Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Aathi
Contributor

Going to expire rule list from checkpoint policy

Hi Team,

 

Is there any mgmt_cli command or api to get the "going to expired rule:s from checkpoint policy.

There is a mgmt_cli command to get the expired rules.need similar way to get the "going to expired rules".

Thanks in advance.

Regards

Aathi

 

 

 

 

 

4 Replies
PhoneBoy
Admin
Admin

What command did you find to give you the expired rules?
Because the only way a rule is expired is if it has something in the Time field and that object has an End date after...now.
That implies some sort of script as there's no API call I'm aware of that will pull "expired" rules, much less rules about to expire.
Aathi
Contributor

Hi Phoneboy,

 

It is disabled rules not expired one.i wrongly mentioned as Expired rules.

Is there any way to get the timebound rules list either via mgmt_cli or api.Please help to get the going to expired rules list.

 

Regards

Aathi

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Why should a rule expire and you need a list to see which is next ? I would rather look for time objects as mentioned by 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

Similar to getting a list of rules that are disabled, you'd have to use a script that basically calls the API and use jq to filter the results.
Specifically, you'd look for rules that have something other than "any" in the Time field.
You can use this as a starting point: https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Disable-Delete-Rules-with-a-Zero-...

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events