- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am creating an automation that gathers all FW rules, network objects, host objects, service objects, and groups. I have found most of the information I need via the web API using show-objects, however I am at a loss on how to find the rules themselves. Via the API I am getting a list of all domains & servers/firewalls from the show-mdss endpoint, logging into the returned domains, gathering access-layers, and gathering all objects. However, I am at a loss on how to pull down the access-sections or access-rules without knowing what name they are using. I have found many examples of how to show the access rules using the name, I am not finding anything for how to get a list of names of all of the access rules. Any help is much appreciated!
Thanks
show access rulebase will do it. In the API docs, just search for rulebase. Good luck!
https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-access-rulebase~v1.8%20
show access rulebase will do it. In the API docs, just search for rulebase. Good luck!
https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-access-rulebase~v1.8%20
Thanks for the reply.
In the API docs it looks like a name or uid is required. I am looking for the endpoint that will give me a list of the rulebase names. While I have a lot of experience with older checkpoints and other modern FW's, I am not super familiar with how the current checkpoints function, so I may just be missing something obvious.
show access-layers is probably what you want.
See: https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-access-layers~v1.8%20
It might also be policy packages (I.e. show packages), keeping in mind a policy package is made up of multiple layers.
See: https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-packages~v1.8%20
Thanks @Art_Zalenekas & @PhoneBoy . show access-layers & show access-rulebase is what I needed. What really threw me off was that the names and uids returned under the access-layers key is what I need to use in the postdata for show access-rulebase or show access-sections. It would be nice if the API docs mentioned this under all 3 of those endpoints 🙂 Thanks again for the help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY