Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Networks_Team_B
Participant

Covert Check Point Security Policy to an Access Control List

Does anyone know if there are any tools that can be used to convert a security policy to an Access Control List? 

Doing this manually would be very time consuming and could result in human error.

Many thanks  

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The policy can be extracted from the management via REST API, which can be used to create ACLs from programmatically.
The target vendor may provide a conversion utility to assist with this.

0 Kudos
Tal_Paz-Fridman
Employee
Employee

You might also consider defining the target object in SmartConsole and installing policy directly on it.

We have not updated this object type for a while but it is worth experimenting in the lab first.

The object type is OSE Device. 

Also refer to https://support.checkpoint.com/results/sk/sk98004

You can also see the file in the Management Server:

 

  • The <conf_file> is the $FWDIR/conf/<Name_or_IP_Address_of_Router_Object>.cl file. This file does not exist when configuring the router network object in SmartDashboard / SmartConsole. This file is created by installing the ACL from SmartDashboard / SmartConsole, when the router is not connected to the Security Management Server / Domain Management Server.

 

OSE Device.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events