<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint L2L inventory using CLI/API - automation in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Checkpoint-L2L-inventory-using-CLI-API-automation/m-p/150247#M6854</link>
    <description>&lt;P&gt;You can get all the information through the API about S2S VPNs, Star or Mesh. You got it right. Good luck!&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jun 2022 16:54:30 GMT</pubDate>
    <dc:creator>Art_Zalenekas</dc:creator>
    <dc:date>2022-06-06T16:54:30Z</dc:date>
    <item>
      <title>Checkpoint L2L inventory using CLI/API - automation</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Checkpoint-L2L-inventory-using-CLI-API-automation/m-p/147345#M6846</link>
      <description>&lt;P&gt;What is the best way to get the inventory of the L2L VPN on Checkpoint firewalls?&lt;/P&gt;&lt;P&gt;I used the CLI commands VPN TU TLIST &amp;amp; VPN TU LIST IKE on the gateways to get the output. With the help of ansible I end up with the following VPN Peer IP, VPN Name, Encryption method, Local hosts, remote hosts and Ike version. I believe I'm still missing the IKE phase1 and IKE phase2 encryption/integrity details. is there another CLI command that can provide that? in addition, I believe that the CLI command provide the list of active tunnels at the command execution time. If the interesting traffic is not crossing a specific tunnel, then we will miss that specific tunnel inventory. right?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found also some documented APIs, I didn't try them yet. However, from the documentation it looks like we may end up with few information like VPN Name, encryption method, IKE phase 1 and IKE phase 2 encryption/integrity algorithm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I'm thinking to combine the output of the CLI and API to get the maximum information about the inventory.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions is highly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 13:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Checkpoint-L2L-inventory-using-CLI-API-automation/m-p/147345#M6846</guid>
      <dc:creator>hichem</dc:creator>
      <dc:date>2022-04-28T13:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint L2L inventory using CLI/API - automation</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Checkpoint-L2L-inventory-using-CLI-API-automation/m-p/150247#M6854</link>
      <description>&lt;P&gt;You can get all the information through the API about S2S VPNs, Star or Mesh. You got it right. Good luck!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 16:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Checkpoint-L2L-inventory-using-CLI-API-automation/m-p/150247#M6854</guid>
      <dc:creator>Art_Zalenekas</dc:creator>
      <dc:date>2022-06-06T16:54:30Z</dc:date>
    </item>
  </channel>
</rss>

