<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add objectX to rule where objectY exists ? in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139587#M6564</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if this is what you are referring to, but you could use following Management API commands:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-access-rule~v1.8%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-access-rule~v1.8%20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can add the relevant objects / servers to a Network Group and then add it to the rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is not what you are referring to please elaborate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Tal&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jan 2022 13:13:34 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2022-01-26T13:13:34Z</dc:date>
    <item>
      <title>Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139579#M6561</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are moving a lot of servers and I would like to add the new objects next to the old ones in the ruleset.&lt;BR /&gt;&lt;BR /&gt;I still have to keep the old ones for a while though so I can not just change the IPs of the objects itself.&lt;/P&gt;&lt;P&gt;So the thing is that now we have an OLDobject with IP 1.1.1.1 and a NEWobject with IP 2.1.1.1.&lt;BR /&gt;There is rule 1 and 145 and 645 where&amp;nbsp;OLDobject as source is present, and I would like to add the&amp;nbsp;NEWobject next to it.&amp;nbsp;&lt;BR /&gt;If I do it manually I have to go over the ruleset and I really would like to not do that. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;That's why I asked the automation, becuase real life is this sample x 100.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Grouping is not really a nice option in my opinion either, because when all the tests ran I have to remove the&amp;nbsp;OLDobject anyway, which would leave a group as source with one member in it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 09:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139579#M6561</guid>
      <dc:creator>lbalogh</dc:creator>
      <dc:date>2022-01-27T09:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139582#M6562</link>
      <description>&lt;P&gt;I dont see why not, as long as there are no IP conflicts. You can try few and then do rule base verification to see if it gives you any warning/errors. I would not be too concerned about warnings, unless its something super important.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 12:27:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139582#M6562</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-26T12:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139584#M6563</link>
      <description>&lt;P&gt;I mean via API or something automated way, becuase I have many to do so.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 12:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139584#M6563</guid>
      <dc:creator>lbalogh</dc:creator>
      <dc:date>2022-01-26T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139587#M6564</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if this is what you are referring to, but you could use following Management API commands:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-access-rule~v1.8%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-access-rule~v1.8%20&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can add the relevant objects / servers to a Network Group and then add it to the rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is not what you are referring to please elaborate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Tal&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 13:13:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139587#M6564</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-01-26T13:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139588#M6565</link>
      <description>&lt;P&gt;Ok, sorry, did not realize there were so many...in that case,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;is correct. API is your best option here.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 13:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139588#M6565</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-26T13:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139675#M6567</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Yes, I would like to avoid grouping.&amp;nbsp;&lt;BR /&gt;So the thing is that now we have an OLDobject with IP 1.1.1.1 and a NEWobject with IP 2.1.1.1.&lt;BR /&gt;There is rule 1 and 145 and 645 where&amp;nbsp;OLDobject as source is present, and I would like to add the&amp;nbsp;NEWobject next to it.&amp;nbsp;&lt;BR /&gt;If I do it manually I have to go over the ruleset and I really would like to not do that. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;That's why I asked the automation, becuase real life is this sample x 100.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Grouping is not really a nice option in my opinion either, because when all the tests ran I have to remove the&amp;nbsp;OLDobject anyway, which would leave a group as source with one member in it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hope this makes more sense, yesterday I was way-way more tired than this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 09:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139675#M6567</guid>
      <dc:creator>lbalogh</dc:creator>
      <dc:date>2022-01-27T09:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139686#M6568</link>
      <description>&lt;P&gt;You would use set-access-rule as noted by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt; to actually change the rules.&lt;BR /&gt;Or are you looking for a programmatic way to find the rules that you need to modify?&lt;BR /&gt;In that case, you probably want to use the where-used API call to find the specific instances where the old object is used and then use set-access-rule to update the rules accordingly.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 12:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139686#M6568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-01-27T12:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139708#M6570</link>
      <description>&lt;P&gt;I would attack this with a script which works like this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ingest pairs of IPs. Old first, then new.&lt;/LI&gt;
&lt;LI&gt;Log in to the management via the API.&lt;/LI&gt;
&lt;LI&gt;For each IP pair, create an object for the new IP if one doesn't exist. Save the new object's UUID. Find all existing objects with the old IP and save their UUIDs.&lt;/LI&gt;
&lt;LI&gt;For each old object, run 'where-used'.&lt;/LI&gt;
&lt;LI&gt;For each resulting access rule, if it's in the source, use the rule UUID and layer UUID to call 'set access-rule source.add' with the new object's UUID.&lt;/LI&gt;
&lt;LI&gt;Repeat for the destination, calling 'set access-rule destination.add'.&lt;/LI&gt;
&lt;LI&gt;For each resulting group, use the group UUID to call 'set group members.add' with the new object's UUID.&lt;/LI&gt;
&lt;LI&gt;After dealing with each pair, publish.&lt;/LI&gt;
&lt;LI&gt;After dealing with all pairs, log out.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;NAT rules are more complex, as they can't have multiple objects in fields. I think I would look for the old object in each field, one at a time, then copy the other fields to a new NAT rule which I add to the policy package immediately below the old NAT rule. If you don't use them in NAT rules directly, then you can skip all that.&lt;/P&gt;
&lt;P&gt;This also wouldn't handle other objects-which-reference-objects situations like Access Roles. Should get you &amp;gt;90% of the way there, though.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 15:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/139708#M6570</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-01-27T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/178600#M7629</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;did someone manage to create such a script and would be willing to share it? I would be very grateful!&lt;BR /&gt;&lt;BR /&gt;KR&lt;BR /&gt;Rok&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/178600#M7629</guid>
      <dc:creator>Mlinko</dc:creator>
      <dc:date>2023-04-20T09:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/204499#M8323</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;+1&lt;/P&gt;&lt;P&gt;I would like has a way to add a newobject in the rule is exists an old object too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some checkpoint expert has an script to perform that requeriment? I think that is a great challenge for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see that&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/How-can-I-quickly-move-from-many-objects-in-many-rules-to-a/td-p/13274" target="_blank"&gt;https://community.checkpoint.com/t5/Management/How-can-I-quickly-move-from-many-objects-in-many-rules-to-a/td-p/13274&lt;/A&gt;. But, sometimes its bettter have both objects than a group object.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/204499#M8323</guid>
      <dc:creator>chymmmy</dc:creator>
      <dc:date>2024-01-30T08:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Add objectX to rule where objectY exists ?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/204586#M8324</link>
      <description>&lt;P&gt;set&amp;nbsp;access-rule command works just fine with adding additional objects, I don't think that writing a script should be too complicated if you have experience with this.&lt;/P&gt;
&lt;P&gt;Just for syntax reference, I used the following:&lt;/P&gt;
&lt;P&gt;mgmt_cli set access-rule layer "Network" -r true rule-number 1 dst.add Host1&lt;/P&gt;
&lt;P&gt;mgmt_cli set access-rule layer "Network" -r true rule-number 1 dst.add Host2&lt;/P&gt;
&lt;P&gt;This added dst to a rule and the second added the second host without subtracting the first one, means this command should be suitable for you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 17:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Add-objectX-to-rule-where-objectY-exists/m-p/204586#M8324</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2024-01-30T17:18:52Z</dc:date>
    </item>
  </channel>
</rss>

