Overview
The CheckpointIntegration allows Cywift to securely connect with Check Point SecurityManagement Server to collect firewall policies, rulebases, objectconfigurations, and compliance-related data.
This integrationhelps improve firewall visibility and automate compliance monitoring.
Before starting theintegration, ensure the following:
• Administrativeaccess to Check Point Management Server
• Management server hostname or IP address
• Valid API username and password
• API service enabled
• Network connectivity between Cywift and Check Point Management Server
Step 1: Enable APIAccess and Create Read-Only User
Cywift usesAPI-based communication to securely collect firewall data.
Enable API Service
Log in to the CheckPoint Management Server CLI.
Check API status:
api status
If API is disabled,start it:
api start
Create Read-OnlyUser
Log in toSmartConsole.
Navigate to:
Manage &Settings → Permissions Profiles
Create or assign aprofile with read-only permissions.
Create a newadministrator and assign the read-only profile.
Publish changes.
Validate API Access
Test API connectivity:
mgmt_cli showgateways-and-servers -u <username> -p <password>
Important Notes:
• Use read-onlypermissions only
• Publish all changes after configuration
• Restrict API access where possible
Step 2: Navigate toIntegrations in Cywift
• Log in to theCywift Platform
• Go to Integration from the left menu
• Under NGFW
• Select Checkpoint
• Click Connect
Step 3: AddIndividual Integration
Use this option whenintegrating a single Check Point Management Server.
Required Fields
Number of Integration
Select Individual Integration
Integration Type
Select NGFW
Collectors
Select a configured collector
Integration System
Select Checkpoint
Alias
Enter a friendly name for the integration
Owner
Select the integration owner
Host Addres
Enter the management server hostname or IP address
Username
Enter the API username
Password
Enter the corresponding password
Actions
Test Connection
Verifies API connectivity and authentication
Cancel
Discards configuration
Step 4: Add BulkIntegration
Use this option tointegrate multiple Check Point Management Servers.
Steps
• Select BulkIntegration
• Choose Integration Type (NGFW)
• Select Collectors
• Choose Integration System: Checkpoint
• Click Download Template
• Fill in the template with required management server details
• Upload the completed file
• Click Test Connection
Troubleshooting Tips
• Ensure API serviceis enabled
• Verify username and password
• Confirm read-only permissions are assigned
• Check management server connectivity
• Ensure firewall rules allow API communication
• Verify SmartConsole changes are published