<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Zones in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168371#M30455</link>
    <description>&lt;P&gt;Hi Hari,&lt;/P&gt;
&lt;P&gt;Not sure if below might be helpful, but I will also check in lab and see what I get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/?#cli/show-security-zone~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/?#cli/show-security-zone~v1.9%20&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 14:38:08 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-19T14:38:08Z</dc:date>
    <item>
      <title>Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168370#M30454</link>
      <description>&lt;P&gt;Hi Checkmates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Is there a way to view the security zones and their associated interfaces using CLI. I can see it in the smart console from the gateway properties. However it is time consuming for my work. I'm in a process of consolidating the Security zone information, associated interfaces and the routing information . I have close to 100 network interfaces configured in multiple security gateways in the VSX cluster and going into every single gateway property to get this information is time consuming and prone to human errors. I say its prone to human error because I have to copy that information in to an excel sheet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if there is way to fetch this information via CLI or any effective methods for both VSX and Checkpoint appliances.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 18:33:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168370#M30454</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-19T18:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168371#M30455</link>
      <description>&lt;P&gt;Hi Hari,&lt;/P&gt;
&lt;P&gt;Not sure if below might be helpful, but I will also check in lab and see what I get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/?#cli/show-security-zone~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/?#cli/show-security-zone~v1.9%20&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 14:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168371#M30455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T14:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168372#M30456</link>
      <description>&lt;P&gt;Does below help?&lt;/P&gt;
&lt;P&gt;By the way, password is smart console password, not ssh.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@QUANTUM-MANAGEMENT:0]# mgmt_cli show security-zones&lt;BR /&gt;Username: admin&lt;BR /&gt;Password:&lt;BR /&gt;objects:&lt;BR /&gt;- uid: "8c4041ea-ff14-4e4b-a9d9-4183d18c790a"&lt;BR /&gt;name: "DMZZone"&lt;BR /&gt;type: "security-zone"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "a0bbbc99-adef-4ef8-bb6d-defdefdefdef"&lt;BR /&gt;name: "Check Point Data"&lt;BR /&gt;domain-type: "data domain"&lt;BR /&gt;icon: "NetworkObjects/zone"&lt;BR /&gt;color: "black"&lt;BR /&gt;- uid: "237a4cbc-7fb6-4d50-872a-4904468271c4"&lt;BR /&gt;name: "ExternalZone"&lt;BR /&gt;type: "security-zone"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "a0bbbc99-adef-4ef8-bb6d-defdefdefdef"&lt;BR /&gt;name: "Check Point Data"&lt;BR /&gt;domain-type: "data domain"&lt;BR /&gt;icon: "NetworkObjects/zone"&lt;BR /&gt;color: "black"&lt;BR /&gt;- uid: "e8131db2-8388-42a5-924a-82de32db20f7"&lt;BR /&gt;name: "InternalZone"&lt;BR /&gt;type: "security-zone"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "a0bbbc99-adef-4ef8-bb6d-defdefdefdef"&lt;BR /&gt;name: "Check Point Data"&lt;BR /&gt;domain-type: "data domain"&lt;BR /&gt;icon: "NetworkObjects/zone"&lt;BR /&gt;color: "black"&lt;BR /&gt;- uid: "57de3848-3675-48ed-b045-41378f4babb3"&lt;BR /&gt;name: "WirelessZone"&lt;BR /&gt;type: "security-zone"&lt;BR /&gt;domain:&lt;BR /&gt;uid: "a0bbbc99-adef-4ef8-bb6d-defdefdefdef"&lt;BR /&gt;name: "Check Point Data"&lt;BR /&gt;domain-type: "data domain"&lt;BR /&gt;icon: "NetworkObjects/zone"&lt;BR /&gt;color: "black"&lt;BR /&gt;from: 1&lt;BR /&gt;to: 4&lt;BR /&gt;total: 4&lt;/P&gt;
&lt;P&gt;[Expert@QUANTUM-MANAGEMENT:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 14:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168372#M30456</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T14:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168373#M30457</link>
      <description>&lt;P&gt;Thanks for the reply. I have tried this already. We don't get the associated interface name from this output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 14:50:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168373#M30457</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-19T14:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168375#M30458</link>
      <description>&lt;P&gt;Would you mind send the output? Blur out any sensitive info please.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 15:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168375#M30458</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T15:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168379#M30459</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When run the 'show security-zones' command in Smart console CLI, I get exactly the same output format as you get, except for different values. I would like to see the association between the security zone and the interface. I'm not sure, but I guess the management API commands cannot help us here. I'm pretty sure that there would be a checkpoint database with this information and would like to get it from there.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 15:24:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168379#M30459</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-19T15:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168380#M30460</link>
      <description>&lt;P&gt;K, I see what you mean. Let me look into it and see if I can get it. So you need correct interfaces to show as associated with the zones displayed...got it. Will update you how far I get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 15:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168380#M30460</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T15:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168395#M30461</link>
      <description>&lt;P&gt;The management API should be able to help for the non-VSX boxes. Log in to a CMA, 'show security-zones' to get the zone objects, then 'show simple-gateways' and 'show simple-clusters'. Each firewall object in the result should have an array of interfaces, which should each have a security-zone boolean and optionally a &lt;SPAN&gt;security-zone-settings object (if security-zone is true). Inside the&amp;nbsp;security-zone-settings, there's auto-calculated and specific-zone.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm not sure about VSs, as I haven't explored that area of the API yet.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 16:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168395#M30461</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-19T16:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168425#M30469</link>
      <description>&lt;P&gt;There are no official APIs for anything VS related (management or gateway).&lt;BR /&gt;I know we plan to address this in the future.&lt;/P&gt;
&lt;P&gt;Having said that, you might be able to do some scripting work to extract the various details.&lt;BR /&gt;This will involve use of the generic-object API and running db_tool from the gateway to get the UUID of the relevant objects as I'm not aware of a way to get them otherwise.&lt;BR /&gt;Since I don't have VSX set up anywhere, I hope someone can give this a try and let me know if it works or not.&lt;BR /&gt;Even without that, I'm sure it'll be useful for regular Security Gateway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;First, use something like the following to list all the objects involved in the policy from the gateway.&lt;BR /&gt;Note the paths will need to be modified for your version and to the specific "state" directory for the given VS.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;db_tool -p /opt/CPsuite-R81.20/fw1/state/local/FW1 get_rules |grep UUID | awk '{split($0,a,":"); print a[2]}' | uniq | awk ' { cmd="db_tool -p /opt/CPsuite-R81.20/fw1/state/local/FW1 get_object -u "$1;system(cmd)}'&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;What you're looking for is the UUID of the VS object, which will only show if the VS is &lt;EM&gt;&lt;STRONG&gt;directly&lt;/STRONG&gt;&lt;/EM&gt; used in the policy.&lt;BR /&gt;Once you have all the UUIDs of all the VS objects, you can get the interface names and zone information with something like this from the management server (note this is for a specific UUID):&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;mgmt_cli -r true --format json show generic-object uid 8414a95f-8f3d-5442-9944-9877f964d08e | jq -r '.interfaces[] | [.officialname, .securityZone ] | @csv'&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This returns the information nicely in CSV format, with one small exception (the Zone is listed as a UUID)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;"eth0","237a4cbc-7fb6-4d50-872a-4904468271c4"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"eth1","e8131db2-8388-42a5-924a-82de32db20f7"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Fortunately, it's easy to get the UUIDs for the Security Zones like so:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt; mgmt_cli -r true --format json show security-zones | jq -r '.objects[] | [.name, .uid] | @csv'&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Which translates (in my case) to:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;"DMZZone","8c4041ea-ff14-4e4b-a9d9-4183d18c790a"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"ExternalZone","237a4cbc-7fb6-4d50-872a-4904468271c4"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"InternalZone","e8131db2-8388-42a5-924a-82de32db20f7"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;"WirelessZone","57de3848-3675-48ed-b045-41378f4babb3"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Which means we can conclude that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;eth0 is a member of External Zone&lt;/LI&gt;
&lt;LI&gt;eth1 is a member of Internal Zone&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Again, whether any of this will work with VSX objects is a separate question.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 18:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168425#M30469</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T18:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168428#M30475</link>
      <description>&lt;P&gt;You can get the VS' UUIDs easily enough using 'show gateways-and-servers'. There are a few relevant object types:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;CpmiVsxClusterMember - VSX cluster member&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;CpmiVsxClusterNetobj - VSX cluster&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;CpmiVsClusterNetobj - VS cluster (a VS on a VSX cluster is technically a cluster of VSs, but the members are automatically managed)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I don't know the types for a non-clustered VSX gateway or a non-clustered VS. I've never actually seen a non-clustered VSX deployment outside a lab.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 19:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168428#M30475</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-19T19:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168429#M30476</link>
      <description>&lt;P&gt;If that API returns information about VSX objects (including VSes), then this particular command from the management might be easier to work with:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;mgmt_cli -r true --format json show gateways-and-servers | jq -r '.objects[] | [.name,&amp;nbsp; .type, .uid] | @csv'&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Again, results are returned in CSV format.&lt;BR /&gt;You'll have to filter the results to VS objects as this will return all gateway/server objects.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 19:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168429#M30476</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T19:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168459#M30479</link>
      <description>&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 07:17:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168459#M30479</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-20T07:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168462#M30480</link>
      <description>&lt;P&gt;Thanks !The mangement API commands have a different effect on the VSs. For example,&amp;nbsp;&lt;SPAN&gt;'show simple-gateways' and 'show simple-clusters' didn't give me any output when I ran them in the VSX cluster. I could be wrong, but just saying that there could be a difference in way we need to execute the commands for VSs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 07:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168462#M30480</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-20T07:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168467#M30481</link>
      <description>&lt;P&gt;Thanks a lot! I believe this should work. I will try this today and will let you know. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 07:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168467#M30481</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2023-01-20T07:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168559#M30490</link>
      <description>&lt;P&gt;I knew 'show simple-gateways' and 'show simple-clusters' don't return anything VSX, but they include the zone information for interfaces on objects which they &lt;EM&gt;do&lt;/EM&gt; return. Meanwhile, 'show gateways-and-servers' includes VSX objects, and some interface information like IP address, but &lt;EM&gt;doesn't&lt;/EM&gt; include the zone information in the interfaces. The API results when dealing with firewalls are super inconsistent between calls.&lt;/P&gt;
&lt;P&gt;'show generic-object' provides the most complete information, but it also only works on one object at a time. It's also not officially stable, so result format might change between versions. Great for one-off stuff like getting this today. Not so great if you want to dump this every week for the foreseeable future.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 15:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168559#M30490</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-20T15:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168562#M30491</link>
      <description>&lt;P&gt;I would start with this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;mgmt_cli -f json -r true show gateways-and-servers limit 500 details-level full \
| jq -c '.objects[]|{type:.type,name:.name,uuid:.uid}' \
| grep -v cluster-member \
| grep -v CpmiVsxClusterNetobj \
| grep -v CpmiVsxClusterMember \
| grep -v "checkpoint-host"&lt;/LI-CODE&gt;
&lt;P&gt;Tweak the 'grep -v' lines (e.g, by adding more) if the list contains objects which aren't firewalls or VSs. Once the list is down to what you want, pipe it into 'jq ".uuid"' and you'll get UUIDs one per line. That's suitable to pipe into something like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;mgmt_cli -f json -r true show gateways-and-servers limit 500 details-level full \
| jq -c '.objects[]|{type:.type,name:.name,uuid:.uid}' \
| grep -v cluster-member \
| grep -v CpmiVsxClusterNetobj \
| grep -v CpmiVsxClusterMember \
| grep -v "checkpoint-host" \
| jq '.uuid' \
| xargs -L 1 -I % sh -c '
mgmt_cli -f json -r true show generic-object uid % \
| jq -c "{name:.name,interface:.interfaces[]|{interfaceName:.officialname,zone:.securityZone}}"'&lt;/LI-CODE&gt;
&lt;P&gt;I find security zones a fantastic way to shoot myself in the foot, so I don't use them at all. As such, I can't be sure if that last field on the last line will return the zone information you want.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 16:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168562#M30491</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-01-20T16:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Security Zones</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168596#M30500</link>
      <description>&lt;P&gt;Right, generic-object isn't formally supported, or even documented in the Management API guide.&lt;BR /&gt;Where possible, use a documented API endpoint, you can get proper support if it doesn't work, etc.&lt;/P&gt;
&lt;P&gt;Having said that, I've never actually seen an instance where generic-object returns different results in different versions.&lt;BR /&gt;Certainly this is the case for&amp;nbsp;object types that still don't have API support.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 20:07:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Zones/m-p/168596#M30500</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-20T20:07:34Z</dc:date>
    </item>
  </channel>
</rss>

