<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Activate PFS in a VPN community via API in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/48863#M3211</link>
    <description>&lt;P&gt;Hey Christian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The standard managment API (still) does not support the configuration that you need.&lt;/P&gt;&lt;P&gt;But&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9262"&gt;@Kim_Moberg&lt;/a&gt;&amp;nbsp;did a nice writeup regarding his solution via the generic objects API - see &lt;A href="https://community.checkpoint.com/t5/Developers-API-CLI/Missing-API-possibility-to-set-vpn-community-star-objects/td-p/20956" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2019 15:24:54 GMT</pubDate>
    <dc:creator>Maik</dc:creator>
    <dc:date>2019-03-27T15:24:54Z</dc:date>
    <item>
      <title>Activate PFS in a VPN community via API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/48861#M3210</link>
      <description>&lt;P&gt;Hello Checkpoint,&lt;/P&gt;&lt;P&gt;in the after Snowden aera,&amp;nbsp; we have learnt that perfect forward secrecy is one of the most important cryptographic features.&lt;/P&gt;&lt;P&gt;From the API documentation it is not clear how to activate PFS and how to select the PFS group when creating a VPN community or modifying an existing one.&lt;/P&gt;&lt;P&gt;Please Clarify: How can I activate PFS and select the PFS DH group via the API?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Christian Riede&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 15:09:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/48861#M3210</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-27T15:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Activate PFS in a VPN community via API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/48863#M3211</link>
      <description>&lt;P&gt;Hey Christian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The standard managment API (still) does not support the configuration that you need.&lt;/P&gt;&lt;P&gt;But&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9262"&gt;@Kim_Moberg&lt;/a&gt;&amp;nbsp;did a nice writeup regarding his solution via the generic objects API - see &lt;A href="https://community.checkpoint.com/t5/Developers-API-CLI/Missing-API-possibility-to-set-vpn-community-star-objects/td-p/20956" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 15:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/48863#M3211</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2019-03-27T15:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Activate PFS in a VPN community via API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/49000#M3219</link>
      <description>&lt;P&gt;Summary:&lt;/P&gt;&lt;P&gt;Get Community uid with:&lt;/P&gt;&lt;P&gt;mgmt_cli show vpn-community-star name "communityname"&lt;/P&gt;&lt;P&gt;Get DH group UIDs with:&lt;/P&gt;&lt;P&gt;mgmt_cli show generic-objects class-name com.checkpoint.objects.classes.dummy."CpmiIkeDiffieHellmanParametersObject"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then:&lt;/P&gt;&lt;P&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1EncAlg "AES_MINUS_256"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1HashAlg "SHA256"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1DhGrp "86ee63a3-cb9a-478e-add4-857aff8a7ab3"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1RekeyTime "1440"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2EncAlg "AES_MINUS_256"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2HashAlg "SHA256"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2RekeyTime "3600"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2UsePfs "true"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2PfsDhGrp "86ee63a3-cb9a-478e-add4-857aff8a7ab3"&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2EnableSupernetFromR8020 "FALSE"&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 10:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/49000#M3219</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-28T10:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Activate PFS in a VPN community via API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/49003#M3220</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summary:&lt;/P&gt;&lt;P&gt;find uid of community&lt;/P&gt;&lt;P&gt;mgmt_cli show vpn-community-star name "communityname"&lt;/P&gt;&lt;P&gt;find uid of dh group:&lt;/P&gt;&lt;P&gt;mgmt_cli show generic-objects class-name com.checkpoint.objects.classes.dummy."CpmiIkeDiffieHellmanParametersObject"&lt;/P&gt;&lt;P&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1EncAlg AES_MINUS_256&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1HashAlg SHA256&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1DhGrp 86ee63a3-cb9a-478e-add4-857aff8a7ab3&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP1.ikeP1RekeyTime 1440&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2EncAlg AES_MINUS_256&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2HashAlg SHA256&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2RekeyTime 3600&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2UsePfs true&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2PfsDhGrp 86ee63a3-cb9a-478e-add4-857aff8a7ab3&lt;BR /&gt;mgmt_cli set generic-object uid "uid-of-community" ikeP2.ikeP2EnableSupernetFromR8020 FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 10:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Activate-PFS-in-a-VPN-community-via-API/m-p/49003#M3220</guid>
      <dc:creator>Christian_Riede</dc:creator>
      <dc:date>2019-03-28T10:56:37Z</dc:date>
    </item>
  </channel>
</rss>

