- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello ansible users!
I used --check for an ansible-playbook (check_point.gaia.cp_gaia_password_policy). Ansible should just check it and not change anything. I was surprised that the configuration has been changed.
Also --diff didn't show any changes.
Are those parameters not available? How can we use ansible in production if you can not check which changes will be made during the next run?
Bye
Hi Daniel, From a quick check, it seems that Gaia Collection doesn't support that, although it's documented as it's supported. (Sorry for that)
We will check that and add it to our roadmap for adding/fixing this support in the next releases.
This issue was documented in sk183620 - you will see the final changes ~15 minutes from now
What is the playbook you were running?
I tried it with
- name: OS Modification
gather_facts: false
hosts: all
connection: httpapi
tasks:
- name: Change password policy
check_point.gaia.cp_gaia_password_policy:
lock_settings: {
'password_expiration_days': 60
}
Maybe @Eden_Brillant has a suggestion here, but it seems like this might be a bug.
What version of management is involved here as well as the version of the Ansible Gaia Collection used.
@PhoneBoy wrote:
What version of management is involved here as well as the version of the Ansible Gaia Collection used.
The gateway is R81.20. Or which version do you mean with management? I use check_point.gaia....
Ansible collections are
$ ansible-galaxy collection list |grep check
check_point.gaia 7.0.0
check_point.mgmt 6.3.0
@Majd_Sharkia for GAIA collection
From the source --check should be supported
https://github.com/CheckPointSW/CheckPointAnsibleGAIACollection/blob/v7.0.0/plugins/modules/cp_gaia_...
And cp_gaia_snmp_user is also not working (and documented with cp_snmp_gaia_user) 😪
Hi Daniel, From a quick check, it seems that Gaia Collection doesn't support that, although it's documented as it's supported. (Sorry for that)
We will check that and add it to our roadmap for adding/fixing this support in the next releases.
This issue was documented in sk183620 - you will see the final changes ~15 minutes from now
If someone tries to open a SR for this: Don't waste you time. I already opened one. It's was closed, because it's an RFE now 😞
Sorry, but is this serious?
The cause is "the docs mistakenly shows that it supports the check mode" and the solution is "check mode is not support, please open an Request for Enhancement"
What about (at least) adjusting the documention of this ansible collection, so it doesn't mention the check mode as supported anymore?
@mib1185 I admire your passion.
However, are you sure the issue is not already fixed in the Ansible Galaxy documentation? I just checked and did not find any documentation reference to "--check" support other than an issue notification there.
Do I miss something here?
Hi @_Val_
each single module documentation mentions "Supports check_mode" under the Notes section - eq. cp_gaia_alias_interface (but also all other module docs) as the docs on Ansible Galaxy are taken from the source repository. But not only the documentation mentions it, also the code itself still enables the check mode support for each module (see here)
Regards,
Michael
It's still documented
It would be great to get a fix for this and not just a modification in the documentation. Using Ansible without check mode greatly reduces the advantages of Ansible.
but yeah, I fully agree with @Daniel_ : "... Using Ansible without check mode greatly reduces the advantages of Ansible."
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY