Skip to content

/AWS1/IF_EC2=>MODIFYCLIENTVPNENDPTAUTHPLY()

About ModifyClientVpnEndpointAuthorizationPolicy

Creates or updates the authorization policy for a Client VPN endpoint. A Client VPN endpoint can have one authorization policy. If a policy already exists for the endpoint, the values that you specify replace the corresponding values in the existing policy, and values that you do not specify remain unchanged.

Method Signature

METHODS /AWS1/IF_EC2~MODIFYCLIENTVPNENDPTAUTHPLY
  IMPORTING
    !IV_CLIENTVPNENDPOINTID TYPE /AWS1/EC2CLIENTVPNENDPOINTID OPTIONAL
    !IV_POLICYDOCUMENT TYPE /AWS1/EC2STRING OPTIONAL
    !IV_DESCRIPTION TYPE /AWS1/EC2STRING OPTIONAL
    !IV_SHADOWMODE TYPE /AWS1/EC2CLIVPNAUTHPLYSHDWMODE OPTIONAL
    !IV_CLIENTTOKEN TYPE /AWS1/EC2STRING OPTIONAL
    !IV_DRYRUN TYPE /AWS1/EC2BOOLEAN OPTIONAL
  RETURNING
    VALUE(OO_OUTPUT) TYPE REF TO /aws1/cl_ec2modclivpnendptau01
  RAISING
    /AWS1/CX_EC2CLIENTEXC
    /AWS1/CX_EC2SERVEREXC
    /AWS1/CX_RT_TECHNICAL_GENERIC
    /AWS1/CX_RT_SERVICE_GENERIC.

IMPORTING

Required arguments:

iv_clientvpnendpointid TYPE /AWS1/EC2CLIENTVPNENDPOINTID /AWS1/EC2CLIENTVPNENDPOINTID

The ID of the Client VPN endpoint.

Optional arguments:

iv_policydocument TYPE /AWS1/EC2STRING /AWS1/EC2STRING

The authorization policy document, written in the Cedar policy language. This parameter is required when you create the authorization policy for a Client VPN endpoint that does not already have one.

iv_description TYPE /AWS1/EC2STRING /AWS1/EC2STRING

A brief description of the authorization policy.

iv_shadowmode TYPE /AWS1/EC2CLIVPNAUTHPLYSHDWMODE /AWS1/EC2CLIVPNAUTHPLYSHDWMODE

Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:

  • enabled - The authorization policy is evaluated and the results are logged, but access is not enforced.

  • disabled - The authorization policy is enforced.

The default value is disabled.

iv_clienttoken TYPE /AWS1/EC2STRING /AWS1/EC2STRING

Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensuring idempotency.

iv_dryrun TYPE /AWS1/EC2BOOLEAN /AWS1/EC2BOOLEAN

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

RETURNING

oo_output TYPE REF TO /aws1/cl_ec2modclivpnendptau01 /AWS1/CL_EC2MODCLIVPNENDPTAU01

Examples

Syntax Example

This is an example of the syntax for calling the method. It includes every possible argument and initializes every possible value. The data provided is not necessarily semantically accurate (for example the value "string" may be provided for something that is intended to be an instance ID, or in some cases two arguments may be mutually exclusive). The syntax shows the ABAP syntax for creating the various data structures.

DATA(lo_result) = lo_client->modifyclientvpnendptauthply(
  iv_clienttoken = |string|
  iv_clientvpnendpointid = |string|
  iv_description = |string|
  iv_dryrun = ABAP_TRUE
  iv_policydocument = |string|
  iv_shadowmode = |string|
).

This is an example of reading all possible response values

lo_result = lo_result.
IF lo_result IS NOT INITIAL.
  lv_clientvpnauthorizationp = lo_result->get_status( ).
ENDIF.