<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mgmt_cli and add-vpn-community-star in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/48538#M3199</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8217"&gt;@Christian_Riede&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This is not a Typo. In Star community you have Central Gateway and Satellite Gateways. These Gateways can be Check-Point Gateways or Externally Managed Gateways (see image below).&lt;/P&gt;
&lt;P&gt;In this example "External_Gateway_1" is of type Externally Managed, it was set in the community as a Central Gateway and since it is Externally Managed, it should be configured with shared secret. This is why it is being listed twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="externally-managed.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/403iBB74445A5A5C8B4A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="externally-managed.png" alt="externally-managed.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2019 21:52:15 GMT</pubDate>
    <dc:creator>Amiad_Stern</dc:creator>
    <dc:date>2019-03-25T21:52:15Z</dc:date>
    <item>
      <title>mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47642#M3158</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;in &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-vpn-community-star~v1.4%20" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-vpn-community-star~v1.4%20&lt;/A&gt;, it says:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;add-vpn-community-star (with shared secrets)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="example-sec-title"&gt;Command&lt;/P&gt;&lt;PRE&gt;mgmt_cli add vpn-community-star name "New_VPN_Community_Star_1" center-gateways "External_Gateway_1" use-shared-secret true shared-secrets.1.external-gateway "External_Gateway_1" shared-secrets.1.shared-secret "mysharedsecret1" --version 1.4 --format json
 • "--format json" is optional. By default the output is presented in plain text.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is the external gateway listed under "central-gateways"? Typo?&lt;/P&gt;&lt;P&gt;Regards, Christian Riede&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 11:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47642#M3158</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-19T11:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47694#M3159</link>
      <description>With External Gateway the only thing I can think of is your gateway at the perimeter, as you can have a external and an Internal gateway.&lt;BR /&gt;For the Remote side I would use the term Remote Gateway as to describe the gateway at the other side.</description>
      <pubDate>Tue, 19 Mar 2019 11:38:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47694#M3159</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-19T11:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47906#M3168</link>
      <description>&lt;P&gt;Hello Checkpoint,&lt;/P&gt;&lt;P&gt;can you please update the documentation? This is obviously inconsistent.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Christian Riede&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 09:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/47906#M3168</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-20T09:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/48538#M3199</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8217"&gt;@Christian_Riede&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This is not a Typo. In Star community you have Central Gateway and Satellite Gateways. These Gateways can be Check-Point Gateways or Externally Managed Gateways (see image below).&lt;/P&gt;
&lt;P&gt;In this example "External_Gateway_1" is of type Externally Managed, it was set in the community as a Central Gateway and since it is Externally Managed, it should be configured with shared secret. This is why it is being listed twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="externally-managed.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/403iBB74445A5A5C8B4A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="externally-managed.png" alt="externally-managed.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/48538#M3199</guid>
      <dc:creator>Amiad_Stern</dc:creator>
      <dc:date>2019-03-25T21:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/48674#M3204</link>
      <description>&lt;P&gt;OK, understood. I our installation (and probably in 99% of all worldwide installations), the center gateway is an internal gateway, so this example is not wrong, but counterintuitive and somehow misleading.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 14:46:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/48674#M3204</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-26T14:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196393#M8129</link>
      <description>&lt;P&gt;The documentation is pretty confusing:&lt;BR /&gt;Can you provide the exact syntax to create a Star community with a central and satellite gateway that uses pre-shared keys?&lt;BR /&gt;&lt;BR /&gt;Here's what I started to write out, which I'm pretty sure is wrong.&lt;/P&gt;
&lt;P&gt;mgmt_cli --session-id $session add vpn-community-star name "VPNCommunity1" center-gateways "CentralFW" statellite-gateways "RemoteFW" encryption-method "prefer ikev2 but support ikev1" encryption-suite "custom" ike-phase-1.data-intergrity "sha256" ike-phase-1.encryption-algorithm "aes-256" ike-phase-1.diffie-hellman-group "group 14" ike-phase-2.data-integrity "sha256" ike-phase-2.encryption-algorithm "aes-256" use-shared-secret true shared-secrets.1.external-gateway "CentralFW" shared-secrets.1.shared-secret "mysharedsecret1"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;----------------------&lt;/P&gt;
&lt;P&gt;Managed to figure things out.&lt;BR /&gt;I noted you can't create an inter-operable device in API version 1.7 (we are using R81), unless someone can tellme I'm wrong and how to do it. So now assuming the interoperable device has been created I did the following:&lt;/P&gt;
&lt;P&gt;Central GW = CentralFW (Managed via a local MGR)&lt;BR /&gt;Satellite GW = RemoteFW (Third-Party managed, and not Checkpoint)&lt;/P&gt;
&lt;P&gt;Phase I:&lt;BR /&gt;IKE Version = 2&lt;BR /&gt;Encryption = AES256&lt;BR /&gt;Auth = SHA256&lt;BR /&gt;DH Group = 5&lt;BR /&gt;Lifetime = default (1440)&lt;/P&gt;
&lt;P&gt;Phase II&lt;BR /&gt;IKE Version = 2&lt;BR /&gt;Encryption = AES256&lt;BR /&gt;Auth = SHA256&lt;BR /&gt;DH Group = 5&lt;BR /&gt;Lifetime = 3000 (seconds)&lt;BR /&gt;Use Preshared = Y&lt;/P&gt;
&lt;P&gt;Below is the mgmt_cli command used:&lt;BR /&gt;mgmt_cli --session-id $session add vpn-community-star name "CommunityTest" center-gateways "CentralFW" satellite-gateways "RemoteFW" use-shared-secret "true" shared-secrets.1.external-gateway "RemoteFW" shared-secrets.1.shared-secret "mysharedsecret1123456" encryption-method "prefer ikev2 but support ikev1" encryption-suite "custom" ike-phase-1.data-integrity "sha256" ike-phase-1.encryption-algorithm "aes-256" ike-phase-1.diffie-hellman-group "group 5" ike-phase-2.data-integrity "sha256" ike-phase-2.encryption-algorithm "aes-256" ike-phase-2.ike-p2-use-pfs true ike-phase-2.ike-p2-pfs-dh-grp "group 5" ike-phase-2.ike-p2-rekey-time 3000 color "red" comments "Test Community"&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:42:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196393#M8129</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-27T15:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196421#M8130</link>
      <description>&lt;P&gt;Which firewall is managed by the management where you are running the command? Which firewall is not managed by that management?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196421#M8130</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-27T15:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196423#M8131</link>
      <description>&lt;P&gt;CentralFW is managed by me, and the remote is a thirdparty not using Checkpoint; commands are run from the Manager using mgmt_cli&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:41:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196423#M8131</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-27T15:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196424#M8132</link>
      <description>&lt;P&gt;I see you got it working. Cool.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196424#M8132</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-27T15:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196425#M8133</link>
      <description>&lt;P&gt;Yes - but I wish there was more examples.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 15:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196425#M8133</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-27T15:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196438#M8134</link>
      <description>&lt;P&gt;You can probably create an interoperable object via generic-object API calls in earlier releases.&lt;BR /&gt;Not exactly sure of the syntax, but believe they are present in the community.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 17:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196438#M8134</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-27T17:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196459#M8135</link>
      <description>&lt;P&gt;any idea what I should search for?&lt;/P&gt;
&lt;P&gt;I've pretty much got everything I need accept that part now.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 08:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196459#M8135</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-10-28T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196461#M8136</link>
      <description>&lt;P&gt;Even then the API isn't complete in the latest versions. For instance, you can't set NAT override or change timers with an API call so if these parameters are of importance, you would need to review them manually.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2023 09:13:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196461#M8136</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-10-28T09:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: mgmt_cli and add-vpn-community-star</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196559#M8137</link>
      <description>&lt;P&gt;You will have to dig through a few threads, starting with this one (and one that's linked in this thread):&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/How-to-find-generic-object-that-is-not-defined-in-the-API/m-p/20885#M1308" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/How-to-find-generic-object-that-is-not-defined-in-the-API/m-p/20885#M1308&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 14:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/mgmt-cli-and-add-vpn-community-star/m-p/196559#M8137</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-30T14:07:45Z</dc:date>
    </item>
  </channel>
</rss>

