Check Point Firewall - Bulk operations in mgmt_cli

Поделиться
HTML-код
  • Опубликовано: 14 ноя 2024

Комментарии • 82

  • @yashpalsingh8649
    @yashpalsingh8649 2 года назад

    This really works. Thanks Magnus for proper explanation.

  • @rizwanrashid172
    @rizwanrashid172 4 года назад +1

    very helpful in production environment, Thanks Magnus

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      Rizwan Rashid I think this is something that can be used easy, especially when you create a new firewall for a customer.
      Quick way to get in hundreds of objects :)

    • @rizwanrashid172
      @rizwanrashid172 4 года назад +1

      agreed

  • @XCursedWarriorX
    @XCursedWarriorX 2 месяца назад

    Very very useful!! Thank you

  • @ahmadabdali914
    @ahmadabdali914 2 года назад

    What a magic
    Got a lot of help form the working in bank checkpoint firewall

  • @senol_yildirim
    @senol_yildirim 4 года назад +2

    Hello Magnus, you are awesome. Thank you so much!!!

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      Thank you for watching and commenting :)
      The mgmt_cli can be really helpful ;) used it today to add 200 networks.
      Doing that manually would be horrible.

  • @taetschmeischter
    @taetschmeischter 3 года назад +1

    hey Magnus,
    just some thoughts:
    try touch servers100.csv instead of cat servers100.csv and quit. you even can just use vi servers100.csv it will be created upon :wq
    have you tried mgmt_cli login user "yourusername" password "yourpassword" > s.txt
    and then on all commands you can append -s s.txt and for the time of timeout you can do commands without always provide username and password.
    best regards

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад +1

      Hehe, great tips!
      am not good at this stuff thankfully I do have devops engineers to help me with automation.
      Next time maybe I should ask one of them to help me make a more advance video in regards to the api :)

  • @bng747
    @bng747 3 года назад +1

    Hello Magnus. Maybe next time - try to run mgmt_cli with " -r true " e.g. mgmt_cli -r true show-hosts --format json

  • @CreaTeach98
    @CreaTeach98 2 года назад

    could you please make one video for custom intelligence feeds checkpoint

  • @hassehaglund
    @hassehaglund 4 года назад

    U saved a couple of hours for me

  • @georgemilev3244
    @georgemilev3244 3 года назад

    Another great video... really enjoying the course. Please, do not stop the good content!!

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад +1

      Thank you for watching and commenting!
      I do appriciate the feedback, more content is on the way :)
      Hope you guys like what is planned,
      Honestly am wondering if this serie did help anyone pass an exam yet.
      When i did study for my Cisco stuff i did use CBT nuggets with Jeremy Chara and that was a huge reason why i manage to take both CCNA, CCNP.

    • @georgemilev3244
      @georgemilev3244 3 года назад

      @@MagnusHolmberg-NetSec i am planning to take the CCSA in the next month, or two. So far i am using your channel as my main source of information for both passing the CCSA exam and learning more about the Firewall itself. I have a strong Cisco background in RS and Sec ( 4 years Cisco TAC support), but for the past 6+ months i am dealing with CP as well and you are helping me a lot :) So, please keep on the good videos. What do you think about making a video / series for troubleshooting packet drops and etc on the the Firewall? Also, a list of useful commands like - "cphaprob state", "fw tab", "fw up execute" and etc? I think this will will be very useful :)
      As i told you i bought a course from Udemy, because i was not able to find any other good resourses. The course is made by a person who was CP TAC and he shares some good info - admit, but i learned a lot of new stuff from your course as well.
      Are you planning to add new videos for the CCSA course, or what is present is enough to pass it?
      Thank you!
      George

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад +1

      ​@George Milev thats awesome to hear!
      Best of luck.
      Yes i will be about 4-5 more CCSA videos to cover more of the exam. (keep in mind i havn´t actually written CCSA since it was R71. ) So for me its 10years ago.
      - Smartlog was intruduced within R80 and it changed how the logs are processed such as a new DB for faster logsearch.
      - Backups, we havn´t mention that topic yet and backup is an important part within any it infra.
      - Smartevent, as this is an admin certification they do expect you to be aware of all gui parts and smartevent we havn´t checked out yet. There are major changes in R80 when it comes to event/reports.
      - Site to Site vpn, this is an important part atleast the basic parts. vpn tu is something that is brought up within the exam and something that you do use within production.
      Its also important to know general IPSEC things and how it actually works to setup the tunnel.
      After those topics i do think its suffciant to pass the exam, one more thing to keep in mind is that even if you go an offical ccsa course (unlinke cisco) check point do expect you to have 6 months experiance to be able to pass the exam even if you go the 3 days course provided by check point,
      The main objective for me has been to give content based on real world and what am expecting a CCSA certified person to acutally know, so some topics within this serie is NOT part of the real exam. But is more or less mandatory in real life. (such as this specific video that we are commenting on now)
      I am not sure how many of the CLI commands are within the CCSA course, think i do need to ask check point to give me a copy of the offical course content! :D A top 10 list of CLI commands i think that we can fix a video for!
      Regards,
      Magnus

    • @georgemilev3244
      @georgemilev3244 3 года назад

      @@MagnusHolmberg-NetSec agreed with everything you said, thank you again for all the effort. Looking forward for the new videos.
      Best of luck and enjoy your holidays.
      George

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад +1

      @@georgemilev3244 Same to you, make sure to take time for yourself and your family!
      Enjoy the holidays :D

  • @kusoagaki
    @kusoagaki 3 года назад

    Would you cover in some other video SNMP configuration and troubleshooting?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад

      Just some basic one when it comes to VSX as its abit diff from normal.
      As in VSX you are able to poll the nodes or the VS itself.

  • @simmonsarkar5023
    @simmonsarkar5023 4 года назад +1

    this video saved my day. kindly show me how to add policy via API to a specific package

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад

      Information regarding the API can be found here
      sc1.checkpoint.com/documents/latest/APIs/#introduction~v1.7
      Make sure to select the correct version that you are using.

    • @simmonsarkar5023
      @simmonsarkar5023 4 года назад

      @@MagnusHolmberg-NetSec kindly make a video on it

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад

      Yes i will make a video about it, but it may take some time as i have promised to fix MDS/VSX and VPN videos before.

  • @farzanamouhamad8804
    @farzanamouhamad8804 2 года назад

    thank you very much

  • @sportsboy5935
    @sportsboy5935 2 года назад

    great demonstration. i also have tested in my lab and it works perfectly fine. As i pass through the below comments, have u created the next playlist to add hosts in the existing group?

  • @khuetran6971
    @khuetran6971 2 года назад

    thank for share. i have question? Can i add multiple domain object with same way . Thank

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  2 года назад

      By that do you mean global domain objects or just same objects within multiple domains?

  • @vasupogula8825
    @vasupogula8825 2 года назад

    What is the CLI command for adding the existing host in the existing Group @Magnus

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  2 года назад

      That would be using the set command.
      sc1.checkpoint.com/documents/latest/APIs/#cli/set-group~v1.8.1%20
      mgmt_cli set group name "New Group 1" members.add "New Host 2"

  • @nicoladepascale8801
    @nicoladepascale8801 2 года назад +1

    Is mandatory to fill all fields in the excel? May I remove, for example, "color" column from excel?

  • @quanngothanh4920
    @quanngothanh4920 2 года назад

    Tks.
    How can I export objects via cli?

  • @EagleWatch79
    @EagleWatch79 4 года назад +1

    Hi Magnus, thank you for this wonderful video.
    But I have a question:
    Can we export the .csv file directly into Management Server by using WinSCP, (say in tmp folder) and then we can execute "mgmt_cli add host --batch .csv" command from tmp folder?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      Thank you for watching and commenting.
      Yes it’s possible, you may need to specify the path (depends where u run the command from)

    • @EagleWatch79
      @EagleWatch79 4 года назад

      ​ like after log into mgmt cli, then goto # cd/tmp

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      @@EagleWatch79 yes :)

  • @lanavoloshyn866
    @lanavoloshyn866 2 года назад

    odd that the --batch flag isn't in the MGMT CLI reference. Also, is the same method for a batch of network objects?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  2 года назад

      I made the video ruclips.net/video/prbaOuQfvfk/видео.html to also include adding it in groups etc.

  • @frano5957
    @frano5957 3 года назад

    Hi Magnus, thank you for your video. How can I modify the comments of my groups, networks or interface ? May I use the SET command ? Or does it exist a MODIFY command ??

  • @timmae1-db9sn
    @timmae1-db9sn 10 месяцев назад

    I get error host already exist and it fails
    Ist it possible to say that the batch operation should not break up but over jump already existing hosts ?

  • @arnoldsalvador804
    @arnoldsalvador804 4 года назад +1

    This is very interesting. Can help to produce video for creating bulk for users and group. This is for my SSLVPN users that use local authentication to checkpoint (checkpoint password). Thank you

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      Thank you Arnold!.
      In API 1.6.1 there is possibility to add users and usergroups.
      sc1.checkpoint.com/documents/latest/APIs/index.html#cli/changelog~v1.6.1%20
      This 1.6.1 is available in R80.30 JFA217 and above or R80.40 JFA 53 and above.
      I would recommend to not use local accounts and actually use like AD or similar.
      Local accounts can be a good backup in worse case scenarios.

    • @arnoldsalvador804
      @arnoldsalvador804 4 года назад

      @@MagnusHolmberg-NetSec I think really cannot add bulk users. :(

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад +1

      Arnold Salvador you need the 1.6.1 API as I said above. It’s brand new so you will need to upgrade your mgmt station

  • @983Boba
    @983Boba 3 года назад

    As first, thank you so much for videos. There are a lot of useful things. I'm interested in APIs migration from one firewall to another (for example Palo Alto to Check Point, Fortinet to Check Point, Cisco ASA to Check Point). Is there any way to automate it, or at least to accelerate migration process? For exmple I have a configuration of Cisco ASA, is there any API which can from that configuration automatically create host, network objects for Check Point?
    Best regards

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад +1

      I think what you are looking for is check point smartmove
      supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115416&t=1619484102459
      This allow you to take an excisting rulebase and create a check point rulebase, including objects, nat etc :)

  • @AnkitSharma-lv8zd
    @AnkitSharma-lv8zd 3 года назад

    Nice thankyou sir

  • @mohamedushamabinnoor6510
    @mohamedushamabinnoor6510 3 года назад

    Is it possible to check there is any host or network objects exist for the Ip? If possible we can ignore to create duplicate object for same host or network.

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад

      i actually belive that the cli will not create duplicate objects, but i will check on it and there will be some followup videos on this one :)

  • @rodolfolavandino4029
    @rodolfolavandino4029 2 года назад

    Please, could you show us How apply access-rules?

  • @simmonsarkar5023
    @simmonsarkar5023 4 года назад +1

    waiting for your reply

  • @babashaebbalshankar1718
    @babashaebbalshankar1718 3 года назад

    How can i add mulitple obect in group (pls give full syntex)

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад

      Check this post out :)
      It include multiple ways to add members in a group, am going to make a video about it next week.
      community.checkpoint.com/t5/API-CLI-Discussion/Adding-members-to-a-group/td-p/2665

  • @joesateriani4532
    @joesateriani4532 2 года назад

    Did you try it with "Web Services" ?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  2 года назад

      If you referring to like dynamic objects or similar, there is a new function within r81.20 that can be used for this

  • @mystic_deepak
    @mystic_deepak 3 года назад

    How can we do same operation using Smartconsole cli??

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад

      sc1.checkpoint.com/documents/latest/APIs/index.html#gui-cli/add-host~v1.6%20

  • @surajrajendrapandey6917
    @surajrajendrapandey6917 3 года назад

    sir can u guide us, how to create vpn access for the customers on check point....Thanks

    • @yasushikono4328
      @yasushikono4328 3 года назад

      You mean, Site-to-Site or Cient-to-Site VPN?

  • @sanjeevprasad8775
    @sanjeevprasad8775 4 года назад

    Hi buddy it is really helpful but can you help me to add the host to an existing group

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад

      Hi, you can do something like this.
      Then the object is created the same time.
      I will make a video on it with a batch files aswell ;)
      mgmt add host name "host1" ip-address "1.1.1.1" groups.1 "MyGroup"
      mgmt add host name "host2" ip-address "2.2.2.2" groups.1 "MyGroup"

    • @simmonsarkar5023
      @simmonsarkar5023 4 года назад +1

      @@MagnusHolmberg-NetSec can we set multiple host to one group at same time ?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  4 года назад

      @@simmonsarkar5023 yes like the command in the comment above.

    • @simmonsarkar5023
      @simmonsarkar5023 4 года назад +1

      @@MagnusHolmberg-NetSec how to do with a batch file? can you show it will be very helpful

  • @cortx84
    @cortx84 2 года назад

    Hello,
    When we have to edit a group without erase what already exist, what is the better to do, Working with object or with group ?
    I'm afraid to use the "add group" command, I worry about writing over the group and erase each host in the group.
    add group name myGroup members myHost1
    add group name myGroup members myHost2
    add group name myGroup members myHost3
    add group name myGroup members myHost4
    Can we batch the CLI command "set host" like that ?
    set host name srv41 groups billing_server
    set host name srv42 groups billing_server
    set host name srv43 groups billing_server
    set host name srv44 groups billing_server
    Thank you.

  • @anasuyathammana6093
    @anasuyathammana6093 3 года назад

    Hii :) I am getting Err_login_failed, Could you please check?

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 года назад

      make sure
      - API is enable.
      - Prefix on your mgmt server is allowed under GUI clients.
      - Your account has write access.
      sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Managing-Security-through-API.htm

  • @sanjeevprasad8775
    @sanjeevprasad8775 4 года назад

    Please I am waiting for your revert