- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello, everyone.
Can anyone guide me with the easiest way to automate object creation, and then after that add the objects to a particular group with the Management API.
We have massive requirements where we get more than 60 IPs per request, to add them to our MDS, and little experience with using ansible or python.
Are there any commands or templates to help me with the deployment of the Management API, that also allow the installation of policies in your process?
We have many Perimetrics where we have to submit changes on a recurring basis.
Thanks for the comments
Hi,
We had a few solutions here in the CheckMates forum, you can browse the API discussion board and choose the option you feel the most comfortable with.
CheckMates API board: https://community.checkpoint.com/t5/API-CLI-Discussion/bd-p/codehub
One of the solutions offered is the following SK: https://support.checkpoint.com/results/sk/sk113078
MGMT API references:
Add host: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/add-host~v2%20
Add host to group: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/set-group~v2%20
Your instinct is correct to use the management API for this. If you have little experience with Ansible, and you also want to learn, I have a video series on YouTube you can go through to understand how to get it setup for your management server and learn Ansible along the way. The episodes do build on each other, and the latest one shows how to achieve what you want (but you really should go through each of them).
The link is in my signature below. I also put together a written form of the episodes on the Substack board, also in the link, in case you want to read through the material, search for things, print it out, etc.
Feel free to reply back here if you have any questions!
Hey bro,
Did what Duane Toler give you last time help? Ansible method, that is.
Andy
Adding to what @Amir_Senn wrote to look at the Management API Best Practices:
https://sc1.checkpoint.com/documents/latest/APIs/index.html#tips_best_practices~v2%20
If this is a recurring pattern, in which you need to add those ~60 weekly IPs to the same few groups, it might be worthwhile to evaluate the use-case and consider alternatives.
For example, if those 60 IPs are malicious / bad reputation IPs that you want to block, then instead of automating them into a group and pushing policy, consider using IoC feeds for blocking in Threat Prevention blades, or a Network Feed that can be placed into a FW policy block rule.
If those IPs are going into a few certain groups that are effectively owned by another team for opening traffic to certain resources, you can also consider a Network Feed with an allow rule, and either fill in the feed yourself or allow that other team to control it.
Using the above alternatives will save you the need to push policy to all your gateways after every update, and will "de-clutter" your Management as you won't need all those host objects.
Depending on the versions/use case, using the API is not necessary.
For a list of IPs, you're probably better off using something like a Network Feed which just reads a file off a webserver with the IPs (or processes JSON output).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY