ICMP, IPIP, GRE, ESP, AH The preset id ID.
The value of min_dst_port.
1 <= x <= 65535The value of max_dst_port.
1 <= x <= 65535Optional notes about the request.
255Response
The record, as a JSON object. There is no envelope.
One filtering rule standing on an address.
The id ID.
"a45afea6-a83e-4685-b7d5-029d0a91e81e"
The value of protocol.
"TCP"
The value of min_dst_port.
443
The value of max_dst_port.
443
The value of preset.
Show child attributes
Show child attributes
{
"id": "19cfb2ea-daa8-4693-ad63-9d147b00b8f7",
"name": "HTTPS",
"protocol": "TCP"
}
Optional notes about the request.
"Black Mesa announcement system"
The provider's own timestamps, in the provider's own format. Kept as strings and parsed where they are rendered: the provider does not promise anything this side could safely read as a date.
"2026-03-04T10:22:51Z"
The date and time for updated at, in UTC.
"2026-03-04T10:22:51Z"