<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting a &amp;quot;Forbidden&amp;quot; error message (HTTP status code 403) in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1674#M15</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;expert# api status&lt;/P&gt;&lt;P&gt;API Settings:&lt;BR /&gt;---------------------&lt;BR /&gt;Accessibility: Allow from 127.0.0.1&lt;BR /&gt;Automatic Start: Enabled&lt;/P&gt;&lt;P&gt;Processes:&lt;/P&gt;&lt;P&gt;Name State PID More Information&lt;BR /&gt;-------------------------------------------------&lt;BR /&gt;API Started 25846&lt;BR /&gt;CPM Started 22711 Check Point Security Management Server is running and ready&lt;BR /&gt;FWM Started 26196&lt;/P&gt;&lt;P&gt;Port Details:&lt;BR /&gt;-------------------&lt;BR /&gt;JETTY Internal Port: 50276&lt;BR /&gt;APACHE Gaia Port: 443&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;Overall API Status: Started&lt;BR /&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;Test SUCCESSFUL. The server is up and ready to receive connections&lt;/P&gt;&lt;P&gt;Notes:&lt;BR /&gt;------------&lt;BR /&gt;To collect troubleshooting data, please run 'api status -s &amp;lt;comment&amp;gt;'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accessibility from localhost?? It's set as All IP addresses in the Sconsole though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Mar 2018 19:02:53 GMT</pubDate>
    <dc:creator>venkata_marutur</dc:creator>
    <dc:date>2018-03-06T19:02:53Z</dc:date>
    <item>
      <title>Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1667#M8</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #000000; font-family: 'Times New Roman';"&gt;&lt;SPAN&gt;In some scenarios browsing to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;management-server&amp;gt;/web_api/ may lead to seeing this error message:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman';"&gt;&lt;/P&gt;&lt;H1 dir="ltr" style="color: #000000; font-family: 'Times New Roman'; padding-left: 30px;"&gt;Forbidden&lt;/H1&gt;&lt;P dir="ltr" style="color: #000000; font-family: 'Times New Roman'; font-size: medium; padding-left: 30px;"&gt;You don't have permission to access /web_api/login on this server.&lt;/P&gt;&lt;P dir="ltr" style="color: #000000; font-family: 'Times New Roman'; font-size: medium; padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;STRONG&gt;What does it mean?&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;It means that the API server is not configured to accept requests from the machine running your browser.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;For security reasons, the default settings for the API server allows him to accept requests only from the management server itself and not from any other IP address.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;If you want your management server to accept API requests from other machines, please follow this procedure:&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Open SmartConsole and log into your management server. If you have a multi-domain environment, log into the MDS domain.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Click on the "Manage &amp;amp; Settings" button on the left.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Select "Blades"&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Look for the "Management API" section and click on "Advanced Settings".&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;Now you can choose between three options:&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;1) Accept API calls from the management server only (the default setting)&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;2) All IP addresses that can be used for GUI clients.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; This option would allow the API server to accept requests only from IP addresses that can be used to connect with the management server using SmartConsole.&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;3) All IP addresses&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;Once you make you selection:&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Click the publish button&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; font-size: medium;"&gt;* Use SSH to log into the management server in "expert mode" and type "api restart".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2016 12:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1667#M8</guid>
      <dc:creator>Uri_Bialik</dc:creator>
      <dc:date>2016-01-12T12:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1668#M9</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any means to change the Management API settings using an initialization script when the management instance is created? (like this:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104080" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104080"&gt;Support, Support Requests, Training, Documentation, and Knowledge base for Check Point products and services&lt;/A&gt;) What I want to do is automate the build of the checkpoint management instance so that once it is created, I can use the web api to configure it. If I have to manually go into the smart console to set the management api blade to allow the api calls from our automation server that would defeat the purpose of automating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 15:59:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1668#M9</guid>
      <dc:creator>James_Tidwell</dc:creator>
      <dc:date>2017-08-18T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1669#M10</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's a CLI for that &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE class="" style="color: #191919; background: #efefef; border: 0px none; margin: 0px 0px 10px; padding: 9.5px;"&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[Expert@eightyten:0]# &lt;STRONG&gt;mgmt_cli -r true set api-settings accepted-api-calls-from "All IP addresses" --domain 'System Data'&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;---------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Time: [10:06:06] 18/8/2017&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;---------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;"Publish operation"&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;succeeded&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;(100%)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[Expert@eightyten:0]# &lt;STRONG&gt;api restart&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;2017-Aug-18 10:06:10 - Stopping API...&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;2017-Aug-18 10:06:13 - API stopped successfully.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;2017-Aug-18 10:06:13 - Starting API...&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;. . . . . . . . . . . . . . . . . . &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;2017-Aug-18 10:07:32 - API started successfully.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[Expert@eightyten:0]# &lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;It'd be cool if you could specify that as part of the First-Time Wizard, of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-api-settings~v1.1" title="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-api-settings~v1.1"&gt;Check Point - Management API reference&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 16:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1669#M10</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-18T16:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1670#M11</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get this error when I try to use that command:&amp;nbsp;MGMT9000 code: "err_inappropriate_domain_type"&lt;BR /&gt;message: "This command can work only on domains of type MDS. Cannot execute it in the current domain (current domain type is Domain)."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 21:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1670#M11</guid>
      <dc:creator>James_Tidwell</dc:creator>
      <dc:date>2017-08-18T21:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1671#M12</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I got a similar message when I&amp;nbsp;&lt;EM&gt;didn't&lt;/EM&gt; specify the --domain parameter.&lt;/P&gt;&lt;P&gt;The example is copy/paste from the docs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Aug 2017 21:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1671#M12</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-18T21:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1672#M13</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did make the change to allow API calls from all IP addresses and did API restart as well. Same error still exists.&lt;/P&gt;&lt;P&gt;I also did reset the password for the username, made sure that the user is added to admin role on the webUI of the smartcenter as well.&lt;/P&gt;&lt;P&gt;#mgmt_cli login with same username and passwords is working on the smartcenter though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still no luck!&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 18:45:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1672#M13</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T18:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1673#M14</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There may be several reasons for this error code.&lt;/P&gt;&lt;P&gt;Please run "api status" command on your management server and paste the response here for analysis.&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 18:59:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1673#M14</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T18:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1674#M15</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;expert# api status&lt;/P&gt;&lt;P&gt;API Settings:&lt;BR /&gt;---------------------&lt;BR /&gt;Accessibility: Allow from 127.0.0.1&lt;BR /&gt;Automatic Start: Enabled&lt;/P&gt;&lt;P&gt;Processes:&lt;/P&gt;&lt;P&gt;Name State PID More Information&lt;BR /&gt;-------------------------------------------------&lt;BR /&gt;API Started 25846&lt;BR /&gt;CPM Started 22711 Check Point Security Management Server is running and ready&lt;BR /&gt;FWM Started 26196&lt;/P&gt;&lt;P&gt;Port Details:&lt;BR /&gt;-------------------&lt;BR /&gt;JETTY Internal Port: 50276&lt;BR /&gt;APACHE Gaia Port: 443&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;Overall API Status: Started&lt;BR /&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;Test SUCCESSFUL. The server is up and ready to receive connections&lt;/P&gt;&lt;P&gt;Notes:&lt;BR /&gt;------------&lt;BR /&gt;To collect troubleshooting data, please run 'api status -s &amp;lt;comment&amp;gt;'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accessibility from localhost?? It's set as All IP addresses in the Sconsole though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1674#M15</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T19:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1675#M16</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please look at the "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Accessibility" property value - it indicates that you have not granted the access from all IPs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Robert.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1675#M16</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T19:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1676#M17</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;take a look at my post -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2731"&gt;https://community.checkpoint.com/docs/DOC-2731&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:12:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1676#M17</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T19:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1677#M18</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Robert&lt;/P&gt;&lt;P&gt;Thank you for the quick reply.&lt;/P&gt;&lt;P&gt;If you look at my last reply, I mentioned that I have set the API calls from "All IP Addresses" in the smart console and automatic start is also in place. Installed the Db, did api restart as well.&lt;/P&gt;&lt;P&gt;I am using super user permission profile to make sure I am not running into permission related issues, anyway I double checked the "super user" profile too and in the mgmt tab, mgmt API login is checked.&lt;/P&gt;&lt;P&gt;Also I did check the server.crt file in web/conf and its just ASCII, no CRLF line terminators.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, this is the script that I am running on the 3rd party server to test:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;curl -k -X POST -H "Content-Type: application/json" -d '{ "user":"xxxx", "password":"xxxx" }' &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.x:443/web_api/login" rel="nofollow"&gt;https://x.x.x.x:443/web_api/login&lt;/A&gt;&lt;BR /&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"&amp;gt;&lt;BR /&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;403 Forbidden&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&lt;BR /&gt;&amp;lt;h1&amp;gt;Forbidden&amp;lt;/h1&amp;gt;&lt;BR /&gt;&amp;lt;p&amp;gt;You don't have permission to access /web_api/login&lt;BR /&gt;on this server.&amp;lt;/p&amp;gt;&lt;BR /&gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other things that can cause this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1677#M18</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T19:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1678#M19</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please check again, this is from your "api status" command reply -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63460_api.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1678#M19</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T19:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1679#M20</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;I understand what you are referring to. api status on the CLI says only from local host. &lt;STRONG&gt;BUT, I did configure it as "All IP addresses" from the smart console, installed DB, restarted the api.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;So the question is why is it not reflecting in the CLI ??&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks for your patience on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1679#M20</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T19:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1680#M21</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I really do not understand what is going here.&lt;/P&gt;&lt;P&gt;Are you running on MDM environment?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1680#M21</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T19:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1681#M22</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, its a single smart center.&lt;/P&gt;&lt;P&gt;FYI,&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63461_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63462_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;expert#mgmt_cli login output:&lt;/P&gt;&lt;P&gt;uid: "4d67542e-21ab-4019-9b23-8e0df9894c2b"&lt;BR /&gt;sid: "6YRu8AnYpjjXMy-vmeWUfP43gykmTu3z0F87E45z_44"&lt;BR /&gt;&lt;SPAN&gt;url: "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://127.0.0.1:443/web_api" rel="nofollow"&gt;https://127.0.0.1:443/web_api&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;BR /&gt;session-timeout: 600&lt;BR /&gt;last-login-was-at:&lt;BR /&gt; posix: 1520359819406&lt;BR /&gt; iso-8601: "2018-03-06T06:10-1200"&lt;BR /&gt;api-server-version: "1"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agreed that it is weird. May be someone can see something different here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1681#M22</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T20:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1682#M23</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mgmt_cli login is running locally on your management server, so it doesn't need any special access.&lt;/P&gt;&lt;P&gt;your problem is when using a WEB Services from a remote server, this is why it needs an access.&lt;/P&gt;&lt;P&gt;what do you mean by "installed db"? do you mean "publish"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1682#M23</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T20:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1683#M24</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it. Installed db = Publish and Install Database.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1683#M24</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T20:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1684#M25</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've noticed that your API server version is "1".&lt;/P&gt;&lt;P&gt;Are you running R80 management (not R80.10)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1684#M25</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T20:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1685#M26</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes its R80 management server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:40:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1685#M26</guid>
      <dc:creator>venkata_marutur</dc:creator>
      <dc:date>2018-03-06T20:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Getting a "Forbidden" error message (HTTP status code 403)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1686#M27</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, try "api reconf" instead of "api restart" that you have done previously, then again "api status".&lt;/P&gt;&lt;P&gt;any changes to "Accessibility" field value?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Getting-a-quot-Forbidden-quot-error-message-HTTP-status-code-403/m-p/1686#M27</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-03-06T20:43:40Z</dc:date>
    </item>
  </channel>
</rss>

