<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inventory MDS for log4j configuration in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Inventory-MDS-for-log4j-configuration/m-p/136583#M6510</link>
    <description>&lt;P&gt;I believe you need to use ips stat on the command line of the gateway to see precisely what profile is in use.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Threat-Prevention/Command-IPS-for-showing-profile-used/m-p/136272#M3460" target="_blank"&gt;https://community.checkpoint.com/t5/Threat-Prevention/Command-IPS-for-showing-profile-used/m-p/136272#M3460&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have a feeling the "detect only" setting is a setting that would only be findable with a generic object and it certainly wouldn't work in the VSX case.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2021 23:58:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-12-16T23:58:50Z</dc:date>
    <item>
      <title>Inventory MDS for log4j configuration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Inventory-MDS-for-log4j-configuration/m-p/136315#M6503</link>
      <description>&lt;P&gt;Hey guys.&amp;nbsp; I'm looking to write a script to identify each firewall managed by and mds for the following information:&amp;nbsp;&lt;/P&gt;&lt;P&gt;CMA Name, Firewall Name, Is IPS in Detect Mode true/false, Assigned IPS Profile, Profile Setting for log4J&lt;/P&gt;&lt;P&gt;CMA Name, Firewall Name are easy, done, no issues&lt;/P&gt;&lt;P&gt;I found how to grab the log4j setting:&lt;/P&gt;&lt;P&gt;mgmt_cli -r true show threat-protection name "Apache Log4j Remote Code Execution (CVE-2021-44228)" --domain x.x.x.x show-profiles true&lt;/P&gt;&lt;P&gt;and If IPS is enabled or not:&lt;/P&gt;&lt;P&gt;mgmt_cli -r true show simple-gateway name "fw name" --domain x.x.x.x | grep ips&lt;BR /&gt;ips: true&lt;/P&gt;&lt;P&gt;The parts I need help with are finding;&lt;/P&gt;&lt;P&gt;1. for each GW object is IPS set to "Detect Only" or not&lt;/P&gt;&lt;P&gt;2. What is the assigned IPS profile for a specific GW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has any clues they can drops that would be fantastic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 18:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Inventory-MDS-for-log4j-configuration/m-p/136315#M6503</guid>
      <dc:creator>Douglas_Rich</dc:creator>
      <dc:date>2021-12-14T18:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Inventory MDS for log4j configuration</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Inventory-MDS-for-log4j-configuration/m-p/136583#M6510</link>
      <description>&lt;P&gt;I believe you need to use ips stat on the command line of the gateway to see precisely what profile is in use.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Threat-Prevention/Command-IPS-for-showing-profile-used/m-p/136272#M3460" target="_blank"&gt;https://community.checkpoint.com/t5/Threat-Prevention/Command-IPS-for-showing-profile-used/m-p/136272#M3460&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have a feeling the "detect only" setting is a setting that would only be findable with a generic object and it certainly wouldn't work in the VSX case.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 23:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Inventory-MDS-for-log4j-configuration/m-p/136583#M6510</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-16T23:58:50Z</dc:date>
    </item>
  </channel>
</rss>

