<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: query rules in checkpoint securemote in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/176003#M5316</link>
    <description>&lt;P&gt;Thank you for the details.&lt;/P&gt;&lt;P&gt;Curious, is there any way I can connect via Postman (API) to the gateway and trigger a lookup or query. Please review below..&lt;/P&gt;&lt;P&gt;I can request my network team to create - Read Only account in gateway&lt;/P&gt;&lt;P&gt;In Postman tool plug-in above read only cred's&lt;/P&gt;&lt;P&gt;Trigger a lookup query against gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inputs appreciated !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 23:58:19 GMT</pubDate>
    <dc:creator>raos</dc:creator>
    <dc:date>2023-03-23T23:58:19Z</dc:date>
    <item>
      <title>query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175304#M5311</link>
      <description>&lt;P&gt;hello experts,&lt;/P&gt;&lt;P&gt;i am newbie&amp;nbsp;&lt;/P&gt;&lt;P&gt;need to learn how to query rules in secuRemote&lt;/P&gt;&lt;P&gt;a url enabled in BigIP F5&lt;/P&gt;&lt;P&gt;find various hops happening in secuRemote until my request reaches the internet&lt;/P&gt;&lt;P&gt;inputs appreciated !&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;rao&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 21:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175304#M5311</guid>
      <dc:creator>raos</dc:creator>
      <dc:date>2023-03-18T21:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175343#M5312</link>
      <description>&lt;P&gt;Not sure what you mean by “rules” in this context.&lt;BR /&gt;What is the precise issue you’re having?&lt;/P&gt;
&lt;P&gt;Not sure how an F5 box relates here.&lt;BR /&gt;Please state versions of all related Check Point components (gateway and client) and provide a network diagram.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 03:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175343#M5312</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-20T03:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175345#M5313</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/91465"&gt;@raos&lt;/a&gt;&amp;nbsp;...welcome to the community! Just to make it easier for everyone, we always appreciate when people provide as many details as possible. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;indicated, it would be nice if you could tell us exactly what you are exactly trying to do here, ie what rules are you referring to? Only rules I can think of when it comes to secure client would be secure client verification feature, unless you are referencing something related to regular security rules.&lt;/P&gt;
&lt;P&gt;Also, I believe F5 is mostly used as load balancer, so not sure how thats releted in thos context. And yes, simple diagram helps, even if you draw something basic in paint in windows : - )&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 03:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175345#M5313</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-20T03:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175623#M5314</link>
      <description>&lt;P&gt;thank you for the follow up team&lt;/P&gt;&lt;P&gt;my bad for the incomplete info in the prior post.&lt;/P&gt;&lt;P&gt;Let me try to explain..&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable single sign-on for an application, I have these tools in place..&lt;/P&gt;&lt;P&gt;LTM, APM in BigIP F5 - virtual server,&amp;nbsp;policy are defined in here&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- I have access to these&lt;/P&gt;&lt;P&gt;route53 in AWS - dns records are in here&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - I can verify with nslookup&lt;/P&gt;&lt;P&gt;checkpoint VPN / secuRemote&amp;nbsp; - publicIP is mapped with the internal IP defined in LTM BIG IP F5&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;I do not have access to checkpoint vpn / secuRemote&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - how to query / view the contents of checkpoint appliance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q - To make sure all above components are configured correct, I need to view the contents defined in checkpoint/secuRemote appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there similar way like&lt;/P&gt;&lt;P&gt;-- powershell to query / view AD objects&lt;/P&gt;&lt;P&gt;-- ldapsearch to query / view openLDAP etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;inputs appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 18:03:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175623#M5314</guid>
      <dc:creator>raos</dc:creator>
      <dc:date>2023-03-21T18:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175637#M5315</link>
      <description>&lt;P&gt;The only thing you can get on the client itself is the encryption domain (i.e. the destinations the client will send across the VPN).&lt;BR /&gt;This can be found by simply reviewing the routing table before and after connecting to the remote site.&lt;/P&gt;
&lt;P&gt;In terms of reviewing the configuration on the gateway itself, there are multiple ways to do this.&lt;BR /&gt;However, all of them require explicit access being granted to the Check Point management to do it (either with SmartConsole, API, CLI, etc).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 18:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/175637#M5315</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-21T18:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/176003#M5316</link>
      <description>&lt;P&gt;Thank you for the details.&lt;/P&gt;&lt;P&gt;Curious, is there any way I can connect via Postman (API) to the gateway and trigger a lookup or query. Please review below..&lt;/P&gt;&lt;P&gt;I can request my network team to create - Read Only account in gateway&lt;/P&gt;&lt;P&gt;In Postman tool plug-in above read only cred's&lt;/P&gt;&lt;P&gt;Trigger a lookup query against gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inputs appreciated !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 23:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/176003#M5316</guid>
      <dc:creator>raos</dc:creator>
      <dc:date>2023-03-23T23:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: query rules in checkpoint securemote</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/176009#M5317</link>
      <description>&lt;P&gt;There isn’t a formal API to query the contents of the installed policy on the gateway.&lt;BR /&gt;The only possible way to do this is&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html#web/run-script~v1.7%20" target="_self"&gt;run-script&lt;/A&gt; to execute &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Show-Ruleset-and-Objects-on-the-Gateway-Emergency-Recovery/m-p/155533#M30470" target="_self"&gt;the necessary CLI commands&lt;/A&gt;.&lt;BR /&gt;Whether these commands contain the information you’re looking for is a separate question.&lt;/P&gt;
&lt;P&gt;As stated previously, the best way to do this is through access to the &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction~v1.9%20" target="_self"&gt;management server API&lt;/A&gt;.&lt;BR /&gt;It is possible to grant read-only access to it.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 01:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/query-rules-in-checkpoint-securemote/m-p/176009#M5317</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-24T01:11:50Z</dc:date>
    </item>
  </channel>
</rss>

