<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ubiquiti Unifi and Check Point Integration in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66226#M4062</link>
    <description>&lt;P&gt;That.&amp;nbsp; Is SUPER COOL!&amp;nbsp; Great post!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2019 11:41:24 GMT</pubDate>
    <dc:creator>Tommy_Forrest</dc:creator>
    <dc:date>2019-10-30T11:41:24Z</dc:date>
    <item>
      <title>Ubiquiti Unifi and Check Point Integration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66216#M4061</link>
      <description>&lt;P&gt;Here is a simple way to integrate Ubiquiti Unifi systems into Check Point environments using the Unifi API and the Identity API. This solution will query the Unifi controller to gather details about the connected clients for a given Unifi site and/or ssid and create network IDs for each active client. In addition to better visibility, you can also configure Access Roles objects for these client identities to be used in the security policy. Since this is querying the Unifi controller you will need to always have the controller up and running in either a VM/container OR by using a cloud key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity in PDP table of the gateway. All of the details gathered from the Unifi controller are added into the Machine field. For this example a client machine named 'dilligj1-e7470' is active on the 'homenet' Unifi site and also connected to port #12 of the switch.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Client identity in pdp table of gateway" style="width: 531px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2918i055CC638DB12E275/image-size/large?v=v2&amp;amp;px=999" role="button" title="pdp entry.PNG" alt="Client identity in pdp table of gateway" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Client identity in pdp table of gateway&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example log inside SmartConsole showing machine identity. Using the search bar for logs you can also type any of the machine details to search the logs for clients connected to that Unifi site or switch.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log example.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2919i278CD904B991E62E/image-size/large?v=v2&amp;amp;px=999" role="button" title="log example.PNG" alt="log example.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to enforce rules based on Unifi sites and/or ssid you are able to create an access role object that represents the Unifi site name and ssid (if wireless clients). The name format for this is '&lt;SPAN style="font-family: inherit;"&gt;Unifi_&amp;lt;SITENAME&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;_&amp;lt;SSID&amp;gt;' for wireless and 'Unifi_&amp;lt;SITENAME&amp;gt;' for wired clients.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="access role example.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2917i014E78D125E87FA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="access role example.PNG" alt="access role example.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For usage examples and the code see my GitHub repository for this project:&amp;nbsp;&lt;A href="https://github.com/joe-at-cp/CPUnifi" target="_blank" rel="noopener"&gt;https://github.com/joe-at-cp/CPUnifi&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Enjoy!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:02:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66216#M4061</guid>
      <dc:creator>Joe_Dillig</dc:creator>
      <dc:date>2019-10-30T11:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ubiquiti Unifi and Check Point Integration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66226#M4062</link>
      <description>&lt;P&gt;That.&amp;nbsp; Is SUPER COOL!&amp;nbsp; Great post!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:41:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66226#M4062</guid>
      <dc:creator>Tommy_Forrest</dc:creator>
      <dc:date>2019-10-30T11:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ubiquiti Unifi and Check Point Integration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66228#M4063</link>
      <description>&lt;P&gt;Thanks, I hope its useful for you! I am using it at home right now and its nice to have the visibility in my Check Point logs as to what device on my network is acting up. I have many more plans for the integration where identified threats by Check Point will be blocked from network access by the same script talking back to the Unifi Controller. Some cool things to come with this&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:47:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66228#M4063</guid>
      <dc:creator>Joe_Dillig</dc:creator>
      <dc:date>2019-10-30T11:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ubiquiti Unifi and Check Point Integration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66608#M4074</link>
      <description>&lt;P&gt;I'm really looking forward to seeing how you'll pass that information back and forth via the ubiquiti api.&amp;nbsp; Can't wait to see what you guys come up with.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 15:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Ubiquiti-Unifi-and-Check-Point-Integration/m-p/66608#M4074</guid>
      <dc:creator>Larry_Chisholm</dc:creator>
      <dc:date>2019-11-05T15:17:41Z</dc:date>
    </item>
  </channel>
</rss>

