Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bob_Zimmerman
Authority
Authority

Tags on Rules and Sections?

Looking at the documentation for management API v1.9, I see tags can be set on access layers, HTTPS layers, policy packages, and NAT sections. Meanwhile, access sections, access rules, HTTPS sections, HTTPS rules, and NAT rules make no mention of them. They all seem to have a tags field internally, but the API documentation only references the field on some of them.

Can tags be set on these objects? If nobody knows, I should be able to try it out tomorrow.

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

@Omer_Kleinstern should be able to tell you for sure.

0 Kudos
Tal_Paz-Fridman
Employee
Employee

I would also recommend looking at the 3 Custom fields:

https://sc1.checkpoint.com/documents/latest/APIs/#cli/set-access-rule~v1.9%20

 

2023-01-25 09_36_05-Check Point - Management API reference.png

 

2023-01-25 09_38_53-Cloud Demo Server [ID_880152402] - SmartConsole.png

0 Kudos
Bob_Zimmerman
Authority
Authority

Sure. I'm not trying to solve any particular problem, I'm just trying to learn what is possible and what isn't. I'm building something to interact with the API, and I'm trying to include local checks so the user can't even try to do things which the API simply doesn't allow. If tags on rules aren't a thing, then I simply won't let the user specify tags to set.

Also I was apparently reading some of the return values on NAT sections. They return a list of tags, but the documentation doesn't have a way to set the tags. Access sections and HTTPS sections also return a list of tags, but don't appear to have a way to set them (outside of 'set generic-object', anyway). The various rule types don't return a list of tags at all.

These little inconsistencies are driving me nuts. 😜 Most things have a comments field and a name field. Rule sections of any kind don't accept comments, but they have names. NAT rules don't have a name, but they have comments. This has led me to try to find all of the inconsistencies I can so I can handle them properly.

0 Kudos
Tomer_Noy
Employee
Employee

We don't currently support tags on Access rules, but we are looking at it for upcoming versions.

0 Kudos
Bob_Zimmerman
Authority
Authority

Thanks for the confirmation! That's what I was expecting. I assume it's the case for other rule types, too.

0 Kudos
Omer_Kleinstern
Employee
Employee

We will support tags on all rule types in the next version and in future HFA of previous versions.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events