<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible to lock an object? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210291#M34820</link>
    <description>&lt;P&gt;Exactly what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;said! Exit the script without publishing the session. The object will remain locked till you publish or discard that session.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2024 15:06:52 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2024-04-02T15:06:52Z</dc:date>
    <item>
      <title>Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/209892#M34759</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;a question came up if it is possible to lock an network object/group object to prevent this from 'overriding or modifying'.&amp;nbsp; I really mean on object level and not on admin permission profiles or similar.&lt;/P&gt;
&lt;P&gt;So, basically the wish to add/use this object in any rule, but should not be possible to modify the object itself without a command/api call.&lt;/P&gt;
&lt;P&gt;I tried the api call '&lt;SPAN&gt;mgmt_cli lock-object'. However, after publishing the session, the lock was reset automatically.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-&amp;gt; see attachement&lt;/P&gt;
&lt;P&gt;Is there any better idea/solution?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 07:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/209892#M34759</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-03-28T07:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210266#M34812</link>
      <description>&lt;P&gt;The whole idea of a locked object is not to publish that session. Did you try that?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 12:30:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210266#M34812</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-02T12:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210280#M34815</link>
      <description>&lt;P&gt;global objects in MDS enviroment &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 13:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210280#M34815</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-04-02T13:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210289#M34818</link>
      <description>&lt;P&gt;hi, not really.&amp;nbsp; The idea behind was that the object can't be overwritten by some admins or api calls.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 14:50:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210289#M34818</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-04-02T14:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210290#M34819</link>
      <description>&lt;P&gt;A lock on an object only lasts until the session holding the lock is published or discarded. You can lock the object and log out without publishing.&lt;/P&gt;
&lt;P&gt;That said, someone might see the lock, see who has it locked, and discard the session so they can make a change. This isn't a way to restrict the ability to change an object, it's only a guardrail against accidental changes.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 14:54:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210290#M34819</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-04-02T14:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210291#M34820</link>
      <description>&lt;P&gt;Exactly what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;said! Exit the script without publishing the session. The object will remain locked till you publish or discard that session.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 15:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210291#M34820</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-02T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to lock an object?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210317#M34827</link>
      <description>&lt;P&gt;It becomes complicated if you want to do this for multiple objects.&lt;/P&gt;
&lt;P&gt;Either you have 1 session per object left open and you will find that you run into problems due to the large number of open sessions.&lt;/P&gt;
&lt;P&gt;Or you have to automate it and release the previous session and re lock the objects. with the inherent chance someone will beat you to it and lock one just before your script got to it.&lt;/P&gt;
&lt;P&gt;So it is a sort of a finger in the dijk solution. It work with one small hole but ties you up as part of it. So choose wisely how to use it. I see way to many ways in which this can go wrong and turn against you.&lt;/P&gt;
&lt;P&gt;The suggestion of a MDS with just 1 domain might have some merits for this purpose. Be it it has it's own challenges.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 05:34:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Possible-to-lock-an-object/m-p/210317#M34827</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-04-03T05:34:00Z</dc:date>
    </item>
  </channel>
</rss>

