check_point.mgmt.cp_mgmt_simple_gateway module – Manages simple-gateway objects on Check Point over Web Services API
Note
This module is part of the check_point.mgmt collection (version 7.0.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install check_point.mgmt.
To use it in a playbook, specify: check_point.mgmt.cp_mgmt_simple_gateway.
New in check_point.mgmt 1.0.0
Synopsis
Manages simple-gateway objects on Check Point devices including creating, updating and removing objects.
All operations are performed over Web Services API.
Available from R80 management version.
Parameters
Parameter |
Comments |
|---|---|
Anti-Bot blade enabled. Choices:
|
|
Anti-Virus blade enabled. Choices:
|
|
Application Control blade enabled. Choices:
|
|
Publish the current session if changes have been performed after task completes. Choices:
|
|
Color of the object. Should be one of existing colors. Choices:
|
|
Comments string. |
|
Content Awareness blade enabled. Available from R80.10 management version. Choices:
|
|
The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object. Choices:
|
|
Enable HTTPS Inspection after defining an outbound inspection certificate. <br>To define the outbound certificate use outbound inspection certificate API. Choices:
|
|
Firewall blade enabled. Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A Choices:
|
|
N/A |
|
N/A |
|
N/A |
|
N/A |
|
Gateway platform version. |
|
Collection of group identifiers. |
|
Identity awareness blade enabled. Choices:
|
|
Gateway Identity Awareness settings. |
|
Enable Browser Based Authentication source. Choices:
|
|
Browser Based Authentication settings. |
|
Authentication Settings for Browser Based Authentication. |
|
Authentication method. Choices:
|
|
Identity provider object identified by the name or UID. Must be set when “authentication-method” was selected to be “identity provider”. |
|
Radius server object identified by the name or UID. Must be set when “authentication-method” was selected to be “radius”. |
|
Users directories. |
|
External user profile. Choices:
|
|
Internal users. Choices:
|
|
LDAP AU objects identified by the name or UID. Must be set when “users-from-external-directories” was selected to be “specific”. |
|
Users from external directories. Choices:
|
|
Browser Based Authentication portal settings. |
|
Configuration of the portal access settings. |
|
Allowed access to the web portal (based on interfaces, or security policy). Choices:
|
|
Configuration of the additional portal access settings for internal interfaces only. |
|
Controls portal access settings for internal interfaces, whose topology is set to ‘DMZ’. Choices:
|
|
Controls portal access settings for internal interfaces, whose topology is set to ‘Undefined’. Choices:
|
|
Controls portal access settings for interfaces that are part of a VPN Encryption Domain. Choices:
|
|
Configuration of the portal certificate settings. |
|
The certificate file encoded in Base64 with padding. This file must be in the *.p12 format. |
|
Password (encoded in Base64 with padding) for the certificate file. |
|
Configuration of the portal web settings. |
|
List of URL aliases that are redirected to the main portal URL. |
|
Optional, IP address for the web portal to use, if your DNS server fails to resolve the main portal URL. Note, If your DNS server resolves the main portal URL, this IP address is ignored. |
|
The main URL for the web portal. |
|
Enable Identity Agent source. Choices:
|
|
Identity Agent settings. |
|
Agents send keepalive period (minutes). |
|
Authentication Settings for Identity Agent. |
|
Authentication method. Choices:
|
|
Radius server object identified by the name or UID. Must be set when “authentication-method” was selected to be “radius”. |
|
Users directories. |
|
External user profile. Choices:
|
|
Internal users. Choices:
|
|
LDAP AU objects identified by the name or UID. Must be set when “users-from-external-directories” was selected to be “specific”. |
|
Users from external directories. Choices:
|
|
Identity Agent accessibility settings. |
|
Configuration of the portal access settings. |
|
Allowed access to the web portal (based on interfaces, or security policy). Choices:
|
|
Configuration of the additional portal access settings for internal interfaces only. |
|
Controls portal access settings for internal interfaces, whose topology is set to ‘DMZ’. Choices:
|
|
Controls portal access settings for internal interfaces, whose topology is set to ‘Undefined’. Choices:
|
|
Controls portal access settings for interfaces that are part of a VPN Encryption Domain. Choices:
|
|
Agent reauthenticate time interval (minutes). |
|
ON, Configures this object as a PEP-only object - identity-based enforcement (PEP) is enabled.<br>OFF, Configures this object as a PDP-only object - identity-based enforcement is disabled. Choices:
|
|
Enable Identity Collector source. Choices:
|
|
Identity Collector settings. |
|
Authentication Settings for Identity Collector. |
|
Users directories. |
|
External user profile. Choices:
|
|
Internal users. Choices:
|
|
LDAP AU objects identified by the name or UID. Must be set when “users-from-external-directories” was selected to be “specific”. |
|
Users from external directories. Choices:
|
|
Authorized Clients. |
|
Host / Network Group Name or UID. |
|
Client Secret. |
|
Identity Collector accessibility settings. |
|
Configuration of the portal access settings. |
|
Allowed access to the web portal (based on interfaces, or security policy). Choices:
|
|
Configuration of the additional portal access settings for internal interfaces only. |
|
Controls portal access settings for internal interfaces, whose topology is set to ‘DMZ’. Choices:
|
|
Controls portal access settings for internal interfaces, whose topology is set to ‘Undefined’. Choices:
|
|
Controls portal access settings for interfaces that are part of a VPN Encryption Domain. Choices:
|
|
Identity sharing settings. |
|
True, In case of connectivity loss from the Policy-Decision-Point (PDP), extend Identity cache up-to “cache-mode-duration”.<br>False, Identity Cache Mode is disabled, in case of connectivity loss from the Policy-Decision-Point, existing Identities will be lost immediately. |
|
Override profile of global configuration. Choices:
|
|
Override value.<br><font color=”red”>Required only for</font> ‘override-profile’ is True. Choices:
|
|
Time limit for keeping Identities in the cache. |
|
Override profile of global configuration. Choices:
|
|
Override value.<br><font color=”red”>Required only for</font> ‘override-profile’ is True. Valid values are in the range 1-2880. |
|
Gateway(s) to receive identity from. |
|
Enable receiving identities from Infinity Identity. Choices:
|
|
Enable receiving identity from other gateways. Choices:
|
|
Enable Scaled Sharing. Choices:
|
|
Enable identity sharing with other gateways. Choices:
|
|
Enable Identity Web API source. Choices:
|
|
Identity Web API settings. |
|
Authentication Settings for Identity Web Api. |
|
Users directories. |
|
External user profile. Choices:
|
|
Internal users. Choices:
|
|
LDAP AU objects identified by the name or UID. Must be set when “users-from-external-directories” was selected to be “specific”. |
|
Users from external directories. Choices:
|
|
Authorized Clients. |
|
Host / Network Group Name or UID. |
|
Client Secret. |
|
Identity Web Api accessibility settings. |
|
Configuration of the portal access settings. |
|
Allowed access to the web portal (based on interfaces, or security policy). Choices:
|
|
Configuration of the additional portal access settings for internal interfaces only. |
|
Controls portal access settings for internal interfaces, whose topology is set to ‘DMZ’. Choices:
|
|
Controls portal access settings for internal interfaces, whose topology is set to ‘Undefined’. Choices:
|
|
Controls portal access settings for interfaces that are part of a VPN Encryption Domain. Choices:
|
|
Identity-Awareness Proxy settings. |
|
Whether to use X-Forward-For HTTP header, which is added by the proxy server to keep track of the original source IP. Choices:
|
|
Enable Remote Access Identity source. Choices:
|
|
Apply changes ignoring errors. You won’t be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored. Choices:
|
|
Apply changes ignoring warnings. Choices:
|
|
Network interfaces. When a gateway is updated with a new interfaces, the existing interfaces are removed. |
|
N/A Choices:
|
|
N/A |
|
If packets will be rejected (the Prevent option) or whether the packets will be monitored (the Detect option). Choices:
|
|
Color of the object. Should be one of existing colors. Choices:
|
|
Comments string. |
|
The level of detail for some of the fields in the response can vary from showing only the UID value of the object to a fully detailed representation of the object. Choices:
|
|
Apply changes ignoring errors. You won’t be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored. Choices:
|
|
Apply changes ignoring warnings. Choices:
|
|
IPv4 or IPv6 address. If both addresses are required use ipv4-address and ipv6-address fields explicitly. |
|
IPv4 address. |
|
IPv4 network mask length. |
|
IPv4 network address. |
|
IPv6 address. |
|
IPv6 network mask length. |
|
IPv6 network address. |
|
IPv4 or IPv6 network mask length. |
|
Object name. |
|
IPv4 or IPv6 network mask. If both masks are required use ipv4-network-mask and ipv6-network-mask fields explicitly. Instead of providing mask itself it is possible to specify IPv4 or IPv6 mask length in mask-length field. If both masks length are required use ipv4-mask-length and ipv6-mask-length fields explicitly. |
|
N/A Choices:
|
|
N/A |
|
Security Zone is calculated according to where the interface leads to. Choices:
|
|
Security Zone specified manually. |
|
Collection of tag identifiers. |
|
N/A Choices:
|
|
N/A |
|
Whether this interface leads to demilitarized zone (perimeter network). Choices:
|
|
N/A Choices:
|
|
Network behind this interface. |
|
IPv4 or IPv6 address. If both addresses are required use ipv4-address and ipv6-address fields explicitly. |
|
Intrusion Prevention System blade enabled. Choices:
|
|
Gateway IPS settings. Available from R82 JHF management version. |
|
Defines whether the IPS blade operates in Detect Only mode or enforces the configured IPS Policy. Choices:
|
|
Disable/enable all IPS protections until CPU and memory levels are back to normal. Choices:
|
|
Track options when all IPS protections are disabled until CPU/memory levels are back to normal. Choices:
|
|
CPU usage high threshold percentage (1-99). |
|
CPU usage low threshold percentage (1-99). |
|
Memory usage high threshold percentage (1-99). |
|
Memory usage low threshold percentage (1-99). |
|
Help improve Check Point Threat Prevention product by sending anonymous information. Choices:
|
|
IPv4 address. |
|
IPv6 address. |
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
Distribute logs between all active servers. Choices:
|
|
N/A Choices:
|
|
N/A |
|
N/A |
|
N/A Choices:
|
|
N/A Choices:
|
|
N/A Choices:
|
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
N/A Choices:
|
|
N/A |
|
Object name. |
|
N/A |
|
Gateway platform operating system. |
|
Save logs locally on the gateway. Choices:
|
|
Server(s) to send alerts to. |
|
Backup server(s) to send logs to. |
|
Server(s) to send logs to. |
|
State of the access rule (present or absent). Choices:
|
|
Collection of tag identifiers. |
|
Threat Emulation blade enabled. Choices:
|
|
Threat Extraction blade enabled. Available from R80.20.M2 management version. Choices:
|
|
URL Filtering blade enabled. Choices:
|
|
Version of checkpoint. If not given one, the latest version taken. |
|
VPN blade enabled. Choices:
|
|
Gateway VPN settings. |
|
N/A |
|
N/A |
|
Wait for the task to end. Such as publish task. Choices:
|
|
How many minutes to wait until throwing a timeout error. Default: |
Examples
- name: add-simple-gateway
cp_mgmt_simple_gateway:
ip_address: 192.0.2.1
name: gw1
state: present
- name: set-simple-gateway
cp_mgmt_simple_gateway:
anti_bot: true
anti_virus: true
application_control: true
ips: true
name: test_gateway
state: present
threat_emulation: true
url_filtering: true
- name: delete-simple-gateway
cp_mgmt_simple_gateway:
name: gw1
state: absent
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
The checkpoint object created or updated. Returned: always, except when deleting the object. |