check_point.mgmt.cp_mgmt_guideline_facts module – Get guideline objects facts on Checkpoint over Web Services API

Note

This module is part of the check_point.mgmt collection (version 7.0.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install check_point.mgmt.

To use it in a playbook, specify: check_point.mgmt.cp_mgmt_guideline_facts.

New in check_point.mgmt 7.0.0

Synopsis

  • Get guideline objects facts on Checkpoint devices.

  • All operations are performed over Web Services API.

  • This module handles both operations, get a specific object and get several objects, For getting a specific object use the parameter ‘name’.

  • Available from R82.20 management version.

Parameters

Parameter

Comments

dereference_group_members

boolean

Indicates whether to dereference “members” field by details level for every object in reply.

Choices:

  • false

  • true

details_level

string

The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object.

Choices:

  • "uid"

  • "standard"

  • "full"

domains_to_process

list / elements=string

Indicates which domains to process the commands on. It cannot be used with the details-level full, must be run from the System Domain only and with ignore-warnings true. Valid values are, CURRENT_DOMAIN, ALL_DOMAINS_ON_THIS_SERVER.

filter

dictionary

Additional filters for the query.

access_layers

list / elements=string

List of access-layers identifiers to filter by. The query will return only guidelines that are attached to the given access-layers.

layer_with_policy

list / elements=dictionary

List of access-layer and policy-package pairs to filter by. For global access-layers, both access-layer and policy-package must match. For local access-layers, only the access-layer needs to match.

access_layer

string

Access-layer attached to guideline identified by the name or UID.if Access-Layer is in the global domain due to Global Assignment Local domain Package is required.

details_level

string

The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object.

Choices:

  • "uid"

  • "standard"

  • "full"

domains_to_process

list / elements=string

Indicates which domains to process the commands on. It cannot be used with the details-level full, must be run from the System Domain only and with ignore-warnings true. Valid values are, CURRENT_DOMAIN, ALL_DOMAINS_ON_THIS_SERVER.

policy_package

string

Policy package context for the access-layer attached to guideline identified by the name or UID.Package will be ignored if the access-layer is local.

policy_packages

string

List of local-domain policy packages identifiers to filter by, in case a guideline is attached to a layer with assigned global policy.

query

string

Search expression to filter objects by. The provided text should be exactly the same as it would be given in SmartConsole Object Explorer. The logical operators in the expression (‘AND’, ‘OR’) should be provided in capital letters. The search involves both a IP search and a textual search in name, comment, tags etc.

indexing_status_layer

string

Relevant only when show-indexing-status is true. The access-layer to show the indexing status of (identified by unique id or ‘any’ for all attached access-layers).

limit

integer

The maximal number of returned results. This parameter is relevant only for getting few objects.

name

string

Object name. This parameter is relevant only for getting a specific object.

offset

integer

Number of the results to initially skip. This parameter is relevant only for getting few objects.

order

list / elements=dictionary

Sorts the results by search criteria. Automatically sorts the results by Name, in the ascending order. This parameter is relevant only for getting few objects.

ASC

string

Sorts results by the given field in ascending order.

Choices:

  • "name"

DESC

string

Sorts results by the given field in descending order.

Choices:

  • "name"

show_indexing_status

boolean

Control whether to show the indexing status of the guideline.

Choices:

  • false

  • true

show_membership

boolean

Indicates whether to calculate and show “groups” field for every object in reply.

Choices:

  • false

  • true

show_only_local_domain

boolean

Indicates whether the query should return only objects from the current local domain. This parameter is only valid for local domain.

Choices:

  • false

  • true

version

string

Version of checkpoint. If not given one, the latest version taken.

Examples

- name: show-guideline
  cp_mgmt_guideline_facts:
    name: Corporate policy

- name: show-guidelines
  cp_mgmt_guideline_facts:

Authors

  • Dor Berenstein (@chkp-dorbe)