Is GRP_Block a dynamic object?
- No.
It is a group object, where the IPs are added manually (currently using the Management API, but by “tranches”).
As there are more than 100 new IPs that have to be created, and after creating them, just add them to the group GRP_Block, this task by the “Command Line” of the MDS, is little “automated” because from the SmartConsole, only allows to add a limited amount, about 30 objects.
The idea of starting to use Ansible is already landed, but like any other client, it is now evaluating its deployment.
Anyway, they want to apply or at least try to apply the script that they build internally.
So, exactly where would you have to “query” the database, regarding how Check Point “behaves”, every time it does an activity like this, create new IPs, and add them to an existing group.