published on Wednesday, Sep 16, 2026 by checkpointsw
published on Wednesday, Sep 16, 2026 by checkpointsw
This resource allows you to add/update/delete Check Point Access Rule.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as checkpoint from "@pulumi/checkpoint";
const rule1 = new checkpoint.ManagementAccessRule("rule1", {
name: "Rule 1",
layer: "Network",
position: {
top: "top",
},
sources: ["Any"],
destinations: ["Any"],
services: ["Any"],
contents: ["Any"],
times: ["Any"],
installOns: ["Policy Targets"],
track: {
type: "Log",
accounting: false,
alert: "none",
enableFirewallSession: false,
perConnection: true,
perSession: false,
},
actionSettings: {},
customFields: {},
vpn: "Any",
});
const rule2 = new checkpoint.ManagementAccessRule("rule2", {
name: "Rule 2",
layer: "Network",
position: {
below: rule1.name,
},
enabled: true,
sources: [
"DMZNet",
"DMZZone",
"WirelessZone",
],
destinations: [
"InternalNet",
"CPDShield",
],
destinationNegate: true,
services: ["Any"],
contents: ["Any"],
times: ["Any"],
installOns: ["Policy Targets"],
track: {
type: "Log",
accounting: false,
alert: "none",
enableFirewallSession: false,
perConnection: true,
perSession: false,
},
actionSettings: {},
customFields: {},
vpn: "All_GwToGw",
});
const rule3 = new checkpoint.ManagementAccessRule("rule3", {
name: "Rule 3",
layer: "Network",
position: {
below: rule2.name,
},
action: "Accept",
actionSettings: {
enableIdentityCaptivePortal: true,
},
sources: ["DMZNet"],
enabled: true,
destinations: ["InternalNet"],
destinationNegate: true,
services: ["EDGE"],
contents: ["Any"],
times: ["Weekend"],
installOns: ["Policy Targets"],
track: {
type: "Log",
accounting: false,
alert: "none",
enableFirewallSession: false,
perConnection: true,
perSession: false,
},
customFields: {},
vpnCommunities: [
"StarCommunity",
"MeshedCommunity",
],
});
const rule4 = new checkpoint.ManagementAccessRule("rule4", {
name: "Rule 4",
layer: "Network",
position: {
below: rule3.name,
},
enabled: false,
sources: ["Any"],
destinations: ["Any"],
services: ["Any"],
contents: ["Any"],
times: ["Any"],
installOns: ["Policy Targets"],
track: {
type: "Log",
accounting: false,
alert: "none",
enableFirewallSession: false,
perConnection: true,
perSession: false,
},
actionSettings: {},
customFields: {},
vpnDirectionals: [{
from: "StarVpn",
to: "MeshedCommunity",
}],
});
const rule5 = new checkpoint.ManagementAccessRule("rule5", {
name: "Rule 5",
layer: "Network",
position: {
below: rule4.name,
},
action: "Accept",
actionSettings: {
enableIdentityCaptivePortal: false,
},
sources: ["Any"],
destinations: ["Any"],
services: ["Any"],
contents: ["Any"],
times: ["Any"],
installOns: ["Policy Targets"],
track: {
type: "Log",
accounting: false,
alert: "none",
enableFirewallSession: false,
perConnection: true,
perSession: false,
},
customFields: {},
vpn: "Any",
});
import pulumi
import pulumi_checkpoint as checkpoint
rule1 = checkpoint.ManagementAccessRule("rule1",
name="Rule 1",
layer="Network",
position={
"top": "top",
},
sources=["Any"],
destinations=["Any"],
services=["Any"],
contents=["Any"],
times=["Any"],
install_ons=["Policy Targets"],
track={
"type": "Log",
"accounting": False,
"alert": "none",
"enable_firewall_session": False,
"per_connection": True,
"per_session": False,
},
action_settings={},
custom_fields={},
vpn="Any")
rule2 = checkpoint.ManagementAccessRule("rule2",
name="Rule 2",
layer="Network",
position={
"below": rule1.name,
},
enabled=True,
sources=[
"DMZNet",
"DMZZone",
"WirelessZone",
],
destinations=[
"InternalNet",
"CPDShield",
],
destination_negate=True,
services=["Any"],
contents=["Any"],
times=["Any"],
install_ons=["Policy Targets"],
track={
"type": "Log",
"accounting": False,
"alert": "none",
"enable_firewall_session": False,
"per_connection": True,
"per_session": False,
},
action_settings={},
custom_fields={},
vpn="All_GwToGw")
rule3 = checkpoint.ManagementAccessRule("rule3",
name="Rule 3",
layer="Network",
position={
"below": rule2.name,
},
action="Accept",
action_settings={
"enable_identity_captive_portal": True,
},
sources=["DMZNet"],
enabled=True,
destinations=["InternalNet"],
destination_negate=True,
services=["EDGE"],
contents=["Any"],
times=["Weekend"],
install_ons=["Policy Targets"],
track={
"type": "Log",
"accounting": False,
"alert": "none",
"enable_firewall_session": False,
"per_connection": True,
"per_session": False,
},
custom_fields={},
vpn_communities=[
"StarCommunity",
"MeshedCommunity",
])
rule4 = checkpoint.ManagementAccessRule("rule4",
name="Rule 4",
layer="Network",
position={
"below": rule3.name,
},
enabled=False,
sources=["Any"],
destinations=["Any"],
services=["Any"],
contents=["Any"],
times=["Any"],
install_ons=["Policy Targets"],
track={
"type": "Log",
"accounting": False,
"alert": "none",
"enable_firewall_session": False,
"per_connection": True,
"per_session": False,
},
action_settings={},
custom_fields={},
vpn_directionals=[{
"from_": "StarVpn",
"to": "MeshedCommunity",
}])
rule5 = checkpoint.ManagementAccessRule("rule5",
name="Rule 5",
layer="Network",
position={
"below": rule4.name,
},
action="Accept",
action_settings={
"enable_identity_captive_portal": False,
},
sources=["Any"],
destinations=["Any"],
services=["Any"],
contents=["Any"],
times=["Any"],
install_ons=["Policy Targets"],
track={
"type": "Log",
"accounting": False,
"alert": "none",
"enable_firewall_session": False,
"per_connection": True,
"per_session": False,
},
custom_fields={},
vpn="Any")
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/checkpoint/v3/checkpoint"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
rule1, err := checkpoint.NewManagementAccessRule(ctx, "rule1", &checkpoint.ManagementAccessRuleArgs{
Name: pulumi.String("Rule 1"),
Layer: pulumi.String("Network"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Top: pulumi.String("top"),
},
Sources: pulumi.StringArray{
pulumi.String("Any"),
},
Destinations: pulumi.StringArray{
pulumi.String("Any"),
},
Services: pulumi.StringArray{
pulumi.String("Any"),
},
Contents: pulumi.StringArray{
pulumi.String("Any"),
},
Times: pulumi.StringArray{
pulumi.String("Any"),
},
InstallOns: pulumi.StringArray{
pulumi.String("Policy Targets"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Type: pulumi.String("Log"),
Accounting: pulumi.Bool(false),
Alert: pulumi.String("none"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(true),
PerSession: pulumi.Bool(false),
},
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{},
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{},
Vpn: pulumi.String("Any"),
})
if err != nil {
return err
}
rule2, err := checkpoint.NewManagementAccessRule(ctx, "rule2", &checkpoint.ManagementAccessRuleArgs{
Name: pulumi.String("Rule 2"),
Layer: pulumi.String("Network"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Below: rule1.Name,
},
Enabled: pulumi.Bool(true),
Sources: pulumi.StringArray{
pulumi.String("DMZNet"),
pulumi.String("DMZZone"),
pulumi.String("WirelessZone"),
},
Destinations: pulumi.StringArray{
pulumi.String("InternalNet"),
pulumi.String("CPDShield"),
},
DestinationNegate: pulumi.Bool(true),
Services: pulumi.StringArray{
pulumi.String("Any"),
},
Contents: pulumi.StringArray{
pulumi.String("Any"),
},
Times: pulumi.StringArray{
pulumi.String("Any"),
},
InstallOns: pulumi.StringArray{
pulumi.String("Policy Targets"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Type: pulumi.String("Log"),
Accounting: pulumi.Bool(false),
Alert: pulumi.String("none"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(true),
PerSession: pulumi.Bool(false),
},
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{},
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{},
Vpn: pulumi.String("All_GwToGw"),
})
if err != nil {
return err
}
rule3, err := checkpoint.NewManagementAccessRule(ctx, "rule3", &checkpoint.ManagementAccessRuleArgs{
Name: pulumi.String("Rule 3"),
Layer: pulumi.String("Network"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Below: rule2.Name,
},
Action: pulumi.String("Accept"),
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{
EnableIdentityCaptivePortal: pulumi.Bool(true),
},
Sources: pulumi.StringArray{
pulumi.String("DMZNet"),
},
Enabled: pulumi.Bool(true),
Destinations: pulumi.StringArray{
pulumi.String("InternalNet"),
},
DestinationNegate: pulumi.Bool(true),
Services: pulumi.StringArray{
pulumi.String("EDGE"),
},
Contents: pulumi.StringArray{
pulumi.String("Any"),
},
Times: pulumi.StringArray{
pulumi.String("Weekend"),
},
InstallOns: pulumi.StringArray{
pulumi.String("Policy Targets"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Type: pulumi.String("Log"),
Accounting: pulumi.Bool(false),
Alert: pulumi.String("none"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(true),
PerSession: pulumi.Bool(false),
},
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{},
VpnCommunities: pulumi.StringArray{
pulumi.String("StarCommunity"),
pulumi.String("MeshedCommunity"),
},
})
if err != nil {
return err
}
rule4, err := checkpoint.NewManagementAccessRule(ctx, "rule4", &checkpoint.ManagementAccessRuleArgs{
Name: pulumi.String("Rule 4"),
Layer: pulumi.String("Network"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Below: rule3.Name,
},
Enabled: pulumi.Bool(false),
Sources: pulumi.StringArray{
pulumi.String("Any"),
},
Destinations: pulumi.StringArray{
pulumi.String("Any"),
},
Services: pulumi.StringArray{
pulumi.String("Any"),
},
Contents: pulumi.StringArray{
pulumi.String("Any"),
},
Times: pulumi.StringArray{
pulumi.String("Any"),
},
InstallOns: pulumi.StringArray{
pulumi.String("Policy Targets"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Type: pulumi.String("Log"),
Accounting: pulumi.Bool(false),
Alert: pulumi.String("none"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(true),
PerSession: pulumi.Bool(false),
},
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{},
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{},
VpnDirectionals: checkpoint.ManagementAccessRuleVpnDirectionalArray{
&checkpoint.ManagementAccessRuleVpnDirectionalArgs{
From: pulumi.String("StarVpn"),
To: pulumi.String("MeshedCommunity"),
},
},
})
if err != nil {
return err
}
_, err = checkpoint.NewManagementAccessRule(ctx, "rule5", &checkpoint.ManagementAccessRuleArgs{
Name: pulumi.String("Rule 5"),
Layer: pulumi.String("Network"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Below: rule4.Name,
},
Action: pulumi.String("Accept"),
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{
EnableIdentityCaptivePortal: pulumi.Bool(false),
},
Sources: pulumi.StringArray{
pulumi.String("Any"),
},
Destinations: pulumi.StringArray{
pulumi.String("Any"),
},
Services: pulumi.StringArray{
pulumi.String("Any"),
},
Contents: pulumi.StringArray{
pulumi.String("Any"),
},
Times: pulumi.StringArray{
pulumi.String("Any"),
},
InstallOns: pulumi.StringArray{
pulumi.String("Policy Targets"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Type: pulumi.String("Log"),
Accounting: pulumi.Bool(false),
Alert: pulumi.String("none"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(true),
PerSession: pulumi.Bool(false),
},
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{},
Vpn: pulumi.String("Any"),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Checkpoint = Pulumi.Checkpoint;
return await Deployment.RunAsync(() =>
{
var rule1 = new Checkpoint.ManagementAccessRule("rule1", new()
{
Name = "Rule 1",
Layer = "Network",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Top = "top",
},
Sources = new[]
{
"Any",
},
Destinations = new[]
{
"Any",
},
Services = new[]
{
"Any",
},
Contents = new[]
{
"Any",
},
Times = new[]
{
"Any",
},
InstallOns = new[]
{
"Policy Targets",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Type = "Log",
Accounting = false,
Alert = "none",
EnableFirewallSession = false,
PerConnection = true,
PerSession = false,
},
ActionSettings = null,
CustomFields = null,
Vpn = "Any",
});
var rule2 = new Checkpoint.ManagementAccessRule("rule2", new()
{
Name = "Rule 2",
Layer = "Network",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Below = rule1.Name,
},
Enabled = true,
Sources = new[]
{
"DMZNet",
"DMZZone",
"WirelessZone",
},
Destinations = new[]
{
"InternalNet",
"CPDShield",
},
DestinationNegate = true,
Services = new[]
{
"Any",
},
Contents = new[]
{
"Any",
},
Times = new[]
{
"Any",
},
InstallOns = new[]
{
"Policy Targets",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Type = "Log",
Accounting = false,
Alert = "none",
EnableFirewallSession = false,
PerConnection = true,
PerSession = false,
},
ActionSettings = null,
CustomFields = null,
Vpn = "All_GwToGw",
});
var rule3 = new Checkpoint.ManagementAccessRule("rule3", new()
{
Name = "Rule 3",
Layer = "Network",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Below = rule2.Name,
},
Action = "Accept",
ActionSettings = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsArgs
{
EnableIdentityCaptivePortal = true,
},
Sources = new[]
{
"DMZNet",
},
Enabled = true,
Destinations = new[]
{
"InternalNet",
},
DestinationNegate = true,
Services = new[]
{
"EDGE",
},
Contents = new[]
{
"Any",
},
Times = new[]
{
"Weekend",
},
InstallOns = new[]
{
"Policy Targets",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Type = "Log",
Accounting = false,
Alert = "none",
EnableFirewallSession = false,
PerConnection = true,
PerSession = false,
},
CustomFields = null,
VpnCommunities = new[]
{
"StarCommunity",
"MeshedCommunity",
},
});
var rule4 = new Checkpoint.ManagementAccessRule("rule4", new()
{
Name = "Rule 4",
Layer = "Network",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Below = rule3.Name,
},
Enabled = false,
Sources = new[]
{
"Any",
},
Destinations = new[]
{
"Any",
},
Services = new[]
{
"Any",
},
Contents = new[]
{
"Any",
},
Times = new[]
{
"Any",
},
InstallOns = new[]
{
"Policy Targets",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Type = "Log",
Accounting = false,
Alert = "none",
EnableFirewallSession = false,
PerConnection = true,
PerSession = false,
},
ActionSettings = null,
CustomFields = null,
VpnDirectionals = new[]
{
new Checkpoint.Inputs.ManagementAccessRuleVpnDirectionalArgs
{
From = "StarVpn",
To = "MeshedCommunity",
},
},
});
var rule5 = new Checkpoint.ManagementAccessRule("rule5", new()
{
Name = "Rule 5",
Layer = "Network",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Below = rule4.Name,
},
Action = "Accept",
ActionSettings = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsArgs
{
EnableIdentityCaptivePortal = false,
},
Sources = new[]
{
"Any",
},
Destinations = new[]
{
"Any",
},
Services = new[]
{
"Any",
},
Contents = new[]
{
"Any",
},
Times = new[]
{
"Any",
},
InstallOns = new[]
{
"Policy Targets",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Type = "Log",
Accounting = false,
Alert = "none",
EnableFirewallSession = false,
PerConnection = true,
PerSession = false,
},
CustomFields = null,
Vpn = "Any",
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.checkpoint.ManagementAccessRule;
import com.pulumi.checkpoint.ManagementAccessRuleArgs;
import com.pulumi.checkpoint.inputs.ManagementAccessRulePositionArgs;
import com.pulumi.checkpoint.inputs.ManagementAccessRuleTrackArgs;
import com.pulumi.checkpoint.inputs.ManagementAccessRuleActionSettingsArgs;
import com.pulumi.checkpoint.inputs.ManagementAccessRuleCustomFieldsArgs;
import com.pulumi.checkpoint.inputs.ManagementAccessRuleVpnDirectionalArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var rule1 = new ManagementAccessRule("rule1", ManagementAccessRuleArgs.builder()
.name("Rule 1")
.layer("Network")
.position(ManagementAccessRulePositionArgs.builder()
.top("top")
.build())
.sources("Any")
.destinations("Any")
.services("Any")
.contents("Any")
.times("Any")
.installOns("Policy Targets")
.track(ManagementAccessRuleTrackArgs.builder()
.type("Log")
.accounting(false)
.alert("none")
.enableFirewallSession(false)
.perConnection(true)
.perSession(false)
.build())
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.build())
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.build())
.vpn("Any")
.build());
var rule2 = new ManagementAccessRule("rule2", ManagementAccessRuleArgs.builder()
.name("Rule 2")
.layer("Network")
.position(ManagementAccessRulePositionArgs.builder()
.below(rule1.name())
.build())
.enabled(true)
.sources(
"DMZNet",
"DMZZone",
"WirelessZone")
.destinations(
"InternalNet",
"CPDShield")
.destinationNegate(true)
.services("Any")
.contents("Any")
.times("Any")
.installOns("Policy Targets")
.track(ManagementAccessRuleTrackArgs.builder()
.type("Log")
.accounting(false)
.alert("none")
.enableFirewallSession(false)
.perConnection(true)
.perSession(false)
.build())
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.build())
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.build())
.vpn("All_GwToGw")
.build());
var rule3 = new ManagementAccessRule("rule3", ManagementAccessRuleArgs.builder()
.name("Rule 3")
.layer("Network")
.position(ManagementAccessRulePositionArgs.builder()
.below(rule2.name())
.build())
.action("Accept")
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.enableIdentityCaptivePortal(true)
.build())
.sources("DMZNet")
.enabled(true)
.destinations("InternalNet")
.destinationNegate(true)
.services("EDGE")
.contents("Any")
.times("Weekend")
.installOns("Policy Targets")
.track(ManagementAccessRuleTrackArgs.builder()
.type("Log")
.accounting(false)
.alert("none")
.enableFirewallSession(false)
.perConnection(true)
.perSession(false)
.build())
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.build())
.vpnCommunities(
"StarCommunity",
"MeshedCommunity")
.build());
var rule4 = new ManagementAccessRule("rule4", ManagementAccessRuleArgs.builder()
.name("Rule 4")
.layer("Network")
.position(ManagementAccessRulePositionArgs.builder()
.below(rule3.name())
.build())
.enabled(false)
.sources("Any")
.destinations("Any")
.services("Any")
.contents("Any")
.times("Any")
.installOns("Policy Targets")
.track(ManagementAccessRuleTrackArgs.builder()
.type("Log")
.accounting(false)
.alert("none")
.enableFirewallSession(false)
.perConnection(true)
.perSession(false)
.build())
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.build())
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.build())
.vpnDirectionals(ManagementAccessRuleVpnDirectionalArgs.builder()
.from("StarVpn")
.to("MeshedCommunity")
.build())
.build());
var rule5 = new ManagementAccessRule("rule5", ManagementAccessRuleArgs.builder()
.name("Rule 5")
.layer("Network")
.position(ManagementAccessRulePositionArgs.builder()
.below(rule4.name())
.build())
.action("Accept")
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.enableIdentityCaptivePortal(false)
.build())
.sources("Any")
.destinations("Any")
.services("Any")
.contents("Any")
.times("Any")
.installOns("Policy Targets")
.track(ManagementAccessRuleTrackArgs.builder()
.type("Log")
.accounting(false)
.alert("none")
.enableFirewallSession(false)
.perConnection(true)
.perSession(false)
.build())
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.build())
.vpn("Any")
.build());
}
}
resources:
rule1:
type: checkpoint:ManagementAccessRule
properties:
name: Rule 1
layer: Network
position:
top: top
sources:
- Any
destinations:
- Any
services:
- Any
contents:
- Any
times:
- Any
installOns:
- Policy Targets
track:
type: Log
accounting: false
alert: none
enableFirewallSession: false
perConnection: true
perSession: false
actionSettings: {}
customFields: {}
vpn: Any
rule2:
type: checkpoint:ManagementAccessRule
properties:
name: Rule 2
layer: Network
position:
below: ${rule1.name}
enabled: true
sources:
- DMZNet
- DMZZone
- WirelessZone
destinations:
- InternalNet
- CPDShield
destinationNegate: true
services:
- Any
contents:
- Any
times:
- Any
installOns:
- Policy Targets
track:
type: Log
accounting: false
alert: none
enableFirewallSession: false
perConnection: true
perSession: false
actionSettings: {}
customFields: {}
vpn: All_GwToGw
rule3:
type: checkpoint:ManagementAccessRule
properties:
name: Rule 3
layer: Network
position:
below: ${rule2.name}
action: Accept
actionSettings:
enableIdentityCaptivePortal: true
sources:
- DMZNet
enabled: true
destinations:
- InternalNet
destinationNegate: true
services:
- EDGE
contents:
- Any
times:
- Weekend
installOns:
- Policy Targets
track:
type: Log
accounting: false
alert: none
enableFirewallSession: false
perConnection: true
perSession: false
customFields: {}
vpnCommunities:
- StarCommunity
- MeshedCommunity
rule4:
type: checkpoint:ManagementAccessRule
properties:
name: Rule 4
layer: Network
position:
below: ${rule3.name}
enabled: false
sources:
- Any
destinations:
- Any
services:
- Any
contents:
- Any
times:
- Any
installOns:
- Policy Targets
track:
type: Log
accounting: false
alert: none
enableFirewallSession: false
perConnection: true
perSession: false
actionSettings: {}
customFields: {}
vpnDirectionals:
- from: StarVpn
to: MeshedCommunity
rule5:
type: checkpoint:ManagementAccessRule
properties:
name: Rule 5
layer: Network
position:
below: ${rule4.name}
action: Accept
actionSettings:
enableIdentityCaptivePortal: false
sources:
- Any
destinations:
- Any
services:
- Any
contents:
- Any
times:
- Any
installOns:
- Policy Targets
track:
type: Log
accounting: false
alert: none
enableFirewallSession: false
perConnection: true
perSession: false
customFields: {}
vpn: Any
Example coming soon!
Create ManagementAccessRule Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new ManagementAccessRule(name: string, args: ManagementAccessRuleArgs, opts?: CustomResourceOptions);@overload
def ManagementAccessRule(resource_name: str,
args: ManagementAccessRuleArgs,
opts: Optional[ResourceOptions] = None)
@overload
def ManagementAccessRule(resource_name: str,
opts: Optional[ResourceOptions] = None,
layer: Optional[str] = None,
position: Optional[ManagementAccessRulePositionArgs] = None,
install_ons: Optional[Sequence[str]] = None,
track: Optional[ManagementAccessRuleTrackArgs] = None,
content_negate: Optional[bool] = None,
contents: Optional[Sequence[str]] = None,
management_access_rule_id: Optional[str] = None,
destination_negate: Optional[bool] = None,
destinations: Optional[Sequence[str]] = None,
enabled: Optional[bool] = None,
fields_with_uid_identifiers: Optional[Sequence[str]] = None,
ignore_errors: Optional[bool] = None,
ignore_warnings: Optional[bool] = None,
inline_layer: Optional[str] = None,
content_direction: Optional[str] = None,
action: Optional[str] = None,
custom_fields: Optional[ManagementAccessRuleCustomFieldsArgs] = None,
name: Optional[str] = None,
action_settings: Optional[ManagementAccessRuleActionSettingsArgs] = None,
service_negate: Optional[bool] = None,
service_resource: Optional[str] = None,
services: Optional[Sequence[str]] = None,
source_negate: Optional[bool] = None,
sources: Optional[Sequence[str]] = None,
times: Optional[Sequence[str]] = None,
comments: Optional[str] = None,
user_check: Optional[ManagementAccessRuleUserCheckArgs] = None,
vpn: Optional[str] = None,
vpn_communities: Optional[Sequence[str]] = None,
vpn_directionals: Optional[Sequence[ManagementAccessRuleVpnDirectionalArgs]] = None)func NewManagementAccessRule(ctx *Context, name string, args ManagementAccessRuleArgs, opts ...ResourceOption) (*ManagementAccessRule, error)public ManagementAccessRule(string name, ManagementAccessRuleArgs args, CustomResourceOptions? opts = null)
public ManagementAccessRule(String name, ManagementAccessRuleArgs args)
public ManagementAccessRule(String name, ManagementAccessRuleArgs args, CustomResourceOptions options)
type: checkpoint:ManagementAccessRule
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "checkpoint_management_access_rule" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args ManagementAccessRuleArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args ManagementAccessRuleArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args ManagementAccessRuleArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args ManagementAccessRuleArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args ManagementAccessRuleArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var managementAccessRuleResource = new Checkpoint.ManagementAccessRule("managementAccessRuleResource", new()
{
Layer = "string",
Position = new Checkpoint.Inputs.ManagementAccessRulePositionArgs
{
Above = "string",
Below = "string",
Bottom = "string",
Top = "string",
},
InstallOns = new[]
{
"string",
},
Track = new Checkpoint.Inputs.ManagementAccessRuleTrackArgs
{
Accounting = false,
Alert = "string",
EnableFirewallSession = false,
PerConnection = false,
PerSession = false,
Type = "string",
},
ContentNegate = false,
Contents = new[]
{
"string",
},
ManagementAccessRuleId = "string",
DestinationNegate = false,
Destinations = new[]
{
"string",
},
Enabled = false,
FieldsWithUidIdentifiers = new[]
{
"string",
},
IgnoreErrors = false,
IgnoreWarnings = false,
InlineLayer = "string",
ContentDirection = "string",
Action = "string",
CustomFields = new Checkpoint.Inputs.ManagementAccessRuleCustomFieldsArgs
{
Field1 = "string",
Field2 = "string",
Field3 = "string",
},
Name = "string",
ActionSettings = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsArgs
{
ClientAuthSettings = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsClientAuthSettingsArgs
{
Destination = "string",
RequireDesktopConfigVerification = false,
SessionsLimit = 0.0,
SignOnMethod = "string",
SignOnType = "string",
Source = "string",
Timeout = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsClientAuthSettingsTimeoutArgs
{
Enable = false,
Minutes = 0.0,
Refreshable = false,
},
Tracking = "string",
UnlimitedSessions = false,
},
EnableIdentityCaptivePortal = false,
Limit = "string",
UserAuthSettings = new Checkpoint.Inputs.ManagementAccessRuleActionSettingsUserAuthSettingsArgs
{
AllowedHttpServers = "string",
Destination = "string",
Source = "string",
},
},
ServiceNegate = false,
ServiceResource = "string",
Services = new[]
{
"string",
},
SourceNegate = false,
Sources = new[]
{
"string",
},
Times = new[]
{
"string",
},
Comments = "string",
UserCheck = new Checkpoint.Inputs.ManagementAccessRuleUserCheckArgs
{
Confirm = "string",
CustomFrequency = new Checkpoint.Inputs.ManagementAccessRuleUserCheckCustomFrequencyArgs
{
Every = 0.0,
Unit = "string",
},
Frequency = "string",
Interaction = "string",
},
Vpn = "string",
VpnCommunities = new[]
{
"string",
},
VpnDirectionals = new[]
{
new Checkpoint.Inputs.ManagementAccessRuleVpnDirectionalArgs
{
From = "string",
To = "string",
},
},
});
example, err := checkpoint.NewManagementAccessRule(ctx, "managementAccessRuleResource", &checkpoint.ManagementAccessRuleArgs{
Layer: pulumi.String("string"),
Position: &checkpoint.ManagementAccessRulePositionArgs{
Above: pulumi.String("string"),
Below: pulumi.String("string"),
Bottom: pulumi.String("string"),
Top: pulumi.String("string"),
},
InstallOns: pulumi.StringArray{
pulumi.String("string"),
},
Track: &checkpoint.ManagementAccessRuleTrackArgs{
Accounting: pulumi.Bool(false),
Alert: pulumi.String("string"),
EnableFirewallSession: pulumi.Bool(false),
PerConnection: pulumi.Bool(false),
PerSession: pulumi.Bool(false),
Type: pulumi.String("string"),
},
ContentNegate: pulumi.Bool(false),
Contents: pulumi.StringArray{
pulumi.String("string"),
},
ManagementAccessRuleId: pulumi.String("string"),
DestinationNegate: pulumi.Bool(false),
Destinations: pulumi.StringArray{
pulumi.String("string"),
},
Enabled: pulumi.Bool(false),
FieldsWithUidIdentifiers: pulumi.StringArray{
pulumi.String("string"),
},
IgnoreErrors: pulumi.Bool(false),
IgnoreWarnings: pulumi.Bool(false),
InlineLayer: pulumi.String("string"),
ContentDirection: pulumi.String("string"),
Action: pulumi.String("string"),
CustomFields: &checkpoint.ManagementAccessRuleCustomFieldsArgs{
Field1: pulumi.String("string"),
Field2: pulumi.String("string"),
Field3: pulumi.String("string"),
},
Name: pulumi.String("string"),
ActionSettings: &checkpoint.ManagementAccessRuleActionSettingsArgs{
ClientAuthSettings: &checkpoint.ManagementAccessRuleActionSettingsClientAuthSettingsArgs{
Destination: pulumi.String("string"),
RequireDesktopConfigVerification: pulumi.Bool(false),
SessionsLimit: pulumi.Float64(0),
SignOnMethod: pulumi.String("string"),
SignOnType: pulumi.String("string"),
Source: pulumi.String("string"),
Timeout: &checkpoint.ManagementAccessRuleActionSettingsClientAuthSettingsTimeoutArgs{
Enable: pulumi.Bool(false),
Minutes: pulumi.Float64(0),
Refreshable: pulumi.Bool(false),
},
Tracking: pulumi.String("string"),
UnlimitedSessions: pulumi.Bool(false),
},
EnableIdentityCaptivePortal: pulumi.Bool(false),
Limit: pulumi.String("string"),
UserAuthSettings: &checkpoint.ManagementAccessRuleActionSettingsUserAuthSettingsArgs{
AllowedHttpServers: pulumi.String("string"),
Destination: pulumi.String("string"),
Source: pulumi.String("string"),
},
},
ServiceNegate: pulumi.Bool(false),
ServiceResource: pulumi.String("string"),
Services: pulumi.StringArray{
pulumi.String("string"),
},
SourceNegate: pulumi.Bool(false),
Sources: pulumi.StringArray{
pulumi.String("string"),
},
Times: pulumi.StringArray{
pulumi.String("string"),
},
Comments: pulumi.String("string"),
UserCheck: &checkpoint.ManagementAccessRuleUserCheckArgs{
Confirm: pulumi.String("string"),
CustomFrequency: &checkpoint.ManagementAccessRuleUserCheckCustomFrequencyArgs{
Every: pulumi.Float64(0),
Unit: pulumi.String("string"),
},
Frequency: pulumi.String("string"),
Interaction: pulumi.String("string"),
},
Vpn: pulumi.String("string"),
VpnCommunities: pulumi.StringArray{
pulumi.String("string"),
},
VpnDirectionals: checkpoint.ManagementAccessRuleVpnDirectionalArray{
&checkpoint.ManagementAccessRuleVpnDirectionalArgs{
From: pulumi.String("string"),
To: pulumi.String("string"),
},
},
})
resource "checkpoint_management_access_rule" "managementAccessRuleResource" {
lifecycle {
create_before_destroy = true
}
layer = "string"
position = {
above = "string"
below = "string"
bottom = "string"
top = "string"
}
install_ons = ["string"]
track = {
accounting = false
alert = "string"
enable_firewall_session = false
per_connection = false
per_session = false
type = "string"
}
content_negate = false
contents = ["string"]
management_access_rule_id = "string"
destination_negate = false
destinations = ["string"]
enabled = false
fields_with_uid_identifiers = ["string"]
ignore_errors = false
ignore_warnings = false
inline_layer = "string"
content_direction = "string"
action = "string"
custom_fields = {
field1 = "string"
field2 = "string"
field3 = "string"
}
name = "string"
action_settings = {
client_auth_settings = {
destination = "string"
require_desktop_config_verification = false
sessions_limit = 0
sign_on_method = "string"
sign_on_type = "string"
source = "string"
timeout = {
enable = false
minutes = 0
refreshable = false
}
tracking = "string"
unlimited_sessions = false
}
enable_identity_captive_portal = false
limit = "string"
user_auth_settings = {
allowed_http_servers = "string"
destination = "string"
source = "string"
}
}
service_negate = false
service_resource = "string"
services = ["string"]
source_negate = false
sources = ["string"]
times = ["string"]
comments = "string"
user_check = {
confirm = "string"
custom_frequency = {
every = 0
unit = "string"
}
frequency = "string"
interaction = "string"
}
vpn = "string"
vpn_communities = ["string"]
vpn_directionals {
from = "string"
to = "string"
}
}
var managementAccessRuleResource = new ManagementAccessRule("managementAccessRuleResource", ManagementAccessRuleArgs.builder()
.layer("string")
.position(ManagementAccessRulePositionArgs.builder()
.above("string")
.below("string")
.bottom("string")
.top("string")
.build())
.installOns("string")
.track(ManagementAccessRuleTrackArgs.builder()
.accounting(false)
.alert("string")
.enableFirewallSession(false)
.perConnection(false)
.perSession(false)
.type("string")
.build())
.contentNegate(false)
.contents("string")
.managementAccessRuleId("string")
.destinationNegate(false)
.destinations("string")
.enabled(false)
.fieldsWithUidIdentifiers("string")
.ignoreErrors(false)
.ignoreWarnings(false)
.inlineLayer("string")
.contentDirection("string")
.action("string")
.customFields(ManagementAccessRuleCustomFieldsArgs.builder()
.field1("string")
.field2("string")
.field3("string")
.build())
.name("string")
.actionSettings(ManagementAccessRuleActionSettingsArgs.builder()
.clientAuthSettings(ManagementAccessRuleActionSettingsClientAuthSettingsArgs.builder()
.destination("string")
.requireDesktopConfigVerification(false)
.sessionsLimit(0.0)
.signOnMethod("string")
.signOnType("string")
.source("string")
.timeout(ManagementAccessRuleActionSettingsClientAuthSettingsTimeoutArgs.builder()
.enable(false)
.minutes(0.0)
.refreshable(false)
.build())
.tracking("string")
.unlimitedSessions(false)
.build())
.enableIdentityCaptivePortal(false)
.limit("string")
.userAuthSettings(ManagementAccessRuleActionSettingsUserAuthSettingsArgs.builder()
.allowedHttpServers("string")
.destination("string")
.source("string")
.build())
.build())
.serviceNegate(false)
.serviceResource("string")
.services("string")
.sourceNegate(false)
.sources("string")
.times("string")
.comments("string")
.userCheck(ManagementAccessRuleUserCheckArgs.builder()
.confirm("string")
.customFrequency(ManagementAccessRuleUserCheckCustomFrequencyArgs.builder()
.every(0.0)
.unit("string")
.build())
.frequency("string")
.interaction("string")
.build())
.vpn("string")
.vpnCommunities("string")
.vpnDirectionals(ManagementAccessRuleVpnDirectionalArgs.builder()
.from("string")
.to("string")
.build())
.build());
management_access_rule_resource = checkpoint.ManagementAccessRule("managementAccessRuleResource",
layer="string",
position={
"above": "string",
"below": "string",
"bottom": "string",
"top": "string",
},
install_ons=["string"],
track={
"accounting": False,
"alert": "string",
"enable_firewall_session": False,
"per_connection": False,
"per_session": False,
"type": "string",
},
content_negate=False,
contents=["string"],
management_access_rule_id="string",
destination_negate=False,
destinations=["string"],
enabled=False,
fields_with_uid_identifiers=["string"],
ignore_errors=False,
ignore_warnings=False,
inline_layer="string",
content_direction="string",
action="string",
custom_fields={
"field1": "string",
"field2": "string",
"field3": "string",
},
name="string",
action_settings={
"client_auth_settings": {
"destination": "string",
"require_desktop_config_verification": False,
"sessions_limit": float(0),
"sign_on_method": "string",
"sign_on_type": "string",
"source": "string",
"timeout": {
"enable": False,
"minutes": float(0),
"refreshable": False,
},
"tracking": "string",
"unlimited_sessions": False,
},
"enable_identity_captive_portal": False,
"limit": "string",
"user_auth_settings": {
"allowed_http_servers": "string",
"destination": "string",
"source": "string",
},
},
service_negate=False,
service_resource="string",
services=["string"],
source_negate=False,
sources=["string"],
times=["string"],
comments="string",
user_check={
"confirm": "string",
"custom_frequency": {
"every": float(0),
"unit": "string",
},
"frequency": "string",
"interaction": "string",
},
vpn="string",
vpn_communities=["string"],
vpn_directionals=[{
"from_": "string",
"to": "string",
}])
const managementAccessRuleResource = new checkpoint.ManagementAccessRule("managementAccessRuleResource", {
layer: "string",
position: {
above: "string",
below: "string",
bottom: "string",
top: "string",
},
installOns: ["string"],
track: {
accounting: false,
alert: "string",
enableFirewallSession: false,
perConnection: false,
perSession: false,
type: "string",
},
contentNegate: false,
contents: ["string"],
managementAccessRuleId: "string",
destinationNegate: false,
destinations: ["string"],
enabled: false,
fieldsWithUidIdentifiers: ["string"],
ignoreErrors: false,
ignoreWarnings: false,
inlineLayer: "string",
contentDirection: "string",
action: "string",
customFields: {
field1: "string",
field2: "string",
field3: "string",
},
name: "string",
actionSettings: {
clientAuthSettings: {
destination: "string",
requireDesktopConfigVerification: false,
sessionsLimit: 0,
signOnMethod: "string",
signOnType: "string",
source: "string",
timeout: {
enable: false,
minutes: 0,
refreshable: false,
},
tracking: "string",
unlimitedSessions: false,
},
enableIdentityCaptivePortal: false,
limit: "string",
userAuthSettings: {
allowedHttpServers: "string",
destination: "string",
source: "string",
},
},
serviceNegate: false,
serviceResource: "string",
services: ["string"],
sourceNegate: false,
sources: ["string"],
times: ["string"],
comments: "string",
userCheck: {
confirm: "string",
customFrequency: {
every: 0,
unit: "string",
},
frequency: "string",
interaction: "string",
},
vpn: "string",
vpnCommunities: ["string"],
vpnDirectionals: [{
from: "string",
to: "string",
}],
});
type: checkpoint:ManagementAccessRule
properties:
action: string
actionSettings:
clientAuthSettings:
destination: string
requireDesktopConfigVerification: false
sessionsLimit: 0
signOnMethod: string
signOnType: string
source: string
timeout:
enable: false
minutes: 0
refreshable: false
tracking: string
unlimitedSessions: false
enableIdentityCaptivePortal: false
limit: string
userAuthSettings:
allowedHttpServers: string
destination: string
source: string
comments: string
contentDirection: string
contentNegate: false
contents:
- string
customFields:
field1: string
field2: string
field3: string
destinationNegate: false
destinations:
- string
enabled: false
fieldsWithUidIdentifiers:
- string
ignoreErrors: false
ignoreWarnings: false
inlineLayer: string
installOns:
- string
layer: string
managementAccessRuleId: string
name: string
position:
above: string
below: string
bottom: string
top: string
serviceNegate: false
serviceResource: string
services:
- string
sourceNegate: false
sources:
- string
times:
- string
track:
accounting: false
alert: string
enableFirewallSession: false
perConnection: false
perSession: false
type: string
userCheck:
confirm: string
customFrequency:
every: 0
unit: string
frequency: string
interaction: string
vpn: string
vpnCommunities:
- string
vpnDirectionals:
- from: string
to: string
ManagementAccessRule Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The ManagementAccessRule resource accepts the following input properties:
- Layer string
- Layer that the rule belongs to identified by the name or UID.
- Position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- Action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- Action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- Comments string
- Comments string.
- Content
Direction string - On which direction the file types processing is applied.
- Content
Negate bool - True if negate is set for data.
- Contents List<string>
- List of processed file types that this rule applies on.
- Custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- Destination
Negate bool - True if negate is set for destination.
- Destinations List<string>
- Collection of Network objects identified by the name or UID.
- Enabled bool
- Enable/Disable the rule.
- Fields
With List<string>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- Ignore
Errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- Ignore
Warnings bool - Apply changes ignoring warnings.
- Inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- Install
Ons List<string> - Which Gateways identified by the name or UID to install the policy on.
- Management
Access stringRule Id - Name string
- Rule name.
- Service
Negate bool - True if negate is set for service.
- Service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- Services List<string>
- Collection of Network objects identified by the name or UID.
- Source
Negate bool - True if negate is set for source.
- Sources List<string>
- Collection of Network objects identified by the name or UID.
- Times List<string>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- Track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- User
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- Vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- Vpn
Communities List<string> - Collection of VPN communities identified by name.
- Vpn
Directionals List<ManagementAccess Rule Vpn Directional> - Collection of VPN directional. VPN directional block documented below.
- Layer string
- Layer that the rule belongs to identified by the name or UID.
- Position
Management
Access Rule Position Args - Position in the rulebase. Position blocks are documented below.
- Action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- Action
Settings ManagementAccess Rule Action Settings Args - Action settings. Action settings blocks are documented below.
- Comments string
- Comments string.
- Content
Direction string - On which direction the file types processing is applied.
- Content
Negate bool - True if negate is set for data.
- Contents []string
- List of processed file types that this rule applies on.
- Custom
Fields ManagementAccess Rule Custom Fields Args - Custom fields. Custom fields blocks are documented below.
- Destination
Negate bool - True if negate is set for destination.
- Destinations []string
- Collection of Network objects identified by the name or UID.
- Enabled bool
- Enable/Disable the rule.
- Fields
With []stringUid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- Ignore
Errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- Ignore
Warnings bool - Apply changes ignoring warnings.
- Inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- Install
Ons []string - Which Gateways identified by the name or UID to install the policy on.
- Management
Access stringRule Id - Name string
- Rule name.
- Service
Negate bool - True if negate is set for service.
- Service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- Services []string
- Collection of Network objects identified by the name or UID.
- Source
Negate bool - True if negate is set for source.
- Sources []string
- Collection of Network objects identified by the name or UID.
- Times []string
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- Track
Management
Access Rule Track Args - Track Settings. Track Settings blocks are documented below.
- User
Check ManagementAccess Rule User Check Args - User check settings. User check settings blocks are documented below.
- Vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- Vpn
Communities []string - Collection of VPN communities identified by name.
- Vpn
Directionals []ManagementAccess Rule Vpn Directional Args - Collection of VPN directional. VPN directional block documented below.
- layer string
- Layer that the rule belongs to identified by the name or UID.
- position object
- Position in the rulebase. Position blocks are documented below.
- action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action_
settings object - Action settings. Action settings blocks are documented below.
- comments string
- Comments string.
- content_
direction string - On which direction the file types processing is applied.
- content_
negate bool - True if negate is set for data.
- contents list(string)
- List of processed file types that this rule applies on.
- custom_
fields object - Custom fields. Custom fields blocks are documented below.
- destination_
negate bool - True if negate is set for destination.
- destinations list(string)
- Collection of Network objects identified by the name or UID.
- enabled bool
- Enable/Disable the rule.
- fields_
with_ list(string)uid_ identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore_
errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore_
warnings bool - Apply changes ignoring warnings.
- inline_
layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install_
ons list(string) - Which Gateways identified by the name or UID to install the policy on.
- management_
access_ stringrule_ id - name string
- Rule name.
- service_
negate bool - True if negate is set for service.
- service_
resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services list(string)
- Collection of Network objects identified by the name or UID.
- source_
negate bool - True if negate is set for source.
- sources list(string)
- Collection of Network objects identified by the name or UID.
- times list(string)
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track object
- Track Settings. Track Settings blocks are documented below.
- user_
check object - User check settings. User check settings blocks are documented below.
- vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn_
communities list(string) - Collection of VPN communities identified by name.
- vpn_
directionals list(object) - Collection of VPN directional. VPN directional block documented below.
- layer String
- Layer that the rule belongs to identified by the name or UID.
- position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- action String
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- comments String
- Comments string.
- content
Direction String - On which direction the file types processing is applied.
- content
Negate Boolean - True if negate is set for data.
- contents List<String>
- List of processed file types that this rule applies on.
- custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- destination
Negate Boolean - True if negate is set for destination.
- destinations List<String>
- Collection of Network objects identified by the name or UID.
- enabled Boolean
- Enable/Disable the rule.
- fields
With List<String>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors Boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings Boolean - Apply changes ignoring warnings.
- inline
Layer String - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons List<String> - Which Gateways identified by the name or UID to install the policy on.
- management
Access StringRule Id - name String
- Rule name.
- service
Negate Boolean - True if negate is set for service.
- service
Resource String - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services List<String>
- Collection of Network objects identified by the name or UID.
- source
Negate Boolean - True if negate is set for source.
- sources List<String>
- Collection of Network objects identified by the name or UID.
- times List<String>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- user
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- vpn String
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities List<String> - Collection of VPN communities identified by name.
- vpn
Directionals List<ManagementAccess Rule Vpn Directional> - Collection of VPN directional. VPN directional block documented below.
- layer string
- Layer that the rule belongs to identified by the name or UID.
- position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- comments string
- Comments string.
- content
Direction string - On which direction the file types processing is applied.
- content
Negate boolean - True if negate is set for data.
- contents string[]
- List of processed file types that this rule applies on.
- custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- destination
Negate boolean - True if negate is set for destination.
- destinations string[]
- Collection of Network objects identified by the name or UID.
- enabled boolean
- Enable/Disable the rule.
- fields
With string[]Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings boolean - Apply changes ignoring warnings.
- inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons string[] - Which Gateways identified by the name or UID to install the policy on.
- management
Access stringRule Id - name string
- Rule name.
- service
Negate boolean - True if negate is set for service.
- service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services string[]
- Collection of Network objects identified by the name or UID.
- source
Negate boolean - True if negate is set for source.
- sources string[]
- Collection of Network objects identified by the name or UID.
- times string[]
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- user
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities string[] - Collection of VPN communities identified by name.
- vpn
Directionals ManagementAccess Rule Vpn Directional[] - Collection of VPN directional. VPN directional block documented below.
- layer str
- Layer that the rule belongs to identified by the name or UID.
- position
Management
Access Rule Position Args - Position in the rulebase. Position blocks are documented below.
- action str
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action_
settings ManagementAccess Rule Action Settings Args - Action settings. Action settings blocks are documented below.
- comments str
- Comments string.
- content_
direction str - On which direction the file types processing is applied.
- content_
negate bool - True if negate is set for data.
- contents Sequence[str]
- List of processed file types that this rule applies on.
- custom_
fields ManagementAccess Rule Custom Fields Args - Custom fields. Custom fields blocks are documented below.
- destination_
negate bool - True if negate is set for destination.
- destinations Sequence[str]
- Collection of Network objects identified by the name or UID.
- enabled bool
- Enable/Disable the rule.
- fields_
with_ Sequence[str]uid_ identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore_
errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore_
warnings bool - Apply changes ignoring warnings.
- inline_
layer str - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install_
ons Sequence[str] - Which Gateways identified by the name or UID to install the policy on.
- management_
access_ strrule_ id - name str
- Rule name.
- service_
negate bool - True if negate is set for service.
- service_
resource str - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services Sequence[str]
- Collection of Network objects identified by the name or UID.
- source_
negate bool - True if negate is set for source.
- sources Sequence[str]
- Collection of Network objects identified by the name or UID.
- times Sequence[str]
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track Args - Track Settings. Track Settings blocks are documented below.
- user_
check ManagementAccess Rule User Check Args - User check settings. User check settings blocks are documented below.
- vpn str
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn_
communities Sequence[str] - Collection of VPN communities identified by name.
- vpn_
directionals Sequence[ManagementAccess Rule Vpn Directional Args] - Collection of VPN directional. VPN directional block documented below.
- layer String
- Layer that the rule belongs to identified by the name or UID.
- position Property Map
- Position in the rulebase. Position blocks are documented below.
- action String
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings Property Map - Action settings. Action settings blocks are documented below.
- comments String
- Comments string.
- content
Direction String - On which direction the file types processing is applied.
- content
Negate Boolean - True if negate is set for data.
- contents List<String>
- List of processed file types that this rule applies on.
- custom
Fields Property Map - Custom fields. Custom fields blocks are documented below.
- destination
Negate Boolean - True if negate is set for destination.
- destinations List<String>
- Collection of Network objects identified by the name or UID.
- enabled Boolean
- Enable/Disable the rule.
- fields
With List<String>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors Boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings Boolean - Apply changes ignoring warnings.
- inline
Layer String - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons List<String> - Which Gateways identified by the name or UID to install the policy on.
- management
Access StringRule Id - name String
- Rule name.
- service
Negate Boolean - True if negate is set for service.
- service
Resource String - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services List<String>
- Collection of Network objects identified by the name or UID.
- source
Negate Boolean - True if negate is set for source.
- sources List<String>
- Collection of Network objects identified by the name or UID.
- times List<String>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track Property Map
- Track Settings. Track Settings blocks are documented below.
- user
Check Property Map - User check settings. User check settings blocks are documented below.
- vpn String
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities List<String> - Collection of VPN communities identified by name.
- vpn
Directionals List<Property Map> - Collection of VPN directional. VPN directional block documented below.
Outputs
All input properties are implicitly available as output properties. Additionally, the ManagementAccessRule resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing ManagementAccessRule Resource
Get an existing ManagementAccessRule resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: ManagementAccessRuleState, opts?: CustomResourceOptions): ManagementAccessRule@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
action: Optional[str] = None,
action_settings: Optional[ManagementAccessRuleActionSettingsArgs] = None,
comments: Optional[str] = None,
content_direction: Optional[str] = None,
content_negate: Optional[bool] = None,
contents: Optional[Sequence[str]] = None,
custom_fields: Optional[ManagementAccessRuleCustomFieldsArgs] = None,
destination_negate: Optional[bool] = None,
destinations: Optional[Sequence[str]] = None,
enabled: Optional[bool] = None,
fields_with_uid_identifiers: Optional[Sequence[str]] = None,
ignore_errors: Optional[bool] = None,
ignore_warnings: Optional[bool] = None,
inline_layer: Optional[str] = None,
install_ons: Optional[Sequence[str]] = None,
layer: Optional[str] = None,
management_access_rule_id: Optional[str] = None,
name: Optional[str] = None,
position: Optional[ManagementAccessRulePositionArgs] = None,
service_negate: Optional[bool] = None,
service_resource: Optional[str] = None,
services: Optional[Sequence[str]] = None,
source_negate: Optional[bool] = None,
sources: Optional[Sequence[str]] = None,
times: Optional[Sequence[str]] = None,
track: Optional[ManagementAccessRuleTrackArgs] = None,
user_check: Optional[ManagementAccessRuleUserCheckArgs] = None,
vpn: Optional[str] = None,
vpn_communities: Optional[Sequence[str]] = None,
vpn_directionals: Optional[Sequence[ManagementAccessRuleVpnDirectionalArgs]] = None) -> ManagementAccessRulefunc GetManagementAccessRule(ctx *Context, name string, id IDInput, state *ManagementAccessRuleState, opts ...ResourceOption) (*ManagementAccessRule, error)public static ManagementAccessRule Get(string name, Input<string> id, ManagementAccessRuleState? state, CustomResourceOptions? opts = null)public static ManagementAccessRule get(String name, Output<String> id, ManagementAccessRuleState state, CustomResourceOptions options)resources: _: type: checkpoint:ManagementAccessRule get: id: ${id}import {
to = checkpoint_management_access_rule.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- Action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- Comments string
- Comments string.
- Content
Direction string - On which direction the file types processing is applied.
- Content
Negate bool - True if negate is set for data.
- Contents List<string>
- List of processed file types that this rule applies on.
- Custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- Destination
Negate bool - True if negate is set for destination.
- Destinations List<string>
- Collection of Network objects identified by the name or UID.
- Enabled bool
- Enable/Disable the rule.
- Fields
With List<string>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- Ignore
Errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- Ignore
Warnings bool - Apply changes ignoring warnings.
- Inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- Install
Ons List<string> - Which Gateways identified by the name or UID to install the policy on.
- Layer string
- Layer that the rule belongs to identified by the name or UID.
- Management
Access stringRule Id - Name string
- Rule name.
- Position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- Service
Negate bool - True if negate is set for service.
- Service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- Services List<string>
- Collection of Network objects identified by the name or UID.
- Source
Negate bool - True if negate is set for source.
- Sources List<string>
- Collection of Network objects identified by the name or UID.
- Times List<string>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- Track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- User
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- Vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- Vpn
Communities List<string> - Collection of VPN communities identified by name.
- Vpn
Directionals List<ManagementAccess Rule Vpn Directional> - Collection of VPN directional. VPN directional block documented below.
- Action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- Action
Settings ManagementAccess Rule Action Settings Args - Action settings. Action settings blocks are documented below.
- Comments string
- Comments string.
- Content
Direction string - On which direction the file types processing is applied.
- Content
Negate bool - True if negate is set for data.
- Contents []string
- List of processed file types that this rule applies on.
- Custom
Fields ManagementAccess Rule Custom Fields Args - Custom fields. Custom fields blocks are documented below.
- Destination
Negate bool - True if negate is set for destination.
- Destinations []string
- Collection of Network objects identified by the name or UID.
- Enabled bool
- Enable/Disable the rule.
- Fields
With []stringUid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- Ignore
Errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- Ignore
Warnings bool - Apply changes ignoring warnings.
- Inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- Install
Ons []string - Which Gateways identified by the name or UID to install the policy on.
- Layer string
- Layer that the rule belongs to identified by the name or UID.
- Management
Access stringRule Id - Name string
- Rule name.
- Position
Management
Access Rule Position Args - Position in the rulebase. Position blocks are documented below.
- Service
Negate bool - True if negate is set for service.
- Service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- Services []string
- Collection of Network objects identified by the name or UID.
- Source
Negate bool - True if negate is set for source.
- Sources []string
- Collection of Network objects identified by the name or UID.
- Times []string
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- Track
Management
Access Rule Track Args - Track Settings. Track Settings blocks are documented below.
- User
Check ManagementAccess Rule User Check Args - User check settings. User check settings blocks are documented below.
- Vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- Vpn
Communities []string - Collection of VPN communities identified by name.
- Vpn
Directionals []ManagementAccess Rule Vpn Directional Args - Collection of VPN directional. VPN directional block documented below.
- action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action_
settings object - Action settings. Action settings blocks are documented below.
- comments string
- Comments string.
- content_
direction string - On which direction the file types processing is applied.
- content_
negate bool - True if negate is set for data.
- contents list(string)
- List of processed file types that this rule applies on.
- custom_
fields object - Custom fields. Custom fields blocks are documented below.
- destination_
negate bool - True if negate is set for destination.
- destinations list(string)
- Collection of Network objects identified by the name or UID.
- enabled bool
- Enable/Disable the rule.
- fields_
with_ list(string)uid_ identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore_
errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore_
warnings bool - Apply changes ignoring warnings.
- inline_
layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install_
ons list(string) - Which Gateways identified by the name or UID to install the policy on.
- layer string
- Layer that the rule belongs to identified by the name or UID.
- management_
access_ stringrule_ id - name string
- Rule name.
- position object
- Position in the rulebase. Position blocks are documented below.
- service_
negate bool - True if negate is set for service.
- service_
resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services list(string)
- Collection of Network objects identified by the name or UID.
- source_
negate bool - True if negate is set for source.
- sources list(string)
- Collection of Network objects identified by the name or UID.
- times list(string)
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track object
- Track Settings. Track Settings blocks are documented below.
- user_
check object - User check settings. User check settings blocks are documented below.
- vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn_
communities list(string) - Collection of VPN communities identified by name.
- vpn_
directionals list(object) - Collection of VPN directional. VPN directional block documented below.
- action String
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- comments String
- Comments string.
- content
Direction String - On which direction the file types processing is applied.
- content
Negate Boolean - True if negate is set for data.
- contents List<String>
- List of processed file types that this rule applies on.
- custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- destination
Negate Boolean - True if negate is set for destination.
- destinations List<String>
- Collection of Network objects identified by the name or UID.
- enabled Boolean
- Enable/Disable the rule.
- fields
With List<String>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors Boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings Boolean - Apply changes ignoring warnings.
- inline
Layer String - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons List<String> - Which Gateways identified by the name or UID to install the policy on.
- layer String
- Layer that the rule belongs to identified by the name or UID.
- management
Access StringRule Id - name String
- Rule name.
- position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- service
Negate Boolean - True if negate is set for service.
- service
Resource String - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services List<String>
- Collection of Network objects identified by the name or UID.
- source
Negate Boolean - True if negate is set for source.
- sources List<String>
- Collection of Network objects identified by the name or UID.
- times List<String>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- user
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- vpn String
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities List<String> - Collection of VPN communities identified by name.
- vpn
Directionals List<ManagementAccess Rule Vpn Directional> - Collection of VPN directional. VPN directional block documented below.
- action string
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings ManagementAccess Rule Action Settings - Action settings. Action settings blocks are documented below.
- comments string
- Comments string.
- content
Direction string - On which direction the file types processing is applied.
- content
Negate boolean - True if negate is set for data.
- contents string[]
- List of processed file types that this rule applies on.
- custom
Fields ManagementAccess Rule Custom Fields - Custom fields. Custom fields blocks are documented below.
- destination
Negate boolean - True if negate is set for destination.
- destinations string[]
- Collection of Network objects identified by the name or UID.
- enabled boolean
- Enable/Disable the rule.
- fields
With string[]Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings boolean - Apply changes ignoring warnings.
- inline
Layer string - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons string[] - Which Gateways identified by the name or UID to install the policy on.
- layer string
- Layer that the rule belongs to identified by the name or UID.
- management
Access stringRule Id - name string
- Rule name.
- position
Management
Access Rule Position - Position in the rulebase. Position blocks are documented below.
- service
Negate boolean - True if negate is set for service.
- service
Resource string - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services string[]
- Collection of Network objects identified by the name or UID.
- source
Negate boolean - True if negate is set for source.
- sources string[]
- Collection of Network objects identified by the name or UID.
- times string[]
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track - Track Settings. Track Settings blocks are documented below.
- user
Check ManagementAccess Rule User Check - User check settings. User check settings blocks are documented below.
- vpn string
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities string[] - Collection of VPN communities identified by name.
- vpn
Directionals ManagementAccess Rule Vpn Directional[] - Collection of VPN directional. VPN directional block documented below.
- action str
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action_
settings ManagementAccess Rule Action Settings Args - Action settings. Action settings blocks are documented below.
- comments str
- Comments string.
- content_
direction str - On which direction the file types processing is applied.
- content_
negate bool - True if negate is set for data.
- contents Sequence[str]
- List of processed file types that this rule applies on.
- custom_
fields ManagementAccess Rule Custom Fields Args - Custom fields. Custom fields blocks are documented below.
- destination_
negate bool - True if negate is set for destination.
- destinations Sequence[str]
- Collection of Network objects identified by the name or UID.
- enabled bool
- Enable/Disable the rule.
- fields_
with_ Sequence[str]uid_ identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore_
errors bool - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore_
warnings bool - Apply changes ignoring warnings.
- inline_
layer str - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install_
ons Sequence[str] - Which Gateways identified by the name or UID to install the policy on.
- layer str
- Layer that the rule belongs to identified by the name or UID.
- management_
access_ strrule_ id - name str
- Rule name.
- position
Management
Access Rule Position Args - Position in the rulebase. Position blocks are documented below.
- service_
negate bool - True if negate is set for service.
- service_
resource str - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services Sequence[str]
- Collection of Network objects identified by the name or UID.
- source_
negate bool - True if negate is set for source.
- sources Sequence[str]
- Collection of Network objects identified by the name or UID.
- times Sequence[str]
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track
Management
Access Rule Track Args - Track Settings. Track Settings blocks are documented below.
- user_
check ManagementAccess Rule User Check Args - User check settings. User check settings blocks are documented below.
- vpn str
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn_
communities Sequence[str] - Collection of VPN communities identified by name.
- vpn_
directionals Sequence[ManagementAccess Rule Vpn Directional Args] - Collection of VPN directional. VPN directional block documented below.
- action String
- Valid values: "Accept", "Drop", "Ask", "Inform", "Reject", "User Auth", "Client Auth", "Apply Layer".
- action
Settings Property Map - Action settings. Action settings blocks are documented below.
- comments String
- Comments string.
- content
Direction String - On which direction the file types processing is applied.
- content
Negate Boolean - True if negate is set for data.
- contents List<String>
- List of processed file types that this rule applies on.
- custom
Fields Property Map - Custom fields. Custom fields blocks are documented below.
- destination
Negate Boolean - True if negate is set for destination.
- destinations List<String>
- Collection of Network objects identified by the name or UID.
- enabled Boolean
- Enable/Disable the rule.
- fields
With List<String>Uid Identifiers - List of resource fields that will use object UIDs as object identifiers. Default is object name.
- ignore
Errors Boolean - Apply changes ignoring errors. You won't be able to publish such a changes. If ignore-warnings flag was omitted - warnings will also be ignored.
- ignore
Warnings Boolean - Apply changes ignoring warnings.
- inline
Layer String - Inline Layer identified by the name or UID. Relevant only if "Action" was set to "Apply Layer".
- install
Ons List<String> - Which Gateways identified by the name or UID to install the policy on.
- layer String
- Layer that the rule belongs to identified by the name or UID.
- management
Access StringRule Id - name String
- Rule name.
- position Property Map
- Position in the rulebase. Position blocks are documented below.
- service
Negate Boolean - True if negate is set for service.
- service
Resource String - Resource of the service identified by the name or UID. When a service-resource exists, the service parameter should contains exactly one service element.
- services List<String>
- Collection of Network objects identified by the name or UID.
- source
Negate Boolean - True if negate is set for source.
- sources List<String>
- Collection of Network objects identified by the name or UID.
- times List<String>
- List of time objects. For example: "Weekend", "Off-Work", "Every-Day".
- track Property Map
- Track Settings. Track Settings blocks are documented below.
- user
Check Property Map - User check settings. User check settings blocks are documented below.
- vpn String
- VPN community identified by name or "Any" or "All_GwToGw".
- vpn
Communities List<String> - Collection of VPN communities identified by name.
- vpn
Directionals List<Property Map> - Collection of VPN directional. VPN directional block documented below.
Supporting Types
ManagementAccessRuleActionSettings, ManagementAccessRuleActionSettingsArgs
- Client
Auth ManagementSettings Access Rule Action Settings Client Auth Settings - Client authentication settings.client_auth_settings blocks are documented below.
- Enable
Identity boolCaptive Portal - N/A.
- Limit string
- N/A.
- User
Auth ManagementSettings Access Rule Action Settings User Auth Settings - User authentication settings.user_auth_settings blocks are documented below.
- Client
Auth ManagementSettings Access Rule Action Settings Client Auth Settings - Client authentication settings.client_auth_settings blocks are documented below.
- Enable
Identity boolCaptive Portal - N/A.
- Limit string
- N/A.
- User
Auth ManagementSettings Access Rule Action Settings User Auth Settings - User authentication settings.user_auth_settings blocks are documented below.
- client_
auth_ objectsettings - Client authentication settings.client_auth_settings blocks are documented below.
- enable_
identity_ boolcaptive_ portal - N/A.
- limit string
- N/A.
- user_
auth_ objectsettings - User authentication settings.user_auth_settings blocks are documented below.
- client
Auth ManagementSettings Access Rule Action Settings Client Auth Settings - Client authentication settings.client_auth_settings blocks are documented below.
- enable
Identity BooleanCaptive Portal - N/A.
- limit String
- N/A.
- user
Auth ManagementSettings Access Rule Action Settings User Auth Settings - User authentication settings.user_auth_settings blocks are documented below.
- client
Auth ManagementSettings Access Rule Action Settings Client Auth Settings - Client authentication settings.client_auth_settings blocks are documented below.
- enable
Identity booleanCaptive Portal - N/A.
- limit string
- N/A.
- user
Auth ManagementSettings Access Rule Action Settings User Auth Settings - User authentication settings.user_auth_settings blocks are documented below.
- client_
auth_ Managementsettings Access Rule Action Settings Client Auth Settings - Client authentication settings.client_auth_settings blocks are documented below.
- enable_
identity_ boolcaptive_ portal - N/A.
- limit str
- N/A.
- user_
auth_ Managementsettings Access Rule Action Settings User Auth Settings - User authentication settings.user_auth_settings blocks are documented below.
- client
Auth Property MapSettings - Client authentication settings.client_auth_settings blocks are documented below.
- enable
Identity BooleanCaptive Portal - N/A.
- limit String
- N/A.
- user
Auth Property MapSettings - User authentication settings.user_auth_settings blocks are documented below.
ManagementAccessRuleActionSettingsClientAuthSettings, ManagementAccessRuleActionSettingsClientAuthSettingsArgs
- Destination string
- Collection of Network objects identified by the name or UID.
- Require
Desktop boolConfig Verification - Require Desktop configuration verification.
- Sessions
Limit double - Maximum number of concurrent sessions.
- Sign
On stringMethod - Sign on method.
- Sign
On stringType - Sign on type.
- Source string
- Collection of Network objects identified by the name or UID.
- Timeout
Management
Access Rule Action Settings Client Auth Settings Timeout - Session timeout settings.
- Tracking string
- Tracking method.
- Unlimited
Sessions bool - Allow an unlimited number of sessions.
- Destination string
- Collection of Network objects identified by the name or UID.
- Require
Desktop boolConfig Verification - Require Desktop configuration verification.
- Sessions
Limit float64 - Maximum number of concurrent sessions.
- Sign
On stringMethod - Sign on method.
- Sign
On stringType - Sign on type.
- Source string
- Collection of Network objects identified by the name or UID.
- Timeout
Management
Access Rule Action Settings Client Auth Settings Timeout - Session timeout settings.
- Tracking string
- Tracking method.
- Unlimited
Sessions bool - Allow an unlimited number of sessions.
- destination string
- Collection of Network objects identified by the name or UID.
- require_
desktop_ boolconfig_ verification - Require Desktop configuration verification.
- sessions_
limit number - Maximum number of concurrent sessions.
- sign_
on_ stringmethod - Sign on method.
- sign_
on_ stringtype - Sign on type.
- source string
- Collection of Network objects identified by the name or UID.
- timeout object
- Session timeout settings.
- tracking string
- Tracking method.
- unlimited_
sessions bool - Allow an unlimited number of sessions.
- destination String
- Collection of Network objects identified by the name or UID.
- require
Desktop BooleanConfig Verification - Require Desktop configuration verification.
- sessions
Limit Double - Maximum number of concurrent sessions.
- sign
On StringMethod - Sign on method.
- sign
On StringType - Sign on type.
- source String
- Collection of Network objects identified by the name or UID.
- timeout
Management
Access Rule Action Settings Client Auth Settings Timeout - Session timeout settings.
- tracking String
- Tracking method.
- unlimited
Sessions Boolean - Allow an unlimited number of sessions.
- destination string
- Collection of Network objects identified by the name or UID.
- require
Desktop booleanConfig Verification - Require Desktop configuration verification.
- sessions
Limit number - Maximum number of concurrent sessions.
- sign
On stringMethod - Sign on method.
- sign
On stringType - Sign on type.
- source string
- Collection of Network objects identified by the name or UID.
- timeout
Management
Access Rule Action Settings Client Auth Settings Timeout - Session timeout settings.
- tracking string
- Tracking method.
- unlimited
Sessions boolean - Allow an unlimited number of sessions.
- destination str
- Collection of Network objects identified by the name or UID.
- require_
desktop_ boolconfig_ verification - Require Desktop configuration verification.
- sessions_
limit float - Maximum number of concurrent sessions.
- sign_
on_ strmethod - Sign on method.
- sign_
on_ strtype - Sign on type.
- source str
- Collection of Network objects identified by the name or UID.
- timeout
Management
Access Rule Action Settings Client Auth Settings Timeout - Session timeout settings.
- tracking str
- Tracking method.
- unlimited_
sessions bool - Allow an unlimited number of sessions.
- destination String
- Collection of Network objects identified by the name or UID.
- require
Desktop BooleanConfig Verification - Require Desktop configuration verification.
- sessions
Limit Number - Maximum number of concurrent sessions.
- sign
On StringMethod - Sign on method.
- sign
On StringType - Sign on type.
- source String
- Collection of Network objects identified by the name or UID.
- timeout Property Map
- Session timeout settings.
- tracking String
- Tracking method.
- unlimited
Sessions Boolean - Allow an unlimited number of sessions.
ManagementAccessRuleActionSettingsClientAuthSettingsTimeout, ManagementAccessRuleActionSettingsClientAuthSettingsTimeoutArgs
- Enable bool
- Enable session timeout.
- Minutes double
- Session timeout in minutes.
- Refreshable bool
- Whether the timeout is refreshable.
- Enable bool
- Enable session timeout.
- Minutes float64
- Session timeout in minutes.
- Refreshable bool
- Whether the timeout is refreshable.
- enable bool
- Enable session timeout.
- minutes number
- Session timeout in minutes.
- refreshable bool
- Whether the timeout is refreshable.
- enable Boolean
- Enable session timeout.
- minutes Double
- Session timeout in minutes.
- refreshable Boolean
- Whether the timeout is refreshable.
- enable boolean
- Enable session timeout.
- minutes number
- Session timeout in minutes.
- refreshable boolean
- Whether the timeout is refreshable.
- enable bool
- Enable session timeout.
- minutes float
- Session timeout in minutes.
- refreshable bool
- Whether the timeout is refreshable.
- enable Boolean
- Enable session timeout.
- minutes Number
- Session timeout in minutes.
- refreshable Boolean
- Whether the timeout is refreshable.
ManagementAccessRuleActionSettingsUserAuthSettings, ManagementAccessRuleActionSettingsUserAuthSettingsArgs
- Allowed
Http stringServers - Allowed HTTP servers.
- Destination string
- Collection of Network objects identified by the name or UID.
- Source string
- Collection of Network objects identified by the name or UID.
- Allowed
Http stringServers - Allowed HTTP servers.
- Destination string
- Collection of Network objects identified by the name or UID.
- Source string
- Collection of Network objects identified by the name or UID.
- allowed_
http_ stringservers - Allowed HTTP servers.
- destination string
- Collection of Network objects identified by the name or UID.
- source string
- Collection of Network objects identified by the name or UID.
- allowed
Http StringServers - Allowed HTTP servers.
- destination String
- Collection of Network objects identified by the name or UID.
- source String
- Collection of Network objects identified by the name or UID.
- allowed
Http stringServers - Allowed HTTP servers.
- destination string
- Collection of Network objects identified by the name or UID.
- source string
- Collection of Network objects identified by the name or UID.
- allowed_
http_ strservers - Allowed HTTP servers.
- destination str
- Collection of Network objects identified by the name or UID.
- source str
- Collection of Network objects identified by the name or UID.
- allowed
Http StringServers - Allowed HTTP servers.
- destination String
- Collection of Network objects identified by the name or UID.
- source String
- Collection of Network objects identified by the name or UID.
ManagementAccessRuleCustomFields, ManagementAccessRuleCustomFieldsArgs
ManagementAccessRulePosition, ManagementAccessRulePositionArgs
ManagementAccessRuleTrack, ManagementAccessRuleTrackArgs
- Accounting bool
- Turns accounting for track on and off.
- Alert string
- Type of alert for the track.
- Enable
Firewall boolSession - Determine whether to generate session log to firewall only connections.
- Per
Connection bool - Determines whether to perform the log per connection.
- Per
Session bool - Determines whether to perform the log per session.
- Type string
- "Log", "Extended Log", "Detailed Log", "None".
- Accounting bool
- Turns accounting for track on and off.
- Alert string
- Type of alert for the track.
- Enable
Firewall boolSession - Determine whether to generate session log to firewall only connections.
- Per
Connection bool - Determines whether to perform the log per connection.
- Per
Session bool - Determines whether to perform the log per session.
- Type string
- "Log", "Extended Log", "Detailed Log", "None".
- accounting bool
- Turns accounting for track on and off.
- alert string
- Type of alert for the track.
- enable_
firewall_ boolsession - Determine whether to generate session log to firewall only connections.
- per_
connection bool - Determines whether to perform the log per connection.
- per_
session bool - Determines whether to perform the log per session.
- type string
- "Log", "Extended Log", "Detailed Log", "None".
- accounting Boolean
- Turns accounting for track on and off.
- alert String
- Type of alert for the track.
- enable
Firewall BooleanSession - Determine whether to generate session log to firewall only connections.
- per
Connection Boolean - Determines whether to perform the log per connection.
- per
Session Boolean - Determines whether to perform the log per session.
- type String
- "Log", "Extended Log", "Detailed Log", "None".
- accounting boolean
- Turns accounting for track on and off.
- alert string
- Type of alert for the track.
- enable
Firewall booleanSession - Determine whether to generate session log to firewall only connections.
- per
Connection boolean - Determines whether to perform the log per connection.
- per
Session boolean - Determines whether to perform the log per session.
- type string
- "Log", "Extended Log", "Detailed Log", "None".
- accounting bool
- Turns accounting for track on and off.
- alert str
- Type of alert for the track.
- enable_
firewall_ boolsession - Determine whether to generate session log to firewall only connections.
- per_
connection bool - Determines whether to perform the log per connection.
- per_
session bool - Determines whether to perform the log per session.
- type str
- "Log", "Extended Log", "Detailed Log", "None".
- accounting Boolean
- Turns accounting for track on and off.
- alert String
- Type of alert for the track.
- enable
Firewall BooleanSession - Determine whether to generate session log to firewall only connections.
- per
Connection Boolean - Determines whether to perform the log per connection.
- per
Session Boolean - Determines whether to perform the log per session.
- type String
- "Log", "Extended Log", "Detailed Log", "None".
ManagementAccessRuleUserCheck, ManagementAccessRuleUserCheckArgs
- Confirm string
- N/A.
- Custom
Frequency ManagementAccess Rule User Check Custom Frequency - N/A. Custom Frequency blocks are documented below.
- Frequency string
- N/A.
- Interaction string
- N/A.
- Confirm string
- N/A.
- Custom
Frequency ManagementAccess Rule User Check Custom Frequency - N/A. Custom Frequency blocks are documented below.
- Frequency string
- N/A.
- Interaction string
- N/A.
- confirm string
- N/A.
- custom_
frequency object - N/A. Custom Frequency blocks are documented below.
- frequency string
- N/A.
- interaction string
- N/A.
- confirm String
- N/A.
- custom
Frequency ManagementAccess Rule User Check Custom Frequency - N/A. Custom Frequency blocks are documented below.
- frequency String
- N/A.
- interaction String
- N/A.
- confirm string
- N/A.
- custom
Frequency ManagementAccess Rule User Check Custom Frequency - N/A. Custom Frequency blocks are documented below.
- frequency string
- N/A.
- interaction string
- N/A.
- confirm str
- N/A.
- custom_
frequency ManagementAccess Rule User Check Custom Frequency - N/A. Custom Frequency blocks are documented below.
- frequency str
- N/A.
- interaction str
- N/A.
- confirm String
- N/A.
- custom
Frequency Property Map - N/A. Custom Frequency blocks are documented below.
- frequency String
- N/A.
- interaction String
- N/A.
ManagementAccessRuleUserCheckCustomFrequency, ManagementAccessRuleUserCheckCustomFrequencyArgs
ManagementAccessRuleVpnDirectional, ManagementAccessRuleVpnDirectionalArgs
Import
checkpoint_management_access_rule can be imported by using the following format: LAYER_NAME;RULE_UID
$ pulumi import checkpoint:index/managementAccessRule:ManagementAccessRule example "Network;9423d36f-2d66-4754-b9e2-e9f4493751d3"
client_auth_settings supports the following:
destination- (Optional) Destination object identified by the name or UID.require_desktop_config_verification- (Optional) Require Desktop configuration verification.sessions_limit- (Optional) Maximum number of concurrent sessions.sign_on_method- (Optional) Sign on method.sign_on_type- (Optional) Sign on type.source- (Optional) Source object identified by the name or UID.timeout- (Optional) Session timeout settings.timeout blocks are documented below.tracking- (Optional) Tracking method.unlimited_sessions- (Optional) Allow an unlimited number of sessions.
timeout supports the following:
enable- (Optional) Enable session timeout.minutes- (Optional) Session timeout in minutes.refreshable- (Optional) Whether the timeout is refreshable.
user_auth_settings supports the following:
allowed_http_servers- (Optional) Allowed HTTP servers.destination- (Optional) Destination object identified by the name or UID.source- (Optional) Source object identified by the name or UID.
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- checkpoint checkpointsw/terraform-provider-checkpoint
- License
- Notes
- This Pulumi package is based on the
checkpointTerraform Provider.
published on Wednesday, Sep 16, 2026 by checkpointsw