check_point.mgmt.cp_mgmt_guideline module – Manages guideline objects on Checkpoint over Web Services API

Note

This module is part of the check_point.mgmt collection (version 7.0.0).

You might already have this collection installed if you are using the ansible package. It is not included in ansible-core. To check whether it is installed, run ansible-galaxy collection list.

To install it, use: ansible-galaxy collection install check_point.mgmt.

To use it in a playbook, specify: check_point.mgmt.cp_mgmt_guideline.

New in check_point.mgmt 7.0.0

Synopsis

  • Manages guideline objects on Checkpoint devices including creating, updating and removing objects.

  • All operations are performed over Web Services API.

  • Available from R82.20 management version.

Parameters

Parameter

Comments

access_layers

list / elements=dictionary

Collection of access-layers (one or more) of the guideline, identified by name or UID.

access_layer

string

Access-layer attached to guideline identified by the name or UID.if Access-Layer is in the global domain due to Global Assignment Local domain Package is required.

details_level

string

The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object.

Choices:

  • "uid"

  • "standard"

  • "full"

domains_to_process

list / elements=string

Indicates which domains to process the commands on. It cannot be used with the details-level full, must be run from the System Domain only and with ignore-warnings true. Valid values are, CURRENT_DOMAIN, ALL_DOMAINS_ON_THIS_SERVER.

policy_package

string

Policy package context for the access-layer attached to guideline identified by the name or UID.Package will be ignored if the access-layer is local.

auto_publish_session

boolean

Publish the current session if changes have been performed after task completes.

Choices:

  • false ← (default)

  • true

cell_actions_override

list / elements=dictionary

Cells that their action will override the default actions of the guideline.

action

string

The action to be applied to the cell. The field is mandatory at add command.

Choices:

  • "All traffic is allowed"

  • "All traffic is not allowed"

  • "Decide later"

allowed_services

list / elements=string

Services (identified by name or UID) that are allowed in the cell. Relevant only if the action in the cell is ‘All traffic is not allowed’. To remove allowed-services call update with the same “All traffic is not allowed” action, or remove the cell-action-override.

from

string

The segment identifier (name or UID) of the cell in the ‘from’ axis. The field is mandatory only if “from-type” is “network group”.

from_type

string

The type of the segment in the ‘from’ axis.

Choices:

  • "network group"

  • "internet"

  • "other"

to

string

The segment identifier (name or UID) of the cell in the ‘to’ axis. The field is mandatory only if “to-type” is “network group”.

to_type

string

The type of the segment in the ‘to’ axis.

Choices:

  • "network group"

  • "internet"

  • "other"

color

string

Color of the object. Should be one of existing colors.

Choices:

  • "aquamarine"

  • "black"

  • "blue"

  • "crete blue"

  • "burlywood"

  • "cyan"

  • "dark green"

  • "khaki"

  • "orchid"

  • "dark orange"

  • "dark sea green"

  • "pink"

  • "turquoise"

  • "dark blue"

  • "firebrick"

  • "brown"

  • "forest green"

  • "gold"

  • "dark gold"

  • "gray"

  • "dark gray"

  • "light green"

  • "lemon chiffon"

  • "coral"

  • "sea green"

  • "sky blue"

  • "magenta"

  • "purple"

  • "slate blue"

  • "violet red"

  • "navy blue"

  • "olive"

  • "orange"

  • "red"

  • "sienna"

  • "yellow"

comments

string

Comments string.

dereference_group_members

boolean

Indicates whether to dereference “members” field by details level for every object in reply.

Choices:

  • false

  • true

details_level

string

The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object.

Choices:

  • "uid"

  • "standard"

  • "full"

guideline_groups

list / elements=dictionary

Collection of segments of the guideline.

name

string

Network group name.

position

string

Guideline-Group Position in the guideline. If a position is specified for one guideline-group, it is required for all guideline-groups.

ignore_errors

boolean

Apply changes ignoring errors. You won’t be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.

Choices:

  • false

  • true

ignore_warnings

boolean

Apply changes ignoring warnings.

Choices:

  • false

  • true

name

string / required

Object name.

show_membership

boolean

Indicates whether to calculate and show “groups” field for every object in reply.

Choices:

  • false

  • true

state

string

State of the access rule (present or absent).

Choices:

  • "present" ← (default)

  • "absent"

version

string

Version of checkpoint. If not given one, the latest version taken.

wait_for_task

boolean

Wait for the task to end. Such as publish task.

Choices:

  • false

  • true ← (default)

wait_for_task_timeout

integer

How many minutes to wait until throwing a timeout error.

Default: 30

Examples

- name: add-guideline
  cp_mgmt_guideline:
    access_layers:
    - Network
    guideline_groups:
    - name: DMZ
    - name: Users networks
    - name: Labs
    name: Corporate policy
    state: present

- name: set-guideline
  cp_mgmt_guideline:
    name: Corporate policy
    state: present

- name: delete-guideline
  cp_mgmt_guideline:
    name: Corporate policy
    state: absent

Return Values

Common return values are documented here, the following are the fields unique to this module:

Key

Description

cp_mgmt_guideline

dictionary

The checkpoint object created or updated.

Returned: always, except when deleting the object.

Authors

  • Dor Berenstein (@chkp-dorbe)