- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
at first glance, the R80 API documentatoin does not explain how to delete a member from a group. Anybody an idea ?
With dbedit, deleting an object, used in a group, implicitly removed the object from that group.
Trying to delete such an object, in R80.10, results in a warning I don't seem to be able to override.
So :
is there a way - via CLI - to remove a group member ?
or is there a way to delete an object with some "force" attribute in case it is used as member in some group ?
Thanks !
Marc
You can use where-used and delete all references .
I do not think that 'force' will be a good idea, you can create a scenario that you break the policy .
For groups, you can use 'remove'
groups | Object v | Collection of group identifiers. | ||||||||||||
or | ||||||||||||||
Object v
| ||||||||||||||
or | ||||||||||||||
string | ||||||||||||||
or | ||||||||||||||
List: string |
I believe the correct approach is to use the "set group" command specifying all members of the group BUT the one you want to delete.
Having a proper "delete from group" API call seems like a good suggestion for future releases.
I'll give it a try - but the first script I'm moving from R77.30 to R80 put 312 members in a group. If, on the next run, I have to delete one by entering the 311 that should remain ...
try this post
Eric provided example for 'batch' option , with one CSV file and a few moments you be able to complete the task
set group --batch <csvfilename> --format json --ignore-errors true
You can use where-used and delete all references .
I do not think that 'force' will be a good idea, you can create a scenario that you break the policy .
For groups, you can use 'remove'
groups | Object v | Collection of group identifiers. | ||||||||||||
or | ||||||||||||||
Object v
| ||||||||||||||
or | ||||||||||||||
string | ||||||||||||||
or | ||||||||||||||
List: string |
Nice one... I didn't catch that the first time.
Thanks for your help !
Interestingly enough the on-line API documentation does not mention "remove" as possibility ...
And I already found that adding "ignore-warnings true" to the "mgmt_cli delete network ..." does the trick.
To remove members from a group (not documented anywhere I could find - trial and error!!!) :
File format:
name,members.remove
group_name,host1
group_name,host2
group_name,host3
group_name,host4
group_name,host5
group_name,host5
Format to run the batch file:
mgmt_cli -r true set group name group_name -b batch_file_name.txt
Hello,
I was looking into that conversation and I would like to ask if there was any solution provided in the new releases?
I am trying to figure out if there is a specific API call that can remove an object from a group.
Thanks,
Vince
The above solution translates to the following API call: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-group~v1.7
if you only do the set it will overwrite everything in group (i've done this before had to put back 350 objects into group)
--Juan
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
5 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY