<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem adding interoperable device via web API in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29875#M1792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;Here is output from show generic-object for working interoprable device created by GUI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;objectValidationState: null&lt;BR /&gt;color: "BLACK"&lt;BR /&gt;manualEncdomain: "d87e9442-eefa-4ba6-8472-2dcba5806642"&lt;BR /&gt;vpnAllowRelay: false&lt;BR /&gt;ipPoolOverrideHide: true&lt;BR /&gt;macAddress: ""&lt;BR /&gt;type: "gateway"&lt;BR /&gt;excludeExternalInterfacesFromEncDomain: false&lt;BR /&gt;thirdPartyEncryption: true&lt;BR /&gt;gtpRateLimit: 2048&lt;BR /&gt;enforceGtpRateLimit: false&lt;BR /&gt;dnsResolverInterval: 600&lt;BR /&gt;interfaces: []&lt;BR /&gt;backupGw: false&lt;BR /&gt;additionalProducts: null&lt;BR /&gt;snmp: null&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enableMulticastAcceleration: false&lt;BR /&gt;ipPoolSecuremoteAllocationName: null&lt;BR /&gt;dag: false&lt;BR /&gt;ipPoolSecuremote: false&lt;BR /&gt;encdomain: "MANUAL"&lt;BR /&gt;addrTypeIndication: "IPV4"&lt;BR /&gt;autoTopologyCustomRecalculationTime: 10&lt;BR /&gt;osInfo: &lt;BR /&gt;&amp;nbsp; objId: "b4a4923a-b997-445e-a4bd-068af7403c4b"&lt;/P&gt;&lt;P&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; osBuildNum: 0&lt;BR /&gt;&amp;nbsp; osspminor: 0&lt;BR /&gt;&amp;nbsp; osType: 0&lt;BR /&gt;&amp;nbsp; osVersionLevel: ""&lt;BR /&gt;&amp;nbsp; osVerMajor: 0&lt;BR /&gt;&amp;nbsp; osName: "Gaia"&lt;BR /&gt;&amp;nbsp; osspmajor: 0&lt;BR /&gt;&amp;nbsp; osVerMinor: 0&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: ""&lt;BR /&gt;dataSource: "NOT_MINUS_INSTALLED"&lt;BR /&gt;natSummaryText: ""&lt;BR /&gt;ipPoolAllocPerDestination: false&lt;BR /&gt;backupGateway: null&lt;BR /&gt;rangeEncdomain: null&lt;BR /&gt;supportIpPoolNat: false&lt;BR /&gt;cpProductsInstalled: false&lt;BR /&gt;edges: []&lt;BR /&gt;securityBladesTopologyMode: "TOPOLOGY_TABLE"&lt;BR /&gt;performEncryption: true&lt;BR /&gt;ipPoolGw2gw: false&lt;BR /&gt;certificates: []&lt;BR /&gt;ipPoolPerInterface: false&lt;BR /&gt;ipPoolExhaustRetInterval: 30&lt;BR /&gt;vpnRelayIfName: ""&lt;BR /&gt;connectra: false&lt;BR /&gt;supportIkeV2: true&lt;BR /&gt;firewall: "NOT_MINUS_INSTALLED"&lt;BR /&gt;connectraSettings: null&lt;BR /&gt;autoTopologyUseCustomRecalculationTime: false&lt;BR /&gt;ipaddr: "10.10.10.2"&lt;BR /&gt;ipPoolUnusedReturnInterval: 60&lt;BR /&gt;vpn: &lt;BR /&gt;&amp;nbsp; objId: "00ace2ae-d15a-4615-b2d7-64b6850292ea"&lt;/P&gt;&lt;P&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; singleVpnIp: ""&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIf: ""&lt;BR /&gt;&amp;nbsp; clientlessVpnAskUserForCertificate: "NONE"&lt;BR /&gt;&amp;nbsp; offerNattResponder: true&lt;BR /&gt;&amp;nbsp; enableInternetRouting: false&lt;BR /&gt;&amp;nbsp; forceNatT: false&lt;BR /&gt;&amp;nbsp; vpnClientsSettingsForGateway: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "01fa7fc8-960d-4378-a238-a01e1650d4a6"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; usb1VpnClientSettings: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnClientSettings: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "d5ea091b-4fb8-4a7e-afd1-3a65466570ca"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnEnable: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnConnectivityMethod: "IPSEC"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: "vpn_clients_settings_for_gateway"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableBasicVpnSecuremote: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableVpnWithEndpointSecurity: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; fwWireLogOnlySyn: true&lt;BR /&gt;&amp;nbsp; singleVpnIpRa: ""&lt;BR /&gt;&amp;nbsp; thirdPartyEncryption: true&lt;BR /&gt;&amp;nbsp; availableVpnIpListGw: []&lt;BR /&gt;&amp;nbsp; isakmpUdpencapsulation: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "f787c070-d69e-4ebf-a143-ee49cea5860f"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb390-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpEmail: ""&lt;BR /&gt;&amp;nbsp; isakmpIpcompSupport: false&lt;BR /&gt;&amp;nbsp; accept3desForClientlessVpn: true&lt;BR /&gt;&amp;nbsp; fwz: null&lt;BR /&gt;&amp;nbsp; tunnelKeepaliveMethod: "TUNNEL_TEST"&lt;BR /&gt;&amp;nbsp; dnsIpResolution: ""&lt;BR /&gt;&amp;nbsp; useService: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp; availableVpnIpList: []&lt;BR /&gt;&amp;nbsp; isakmpDn: ""&lt;BR /&gt;&amp;nbsp; isakmpDoDnsResolve: false&lt;BR /&gt;&amp;nbsp; useCert: ""&lt;BR /&gt;&amp;nbsp; multipleIspVpn: false&lt;BR /&gt;&amp;nbsp; ipResolutionMechanismGw: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; disableNoSaLogsForUser: true&lt;BR /&gt;&amp;nbsp; replyFromSameIp: true&lt;BR /&gt;&amp;nbsp; vpnTunnelMtu: 0&lt;BR /&gt;&amp;nbsp; linkSelectionMode: "HIGHAVAILABILITY"&lt;BR /&gt;&amp;nbsp; outgoingSourceIp: "AUTOMATIC"&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCert: []&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIfGw: ""&lt;BR /&gt;&amp;nbsp; ipResolutionMechanism: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; ikeSendFrags: false&lt;BR /&gt;&amp;nbsp; applyResolvingMechanismToSr: true&lt;BR /&gt;&amp;nbsp; isakmpSubnetSupport: true&lt;BR /&gt;&amp;nbsp; isakmpAuthmethods: []&lt;BR /&gt;&amp;nbsp; enableRouting: true&lt;BR /&gt;&amp;nbsp; vpnCompLevel: 2&lt;BR /&gt;&amp;nbsp; useClientlessVpn: false&lt;BR /&gt;&amp;nbsp; dnsIpResolutionGw: ""&lt;BR /&gt;&amp;nbsp; replyToSameIp: true&lt;BR /&gt;&amp;nbsp; vpnLinkResolverNotification: "NONE"&lt;BR /&gt;&amp;nbsp; supportWireMode: false&lt;BR /&gt;&amp;nbsp; ike: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "95903133-3add-438c-92f8-1e844ff8f09c"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1RekeyingTime: 1440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpHashmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpCrlreq: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1DhGroups: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "97aeb629-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpkeymanager: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ikeEmptyUdpSocket: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingKbytes: 50000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpsharedkey: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingTime: 3600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2UseRekeyingKbytes: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpEncmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpAggressiveSupport: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; clientlessProcNum: 1&lt;BR /&gt;&amp;nbsp; useInterfaceIp: true&lt;BR /&gt;&amp;nbsp; tcpt: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "b4a4923a-b997-445e-a4bd-068af7403c4b"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cpmiInterface: "All IPs"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpndInternalBindPort: 444&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpDnsName: ""&lt;BR /&gt;&amp;nbsp; ipsecReplayCounterWindowSize: 64&lt;BR /&gt;&amp;nbsp; sslNe: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "a0201a4b-3e2f-49c5-b67a-e7251cdbe026"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; internalListeningPort: "b8f7c593-f9ee-4c55-b48a-6ce3be6760ac"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; neoEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gwCertificate: "defaultCert"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endPointNameResolution: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "f787c070-d69e-4ebf-a143-ee49cea5860f"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; downloadNameResolutionSettingsToEndPoint: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useSameSettingsAsGw: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientType: "AUTODETECT"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; name: ""&lt;BR /&gt;&amp;nbsp; ipsecDontFragment: true&lt;BR /&gt;&amp;nbsp; rerouteEncryptedPackets: true&lt;BR /&gt;&amp;nbsp; outgoingSingleIp: ""&lt;BR /&gt;&amp;nbsp; ikeFetchCrlFailOpen: false&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToOuter: true&lt;BR /&gt;&amp;nbsp; icon: "Unknown"&lt;BR /&gt;&amp;nbsp; takeTunnelGranularityFromComm: true&lt;BR /&gt;&amp;nbsp; fwWireLog: false&lt;BR /&gt;&amp;nbsp; isakmpMatchpeer: []&lt;BR /&gt;&amp;nbsp; useInterfaceIpGw: true&lt;BR /&gt;&amp;nbsp; ipsecFragmentInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCa: null&lt;BR /&gt;&amp;nbsp; dpdAllowedToInitIke: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalProtocol: "WILDCARD_IDS"&lt;BR /&gt;&amp;nbsp; ikeSupportNatT: true&lt;BR /&gt;&amp;nbsp; color: "BLACK"&lt;BR /&gt;&amp;nbsp; natdSendAllIfcs: false&lt;BR /&gt;&amp;nbsp; displayName: ""&lt;BR /&gt;&amp;nbsp; ikev2AcceptAllTs: false&lt;BR /&gt;&amp;nbsp; respondFromSameIfc: false&lt;BR /&gt;&amp;nbsp; offerNattInitator: false&lt;BR /&gt;&amp;nbsp; comments: ""&lt;BR /&gt;&amp;nbsp; sendSingleNatdSource: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalSupport: true&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; features: []&lt;BR /&gt;&amp;nbsp; systemTags: []&lt;BR /&gt;&amp;nbsp; tags: []&lt;BR /&gt;&amp;nbsp; customFields: []&lt;BR /&gt;&amp;nbsp; metaInfo: null&lt;BR /&gt;dataSourceSettings: null&lt;BR /&gt;nat: null&lt;BR /&gt;ipaddr6: ""&lt;BR /&gt;addAdtrRule: false&lt;BR /&gt;floodgate: "NOT_MINUS_INSTALLED"&lt;BR /&gt;uid: "16fdac28-af5c-4581-94a2-ee3030968bcb"&lt;/P&gt;&lt;P&gt;folder: &lt;BR /&gt;&amp;nbsp; uid: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; name: "Global Objects"&lt;BR /&gt;domain: &lt;BR /&gt;&amp;nbsp; uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; name: "SMC User"&lt;BR /&gt;meta-info: &lt;BR /&gt;&amp;nbsp; metaOwned: false&lt;BR /&gt;&amp;nbsp; lockStateResponse: null&lt;BR /&gt;&amp;nbsp; validationState: "OK"&lt;BR /&gt;&amp;nbsp; deletable: true&lt;BR /&gt;&amp;nbsp; renameable: true&lt;BR /&gt;&amp;nbsp; newObject: false&lt;BR /&gt;&amp;nbsp; lastModifytime: 1549127325577&lt;BR /&gt;&amp;nbsp; lastModifier: "mnemeth"&lt;BR /&gt;&amp;nbsp; creationTime: 1549127325577&lt;BR /&gt;&amp;nbsp; creator: "mnemeth"&lt;BR /&gt;tags: []&lt;BR /&gt;name: "test2"&lt;BR /&gt;icon: "NetworkObjects/gateway"&lt;BR /&gt;comments: ""&lt;BR /&gt;display-name: ""&lt;BR /&gt;customFields: []&lt;BR /&gt;_original_type: "CpmiGatewayPlain"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is the exact same device created by above script which is not working correctly&amp;nbsp;... I just changed this &lt;STRONG style="color: #008000; "&gt;isakmpIpcompSupport'&lt;/STRONG&gt;: &lt;SPAN style="color: #000080;"&gt;True to False because GUI object had this property False... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;objectValidationState: null&lt;BR /&gt;color: "BLACK"&lt;BR /&gt;manualEncdomain: "d87e9442-eefa-4ba6-8472-2dcba5806642"&lt;BR /&gt;vpnAllowRelay: false&lt;BR /&gt;ipPoolOverrideHide: true&lt;BR /&gt;macAddress: ""&lt;BR /&gt;type: "gateway"&lt;BR /&gt;excludeExternalInterfacesFromEncDomain: false&lt;BR /&gt;thirdPartyEncryption: true&lt;BR /&gt;gtpRateLimit: 2048&lt;BR /&gt;enforceGtpRateLimit: false&lt;BR /&gt;dnsResolverInterval: 600&lt;BR /&gt;interfaces: []&lt;BR /&gt;backupGw: false&lt;BR /&gt;additionalProducts: null&lt;/P&gt;&lt;P&gt;snmp: &lt;BR /&gt;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; sysContact: ""&lt;BR /&gt;&amp;nbsp; sysDescr: ""&lt;BR /&gt;&amp;nbsp; readCommunity: ""&lt;BR /&gt;&amp;nbsp; sysLocation: ""&lt;BR /&gt;&amp;nbsp; sysName: ""&lt;BR /&gt;&amp;nbsp; writeCommunity: ""&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;enableMulticastAcceleration: false&lt;BR /&gt;ipPoolSecuremoteAllocationName: null&lt;BR /&gt;dag: false&lt;BR /&gt;ipPoolSecuremote: false&lt;BR /&gt;encdomain: "MANUAL"&lt;BR /&gt;addrTypeIndication: "IPV4"&lt;BR /&gt;autoTopologyCustomRecalculationTime: 10&lt;BR /&gt;osInfo:&lt;/P&gt;&lt;P&gt;&amp;nbsp; objId: "431b7a78-ae8b-4e69-9b9c-0d89840f53e2"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; osBuildNum: 0&lt;BR /&gt;&amp;nbsp; osspminor: 0&lt;BR /&gt;&amp;nbsp; osType: 0&lt;BR /&gt;&amp;nbsp; osVersionLevel: ""&lt;BR /&gt;&amp;nbsp; osVerMajor: 0&lt;BR /&gt;&amp;nbsp; osName: "Gaia"&lt;BR /&gt;&amp;nbsp; osspmajor: 0&lt;BR /&gt;&amp;nbsp; osVerMinor: 0&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: ""&lt;BR /&gt;dataSource: "NOT_MINUS_INSTALLED"&lt;BR /&gt;natSummaryText: ""&lt;BR /&gt;ipPoolAllocPerDestination: false&lt;BR /&gt;backupGateway: null&lt;BR /&gt;rangeEncdomain: null&lt;BR /&gt;supportIpPoolNat: false&lt;BR /&gt;cpProductsInstalled: false&lt;BR /&gt;edges: []&lt;BR /&gt;securityBladesTopologyMode: "TOPOLOGY_TABLE"&lt;BR /&gt;performEncryption: true&lt;BR /&gt;ipPoolGw2gw: false&lt;BR /&gt;certificates: []&lt;BR /&gt;ipPoolPerInterface: false&lt;BR /&gt;ipPoolExhaustRetInterval: 30&lt;BR /&gt;vpnRelayIfName: ""&lt;BR /&gt;connectra: false&lt;BR /&gt;supportIkeV2: true&lt;BR /&gt;firewall: "NOT_MINUS_INSTALLED"&lt;BR /&gt;connectraSettings: null&lt;BR /&gt;autoTopologyUseCustomRecalculationTime: false&lt;BR /&gt;ipaddr: "10.10.10.2"&lt;BR /&gt;ipPoolUnusedReturnInterval: 60&lt;BR /&gt;vpn:&lt;/P&gt;&lt;P&gt;&amp;nbsp; objId: "06e8963e-cce6-44f5-926f-15f482109854"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; singleVpnIp: ""&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIf: ""&lt;BR /&gt;&amp;nbsp; clientlessVpnAskUserForCertificate: "NONE"&lt;BR /&gt;&amp;nbsp; offerNattResponder: true&lt;BR /&gt;&amp;nbsp; enableInternetRouting: false&lt;BR /&gt;&amp;nbsp; forceNatT: false&lt;BR /&gt;&amp;nbsp; vpnClientsSettingsForGateway:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "48c0e8f1-a320-45a2-8043-3b3ac22deeae"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; usb1VpnClientSettings: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnClientSettings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "6d30bba1-3bd4-41a6-a6ae-5d777ac929ae"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnEnable: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnConnectivityMethod: "IPSEC"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: "vpn_clients_settings_for_gateway"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableBasicVpnSecuremote: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableVpnWithEndpointSecurity: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; fwWireLogOnlySyn: true&lt;BR /&gt;&amp;nbsp; singleVpnIpRa: ""&lt;BR /&gt;&amp;nbsp; thirdPartyEncryption: true&lt;BR /&gt;&amp;nbsp; availableVpnIpListGw: []&lt;BR /&gt;&amp;nbsp; isakmpUdpencapsulation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb390-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpEmail: ""&lt;BR /&gt;&amp;nbsp; isakmpIpcompSupport: false&lt;BR /&gt;&amp;nbsp; accept3desForClientlessVpn: true&lt;BR /&gt;&amp;nbsp; fwz: null&lt;BR /&gt;&amp;nbsp; tunnelKeepaliveMethod: "TUNNEL_TEST"&lt;BR /&gt;&amp;nbsp; dnsIpResolution: ""&lt;BR /&gt;&amp;nbsp; useService: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp; availableVpnIpList: []&lt;BR /&gt;&amp;nbsp; isakmpDn: ""&lt;BR /&gt;&amp;nbsp; isakmpDoDnsResolve: false&lt;BR /&gt;&amp;nbsp; useCert: ""&lt;BR /&gt;&amp;nbsp; multipleIspVpn: false&lt;BR /&gt;&amp;nbsp; ipResolutionMechanismGw: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; disableNoSaLogsForUser: true&lt;BR /&gt;&amp;nbsp; replyFromSameIp: true&lt;BR /&gt;&amp;nbsp; vpnTunnelMtu: 0&lt;BR /&gt;&amp;nbsp; linkSelectionMode: "HIGHAVAILABILITY"&lt;BR /&gt;&amp;nbsp; outgoingSourceIp: "AUTOMATIC"&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCert: []&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIfGw: ""&lt;BR /&gt;&amp;nbsp; ipResolutionMechanism: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; ikeSendFrags: false&lt;BR /&gt;&amp;nbsp; applyResolvingMechanismToSr: true&lt;BR /&gt;&amp;nbsp; isakmpSubnetSupport: true&lt;BR /&gt;&amp;nbsp; isakmpAuthmethods: []&lt;BR /&gt;&amp;nbsp; enableRouting: true&lt;BR /&gt;&amp;nbsp; vpnCompLevel: 2&lt;BR /&gt;&amp;nbsp; useClientlessVpn: false&lt;BR /&gt;&amp;nbsp; dnsIpResolutionGw: ""&lt;BR /&gt;&amp;nbsp; replyToSameIp: true&lt;BR /&gt;&amp;nbsp; vpnLinkResolverNotification: "NONE"&lt;BR /&gt;&amp;nbsp; supportWireMode: false&lt;BR /&gt;&amp;nbsp; ike:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "d48f659f-8efd-49dd-9339-48ba59de2ad0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1RekeyingTime: 1440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpHashmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpCrlreq: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1DhGroups: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "97aeb629-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpkeymanager: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ikeEmptyUdpSocket: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingKbytes: 50000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpsharedkey: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingTime: 3600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2UseRekeyingKbytes: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpEncmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpAggressiveSupport: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; clientlessProcNum: 1&lt;BR /&gt;&amp;nbsp; useInterfaceIp: true&lt;BR /&gt;&amp;nbsp; tcpt:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "431b7a78-ae8b-4e69-9b9c-0d89840f53e2"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cpmiInterface: "All IPs"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpndInternalBindPort: 444&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpDnsName: ""&lt;BR /&gt;&amp;nbsp; ipsecReplayCounterWindowSize: 64&lt;BR /&gt;&amp;nbsp; sslNe:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "c1293112-01c6-4448-82c7-1be64593dad3"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; internalListeningPort: "b8f7c593-f9ee-4c55-b48a-6ce3be6760ac"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; neoEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gwCertificate: "defaultCert"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endPointNameResolution:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; downloadNameResolutionSettingsToEndPoint: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useSameSettingsAsGw: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientType: "AUTODETECT"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; name: ""&lt;BR /&gt;&amp;nbsp; ipsecDontFragment: true&lt;BR /&gt;&amp;nbsp; rerouteEncryptedPackets: true&lt;BR /&gt;&amp;nbsp; outgoingSingleIp: ""&lt;BR /&gt;&amp;nbsp; ikeFetchCrlFailOpen: false&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToOuter: true&lt;BR /&gt;&amp;nbsp; icon: "Unknown"&lt;BR /&gt;&amp;nbsp; takeTunnelGranularityFromComm: true&lt;BR /&gt;&amp;nbsp; fwWireLog: false&lt;BR /&gt;&amp;nbsp; isakmpMatchpeer: []&lt;BR /&gt;&amp;nbsp; useInterfaceIpGw: true&lt;BR /&gt;&amp;nbsp; ipsecFragmentInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCa: null&lt;BR /&gt;&amp;nbsp; dpdAllowedToInitIke: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalProtocol: "WILDCARD_IDS"&lt;BR /&gt;&amp;nbsp; ikeSupportNatT: true&lt;BR /&gt;&amp;nbsp; color: "BLACK"&lt;BR /&gt;&amp;nbsp; natdSendAllIfcs: false&lt;BR /&gt;&amp;nbsp; displayName: ""&lt;BR /&gt;&amp;nbsp; ikev2AcceptAllTs: false&lt;BR /&gt;&amp;nbsp; respondFromSameIfc: false&lt;BR /&gt;&amp;nbsp; offerNattInitator: false&lt;BR /&gt;&amp;nbsp; comments: ""&lt;BR /&gt;&amp;nbsp; sendSingleNatdSource: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalSupport: true&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; features: []&lt;BR /&gt;&amp;nbsp; systemTags: []&lt;BR /&gt;&amp;nbsp; tags: []&lt;BR /&gt;&amp;nbsp; customFields: []&lt;BR /&gt;&amp;nbsp; metaInfo: null&lt;BR /&gt;dataSourceSettings: null&lt;BR /&gt;nat: null&lt;BR /&gt;ipaddr6: ""&lt;BR /&gt;addAdtrRule: false&lt;BR /&gt;floodgate: "NOT_MINUS_INSTALLED"&lt;/P&gt;&lt;P&gt;uid: "054e4752-3c98-4a59-bf7e-6e7ff99fcab5"&lt;BR /&gt;folder: &lt;BR /&gt;&amp;nbsp; uid: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; name: "Global Objects"&lt;BR /&gt;domain: &lt;BR /&gt;&amp;nbsp; uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; name: "SMC User"&lt;BR /&gt;meta-info: &lt;BR /&gt;&amp;nbsp; metaOwned: false&lt;BR /&gt;&amp;nbsp; lockStateResponse: null&lt;BR /&gt;&amp;nbsp; validationState: "OK"&lt;BR /&gt;&amp;nbsp; deletable: true&lt;BR /&gt;&amp;nbsp; renameable: true&lt;BR /&gt;&amp;nbsp; newObject: false&lt;BR /&gt;&amp;nbsp; lastModifytime: 1549127013761&lt;BR /&gt;&amp;nbsp; lastModifier: "mnemeth-API"&lt;BR /&gt;&amp;nbsp; creationTime: 1549127013761&lt;BR /&gt;&amp;nbsp; creator: "mnemeth-API"&lt;BR /&gt;tags: []&lt;BR /&gt;name: "test2"&lt;BR /&gt;icon: "NetworkObjects/gateway"&lt;BR /&gt;comments: ""&lt;BR /&gt;display-name: ""&lt;BR /&gt;customFields: []&lt;BR /&gt;_original_type: "CpmiGatewayPlain"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you pass these both objects to editor and&amp;nbsp;compare it, you will find that the objects ARE ALMOST THE SAME!. What is different are obviously UIDs of components, time of creation, admin username (I am using -API for scripts) and correct object has no snmp section while script obkect has snmp section. So... what can be wrong with second object, or other question, what to change in script to be correct???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another strange thing is, when I run this command from command line from SmartConsole, the same object will be almost correct. But only almost... For first it will NOT be visible fro VPN Community, but if you assign VPN Community to the object, it will be OK and if you remove it again, after this it will be now visible from VPN&amp;nbsp;Community too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And If I create same object through dbedit with something like this (template for jinja2):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create gateway_plain {{ peerName }}&lt;BR /&gt;modify network_objects {{ peerName }} DAG false&lt;BR /&gt;modify network_objects {{ peerName }} color {{ color }}&lt;BR /&gt;modify network_objects {{ peerName }} VPN VPN&lt;BR /&gt;modify network_objects {{ peerName }} VPN:third_party_encryption true&lt;BR /&gt;modify network_objects {{ peerName }} VPN:IKE IKE&lt;BR /&gt;modify network_objects {{ peerName }} SNMP NULL&lt;BR /&gt;modify network_objects {{ peerName }} type gateway&lt;BR /&gt;modify network_objects {{ peerName }} add_adtr_rule false&lt;BR /&gt;modify network_objects {{ peerName }} ipaddr {{ peerIP }}&lt;BR /&gt;modify network_objects {{ peerName }} encdomain manual&lt;BR /&gt;modify network_objects {{ peerName }} manual_encdomain network_objects:{{ cryptoDomainGrp }}&lt;BR /&gt;update_all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will work without any issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it seems, that 4 different methods of creating the same Interoperable device (GUI, command line API, WEB API and&amp;nbsp;dbedit)&amp;nbsp;have different results... Strange,&amp;nbsp;isnt't it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael Nemeth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 02 Feb 2019 17:48:57 GMT</pubDate>
    <dc:creator>Michael_Nemeth</dc:creator>
    <dc:date>2019-02-02T17:48:57Z</dc:date>
    <item>
      <title>problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29873#M1790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys&lt;/P&gt;&lt;P&gt;I am trying to create interoperable device via python web API (I have v1.1)&lt;/P&gt;&lt;P&gt;I have this payload to put into commend 'add-generic-object'&lt;/P&gt;&lt;PRE style="background-color: #ffffff; color: #000000; font-family: 'Courier New'; font-size: 9,0pt;"&gt;object = {&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiGatewayPlain'&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'name'&lt;/SPAN&gt;: deviceName,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ipaddr'&lt;/SPAN&gt;: deviceIP,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'thirdPartyEncryption'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;True&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'osInfo'&lt;/SPAN&gt;: {&lt;BR /&gt;        &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'osName'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'Gaia'&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #008000; font-weight: bold;"&gt;    &lt;/SPAN&gt;},&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'vpn'&lt;/SPAN&gt;: {&lt;BR /&gt;        &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiVpn'&lt;/SPAN&gt;,&lt;BR /&gt;        &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'owned-object'&lt;/SPAN&gt;: {&lt;BR /&gt;            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'vpnClientsSettingsForGateway'&lt;/SPAN&gt;: {&lt;BR /&gt;                &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;:&lt;BR /&gt;                    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway'&lt;/SPAN&gt;,&lt;BR /&gt;                &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'owned-object'&lt;/SPAN&gt;: {&lt;BR /&gt;                    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'endpointVpnClientSettings'&lt;/SPAN&gt;: {&lt;BR /&gt;                        &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;:&lt;BR /&gt;                            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway'&lt;/SPAN&gt;,&lt;BR /&gt;                        &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'owned-object'&lt;/SPAN&gt;: {&lt;BR /&gt;                            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'endpointVpnEnable'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;True&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000080;"&gt;                        &lt;/SPAN&gt;}&lt;BR /&gt;                    }&lt;BR /&gt;                }&lt;BR /&gt;            },&lt;BR /&gt;            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ike'&lt;/SPAN&gt;: {&lt;BR /&gt;                &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiIke'&lt;/SPAN&gt;,&lt;BR /&gt;            },&lt;BR /&gt;            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'sslNe'&lt;/SPAN&gt;: {&lt;BR /&gt;                &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'create'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender'&lt;/SPAN&gt;,&lt;BR /&gt;                &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'owned-object'&lt;/SPAN&gt;: {&lt;BR /&gt;                    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'sslEnable'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;False&lt;/SPAN&gt;,&lt;BR /&gt;                    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'gwCertificate'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'defaultCert'&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #008000; font-weight: bold;"&gt;                &lt;/SPAN&gt;}&lt;BR /&gt;            },&lt;BR /&gt;            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'isakmpIpcompSupport'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;True&lt;/SPAN&gt;,&lt;BR /&gt;            &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'isakmpUniversalSupport'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;True&lt;/SPAN&gt;,&lt;BR /&gt;        }&lt;BR /&gt;    },&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'dataSourceSettings'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;None&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'nat'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;None&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'encdomain'&lt;/SPAN&gt;: &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ADDRESSES_BEHIND_GW'&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ignore-warnings'&lt;/SPAN&gt;: &lt;SPAN style="color: #000080;"&gt;True&lt;/SPAN&gt;,&lt;BR /&gt;    &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'color'&lt;/SPAN&gt;: color.upper()}&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After I run script, object is visible in Interoperable devices, but I cannot use is. It is NOT visible when I try it add to VPN communities and also when I try add VPN community to this object it ends with error: A blocking validation error was found: Gateway does not comply to 'Participant Gateways' of Meshed community. In order to comply the gateway needs to be VPN installed and of type Host / Gateway / Cluster / Interoperable device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object can be 'fixed' via GUI by setting IPSec VPN -&amp;gt; Traditional mode configuration -&amp;gt; Select some enc and hash&amp;nbsp; (i.e. 3des sha1) -&amp;gt; OK, But I cannot find the way set this through set-gneric-object&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this does not work:&lt;/P&gt;&lt;PRE style="background-color: #ffffff; color: #000000; font-family: 'Courier New'; font-size: 9,0pt;"&gt;{&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'uid'&lt;/SPAN&gt;: objectUID, &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'vpn' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ike' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'isakmpHashmethods'&lt;/SPAN&gt;: [&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'SHA1'&lt;/SPAN&gt;]}}}&lt;/PRE&gt;&lt;P&gt;what am I doing wrong? Via dbedit it works, but I would like to use clearer way ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 14:40:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29873#M1790</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-01T14:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29874#M1791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possible this may help you find the right way:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/11337-class-names-available-for-use-with-the-show-generic-objects-api-command" target="_blank"&gt;https://community.checkpoint.com/thread/11337-class-names-available-for-use-with-the-show-generic-objects-api-command&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29874#M1791</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29875#M1792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;Here is output from show generic-object for working interoprable device created by GUI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;objectValidationState: null&lt;BR /&gt;color: "BLACK"&lt;BR /&gt;manualEncdomain: "d87e9442-eefa-4ba6-8472-2dcba5806642"&lt;BR /&gt;vpnAllowRelay: false&lt;BR /&gt;ipPoolOverrideHide: true&lt;BR /&gt;macAddress: ""&lt;BR /&gt;type: "gateway"&lt;BR /&gt;excludeExternalInterfacesFromEncDomain: false&lt;BR /&gt;thirdPartyEncryption: true&lt;BR /&gt;gtpRateLimit: 2048&lt;BR /&gt;enforceGtpRateLimit: false&lt;BR /&gt;dnsResolverInterval: 600&lt;BR /&gt;interfaces: []&lt;BR /&gt;backupGw: false&lt;BR /&gt;additionalProducts: null&lt;BR /&gt;snmp: null&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enableMulticastAcceleration: false&lt;BR /&gt;ipPoolSecuremoteAllocationName: null&lt;BR /&gt;dag: false&lt;BR /&gt;ipPoolSecuremote: false&lt;BR /&gt;encdomain: "MANUAL"&lt;BR /&gt;addrTypeIndication: "IPV4"&lt;BR /&gt;autoTopologyCustomRecalculationTime: 10&lt;BR /&gt;osInfo: &lt;BR /&gt;&amp;nbsp; objId: "b4a4923a-b997-445e-a4bd-068af7403c4b"&lt;/P&gt;&lt;P&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; osBuildNum: 0&lt;BR /&gt;&amp;nbsp; osspminor: 0&lt;BR /&gt;&amp;nbsp; osType: 0&lt;BR /&gt;&amp;nbsp; osVersionLevel: ""&lt;BR /&gt;&amp;nbsp; osVerMajor: 0&lt;BR /&gt;&amp;nbsp; osName: "Gaia"&lt;BR /&gt;&amp;nbsp; osspmajor: 0&lt;BR /&gt;&amp;nbsp; osVerMinor: 0&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: ""&lt;BR /&gt;dataSource: "NOT_MINUS_INSTALLED"&lt;BR /&gt;natSummaryText: ""&lt;BR /&gt;ipPoolAllocPerDestination: false&lt;BR /&gt;backupGateway: null&lt;BR /&gt;rangeEncdomain: null&lt;BR /&gt;supportIpPoolNat: false&lt;BR /&gt;cpProductsInstalled: false&lt;BR /&gt;edges: []&lt;BR /&gt;securityBladesTopologyMode: "TOPOLOGY_TABLE"&lt;BR /&gt;performEncryption: true&lt;BR /&gt;ipPoolGw2gw: false&lt;BR /&gt;certificates: []&lt;BR /&gt;ipPoolPerInterface: false&lt;BR /&gt;ipPoolExhaustRetInterval: 30&lt;BR /&gt;vpnRelayIfName: ""&lt;BR /&gt;connectra: false&lt;BR /&gt;supportIkeV2: true&lt;BR /&gt;firewall: "NOT_MINUS_INSTALLED"&lt;BR /&gt;connectraSettings: null&lt;BR /&gt;autoTopologyUseCustomRecalculationTime: false&lt;BR /&gt;ipaddr: "10.10.10.2"&lt;BR /&gt;ipPoolUnusedReturnInterval: 60&lt;BR /&gt;vpn: &lt;BR /&gt;&amp;nbsp; objId: "00ace2ae-d15a-4615-b2d7-64b6850292ea"&lt;/P&gt;&lt;P&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; singleVpnIp: ""&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIf: ""&lt;BR /&gt;&amp;nbsp; clientlessVpnAskUserForCertificate: "NONE"&lt;BR /&gt;&amp;nbsp; offerNattResponder: true&lt;BR /&gt;&amp;nbsp; enableInternetRouting: false&lt;BR /&gt;&amp;nbsp; forceNatT: false&lt;BR /&gt;&amp;nbsp; vpnClientsSettingsForGateway: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "01fa7fc8-960d-4378-a238-a01e1650d4a6"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; usb1VpnClientSettings: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnClientSettings: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "d5ea091b-4fb8-4a7e-afd1-3a65466570ca"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnEnable: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnConnectivityMethod: "IPSEC"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: "vpn_clients_settings_for_gateway"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableBasicVpnSecuremote: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableVpnWithEndpointSecurity: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; fwWireLogOnlySyn: true&lt;BR /&gt;&amp;nbsp; singleVpnIpRa: ""&lt;BR /&gt;&amp;nbsp; thirdPartyEncryption: true&lt;BR /&gt;&amp;nbsp; availableVpnIpListGw: []&lt;BR /&gt;&amp;nbsp; isakmpUdpencapsulation: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "f787c070-d69e-4ebf-a143-ee49cea5860f"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb390-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpEmail: ""&lt;BR /&gt;&amp;nbsp; isakmpIpcompSupport: false&lt;BR /&gt;&amp;nbsp; accept3desForClientlessVpn: true&lt;BR /&gt;&amp;nbsp; fwz: null&lt;BR /&gt;&amp;nbsp; tunnelKeepaliveMethod: "TUNNEL_TEST"&lt;BR /&gt;&amp;nbsp; dnsIpResolution: ""&lt;BR /&gt;&amp;nbsp; useService: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp; availableVpnIpList: []&lt;BR /&gt;&amp;nbsp; isakmpDn: ""&lt;BR /&gt;&amp;nbsp; isakmpDoDnsResolve: false&lt;BR /&gt;&amp;nbsp; useCert: ""&lt;BR /&gt;&amp;nbsp; multipleIspVpn: false&lt;BR /&gt;&amp;nbsp; ipResolutionMechanismGw: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; disableNoSaLogsForUser: true&lt;BR /&gt;&amp;nbsp; replyFromSameIp: true&lt;BR /&gt;&amp;nbsp; vpnTunnelMtu: 0&lt;BR /&gt;&amp;nbsp; linkSelectionMode: "HIGHAVAILABILITY"&lt;BR /&gt;&amp;nbsp; outgoingSourceIp: "AUTOMATIC"&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCert: []&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIfGw: ""&lt;BR /&gt;&amp;nbsp; ipResolutionMechanism: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; ikeSendFrags: false&lt;BR /&gt;&amp;nbsp; applyResolvingMechanismToSr: true&lt;BR /&gt;&amp;nbsp; isakmpSubnetSupport: true&lt;BR /&gt;&amp;nbsp; isakmpAuthmethods: []&lt;BR /&gt;&amp;nbsp; enableRouting: true&lt;BR /&gt;&amp;nbsp; vpnCompLevel: 2&lt;BR /&gt;&amp;nbsp; useClientlessVpn: false&lt;BR /&gt;&amp;nbsp; dnsIpResolutionGw: ""&lt;BR /&gt;&amp;nbsp; replyToSameIp: true&lt;BR /&gt;&amp;nbsp; vpnLinkResolverNotification: "NONE"&lt;BR /&gt;&amp;nbsp; supportWireMode: false&lt;BR /&gt;&amp;nbsp; ike: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "95903133-3add-438c-92f8-1e844ff8f09c"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1RekeyingTime: 1440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpHashmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpCrlreq: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1DhGroups: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "97aeb629-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpkeymanager: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ikeEmptyUdpSocket: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingKbytes: 50000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpsharedkey: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingTime: 3600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2UseRekeyingKbytes: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpEncmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpAggressiveSupport: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; clientlessProcNum: 1&lt;BR /&gt;&amp;nbsp; useInterfaceIp: true&lt;BR /&gt;&amp;nbsp; tcpt: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "b4a4923a-b997-445e-a4bd-068af7403c4b"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cpmiInterface: "All IPs"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpndInternalBindPort: 444&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpDnsName: ""&lt;BR /&gt;&amp;nbsp; ipsecReplayCounterWindowSize: 64&lt;BR /&gt;&amp;nbsp; sslNe: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "a0201a4b-3e2f-49c5-b67a-e7251cdbe026"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; internalListeningPort: "b8f7c593-f9ee-4c55-b48a-6ce3be6760ac"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; neoEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gwCertificate: "defaultCert"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endPointNameResolution: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "f787c070-d69e-4ebf-a143-ee49cea5860f"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; downloadNameResolutionSettingsToEndPoint: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useSameSettingsAsGw: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientType: "AUTODETECT"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; name: ""&lt;BR /&gt;&amp;nbsp; ipsecDontFragment: true&lt;BR /&gt;&amp;nbsp; rerouteEncryptedPackets: true&lt;BR /&gt;&amp;nbsp; outgoingSingleIp: ""&lt;BR /&gt;&amp;nbsp; ikeFetchCrlFailOpen: false&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToOuter: true&lt;BR /&gt;&amp;nbsp; icon: "Unknown"&lt;BR /&gt;&amp;nbsp; takeTunnelGranularityFromComm: true&lt;BR /&gt;&amp;nbsp; fwWireLog: false&lt;BR /&gt;&amp;nbsp; isakmpMatchpeer: []&lt;BR /&gt;&amp;nbsp; useInterfaceIpGw: true&lt;BR /&gt;&amp;nbsp; ipsecFragmentInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCa: null&lt;BR /&gt;&amp;nbsp; dpdAllowedToInitIke: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalProtocol: "WILDCARD_IDS"&lt;BR /&gt;&amp;nbsp; ikeSupportNatT: true&lt;BR /&gt;&amp;nbsp; color: "BLACK"&lt;BR /&gt;&amp;nbsp; natdSendAllIfcs: false&lt;BR /&gt;&amp;nbsp; displayName: ""&lt;BR /&gt;&amp;nbsp; ikev2AcceptAllTs: false&lt;BR /&gt;&amp;nbsp; respondFromSameIfc: false&lt;BR /&gt;&amp;nbsp; offerNattInitator: false&lt;BR /&gt;&amp;nbsp; comments: ""&lt;BR /&gt;&amp;nbsp; sendSingleNatdSource: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalSupport: true&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; features: []&lt;BR /&gt;&amp;nbsp; systemTags: []&lt;BR /&gt;&amp;nbsp; tags: []&lt;BR /&gt;&amp;nbsp; customFields: []&lt;BR /&gt;&amp;nbsp; metaInfo: null&lt;BR /&gt;dataSourceSettings: null&lt;BR /&gt;nat: null&lt;BR /&gt;ipaddr6: ""&lt;BR /&gt;addAdtrRule: false&lt;BR /&gt;floodgate: "NOT_MINUS_INSTALLED"&lt;BR /&gt;uid: "16fdac28-af5c-4581-94a2-ee3030968bcb"&lt;/P&gt;&lt;P&gt;folder: &lt;BR /&gt;&amp;nbsp; uid: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; name: "Global Objects"&lt;BR /&gt;domain: &lt;BR /&gt;&amp;nbsp; uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; name: "SMC User"&lt;BR /&gt;meta-info: &lt;BR /&gt;&amp;nbsp; metaOwned: false&lt;BR /&gt;&amp;nbsp; lockStateResponse: null&lt;BR /&gt;&amp;nbsp; validationState: "OK"&lt;BR /&gt;&amp;nbsp; deletable: true&lt;BR /&gt;&amp;nbsp; renameable: true&lt;BR /&gt;&amp;nbsp; newObject: false&lt;BR /&gt;&amp;nbsp; lastModifytime: 1549127325577&lt;BR /&gt;&amp;nbsp; lastModifier: "mnemeth"&lt;BR /&gt;&amp;nbsp; creationTime: 1549127325577&lt;BR /&gt;&amp;nbsp; creator: "mnemeth"&lt;BR /&gt;tags: []&lt;BR /&gt;name: "test2"&lt;BR /&gt;icon: "NetworkObjects/gateway"&lt;BR /&gt;comments: ""&lt;BR /&gt;display-name: ""&lt;BR /&gt;customFields: []&lt;BR /&gt;_original_type: "CpmiGatewayPlain"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is the exact same device created by above script which is not working correctly&amp;nbsp;... I just changed this &lt;STRONG style="color: #008000; "&gt;isakmpIpcompSupport'&lt;/STRONG&gt;: &lt;SPAN style="color: #000080;"&gt;True to False because GUI object had this property False... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;objectValidationState: null&lt;BR /&gt;color: "BLACK"&lt;BR /&gt;manualEncdomain: "d87e9442-eefa-4ba6-8472-2dcba5806642"&lt;BR /&gt;vpnAllowRelay: false&lt;BR /&gt;ipPoolOverrideHide: true&lt;BR /&gt;macAddress: ""&lt;BR /&gt;type: "gateway"&lt;BR /&gt;excludeExternalInterfacesFromEncDomain: false&lt;BR /&gt;thirdPartyEncryption: true&lt;BR /&gt;gtpRateLimit: 2048&lt;BR /&gt;enforceGtpRateLimit: false&lt;BR /&gt;dnsResolverInterval: 600&lt;BR /&gt;interfaces: []&lt;BR /&gt;backupGw: false&lt;BR /&gt;additionalProducts: null&lt;/P&gt;&lt;P&gt;snmp: &lt;BR /&gt;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; sysContact: ""&lt;BR /&gt;&amp;nbsp; sysDescr: ""&lt;BR /&gt;&amp;nbsp; readCommunity: ""&lt;BR /&gt;&amp;nbsp; sysLocation: ""&lt;BR /&gt;&amp;nbsp; sysName: ""&lt;BR /&gt;&amp;nbsp; writeCommunity: ""&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;enableMulticastAcceleration: false&lt;BR /&gt;ipPoolSecuremoteAllocationName: null&lt;BR /&gt;dag: false&lt;BR /&gt;ipPoolSecuremote: false&lt;BR /&gt;encdomain: "MANUAL"&lt;BR /&gt;addrTypeIndication: "IPV4"&lt;BR /&gt;autoTopologyCustomRecalculationTime: 10&lt;BR /&gt;osInfo:&lt;/P&gt;&lt;P&gt;&amp;nbsp; objId: "431b7a78-ae8b-4e69-9b9c-0d89840f53e2"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; osBuildNum: 0&lt;BR /&gt;&amp;nbsp; osspminor: 0&lt;BR /&gt;&amp;nbsp; osType: 0&lt;BR /&gt;&amp;nbsp; osVersionLevel: ""&lt;BR /&gt;&amp;nbsp; osVerMajor: 0&lt;BR /&gt;&amp;nbsp; osName: "Gaia"&lt;BR /&gt;&amp;nbsp; osspmajor: 0&lt;BR /&gt;&amp;nbsp; osVerMinor: 0&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: ""&lt;BR /&gt;dataSource: "NOT_MINUS_INSTALLED"&lt;BR /&gt;natSummaryText: ""&lt;BR /&gt;ipPoolAllocPerDestination: false&lt;BR /&gt;backupGateway: null&lt;BR /&gt;rangeEncdomain: null&lt;BR /&gt;supportIpPoolNat: false&lt;BR /&gt;cpProductsInstalled: false&lt;BR /&gt;edges: []&lt;BR /&gt;securityBladesTopologyMode: "TOPOLOGY_TABLE"&lt;BR /&gt;performEncryption: true&lt;BR /&gt;ipPoolGw2gw: false&lt;BR /&gt;certificates: []&lt;BR /&gt;ipPoolPerInterface: false&lt;BR /&gt;ipPoolExhaustRetInterval: 30&lt;BR /&gt;vpnRelayIfName: ""&lt;BR /&gt;connectra: false&lt;BR /&gt;supportIkeV2: true&lt;BR /&gt;firewall: "NOT_MINUS_INSTALLED"&lt;BR /&gt;connectraSettings: null&lt;BR /&gt;autoTopologyUseCustomRecalculationTime: false&lt;BR /&gt;ipaddr: "10.10.10.2"&lt;BR /&gt;ipPoolUnusedReturnInterval: 60&lt;BR /&gt;vpn:&lt;/P&gt;&lt;P&gt;&amp;nbsp; objId: "06e8963e-cce6-44f5-926f-15f482109854"&lt;BR /&gt;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; singleVpnIp: ""&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIf: ""&lt;BR /&gt;&amp;nbsp; clientlessVpnAskUserForCertificate: "NONE"&lt;BR /&gt;&amp;nbsp; offerNattResponder: true&lt;BR /&gt;&amp;nbsp; enableInternetRouting: false&lt;BR /&gt;&amp;nbsp; forceNatT: false&lt;BR /&gt;&amp;nbsp; vpnClientsSettingsForGateway:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "48c0e8f1-a320-45a2-8043-3b3ac22deeae"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; usb1VpnClientSettings: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnClientSettings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "6d30bba1-3bd4-41a6-a6ae-5d777ac929ae"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnEnable: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; endpointVpnConnectivityMethod: "IPSEC"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: "vpn_clients_settings_for_gateway"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableBasicVpnSecuremote: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; enableVpnWithEndpointSecurity: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; fwWireLogOnlySyn: true&lt;BR /&gt;&amp;nbsp; singleVpnIpRa: ""&lt;BR /&gt;&amp;nbsp; thirdPartyEncryption: true&lt;BR /&gt;&amp;nbsp; availableVpnIpListGw: []&lt;BR /&gt;&amp;nbsp; isakmpUdpencapsulation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb390-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpEmail: ""&lt;BR /&gt;&amp;nbsp; isakmpIpcompSupport: false&lt;BR /&gt;&amp;nbsp; accept3desForClientlessVpn: true&lt;BR /&gt;&amp;nbsp; fwz: null&lt;BR /&gt;&amp;nbsp; tunnelKeepaliveMethod: "TUNNEL_TEST"&lt;BR /&gt;&amp;nbsp; dnsIpResolution: ""&lt;BR /&gt;&amp;nbsp; useService: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp; availableVpnIpList: []&lt;BR /&gt;&amp;nbsp; isakmpDn: ""&lt;BR /&gt;&amp;nbsp; isakmpDoDnsResolve: false&lt;BR /&gt;&amp;nbsp; useCert: ""&lt;BR /&gt;&amp;nbsp; multipleIspVpn: false&lt;BR /&gt;&amp;nbsp; ipResolutionMechanismGw: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; disableNoSaLogsForUser: true&lt;BR /&gt;&amp;nbsp; replyFromSameIp: true&lt;BR /&gt;&amp;nbsp; vpnTunnelMtu: 0&lt;BR /&gt;&amp;nbsp; linkSelectionMode: "HIGHAVAILABILITY"&lt;BR /&gt;&amp;nbsp; outgoingSourceIp: "AUTOMATIC"&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCert: []&lt;BR /&gt;&amp;nbsp; interfaceResolvingHaPrimaryIfGw: ""&lt;BR /&gt;&amp;nbsp; ipResolutionMechanism: "MAINIPVPN"&lt;BR /&gt;&amp;nbsp; ikeSendFrags: false&lt;BR /&gt;&amp;nbsp; applyResolvingMechanismToSr: true&lt;BR /&gt;&amp;nbsp; isakmpSubnetSupport: true&lt;BR /&gt;&amp;nbsp; isakmpAuthmethods: []&lt;BR /&gt;&amp;nbsp; enableRouting: true&lt;BR /&gt;&amp;nbsp; vpnCompLevel: 2&lt;BR /&gt;&amp;nbsp; useClientlessVpn: false&lt;BR /&gt;&amp;nbsp; dnsIpResolutionGw: ""&lt;BR /&gt;&amp;nbsp; replyToSameIp: true&lt;BR /&gt;&amp;nbsp; vpnLinkResolverNotification: "NONE"&lt;BR /&gt;&amp;nbsp; supportWireMode: false&lt;BR /&gt;&amp;nbsp; ike:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "d48f659f-8efd-49dd-9339-48ba59de2ad0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1RekeyingTime: 1440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpHashmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpCrlreq: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase1DhGroups: &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "97aeb629-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpkeymanager: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ikeEmptyUdpSocket: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingKbytes: 50000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpsharedkey: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2RekeyingTime: 3600&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpPhase2UseRekeyingKbytes: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpEncmethods: []&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isakmpAggressiveSupport: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; clientlessProcNum: 1&lt;BR /&gt;&amp;nbsp; useInterfaceIp: true&lt;BR /&gt;&amp;nbsp; tcpt:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "431b7a78-ae8b-4e69-9b9c-0d89840f53e2"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; resource: "97aeb443-9aea-11d5-bd16-0090272ccb30"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cpmiInterface: "All IPs"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpndInternalBindPort: 444&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; isakmpDnsName: ""&lt;BR /&gt;&amp;nbsp; ipsecReplayCounterWindowSize: 64&lt;BR /&gt;&amp;nbsp; sslNe:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "c1293112-01c6-4448-82c7-1be64593dad3"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; internalListeningPort: "b8f7c593-f9ee-4c55-b48a-6ce3be6760ac"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; neoEnable: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gwCertificate: "defaultCert"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; endPointNameResolution:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; objId: "471f5a48-9650-423a-982b-63440b53d9b0"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; checkPointObjId: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domainId: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; downloadNameResolutionSettingsToEndPoint: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useSameSettingsAsGw: true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientType: "AUTODETECT"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ownedName: ""&lt;BR /&gt;&amp;nbsp; name: ""&lt;BR /&gt;&amp;nbsp; ipsecDontFragment: true&lt;BR /&gt;&amp;nbsp; rerouteEncryptedPackets: true&lt;BR /&gt;&amp;nbsp; outgoingSingleIp: ""&lt;BR /&gt;&amp;nbsp; ikeFetchCrlFailOpen: false&lt;BR /&gt;&amp;nbsp; ipsecCopyTosToOuter: true&lt;BR /&gt;&amp;nbsp; icon: "Unknown"&lt;BR /&gt;&amp;nbsp; takeTunnelGranularityFromComm: true&lt;BR /&gt;&amp;nbsp; fwWireLog: false&lt;BR /&gt;&amp;nbsp; isakmpMatchpeer: []&lt;BR /&gt;&amp;nbsp; useInterfaceIpGw: true&lt;BR /&gt;&amp;nbsp; ipsecFragmentInner: false&lt;BR /&gt;&amp;nbsp; isakmpAllowedCa: null&lt;BR /&gt;&amp;nbsp; dpdAllowedToInitIke: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalProtocol: "WILDCARD_IDS"&lt;BR /&gt;&amp;nbsp; ikeSupportNatT: true&lt;BR /&gt;&amp;nbsp; color: "BLACK"&lt;BR /&gt;&amp;nbsp; natdSendAllIfcs: false&lt;BR /&gt;&amp;nbsp; displayName: ""&lt;BR /&gt;&amp;nbsp; ikev2AcceptAllTs: false&lt;BR /&gt;&amp;nbsp; respondFromSameIfc: false&lt;BR /&gt;&amp;nbsp; offerNattInitator: false&lt;BR /&gt;&amp;nbsp; comments: ""&lt;BR /&gt;&amp;nbsp; sendSingleNatdSource: true&lt;BR /&gt;&amp;nbsp; isakmpUniversalSupport: true&lt;BR /&gt;&amp;nbsp; folderPath: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; text: null&lt;BR /&gt;&amp;nbsp; folder: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; is_owned: false&lt;BR /&gt;&amp;nbsp; ownedName: "test2"&lt;BR /&gt;&amp;nbsp; features: []&lt;BR /&gt;&amp;nbsp; systemTags: []&lt;BR /&gt;&amp;nbsp; tags: []&lt;BR /&gt;&amp;nbsp; customFields: []&lt;BR /&gt;&amp;nbsp; metaInfo: null&lt;BR /&gt;dataSourceSettings: null&lt;BR /&gt;nat: null&lt;BR /&gt;ipaddr6: ""&lt;BR /&gt;addAdtrRule: false&lt;BR /&gt;floodgate: "NOT_MINUS_INSTALLED"&lt;/P&gt;&lt;P&gt;uid: "054e4752-3c98-4a59-bf7e-6e7ff99fcab5"&lt;BR /&gt;folder: &lt;BR /&gt;&amp;nbsp; uid: "e5c2231d-1dc3-408c-8cb9-588b275c2d8c"&lt;BR /&gt;&amp;nbsp; name: "Global Objects"&lt;BR /&gt;domain: &lt;BR /&gt;&amp;nbsp; uid: "41e821a0-3720-11e3-aa6e-0800200c9fde"&lt;BR /&gt;&amp;nbsp; name: "SMC User"&lt;BR /&gt;meta-info: &lt;BR /&gt;&amp;nbsp; metaOwned: false&lt;BR /&gt;&amp;nbsp; lockStateResponse: null&lt;BR /&gt;&amp;nbsp; validationState: "OK"&lt;BR /&gt;&amp;nbsp; deletable: true&lt;BR /&gt;&amp;nbsp; renameable: true&lt;BR /&gt;&amp;nbsp; newObject: false&lt;BR /&gt;&amp;nbsp; lastModifytime: 1549127013761&lt;BR /&gt;&amp;nbsp; lastModifier: "mnemeth-API"&lt;BR /&gt;&amp;nbsp; creationTime: 1549127013761&lt;BR /&gt;&amp;nbsp; creator: "mnemeth-API"&lt;BR /&gt;tags: []&lt;BR /&gt;name: "test2"&lt;BR /&gt;icon: "NetworkObjects/gateway"&lt;BR /&gt;comments: ""&lt;BR /&gt;display-name: ""&lt;BR /&gt;customFields: []&lt;BR /&gt;_original_type: "CpmiGatewayPlain"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you pass these both objects to editor and&amp;nbsp;compare it, you will find that the objects ARE ALMOST THE SAME!. What is different are obviously UIDs of components, time of creation, admin username (I am using -API for scripts) and correct object has no snmp section while script obkect has snmp section. So... what can be wrong with second object, or other question, what to change in script to be correct???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another strange thing is, when I run this command from command line from SmartConsole, the same object will be almost correct. But only almost... For first it will NOT be visible fro VPN Community, but if you assign VPN Community to the object, it will be OK and if you remove it again, after this it will be now visible from VPN&amp;nbsp;Community too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And If I create same object through dbedit with something like this (template for jinja2):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create gateway_plain {{ peerName }}&lt;BR /&gt;modify network_objects {{ peerName }} DAG false&lt;BR /&gt;modify network_objects {{ peerName }} color {{ color }}&lt;BR /&gt;modify network_objects {{ peerName }} VPN VPN&lt;BR /&gt;modify network_objects {{ peerName }} VPN:third_party_encryption true&lt;BR /&gt;modify network_objects {{ peerName }} VPN:IKE IKE&lt;BR /&gt;modify network_objects {{ peerName }} SNMP NULL&lt;BR /&gt;modify network_objects {{ peerName }} type gateway&lt;BR /&gt;modify network_objects {{ peerName }} add_adtr_rule false&lt;BR /&gt;modify network_objects {{ peerName }} ipaddr {{ peerIP }}&lt;BR /&gt;modify network_objects {{ peerName }} encdomain manual&lt;BR /&gt;modify network_objects {{ peerName }} manual_encdomain network_objects:{{ cryptoDomainGrp }}&lt;BR /&gt;update_all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will work without any issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it seems, that 4 different methods of creating the same Interoperable device (GUI, command line API, WEB API and&amp;nbsp;dbedit)&amp;nbsp;have different results... Strange,&amp;nbsp;isnt't it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael Nemeth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:48:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29875#M1792</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-02T17:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29876#M1793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another strange thing is that GUI created Interoperable object HAS in traditional mode parameters DES and MD5 selected, but&amp;nbsp;these params&amp;nbsp;are not shown in list from command, show generic-object... Why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So after this recherche&amp;nbsp;I think something like this &lt;/P&gt;&lt;PRE style="color: #000000; font-family: 'Courier New'; background-color: #ffffff;"&gt;{&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'uid'&lt;/SPAN&gt;: result[&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'uid'&lt;/SPAN&gt;], &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'vpn' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ike' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'isakmpHashmethods'&lt;/SPAN&gt;: [&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'MD5'&lt;/SPAN&gt;]}}}&lt;BR /&gt;{&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'uid'&lt;/SPAN&gt;: result[&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'uid'&lt;/SPAN&gt;], &lt;SPAN style="color: #008000; font-weight: bold;"&gt;'vpn' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'ike' &lt;/SPAN&gt;: {&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'isakmpEncmethods'&lt;/SPAN&gt;: [&lt;SPAN style="color: #008000; font-weight: bold;"&gt;'DES'&lt;/SPAN&gt;]}}}&lt;/PRE&gt;&lt;P&gt;should definitelly help to create correct iteroperable device through WEB API, but I did not find way how to set&amp;nbsp; list of methods to isakmpHashmethods and isakmpEncmethods&amp;nbsp;using add generic-object or set generic-object... Is there any possibility how to do it? Thanks for help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="color: #000000; font-family: 'Courier New'; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 18:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29876#M1793</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-02T18:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29877#M1794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again ... &lt;/P&gt;&lt;P&gt;I finally found in other thread "hack" with dbedit - change something (for example color), update_all, change something back, update_all. And it works....&lt;/P&gt;&lt;P&gt;But it makes no sence, if I NEED to use dbedit, I can make whole object through it, am I right? And I really wanted to avoid in my script connecting via ssh to SmartCenter (or in our case MDS) and run dbedit commands...&lt;/P&gt;&lt;P&gt;There istn't really another way to make it work WITHOUT dbedit?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 06:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29877#M1794</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-04T06:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29878#M1795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now, you are correct: no way to make this object entirely thru API.&lt;/P&gt;&lt;P&gt;There are a handful of objects like this currently (gateway cluster objects being most requested).&lt;/P&gt;&lt;P&gt;We do plan to address this in later releases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 11:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29878#M1795</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-04T11:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29879#M1796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, thnx very much. I can live with this somehow ... Another quick question. We need also create dynamic Interoperable devices ... Problem is, that if you create dynamic interoperable device through GUI, it assign some IP 0.0.x.y and increment some internal counter. I can do the same through dbedit or generic-object API, but I need to select IP manually. Is it OK to select some random "dynamic" IP from some range? I am really afraid to pud such "workaround" to production. Best way I am doing this now is creating non dynamic device with API and then finish configuration through GUI, where I just create dynamic interface and change type to dynamic (DAG)... Is there any workaround to correctly fully automate this action?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 14:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29879#M1796</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-04T14:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29880#M1797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2192"&gt;Amiad Stern&lt;/A&gt;‌?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 18:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29880#M1797</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-04T18:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29881#M1798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just for you guys, If you will have same problem. You really don't need use dbedit for alter color. But you really have to change something on newly created object (for example color is easiest). It works for me when I create interoperable device using add-generic-object and publish, then I change color with command set-generic-object (color is in CAPS) and again publish and then object is finally visible in VPN communities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 06:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29881#M1798</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-20T06:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29882#M1799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have maybe final question regarding this Interoperable device creation. I see, that if you creating some section or list of interfaces for example, with add-generic-object you are using &lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;"&lt;/SPAN&gt;&lt;SPAN style="color: #008000;"&gt;&lt;SPAN style="color: #ff0000;"&gt;com.checkpoint.objects.classes.dummy.CPSomething"&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there any list of these dummy classes?&lt;/STRONG&gt; Because I finally don't need use dbedit at all, as I mentioned in my last comment, but if I have Interoperable device with certificate and I want to check DN, in object created via GUI show-generic-object looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;isakmpMatchpeer: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&amp;nbsp; - "DN"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and same object without checked DN checkbox looks like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;isakmpMatchpeer: []&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With dbedit I can create this "DN" element with command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;addelement network_objects someObjectName VPN:isakmp.matchpeer DN.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I expect that for the same action in add-generic-objects it should be something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;'isakmpMatchpeer' : {'create' : 'com.checkpoint.objects.classes.dummy.CP????}&lt;/SPAN&gt; . &lt;/STRONG&gt;&lt;/EM&gt;maybe CPDN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shortly: I need create in tree vpn -&amp;gt;&amp;nbsp; isakmpMatcheer list with one element "DN".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way how to do it with add-generic-object or set-generic-object or I still need to use for this dbedit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnx much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 06:38:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29882#M1799</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-21T06:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29883#M1800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you’ve reviewed:&lt;A href="https://community.checkpoint.com/message/18814"&gt;Re: How to find generic-object that is not defined in the API?&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 07:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29883#M1800</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-21T07:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29884#M1801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Michael,&lt;/P&gt;&lt;P&gt;I'm experiencing same "problems".&lt;/P&gt;&lt;P&gt;Maybe I'm something for you: I've discovered the class "com.checkpoint.objects.classes.dummy.CpmiDAGInterface" usefull to add an external interface with dynamic IP without getting into problems when try to modify the object from GUI (if I create an "com.checkpoint.objects.classes.dummy.CpmiInterface" with dynamicIp field setted to true when I try to modify object usong GUI it raise a strange error ... before this 'discovery' the only solution I had was to add the interface using GUI).&lt;/P&gt;&lt;P&gt;Shoud be wonderfull if CheckPoint will provide more complete documentation about Man API usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm trying to solve the "other problem": add elements using API.&lt;/P&gt;&lt;P&gt;I've to add elements to "isakmpHashmethods" and "isakmpEncmethods" ..... but at the moment I'm able to do it only using dbedit &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; ..... I keep trying ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 11:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29884#M1801</guid>
      <dc:creator>Matteo_Martini</dc:creator>
      <dc:date>2019-02-21T11:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29885#M1802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've realized that I'd made a typo on class name (no copy'n'paste), the correct class name is "com.checkpoint.objects.classes.dummy.CpmiDagInterface"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 13:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29885#M1802</guid>
      <dc:creator>Matteo_Martini</dc:creator>
      <dc:date>2019-02-21T13:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29886#M1803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnx for info I will test it ...I have issue with DAG, that if you create object through GUI it will assign to this object some phantom IP (0.0.x.y) and keeps counter for already assigned addresses somewhere. But if I will create object with dbedit, I don't know how to use this internal counter, I need to choose object IP by myself. And I don't know if I choose something, if it will not mess whole database or SmartCenter at all. So I am afraid to do it in production. In testing management it kinda works. Anyway here is my dbedit script for create DAG Interoprable device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create gateway_plain {{ objName }}&lt;BR /&gt;modify network_objects {{ objName }} DAG true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} color orange&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} VPN VPN&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} VPN:third_party_encryption true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} VPN:IKE IKE&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} SNMP NULL&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} type gateway&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} add_adtr_rule false&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;modify network_objects {{ objName }} ipaddr {{ ipAddr }} =====&amp;gt; here you MUST choose and set some object IP even if it is dynamic Interoperable device&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;addelement network_objects {{&amp;nbsp;objName }} VPN:isakmp.matchpeer DN&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} VPN:isakmp.dn '{{ your DN here }}'&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} VPN:isakmp.allowed_ca servers: {{ your CA name here }}&lt;BR /&gt;addelement network_objects {{&amp;nbsp;objName }} interfaces interface&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:ipaddr {{ lanIP }}&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:netmask {{ lanNetmask }}&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:officialname lan&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:ifindex 0&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:security:antispoof true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:security:netaccess:access this&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:0:security:netaccess:perform_anti_spoofing true&lt;BR /&gt;addelement network_objects {{&amp;nbsp;objName }} interfaces interface&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:ipaddr {{ wanIP }}&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:netmask {{ wanNetmask }}&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:officialname wan_real&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:security:netaccess:leads_to_internet true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:security:antispoof true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:security:netaccess:perform_anti_spoofing true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:1:ifindex 1&lt;BR /&gt;addelement network_objects {{&amp;nbsp;objName }} interfaces DAG_interface&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:2:dynamic_ip true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:2:officialname wan&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:2:security:netaccess:leads_to_internet true&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:2:security:netaccess:perform_anti_spoofing false&lt;BR /&gt;modify network_objects {{&amp;nbsp;objName }} interfaces:2:ifindex 2&lt;BR /&gt;update_all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you need to add isakmp methods to the Interoperable device... Methods in interoperable device are important only if you run VPN rulebase in traditional mode (Which is not supported now). It is totally ok to set up crypto methods only in VPN community ... If you want I can pass my solution for VPN community also...&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But even with possibility adding DAG interface, it is not solving my problem with adding DN list. I need dummy class like this. But I dont know if it exists&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG style="color: #ff0000; "&gt;com.checkpoint.objects.classes.dummy.CpmiDN&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;If I can ask, how and where did you discover this DAG dummy class? Maybe we can find another classes, which checkpoint is silently hiding from us &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2019 07:50:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29886#M1803</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2019-02-25T07:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29887#M1804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;I'm not able to find where checkpoint puts the "DAG IP counter", as you know checkpoint increment this every time you configure a gw from SmartConsole (even if you discard changes).&lt;/P&gt;&lt;P&gt;In ipaddr filed of a dag gw you have to use an IP from 0.0.0.0/8 network (0.0.0.0 excluded)&lt;/P&gt;&lt;P&gt;I think that checkpoint do it in that way hoping that nobody will configure more that ~16581375 gateways ....&lt;/P&gt;&lt;P&gt;If you configure through api a gw using a following IP smartconsole it doesn't check if the ip exists, and a duplication results in (I doesn't test the consequences of this situation ... ).&lt;/P&gt;&lt;P&gt;A workaround could be to use the same "checkpoint thinking" .... but in reverse order: starting using 0.255.255.255 and go backwards, maybe using a script that will find the last used IP to assign the previous one to the new gw. In that way is improbable that the two counters will meed each others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To discover checkpoint classes .... I've started doing "bruteforce" .... but then I've found the ws schema!&lt;/P&gt;&lt;P&gt;isakmpMatchpeer type is not related to a class, let me show:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:element maxOccurs="unbounded" minOccurs="0" name="&lt;STRONG&gt;isakmpMatchpeer&lt;/STRONG&gt;" nillable="true" type="&lt;STRONG&gt;tns:CpmiPublicKeyMatchingCriteriaIntCpmiPublicKeyMatchingCriteriaIsakmpMatchpeer&lt;/STRONG&gt;"&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:annotation&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:appinfo&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;DisplayName description="" value="Matching Criteria List"/&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/xs:appinfo&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/xs:annotation&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/xs:element&amp;gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is only a restriction (I think ... I'm not so 'in touch' with web services schemas)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:simpleType name="CpmiPublicKeyMatchingCriteriaIntCpmiPublicKeyMatchingCriteriaIsakmpMatchpeer"&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:restriction base="xs:string"&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:enumeration value="DN"/&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:enumeration value="EMAIL"/&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;xs:enumeration value="DNS_IP"/&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/xs:restriction&amp;gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/xs:simpleType&amp;gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but a wasn't able to fill isakmpMatchpeer field anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe using two brains we can reach a solution ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 15:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/29887#M1804</guid>
      <dc:creator>Matteo_Martini</dc:creator>
      <dc:date>2019-02-27T15:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/72522#M4308</link>
      <description>&lt;P&gt;Old post, but still just in case others are still reading this (I did) i found a solution to fix the object through the API.&lt;/P&gt;&lt;P&gt;Your comments that editing the object in dbedit fixed it made me try the same thing through the REST API.&lt;/P&gt;&lt;P&gt;We're using PowerShell due to our automation system, but the example below should be easy enough to port to python for those who prefer that.&lt;/P&gt;&lt;P&gt;Right now, I don't set interfaces, and the VPN Domain is set to a manually specified group in the first section.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# Ignore SSL:
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}


# Set Variables (Change These to match your environment)
$BaseUri = "https://10.20.30.40/web_api"
$domain = "CMA_Domain_Name"
$InterDevName = "InterOpGateway1"
$InterDevIP = "10.10.10.1"
$InterDevVpnDomain = "VPNDomainGroup"
# Posted variables for easy example, but  [PSCredential] are recommended for PowerShell scripting.
$user = "s_api"
$pass = "ApiRocks!"


# No changes should be required below this part, but feel free to play around. 
# Remove domain for standalone managements. (Written for MDS)
$loginData = @{
    "user" = $user
    "password" = $password
    "domain" = $domain
} | ConvertTo-Json

Write-Output "Invoking Login"
$login = Invoke-RestMethod -Method Post -Uri "$BaseUri/login" -Body $loginData -Headers @{ "content-type" = "application/json" }
$headers = @{
    "content-type" = "application/json"
    "x-chkp-sid" = $login.sid
}
$body = @"
{
    "name":  "$InterDevVpnDomain"
}
"@

$group = Invoke-RestMethod -Method Post -Uri "$BaseUri/show-group" -Body $body -Headers $headers
$groupuid = $group.uid
$addgw = @"
{
	"create" : "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain",
	"name" : "$InterDevName",
	"osInfo" : {
		"osName" : "Gaia"
	},
	"ipaddr" : "$InterDevIP",
	"thirdPartyEncryption" : "true",
    "nat" : null,
    "dataSourceSettings" : null,
    "manualEncdomain":  "$groupuid",
    "encdomain":  "MANUAL",
	"vpn" : {
		"create" : "com.checkpoint.objects.classes.dummy.CpmiVpn",
        "isakmpIpcompSupport":  false,
        "isakmpUniversalSupport":  false,
		"owned-object" : {

			"vpnClientsSettingsForGateway" : {
				"create" : "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway",
				"owned-object": {
					"endpointVpnClientSettings" : {
						"create": "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway",
						"owned-object" : {
							"endpointVpnEnable" : "true"
						}
					}
				}
			},
			"ike" : {
				"create" : "com.checkpoint.objects.classes.dummy.CpmiIke"
			},

			"sslNe": {
				"create": "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender",
				"owned-object" : {
					"sslEnable" : "false",
					"gwCertificate" : "defaultCert"
				}
			},
			"isakmpIpcompSupport" : "true",
			"isakmpUniversalSupport" : "true"
		}
	}
}

"@


# Add Interoperable device
Write-Output "Adding InterOperable gateway"
$gw = Invoke-RestMethod -Method Post -Uri "$BaseUri/add-generic-object" -Body $addgw -Headers $headers
$null = Invoke-RestMethod -Method Post -Uri "$BaseUri/publish" -Body "{}" -Headers $headers
Sleep 5

# Update Interoperable device to make it available for VPN Community
$gwuid = $gw.uid
$setgw = @"
{
"uid" : "$gwuid",
"nat" : null,
"dataSourceSettings" : null,
"manualEncdomain":  "$groupuid",
"encdomain":  "MANUAL",
"vpn" : {
    "isakmpIpcompSupport":  false,
"isakmpUniversalSupport":  false
 }
}
"@
Write-Output "Editing InterOperable gateway"
$null = Invoke-RestMethod -Method Post -Uri "$BaseUri/set-generic-object" -Body $setgw -Headers $headers
$null = Invoke-RestMethod -Method Post -Uri "$BaseUri/publish" -Body "{}" -Headers $headers

#Logout
Write-Output "All done, terminating session."
Invoke-RestMethod -Method Post -Uri "$BaseUri/logout" -Body "{}" -Headers $headers&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this can help others automate their tasks. Let me know if anything is unclear and I'll try to clearify.&lt;/P&gt;&lt;P&gt;/S&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 11:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/72522#M4308</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-01-17T11:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/74412#M4351</link>
      <description>&lt;P&gt;Yes, you are right ... to change something on freshly added device will fix it in Smartcenter, but I still have no solution for Matching Criteria and for choosing IP address of dynamic device ... Unfortunatelly we have plenty of VPNs connected here via private APNs from two mobile operators (if one fails second one is active), so DAIP is mandatory, but I am still forced to click them manually into SmartCenter &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; ... Two years later, R80.40 is out and still no fresh wind into Interoperable Devices API.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 09:34:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/74412#M4351</guid>
      <dc:creator>Michael_Nemeth</dc:creator>
      <dc:date>2020-02-07T09:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/74938#M4369</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10350"&gt;@Michael_Nemeth&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;If you change the last json bit that edits the interoperable gateway, you will be able to select "Use DNS resolving" on the object. (if this is your missing bit.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;$setgw = @"
{
"uid" : "$gwuid",
"nat" : null,
"dataSourceSettings" : null,
"manualEncdomain":  "$groupuid",
"encdomain":  "MANUAL",
"vpn" : {
    "isakmpIpcompSupport":  false,
    "isakmpUniversalSupport":  false,
    "ipResolutionMechanismGw": "DNSLOOKUP",
    "dnsIpResolutionGw": "daip.ddns.net"
 }
}
"@&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="daip.PNG" style="width: 633px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4414iAA2EF680882CB2D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="daip.PNG" alt="daip.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The set-generic-object isn't officially supported, but it helps of get past the missing API's for now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I misunderstood your need, please let me know, I'm quite interested in solving/automating the entire VPN setups for all our use cases as well.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 08:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/74938#M4369</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-02-12T08:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/134136#M6431</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;where can I see the structure of this method?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/134136#M6431</guid>
      <dc:creator>Samat</dc:creator>
      <dc:date>2021-11-16T09:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: problem adding interoperable device via web API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/150699#M6865</link>
      <description>&lt;P&gt;R81.20 has formal API support for this.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-interoperable-device~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-interoperable-device~v1.9%20&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 16:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/problem-adding-interoperable-device-via-web-API/m-p/150699#M6865</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-13T16:00:01Z</dc:date>
    </item>
  </channel>
</rss>

