<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I turn on IA from mgmt_cli? in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94668#M5124</link>
    <description>&lt;P&gt;This might have to be done with dbedit itself, though I'm not sure of the syntax there either.&lt;BR /&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37502"&gt;@Omer_Kleinstern&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2020 23:46:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-19T23:46:03Z</dc:date>
    <item>
      <title>How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94658#M5123</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;--&amp;gt; How do I turn on IA from mgmt_cli?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Actually my question is really more general. &amp;nbsp;The gw object contains a field &lt;FONT face="courier new,courier"&gt;identityAwareBlade&lt;/FONT&gt;, which when used contains an owned object. &amp;nbsp;Within that is a field&amp;nbsp;&lt;FONT face="courier new,courier"&gt;identityAwareBladeInstalled&lt;/FONT&gt; with a simple string value to say whether it is turned on.&lt;/P&gt;&lt;P&gt;If you have enabled and disabled the blade, then the object is in place and the blade can be flipped with the&amp;nbsp;&lt;FONT face="courier new,courier"&gt;identityAwareBladeInstalled&lt;/FONT&gt; field. &amp;nbsp;If it's never been turned on, then the owned object is not present.&lt;/P&gt;&lt;P&gt;So my question is really more general than IA. &amp;nbsp;It is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;--&amp;gt; How do you create a single owned object?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I know how to create an owned object in an array - this is well documented for adding interfaces:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;set generic-object uid FWUID interfaces.add.create "com.checkpoint.objects.classes.dummy.CpmiClusterInterface" \&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; interfaces.add.owned-object.netmask "255.255.255.0" \&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; interfaces.add.owned-object.ipaddr 22.22.22.22&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;But in this case there is no array. &amp;nbsp;I also cannot even try the same syntax because fishing inside the &lt;FONT face="courier new,courier"&gt;identityAwareBlade&lt;/FONT&gt; field in a working IA installation does not reveal an object class, which would be required to experiment with the above syntax. There is an objectclass in dbedit but that's not very useful as there is some guesswork in translating between the two.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So I'm stuck. &amp;nbsp;Any help would be appreciated! Thanks!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(Follow-on question... is there a table of object schema anywhere?)&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 22:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94658#M5123</guid>
      <dc:creator>Greg_Harewood</dc:creator>
      <dc:date>2020-08-19T22:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94668#M5124</link>
      <description>&lt;P&gt;This might have to be done with dbedit itself, though I'm not sure of the syntax there either.&lt;BR /&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37502"&gt;@Omer_Kleinstern&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 23:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94668#M5124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-19T23:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94706#M5125</link>
      <description>&lt;P&gt;I wouldn't recommend turning on the Identity Awareness blade using the generic API.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if we got exactly all the changes that are done in the DB on the GW object, there are other logics that are executed during the enablement of this blade which are not straight forward, and require some thorough investigation to get correctly.&lt;/P&gt;&lt;P&gt;Providing a formal API to enable and configure this blade is on our roadmap, and should be available in future versions, however I can't say exactly when at the moment&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 07:54:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94706#M5125</guid>
      <dc:creator>Uriel_F</dc:creator>
      <dc:date>2020-08-20T07:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94717#M5126</link>
      <description>&lt;P&gt;So I've got as far as...&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;set generic-object uid FWUID identityAwareBlade.create "com.checkpoint.objects.classes....identityAwareBlade??" \&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; identityAwareBlade.identityAwareBladeInstalled INSTALLED&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;This gets me forward a little, having found the syntax for adding a single owned object not in an array. &amp;nbsp;But I still need the object class name.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6754"&gt;@Uriel_F&lt;/a&gt;&amp;nbsp;- I appreciate your looking at your caution. &amp;nbsp;What I didn't say is that I got a start on this from&amp;nbsp;&lt;STRONG&gt;Yevgeniy Yeryomin&lt;/STRONG&gt;&amp;nbsp;who gave me a relevant ansible runbook that he's used before. &amp;nbsp;He's either not worried about side effects for our application, or the engine that processes the ansible runbook is doing some other magic that I need to get to the bottom of. In any case the relevant section is...&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;EM&gt;##&amp;nbsp;Step&amp;nbsp;10:&amp;nbsp;Modify&amp;nbsp;gateway&amp;nbsp;object,&amp;nbsp;IDA&amp;nbsp;blade&amp;nbsp;parameters&lt;BR /&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;-&amp;nbsp;name:&amp;nbsp;"Modify&amp;nbsp;gateway&amp;nbsp;object,&amp;nbsp;IDA&amp;nbsp;blade&amp;nbsp;parameters"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;check_point_mgmt:&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;command:&amp;nbsp;set-generic-object&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;parameters:&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;uid:&amp;nbsp;"{{&amp;nbsp;gwuid&amp;nbsp;}}"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;identityAwareBlade:&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;identityAwareBladeInstalled:&amp;nbsp;"INSTALLED"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enableIdaApi:&amp;nbsp;"true"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;shareIdentitiesWithOtherGateways:&amp;nbsp;"false"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enableOtherGateways:&amp;nbsp;"false"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;iaMaxAuthenticatedUsers:&amp;nbsp;"70000"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;iaMaxEnforcedIdentities:&amp;nbsp;"70000"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;cccMaxMsgSize:&amp;nbsp;"65535"&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;publishMethod:&amp;nbsp;"PUSH"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;There's a bit more to it but you can see that for our application we are going to have a very simple configuration that relies only on a pdp/pep share from another gateway, which is possibly why we can get away with enabling it this way.&lt;/P&gt;&lt;P&gt;Please help me with the object class so that I can convert the script. &amp;nbsp;I'm not sure what magic ansible is pulling not to need to know it, but mgmt_cli and web_api both seem to need it and cannot magically guess what kind of object goes in here.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 09:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/94717#M5126</guid>
      <dc:creator>Greg_Harewood</dc:creator>
      <dc:date>2020-08-20T09:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/95024#M5131</link>
      <description>&lt;P&gt;So the answer is...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="ruby"&gt;cat &amp;gt; dbEdit.tmp &amp;lt;&amp;lt;EOF
modify network_objects ${GWNAME} identity_aware_blade identity_aware_blade
modify network_objects ${GWNAME} identity_aware_blade:identity_aware_blade_installed installed
update_all
EOF

dbedit -s ${DOMAINIP} -u "${SCRIPTUSER}" -p "${SCRIPTPASS}" -f dbEdit.tmp&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It requires side effects and dbedit seems to be the one supported scripting choice that already includes the correct side effects when enabling IA.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 10:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/95024#M5131</guid>
      <dc:creator>Greg_Harewood</dc:creator>
      <dc:date>2020-08-24T10:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/128000#M6180</link>
      <description>&lt;P&gt;Any update on the formal API implementation? I checked R81.10 and didn't find any IA feature here either.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to share the API roadmap? It would at least temper expectations.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 17:04:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/128000#M6180</guid>
      <dc:creator>Harald_Hansen</dc:creator>
      <dc:date>2021-08-25T17:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129828#M6256</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I've followed some of the tips here and with a little trial and error, got IA enabled using only the API. Usual disclaimer applies when using the generic object approaches of course, but this works and is consistent when applied automatically. This is an excerpt from a larger Ansible playbook - but the general flow is:&lt;/P&gt;
&lt;P&gt;- Get the UID of the gateway you're enabling IA on (in this case, it's a VS).&lt;/P&gt;
&lt;P&gt;- Create a localhost object with the IP of 127.0.0.1&lt;/P&gt;
&lt;P&gt;- Capture the UID for this (or look up the UID of an object if one exists)&lt;/P&gt;
&lt;P&gt;- Set the IA properties on the gateway with its UID, observing the proper formatting and schema structure. In this instance, I used the web API because it will accept JSON formatted data which is a lot easier to interpret than the mgmt_cli something.1 format (for me, at least).&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;- name: Create localhost object for IDA whitelist
 hosts: chkpmds
 gather_facts: no
 connection: httpapi
 vars:
 ansible_ssh_user:
 ansible_ssh_pass:
 ansible_ssh_common_args:
 tasks:
 - name: Create cloudguard_local object
 check_point.mgmt.cp_mgmt_host:
 auto_publish_session: true
 name: cloudguard_local
 ipv4_address: 127.0.0.1
 state: present
 
 - name: Configure Identity Awareness
 gather_facts: no
 hosts: chkpmds
 connection: httpapi
 vars:
 ansible_ssh_user:
 ansible_ssh_pass:
 tasks:
 - name: get localhost object UID
 check_point.mgmt.cp_mgmt_host_facts:
 name: cloudguard_local
 - name: get FW obj UID
 check_point.mgmt.checkpoint_object_facts:
 object_filter: "{{ vs_name }}"
 - name: UID for VS_1
 ansible.builtin.debug:
 var: ansible_facts.checkpoint_objects.objects.0.uid
 verbosity: 2
 - name: UID for localhost obj
 ansible.builtin.debug:
 var: ansible_facts.host.uid
 verbosity: 2
 
  - name: Set properties of IA object
 uri:
 url: https://[mgmt IP]/web_api/v1.7/set-generic-object
 method: POST
 body_format: json
 headers:
 X-chkp-sid: "{{ login_token_details.json.sid }}"
 validate_certs: no
 body: '{"uid":"{{ ansible_facts.checkpoint_objects.objects.0.uid }}","identityAwareBlade":{"create":"com.checkpoint.objects.classes.dummy.CpmiIdentityAwareBlade","owned-object":{"idaApiSettings":{"idaApiClientVerificationSettings":[]},"enableIdaApi":"True","idcSettings":[],"isCollectingIdentities":"True","identityAwareBladeInstalled":"INSTALLED"}}}'
 - name: Set properties of IA object
 uri:
 url: https://[mgmt IP]/web_api/v1.7/set-generic-object
 method: POST
 body_format: json
 headers:
 X-chkp-sid: "{{ login_token_details.json.sid }}"
 validate_certs: no
 body: '{"uid":"{{ ansible_facts.checkpoint_objects.objects.0.uid }}","identityAwareBlade":{"idaApiSettings":{"idaApiClientVerificationSettings":[{"create":"com.checkpoint.objects.identity_awareness_classes.dummy.CpmiIdentityAwareClientVerificationEntry","owned-object":{"preSharedSecret":"sausage123","whiteListClient":"{{ ansible_facts.host.uid }}"}}]}}}'&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This gets the settings added to the object, then you need to install policy (or for a VS, make a dummy change via vsx_provisioning_tool to 'push' the config).&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 09:05:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129828#M6256</guid>
      <dc:creator>StuartGreen</dc:creator>
      <dc:date>2021-09-21T09:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129870#M6258</link>
      <description>&lt;P&gt;Wow, nicely done!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 16:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129870#M6258</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-21T16:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I turn on IA from mgmt_cli?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129904#M6263</link>
      <description>&lt;P&gt;Just updating that we are planning to include official Identity Awareness Management APIs to the gateway / cluster object in the upcoming R81.20.&lt;/P&gt;
&lt;P&gt;You are more than welcome to join the EA to try it out, or reach out to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9401"&gt;@Alon_Alapi&lt;/a&gt;&amp;nbsp;for more info.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 05:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/How-do-I-turn-on-IA-from-mgmt-cli/m-p/129904#M6263</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2021-09-22T05:10:53Z</dc:date>
    </item>
  </channel>
</rss>

