- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
R80.20 API v1.3 can't seem to find "install Database". We have close to 90 Domains across multiple MDS / Provider1 environments. With that said when I need to make a change that requires an "Install Database" - I need to be able to do this via the API. To me this is crazy that CheckPoint has left this out. Or should I say I can't seem to find it. Take a tool like Firemon that may require us to make a change and do an "install Database".
Please tell me there is an easy way to do an "install Database" across 90+ domains without having to log into each one.
Thank you,
Functions that must be handled by the older fwm daemon on a SMS/MDS generally cannot be automated through the API as fwm is not API-aware. Any management function being handled by the newer cpm daemon can potentially be accessed through the API. So as far as I know the inability to perform an Install Database via the API is more of a technical limitation of fwm than anything else.
A common question I get in the CCAS class is what management functions cannot be handled through the API, and must be performed in the SmartConsole GUI:
Pretty much all the functions listed are handled by fwm (hence the need to use the old SmartDashboard GUI to work with many of these functions), looks like performing an Install Database operation needs to be added to the list.
Hi,
Please see this new post about usage of $MDSVERUTIL AllCMAs command for running the Install Database on all domain at once.
Regards,
Ofer
Pretty sure there is no API call for this function currently.
Wow. I can't believe this basic function is not in the API. Can you tell if it is even on the roadmap for 1.4 or 1.5 of the API? So basically what I am hearing is that for large clients that have many domains and tools such as Firemon or Tufin, we have to manually log into every domain and do an install database for changes in setting to take affect. At least is there a CLI command way that I can perform this? If so I could write a BASH script and loop through all the domains.
API 1.4 is released as part of R80.20.M2 -- nothing there about it.
API 1.5 is the upcoming R80.30 and nothing there about it either.
Not sure where this is in the plans to add.
If you want to do this on the CLI, the command is fwm dbload target-name
If you really want to do this over REST API today, you could potentially install https://community.checkpoint.com/community/infinity-general/appliances-and-gaia/blog/2019/01/21/new-... and use that.
If we can do this by the command line on the MDS it will get us by for now. I may write a quick BASH script iterate through all the domains and do the "fwm dbload target-name".
It sounds like this is not on the near road map of the API. I still can't believe "Install Database" is not an option.
Thank you for checking.
If you do an upgrade you need to install database on each domain, that means login to each domain and do install database.
I hope checkpoint implements something to do an install database from the top level MDS server.
Functions that must be handled by the older fwm daemon on a SMS/MDS generally cannot be automated through the API as fwm is not API-aware. Any management function being handled by the newer cpm daemon can potentially be accessed through the API. So as far as I know the inability to perform an Install Database via the API is more of a technical limitation of fwm than anything else.
A common question I get in the CCAS class is what management functions cannot be handled through the API, and must be performed in the SmartConsole GUI:
Pretty much all the functions listed are handled by fwm (hence the need to use the old SmartDashboard GUI to work with many of these functions), looks like performing an Install Database operation needs to be added to the list.
Hi,
Please see this new post about usage of $MDSVERUTIL AllCMAs command for running the Install Database on all domain at once.
Regards,
Ofer
i Agree 😉
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY