<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global vs Local rule bases in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96867#M5159</link>
    <description>&lt;P&gt;Is it possible to extract the global and local rules within a CMA with one API call? Or is it a requirement to extract both separately and then "insert" the local rules into the "Placeholder for domain rules" section? I am attempting to emulate what was delivered using cp_merge.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 14:24:12 GMT</pubDate>
    <dc:creator>mikesleath</dc:creator>
    <dc:date>2020-09-16T14:24:12Z</dc:date>
    <item>
      <title>Global vs Local rule bases</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96867#M5159</link>
      <description>&lt;P&gt;Is it possible to extract the global and local rules within a CMA with one API call? Or is it a requirement to extract both separately and then "insert" the local rules into the "Placeholder for domain rules" section? I am attempting to emulate what was delivered using cp_merge.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 14:24:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96867#M5159</guid>
      <dc:creator>mikesleath</dc:creator>
      <dc:date>2020-09-16T14:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global vs Local rule bases</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96876#M5160</link>
      <description>&lt;P&gt;I think I have answered my own question.... the "local" rules query will contain the global rules, but the rule base is not in the order I was expecting.... global-pre-local and global-post-local are included prior to the local rules but not included in the "total". Apologies for not digging in more detail before posting.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 16:19:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96876#M5160</guid>
      <dc:creator>mikesleath</dc:creator>
      <dc:date>2020-09-16T16:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global vs Local rule bases</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96883#M5161</link>
      <description>&lt;P&gt;You can only get the Domain you have logged into from the API, so when you need the Global rules, you need to collect them from the MDS level domain. For each domain/CMA you need to login with the -d parameter to get the info from that specific domain/CMA. And this cannot be done within the same call.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 17:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96883#M5161</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-09-16T17:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global vs Local rule bases</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96907#M5164</link>
      <description>&lt;P&gt;I think the domain will also show me the global rules that have been assigned. I need to make two calls like this&lt;/P&gt;&lt;P&gt;to get global policy rules as currently assigned to domain&lt;/P&gt;&lt;P&gt;&lt;FONT face="terminal,monaco"&gt;&lt;SPAN&gt;mgmt_cli -d DOMAIN1 -r true show access-rulebase name "DOMAIN1_GlobalPol&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Security" limit 100 use-object-dictionary true --format json&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;to get local rules for the domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="terminal,monaco"&gt;&lt;SPAN&gt;mgmt_cli -d DOMAIN1 -r true show access-rulebase name "DOMAIN1_LocalPol&amp;nbsp;Security" limit 100 use-object-dictionary true --format json&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can combine the results and "insert" the local rule at the "place holder for domain rules slot" but was wondering if there was a command to pull back the combined rule base as cp_merge did previously?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I connect to the MDS level and extract the global rules, i get the view of the rules at the MDS level which, in some circumstances, may not match that which is assigned to the domain level.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 06:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Global-vs-Local-rule-bases/m-p/96907#M5164</guid>
      <dc:creator>mikesleath</dc:creator>
      <dc:date>2020-09-17T06:16:18Z</dc:date>
    </item>
  </channel>
</rss>

