check_point.mgmt.cp_mgmt_firewall_best_practice_facts module – Get firewall-best-practice objects facts on Checkpoint over Web Services API

Note

This module is part of the check_point.mgmt collection (version 7.0.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install check_point.mgmt.

To use it in a playbook, specify: check_point.mgmt.cp_mgmt_firewall_best_practice_facts.

New in check_point.mgmt 7.0.0

Synopsis

  • Get firewall-best-practice objects facts on Checkpoint devices.

  • All operations are performed over Web Services API.

  • This module handles both operations, get a specific object and get several objects, For getting a specific object use the parameter ‘name’.

  • Available from R82.20 management version.

Parameters

Parameter

Comments

best_practice_id

string

Best Practice ID.

details_level

string

The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object.

Choices:

  • "uid"

  • "standard"

  • "full"

domains_to_process

list / elements=string

Indicates which domains to process the commands on. It cannot be used with the details-level full, must be run from the System Domain only and with ignore-warnings true. Valid values are, CURRENT_DOMAIN, ALL_DOMAINS_ON_THIS_SERVER.

filter

string

Search expression to filter objects by. The provided text should be exactly the same as it would be given in SmartConsole Object Explorer. The logical operators in the expression (‘AND’, ‘OR’) should be provided in capital letters. The search involves both a IP search and a textual search in name, comment, tags etc.

filter_by

dictionary

Filter the result set by user-defined-only and status.

status

list / elements=string

Filter by best-practice status.

user_defined_only

boolean

Restrict the result set to user-defined Firewall Best Practices.

Choices:

  • false

  • true

limit

integer

The maximal number of returned results. This parameter is relevant only for getting few objects.

name

string

Best Practice Name. This parameter is relevant only for getting a specific object.

offset

integer

Number of the results to initially skip. This parameter is relevant only for getting few objects.

order

list / elements=dictionary

Sorts the results by search criteria. Automatically sorts the results by Name, in the ascending order. This parameter is relevant only for getting few objects.

ASC

string

Sorts results by the given field in ascending order.

Choices:

  • "name"

DESC

string

Sorts results by the given field in descending order.

Choices:

  • "name"

show_only_local_domain

boolean

Indicates whether the query should return only objects from the current local domain. This parameter is only valid for local domain.

Choices:

  • false

  • true

show_regulations

boolean

Show the applicable regulations of the Best Practice.

Choices:

  • false

  • true

show_relevant_objects

boolean

Show the relevant objects of the Best Practice.

Choices:

  • false

  • true

version

string

Version of checkpoint. If not given one, the latest version taken.

Examples

- name: show-firewall-best-practice
  cp_mgmt_firewall_best_practice_facts:
    best_practice_id: FW001
    details_level: full
    show_regulations: true

- name: show-firewall-best-practices
  cp_mgmt_firewall_best_practice_facts:
    details_level: full
    limit: 2

Authors

  • Dor Berenstein (@chkp-dorbe)