<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to add bond interface into zone using CLI or API Connect in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-add-bond-interface-into-zone-using-CLI-or-API-Connect/m-p/196283#M36626</link>
    <description>&lt;P&gt;The API does not have any support for modifying VS objects right now.&lt;/P&gt;
&lt;P&gt;For non-VSX clusters, you would use &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-simple-cluster~v1.9.1%20" target="_self"&gt;set-simple-cluster&lt;/A&gt;. You need to provide the whole cluster object including all interfaces together. Any interfaces not in your list get removed from the object. You want .interfaces' "&lt;SPAN&gt;List: Object" parameter form. You will probably want to set security-zone to true and security-zone-settings.specific-zone to the UUID of the zone you're trying to set.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For single firewalls not in a cluster, it's basically the same, but the call is &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-simple-gateway~v1.9.1%20" target="_self"&gt;set-simple-gateway&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Separately, I urge you to reconsider this. Security zones give you a lot of ways to shoot yourself in the foot really impressively. They cause the same traffic to behave differently depending on which interface it arrives at the firewall. Using them is a mistake, and adding them to a policy which doesn't use them today is a bad idea.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 13:41:10 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-10-26T13:41:10Z</dc:date>
    <item>
      <title>Need to add bond interface into zone using CLI or API Connect</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-add-bond-interface-into-zone-using-CLI-or-API-Connect/m-p/196261#M36623</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on adding the bond interfaces into zoning groups as per there environment.&lt;/P&gt;&lt;P&gt;Right now we have multiple Virtual System containing multiple bonding groups which need to be added into zoning groups.&lt;/P&gt;&lt;P&gt;Can anyone tell me if i can use API calls using python add all the bonding groups into zones which i have created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not able to find any article related to adding zone using CLI or API calls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saish&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 09:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-add-bond-interface-into-zone-using-CLI-or-API-Connect/m-p/196261#M36623</guid>
      <dc:creator>TCS-DNB</dc:creator>
      <dc:date>2023-10-26T09:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need to add bond interface into zone using CLI or API Connect</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-add-bond-interface-into-zone-using-CLI-or-API-Connect/m-p/196283#M36626</link>
      <description>&lt;P&gt;The API does not have any support for modifying VS objects right now.&lt;/P&gt;
&lt;P&gt;For non-VSX clusters, you would use &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-simple-cluster~v1.9.1%20" target="_self"&gt;set-simple-cluster&lt;/A&gt;. You need to provide the whole cluster object including all interfaces together. Any interfaces not in your list get removed from the object. You want .interfaces' "&lt;SPAN&gt;List: Object" parameter form. You will probably want to set security-zone to true and security-zone-settings.specific-zone to the UUID of the zone you're trying to set.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For single firewalls not in a cluster, it's basically the same, but the call is &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-simple-gateway~v1.9.1%20" target="_self"&gt;set-simple-gateway&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Separately, I urge you to reconsider this. Security zones give you a lot of ways to shoot yourself in the foot really impressively. They cause the same traffic to behave differently depending on which interface it arrives at the firewall. Using them is a mistake, and adding them to a policy which doesn't use them today is a bad idea.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 13:41:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-add-bond-interface-into-zone-using-CLI-or-API-Connect/m-p/196283#M36626</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-26T13:41:10Z</dc:date>
    </item>
  </channel>
</rss>

