- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm looking for API/CLI option from MDS to create a single (or even multiple in future) group and push it into all CMA's/Domains. I tried to see if anything possible apart from logging into each CMA's manually in Dashboard or in CLI too, but didn't find any. So if there is any option to add a group from MDS level that can drill down to all CMA's/domains (we have 13-14 domains)
Note: I've tried using mgmt_cli from MDS and it shows successfully completed but manual check in each domain shows no group created.
It sounds like you want to use the MDS global policy. You can create your objects in the global domain and those can be shared with the regular domains.
For that to work, you need to first set a global policy for each domain that you want to use those objects. This is a one-time operation. You can do it from the UI of course, but here is the command if you want to use API:
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-global-assignment~v1.7%20
After that, you can decide when to apply the global objects to the domains. That can be done by assigning the global policy. Again, that can be done from the SmartConsole UI, but for reference, here is the API command:
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/assign-global-assignment~v1.7%20
BTW, if the use-case that you are trying to achieve is shared block lists, you might want to look at IoC feeds, which is another alternative with some benefits.
Thanks Tomer, I'm not looking with MDS global policy, that option probably a last resort. Is there a reason on why from MDS cli, it doesn't accept to push the group to multiple domains/CMA's.?
Just create global domain assignement on particular CMA's and don't specify any access control policy and then objects created on global will be displayed under each CMA. After each change on global objects you just need to run re-assignement.
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/assign-global-assignment~v1.1%20
You can use bash/API script or any other
#/bin/bash
printf "Enter group name\n"
read GROUPNAME
mgmt_cli -d %DOMAINNAME1% add group name \"$GROUPNAME\"
.
.
mgmt_cli -d %DOMAINNAMEN% add group name \"$GROUPNAME\"
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY