Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Networks_Team_B
Participant

Covert Check Point Security Policy to an Access Control List

Does anyone know if there are any tools that can be used to convert a security policy to an Access Control List? 

Doing this manually would be very time consuming and could result in human error.

Many thanks  

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The policy can be extracted from the management via REST API, which can be used to create ACLs from programmatically.
The target vendor may provide a conversion utility to assist with this.

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

You might also consider defining the target object in SmartConsole and installing policy directly on it.

We have not updated this object type for a while but it is worth experimenting in the lab first.

The object type is OSE Device. 

Also refer to https://support.checkpoint.com/results/sk/sk98004

You can also see the file in the Management Server:

 

  • The <conf_file> is the $FWDIR/conf/<Name_or_IP_Address_of_Router_Object>.cl file. This file does not exist when configuring the router network object in SmartDashboard / SmartConsole. This file is created by installing the ACL from SmartDashboard / SmartConsole, when the router is not connected to the Security Management Server / Domain Management Server.

 

OSE Device.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events