- NAME
-
- gcloud beta network-security firewall-endpoints create - create a Firewall Plus endpoint
- SYNOPSIS
-
-
gcloud beta network-security firewall-endpoints create(FIREWALL_ENDPOINT:--organization=ORGANIZATION--zone=ZONE) [--async] [--billing-project=BILLING_PROJECT] [--block-partial-http] [--content-cloud-region=CONTENT_CLOUD_REGION] [--description=DESCRIPTION] [--enable-jumbo-frames] [--enable-wildfire] [--enable-wildfire-analysis-logging] [--labels=[KEY=VALUE,…]] [--location=LOCATION] [--max-wait=MAX_WAIT; default="60m"] [--wildfire-analysis-action=WILDFIRE_ANALYSIS_ACTION] [--wildfire-analysis-timeout=WILDFIRE_ANALYSIS_TIMEOUT] [--wildfire-lookup-action=WILDFIRE_LOOKUP_ACTION] [--wildfire-lookup-timeout=WILDFIRE_LOOKUP_TIMEOUT] [--wildfire-region=WILDFIRE_REGION] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(BETA)Create a firewall endpoint. Successful creation of an endpoint results in an endpoint in READY state. Check the progress of endpoint creation by usinggcloud network-security firewall-endpoints list.For more examples, refer to the EXAMPLES section below.
- EXAMPLES
-
To create a firewall endpoint called
my-endpoint, in zoneus-central1-aand organization ID 1234, run:gcloud beta network-security firewall-endpoints create my-endpoint --zone=us-central1-a --organization=1234 - POSITIONAL ARGUMENTS
-
-
Firewall endpoint resource - Firewall Plus. The arguments in this group can be
used to specify the attributes of this resource. (NOTE) Some attributes are not
given arguments in this group but can be set in other ways.
To set the
projectattribute:-
provide the argument
FIREWALL_ENDPOINTon the command line with a fully specified name; -
set the property
core/project. This resource can be one of the following types: [networksecurity.organizations.locations.firewallEndpoints, networksecurity.projects.locations.firewallEndpoints].
This must be specified.
FIREWALL_ENDPOINT-
ID of the firewall endpoint or fully qualified identifier for the firewall
endpoint.
To set the
endpoint-nameattribute:-
provide the argument
FIREWALL_ENDPOINTon the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--organization=ORGANIZATION-
Organization ID of the firewall endpoint.
To set the
organizationattribute:-
provide the argument
FIREWALL_ENDPOINTon the command line with a fully specified name; -
provide the argument
--organizationon the command line. Must be specified for resource of type [networksecurity.organizations.locations.firewallEndpoints].
-
provide the argument
--zone=ZONE-
Zone of the firewall endpoint.
To set the
zoneattribute:-
provide the argument
FIREWALL_ENDPOINTon the command line with a fully specified name; -
provide the argument
--zoneon the command line; -
provide the argument
--locationon the command line.
-
provide the argument
-
provide the argument
-
Firewall endpoint resource - Firewall Plus. The arguments in this group can be
used to specify the attributes of this resource. (NOTE) Some attributes are not
given arguments in this group but can be set in other ways.
- FLAGS
-
--async-
Return immediately, without waiting for the operation in progress to complete.
The default is
True. Enabled by default, use--no-asyncto disable. --billing-project=BILLING_PROJECT-
The Google Cloud project ID to use for API enablement check, quota, and endpoint
uptime billing. Overrides the default
billing/quota_projectproperty value for this command invocation. --block-partial-http-
Block HTTP partial responses. Defaults to false. Use
--block-partial-httpto enable. To disable, use--no-block-partial-http. --content-cloud-region=CONTENT_CLOUD_REGION- The content cloud region the endpoint will use. Defaults to the nearest available region.
--description=DESCRIPTION- Description of the endpoint
--enable-jumbo-frames- Enable jumbo frames for the firewall endpoint. To disable jumbo frames, use --no-enable-jumbo-frames.
--enable-wildfire- Enable WildFire functionality on the endpoint. Use --enable-wildfire to enable. To disable, use --no-enable-wildfire.
--enable-wildfire-analysis-logging-
Enable WildFire inline cloud analysis submission timeout logging. This is
enabled by default. Use
--no-enable-wildfire-analysis-loggingto disable. --labels=[KEY=VALUE,…]-
List of label KEY=VALUE pairs to add.
Keys must start with a lowercase character and contain only hyphens (
-), underscores (_), lowercase characters, and numbers. Values must contain only hyphens (-), underscores (_), lowercase characters, and numbers. --location=LOCATION- Location of the endpoint
--max-wait=MAX_WAIT; default="60m"- Time to synchronously wait for the operation to complete, after which the operation continues asynchronously. Ignored if --no-async isn't specified. See $ gcloud topic datetimes for information on time formats.
--wildfire-analysis-action=WILDFIRE_ANALYSIS_ACTION-
The action to take on WildFire inline cloud analysis timeout.
WILDFIRE_ANALYSIS_ACTIONmust be one of:ALLOW,DENY. --wildfire-analysis-timeout=WILDFIRE_ANALYSIS_TIMEOUT- The timeout (in milliseconds) on a file being held while WildFire inline cloud analysis is performed.
--wildfire-lookup-action=WILDFIRE_LOOKUP_ACTION-
The action to take on WildFire real time signature lookup timeout.
WILDFIRE_LOOKUP_ACTIONmust be one of:ALLOW,DENY. --wildfire-lookup-timeout=WILDFIRE_LOOKUP_TIMEOUT- The timeout (in milliseconds) to hold a file while the WildFire real time signature cloud performs a signature lookup.
--wildfire-region=WILDFIRE_REGION- The region WildFire submissions from this endpoint will be sent to for analysis by WildFire. Defaults to the nearest available region.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - NOTES
-
This command is currently in beta and might change without notice. These
variants are also available:
gcloud network-security firewall-endpoints creategcloud alpha network-security firewall-endpoints create
gcloud beta network-security firewall-endpoints create
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-06-16 UTC.