Automate Check Point management with mgmt cli and Web API
More actions
Automate Check Point management objects and policy changes with mgmt_cli, Gaia management commands or the HTTPS Management API.
API workflow
A normal multi-command Management API workflow is:
- Log in and obtain a session.
- Make one or more changes.
- Review the results.
- Publish the session, or discard it if validation fails.
- Log out.
This is important because Management API changes made within a session are not committed until they are published.
mgmt_cli session example
The following interactive login avoids placing a password directly in the command line and writes the session response to a local file.
mgmt_cli login > id.txt
Use the session file for subsequent commands:
mgmt_cli add host name host1 ip-address 192.0.2.10 -s id.txt
Publish the changes:
mgmt_cli publish -s id.txt
Then log out:
mgmt_cli logout -s id.txt
id.txt contains a usable session identifier. Restrict access to it and delete it securely when the automation completes.Single-command behaviour
Check Point documents that when mgmt_cli is invoked with credentials rather than an existing session, it can perform login, the requested command, publish and logout as one operation.
For controlled automation involving multiple related changes, using an explicit session makes the publish/discard boundary clearer.
Gaia Clish management commands
On a management server, Check Point also supports management commands from Gaia Clish after a management login.
mgmt login mgmt add host name myHost12 ip-address 192.0.2.12 mgmt publish
HTTPS Web API
The Management API is also available through HTTPS:
POST https://<management-server>/web_api/<command>
After the login request, subsequent requests include the returned session identifier in the X-chkp-sid HTTP header.
A typical sequence is:
loginadd-host,set-host, policy or other API operationspublishlogout