<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating multiple remote Gateway for IPsec VPN in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8127#M670</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any one to comment on ? my migration is stuck based on this &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Oct 2017 10:40:22 GMT</pubDate>
    <dc:creator>SD_Networking</dc:creator>
    <dc:date>2017-10-30T10:40:22Z</dc:date>
    <item>
      <title>Creating multiple Remote Gateways/Interoperable Devices for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8125#M668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to create multiple 3rd party remote gateway for IPsec VPN, i can create the object via Smartdashboard by&lt;/P&gt;&lt;P&gt;Object Exporer --&amp;gt; New--Network Object--More ---Interoperable Devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot find, how can i do it via Script ? any one has worked on migration of VPN customers from ASA to Checkpoint ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 09:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8125#M668</guid>
      <dc:creator>SD_Networking</dc:creator>
      <dc:date>2017-10-26T09:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8126#M669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the answer here:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/community/checkmates-live/blog/2017/09/02/i-am-dorit-dor-vp-of-products-for-check-point-ask-me-anything?commentID=2561#comment-2467" title="https://community.checkpoint.com/community/checkmates-live/blog/2017/09/02/i-am-dorit-dor-vp-of-products-for-check-point-ask-me-anything?commentID=2561#comment-2467"&gt;https://community.checkpoint.com/community/checkmates-live/blog/2017/09/02/i-am-dorit-dor-vp-of-products-for-check-point…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still i cannot create the objects as i can't find correct syntax to create new object, this comment do provide how to edit but not how to create new, i am getting following error.&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt; "code": "generic_err_missing_required_parameters",&lt;BR /&gt; "message": "Missing parameter: [create]"&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;Not sure, wht should be the value of create ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 11:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8126#M669</guid>
      <dc:creator>SD_Networking</dc:creator>
      <dc:date>2017-10-26T11:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8127#M670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any one to comment on ? my migration is stuck based on this &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Oct 2017 10:40:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8127#M670</guid>
      <dc:creator>SD_Networking</dc:creator>
      <dc:date>2017-10-30T10:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8128#M671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm curious how your upgrade is stuck on this as I&amp;nbsp;do not believe this was possible in R77.x (but could be wrong).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, let me see if we can get the create scripts that were promised in the AMA posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Oct 2017 23:34:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8128#M671</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-30T23:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8129#M672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, my migration is stuck as i cant make huge number of Interoperable objects &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;via api, and dont want to do it manually one by one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was just curious if checkpoint will release the script promised in another post, it will make my life easier &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 07:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8129#M672</guid>
      <dc:creator>SD_Networking</dc:creator>
      <dc:date>2017-10-31T07:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8130#M673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is how it can be done using the "Generic-Object" API:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a basic Interoperable device with given name "interdev_2" and IP address "10.1.1.2"&lt;BR /&gt;=====================================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mgmt_cli add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" name "interdev_2" ipaddr "10.1.1.2" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" vpn.owned-object.isakmpUniversalSupport "True"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTPUT:&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;{ &lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain",&lt;BR /&gt; "name" : "interdev_2",&lt;BR /&gt; "ipaddr" : "10.1.1.2",&lt;BR /&gt; "thirdPartyEncryption" : true,&lt;BR /&gt; "osInfo" : {&lt;BR /&gt; "osName" : "Gaia"&lt;BR /&gt; },&lt;BR /&gt; "vpn" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpn",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; &lt;BR /&gt; "vpnClientsSettingsForGateway" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnClientSettings" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnEnable" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "ike" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiIke"&lt;BR /&gt; },&lt;BR /&gt; "sslNe" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "sslEnable" : false,&lt;BR /&gt; "gwCertificate" : "defaultCert"&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "isakmpUniversalSupport" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create Interoperable device with the given name "interdev_2" and IP address "10.1.1.2", also add interface:&lt;BR /&gt;==================================================================================&lt;BR /&gt;Added interfaces list section with interface:&lt;BR /&gt; - name eth0&lt;BR /&gt; - IP Address 10.1.1.1&lt;BR /&gt; - netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mgmt_cli -s id.txt add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" name "interdev_2" ipaddr "10.1.1.2" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" vpn.owned-object.isakmpUniversalSupport "True" interfaces.add.1.create "com.checkpoint.objects.classes.dummy.CpmiInterface" interfaces.add.1.owned-object.officialname "eth0" interfaces.add.1.owned-object.ipaddr "10.1.1.1" interfaces.add.1.owned-object.netmask "255.255.255.0" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTPUT:&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;{ &lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain",&lt;BR /&gt; "name" : "interdev_2",&lt;BR /&gt; "ipaddr" : "10.1.1.2",&lt;BR /&gt; "thirdPartyEncryption" : true,&lt;BR /&gt; "osInfo" : {&lt;BR /&gt; "osName" : "Gaia"&lt;BR /&gt; },&lt;BR /&gt; "vpn" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpn",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; &lt;BR /&gt; "vpnClientsSettingsForGateway" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnClientSettings" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnEnable" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "ike" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiIke"&lt;BR /&gt; },&lt;BR /&gt; "sslNe" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "sslEnable" : false,&lt;BR /&gt; "gwCertificate" : "defaultCert"&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "isakmpUniversalSupport" : true&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "interfaces" : {&lt;BR /&gt; "add" : [&lt;BR /&gt; {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiInterface",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "officialname" : "eth0",&lt;BR /&gt; "ipaddr": "10.1.1.1",&lt;BR /&gt; "netmask": "255.255.255.0"&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; ]&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Topology settings - Create Interoperable device with the given name "interdev_2" and IP address "10.1.1.2", also add interface.&lt;BR /&gt;=========================================================================================&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The topology of the added interface was set to be behind the given network (in my case - CP_default_Office_Mode_addresses_pool).&lt;/P&gt;&lt;P&gt;In an interface object, the field: security.netaccess.access set to "SPECIFIC" and&lt;BR /&gt;security.netaccess.allowed is set to UID of the required network object.&lt;/P&gt;&lt;P&gt;Use the following Bash command to find out the UID of the required network, i.e. : CP_default_Office_Mode_addresses_pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;local_network=$(mgmt_cli -s id.txt show-generic-objects name CP_default_Office_Mode_addresses_pool -f json | /opt/CPshrd-R80/jq/jq -r '.objects[] | select (.type | contains("network")) | .uid')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mgmt_cli -s id.txt add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" name "interdev_2" ipaddr "10.1.1.2" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" vpn.owned-object.isakmpUniversalSupport "True" interfaces.add.1.create "com.checkpoint.objects.classes.dummy.CpmiInterface" interfaces.add.1.owned-object.officialname "eth0" interfaces.add.1.owned-object.ipaddr "10.1.1.1" interfaces.add.1.owned-object.netmask "255.255.255.0" interfaces.add.1.owned-object.security.netaccess.access "SPECIFIC" interfaces.add.1.owned-object.security.netaccess.allowed $local_network interfaces.add.1.owned-object.security.netaccess.performAntiSpoofing "True" interfaces.add.1.owned-object.security.antispoof "True"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTPUT:&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;{ &lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain",&lt;BR /&gt; "name" : "interdev_2",&lt;BR /&gt; "ipaddr" : "10.1.1.2",&lt;BR /&gt; "thirdPartyEncryption" : true,&lt;BR /&gt; "osInfo" : {&lt;BR /&gt; "osName" : "Gaia"&lt;BR /&gt; },&lt;BR /&gt; "vpn" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpn",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; &lt;BR /&gt; "vpnClientsSettingsForGateway" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnClientSettings" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnEnable" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "ike" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiIke"&lt;BR /&gt; },&lt;BR /&gt; "sslNe" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "sslEnable" : false,&lt;BR /&gt; "gwCertificate" : "defaultCert"&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "isakmpUniversalSupport" : true&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "interfaces" : {&lt;BR /&gt; "add" : [&lt;BR /&gt; {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiInterface",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "officialname" : "eth0",&lt;BR /&gt; "ipaddr": "10.1.1.1",&lt;BR /&gt; "netmask": "255.255.255.0",&lt;BR /&gt; "security" : {&lt;BR /&gt; "netaccess" : {&lt;BR /&gt; "access" : "SPECIFIC",&lt;BR /&gt; "allowed" : "065e3266-f32a-4bec-9eee-7947888ad122",&lt;BR /&gt; "performAntiSpoofing": true&lt;BR /&gt; },&lt;BR /&gt; "antispoof" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; ]&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create Interoperable device with the given name "interdev_2" and IP address "10.1.1.2", also set Manually Defined VPN encryption domain&lt;BR /&gt;===========================================================================================&lt;BR /&gt;Set encdomain to be MANUAL.&lt;BR /&gt;Set manualEncdomain field to hold the UID of the required network.&lt;BR /&gt;Use the following Bash command to find out the UID of the required network, i.e. : CP_default_Office_Mode_addresses_pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpn_enc_domain=$(mgmt_cli -s id.txt show-generic-objects name CP_default_Office_Mode_addresses_pool -f json | /opt/CPshrd-R80/jq/jq -r '.objects[] | select (.type | contains("network")) | .uid')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mgmt_cli -s id.txt add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" name "interdev_2" ipaddr "10.1.1.2" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" manualEncdomain $vpn_enc_domain encdomain "MANUAL"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTPUT:&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;{ &lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain",&lt;BR /&gt; "name" : "interdev_2",&lt;BR /&gt; "ipaddr" : "10.1.1.2",&lt;BR /&gt; "thirdPartyEncryption" : true,&lt;BR /&gt; "osInfo" : {&lt;BR /&gt; "osName" : "Gaia"&lt;BR /&gt; },&lt;BR /&gt; "vpn" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpn",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; &lt;BR /&gt; "vpnClientsSettingsForGateway" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnClientSettings" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "endpointVpnEnable" : true&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "ike" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiIke"&lt;BR /&gt; },&lt;BR /&gt; "sslNe" : {&lt;BR /&gt; "create" : "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender",&lt;BR /&gt; "owned-object" : {&lt;BR /&gt; "sslEnable" : false,&lt;BR /&gt; "gwCertificate" : "defaultCert"&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; }&lt;BR /&gt; },&lt;BR /&gt; "manualEncdomain" : "065e3266-f32a-4bec-9eee-7947888ad122",&lt;BR /&gt; "encdomain" : "MANUAL"&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ENJOY!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 09:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8130#M673</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2017-10-31T09:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8131#M674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks man &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2017 09:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8131#M674</guid>
      <dc:creator>SD_Networking</dc:creator>
      <dc:date>2017-11-02T09:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8132#M675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;An important disclaimer!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 14px;"&gt;These APIs provide direct access to different objects and fields in the database. As a result, when the objects schema change, scripts that rely on specific schema fields may break.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The usage of generic-object API is similar to use dbedit script allowing customers to manipulate the Check Point database. The generic-object API calls are supported calls that customers are allowed to use. However, if a customer writes a script using generic-object API calls and later that script is “broken” because Check Point had changed the schema of the database. Check Point TAC will not be responsible for adjusting the customer’s script to use the new schema.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; font-size: 14px; margin: 10px 0px 0px;"&gt;When you have the option, always use the documented APIs and not the generic APIs:&lt;/P&gt;&lt;UL style="color: #333333; background-color: #ffffff; font-size: 14px; margin: 10px 0px 0px;"&gt;&lt;LI&gt;They are documented&lt;/LI&gt;&lt;LI&gt;They are future compatible&lt;/LI&gt;&lt;LI&gt;They are tested&lt;/LI&gt;&lt;LI&gt;They have owners and you can get support if you run into trouble&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 10:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8132#M675</guid>
      <dc:creator>Amiad_Stern</dc:creator>
      <dc:date>2018-02-21T10:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple Remote Gateways/Interoperable Devices for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8133#M676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need to add that interoperable device as a center/satellite gateway to a VPN community, follow my post in this thread -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/7668-how-to-add-interoperative-device-via-api"&gt;https://community.checkpoint.com/thread/7668-how-to-add-interoperative-device-via-api&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 11:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/8133#M676</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-05-01T11:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144808#M6669</link>
      <description>&lt;P&gt;Hey Robert first thank you for this. I do have a question how would we do a batch on this? let say I have a list of 100 objects with name and IP's. I was trying a CVS and running a batch. Just an example&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt_cli add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" vpn.owned-object.isakmpUniversalSupport "True" --batch ssg_test1.csv&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt_cli add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" --batch ssg_test1.csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;both didn't get anywhere so I'm just trying to get this batch working. Any feedback would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 19:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144808#M6669</guid>
      <dc:creator>Francisco_Melo</dc:creator>
      <dc:date>2022-03-25T19:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144811#M6670</link>
      <description>&lt;P&gt;What did the file precisely look like and what precise results did you get?&lt;BR /&gt;I suspect this may not be supported with generic objects.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 22:07:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144811#M6670</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-25T22:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144898#M6679</link>
      <description>&lt;P&gt;name ,ipaddr&lt;BR /&gt;Ahemadnagar_India_VRoom,172.18.201.250&lt;BR /&gt;Airdrie_Alberta_Canada_VRoom,151.110.77.19&lt;BR /&gt;Aldridge_UK_CoopSaf_Vroom,10.253.64.132&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**how will it work with generic objects to create a bulk of them? is it through a perl code? or how exactly can I make this work. thank you for the prompt response.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 13:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144898#M6679</guid>
      <dc:creator>Francisco_Melo</dc:creator>
      <dc:date>2022-03-28T13:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144903#M6680</link>
      <description>&lt;P&gt;You would have to create a CSV with each name/value pair, not just the name and ipaddr.&lt;BR /&gt;Your CLI would look something like:&amp;nbsp;&lt;SPAN&gt;mgmt_cli add generic-object --batch file.csv&lt;/SPAN&gt;&lt;BR /&gt;Whether you can make this work or not is a separate question.&lt;BR /&gt;Also, keep in mind generic-objects aren't formally supported.&lt;/P&gt;
&lt;P&gt;I think you're better off scripting this (either with Perl, Bash, or whatever language you feel comfortable in).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 13:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/144903#M6680</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-28T13:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145864#M6712</link>
      <description>&lt;P&gt;Thank you, I have done the perl Script and almost got it. I need to add it to an encryption domain when I'm using&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10726"&gt;@Robert_Decker&lt;/a&gt;&amp;nbsp; script of:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vpn_enc_domain=$(mgmt_cli -s id.txt show-generic-objects name CP_default_Office_Mode_addresses_pool -f json | /opt/CPshrd-R80/jq/jq -r '.objects[] | select (.type | contains("network")) | .uid')&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mgmt_cli -s id.txt add generic-object create "com.checkpoint.objects.classes.dummy.CpmiGatewayPlain" name "interdev_2" ipaddr "10.1.1.2" thirdPartyEncryption "True" osInfo.osName "Gaia" vpn.create "com.checkpoint.objects.classes.dummy.CpmiVpn" vpn.owned-object.vpnClientsSettingsForGateway.create "com.checkpoint.objects.classes.dummy.CpmiVpnClientsSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.create "com.checkpoint.objects.classes.dummy.CpmiEndpointVpnClientSettingsForGateway" vpn.owned-object.vpnClientsSettingsForGateway.owned-object.endpointVpnClientSettings.owned-object.endpointVpnEnable "True" vpn.owned-object.ike.create "com.checkpoint.objects.classes.dummy.CpmiIke" vpn.owned-object.sslNe.create "com.checkpoint.objects.classes.dummy.CpmiSslNetworkExtender" vpn.owned-object.sslNe.owned-object.sslEnable "False" vpn.owned-object.sslNe.owned-object.gwCertificate "defaultCert" manualEncdomain $vpn_enc_domain encdomain "MANUAL"&lt;/P&gt;&lt;P&gt;I get this&amp;nbsp;sh: line 5: /opt/CPshrd-80.40/jq/jq: No such file or directory&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 21:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145864#M6712</guid>
      <dc:creator>Francisco_Melo</dc:creator>
      <dc:date>2022-04-08T21:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145873#M6713</link>
      <description>&lt;P&gt;The path to the jq binary is wrong.&lt;BR /&gt;You will need to modify it accordingly based on your precise version.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 02:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145873#M6713</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-09T02:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145963#M6715</link>
      <description>&lt;P&gt;Thanks, but how do I actually find it. I try a couple but no go. Here are the only JQ directories I found .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;./opt/CPshrd-R80.40/bin/jq&lt;BR /&gt;./opt/CPshrd-R80.40/jq&lt;BR /&gt;./opt/CPshrd-R80.40/jq/jq&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 12:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145963#M6715</guid>
      <dc:creator>Francisco_Melo</dc:creator>
      <dc:date>2022-04-11T12:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Creating multiple remote Gateway for IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145979#M6719</link>
      <description>&lt;P&gt;Typing which jq from the expert CLI should tell you what binary is being used.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 14:43:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Creating-multiple-Remote-Gateways-Interoperable-Devices-for/m-p/145979#M6719</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-11T14:43:51Z</dc:date>
    </item>
  </channel>
</rss>

