- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Covert Check Point Security Policy to an Acces...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Covert Check Point Security Policy to an Access Control List
Does anyone know if there are any tools that can be used to convert a security policy to an Access Control List?
Doing this manually would be very time consuming and could result in human error.
Many thanks
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The policy can be extracted from the management via REST API, which can be used to create ACLs from programmatically.
The target vendor may provide a conversion utility to assist with this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You might also consider defining the target object in SmartConsole and installing policy directly on it.
We have not updated this object type for a while but it is worth experimenting in the lab first.
The object type is OSE Device.
Also refer to https://support.checkpoint.com/results/sk/sk98004
You can also see the file in the Management Server:
- The
<conf_file>
is the$FWDIR/conf/<Name_or_IP_Address_of_Router_Object>.cl
file. This file does not exist when configuring the router network object in SmartDashboard / SmartConsole. This file is created by installing the ACL from SmartDashboard / SmartConsole, when the router is not connected to the Security Management Server / Domain Management Server.
