---
title: "POST /v1/apps/{appsId}/firewall/ingressRules:batchUpdate"
method: POST
path: "/v1/apps/{appsId}/firewall/ingressRules:batchUpdate"
tags: ["apps"]
---

# POST /v1/apps/{appsId}/firewall/ingressRules:batchUpdate

`POST /v1/apps/{appsId}/firewall/ingressRules:batchUpdate`

Replaces the entire firewall ruleset in one bulk operation. This overrides and replaces the rules of an existing firewall with the new rules.If the final rule does not match traffic with the '*' wildcard IP range, then an "allow all" rule is explicitly added to the end of the list.

## Path parameters

- `appsId` string, required

## Request body

- BatchUpdateIngressRulesRequest — Request message for Firewall.BatchUpdateIngressRules.
  - `ingressRules` FirewallRule[] — A list of FirewallRules to replace the existing set.
    - `action` 'UNSPECIFIED_ACTION' | 'ALLOW' | 'DENY' — The action to take on matched requests.
    - `priority` integer
    - `sourceRange` string — IP address or range, defined using CIDR notation, of requests that this rule applies to. You can use the wildcard character "*" to match all IPs equivalent to "0/0" and "::/0" together. Examples: 192.168.1.1 or 192.168.0.0/16 or 2001:db8::/32 or 2001:0db8:0000:0042:0000:8a2e:0370:7334. Truncation will be silently performed on addresses which are not properly truncated. For example, 1.2.3.4/24 is accepted as the same address as 1.2.3.0/24. Similarly, for IPv6, 2001:db8::1/32 is accepted as the same address as 2001:db8::/32.
    - `description` string — An optional string description of this rule. This field has a maximum length of 400 characters.

## Response `200`

Successful response

---

[API](https://skmtc.dev/google/apis/appengine.md) · [All operations](https://skmtc.dev/google/apis/appengine/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/google/appengine/revisions/ee6b3d5f5200/schema)
