## checkpoint\_management\_group - cannot delete host

Hello all,

1. using checkpoint\_management\_host with a for\_each loop to iterate over a local nested map and create hosts.
2. using checkpoint\_management\_group to create a group and in members, add the values of the hosts i've just created.

Works fine when i create hosts, but when I remove them(from the map), terraform tries to delete the host before removing it from the group. CP API is then giving an error that it can't delete an used object.

The destroy happens before the update-in-place and the only way to change that is to use create\_before\_destroy but then I run into other issues with publishing/installing policies, because those use destroy and then create replacement.

Tried adding the replace\_triggered\_by to the group, but still it does update-in-place.

Any ideas how to solve this ?

Code:

\`\`

locals {

clients = {

"client\_1" = {

remote\_ip = "10.100.200.1"

remote\_port = "3001"

}

"client\_2" = {

remote\_ip = "10.100.200.2"

remote\_port = "3002"

}

"client\_3" = {

remote\_ip = "10.100.200.3"

remote\_port = "3003"

}

}

}

resource "checkpoint\_management\_host" "hosts\_lab" {

for\_each = local.clients

name = "host\_${each.key}"

ipv4\_address = each.value\["remote\_ip"\]

ignore\_warnings = true

nat\_settings = {}

tags = \[\]

lifecycle {

precondition {

condition = can(cidrsubnet("${each.value\["remote\_ip"\]}/32",0,0))

error\_message = "Must be valid IPv4 Address."

}

}

}

resource "checkpoint\_management\_group" "groups\_lab" {

name = "group\_terraformed"

members = values(checkpoint\_management\_host.hosts\_lab)\[\*\].name

ignore\_warnings = true

depends\_on = \[ checkpoint\_management\_host.hosts\_lab\]

lifecycle {

replace\_triggered\_by = \[checkpoint\_management\_host.hosts\_lab \]

}

}

resource "checkpoint\_management\_service\_tcp" "tcp\_service" {

for\_each = local.clients

name = "tcp\_${each.key}"

port = "${each.value.remote\_port}"

session\_timeout = 3600

match\_for\_any = true

sync\_connections\_on\_cluster = true

ignore\_warnings = true

aggressive\_aging = {

enable = true

timeout = 360

use\_default\_timeout = false

}

keep\_connections\_open\_after\_policy\_installation = true

tags = \[\]

lifecycle {

precondition {

condition = (

each.value\["remote\_port"\] >= 1000 &&

each.value\["remote\_port"\] <= 65000

)

error\_message = "Port number must be between 1000 and 65000"

}

}

}

resource "checkpoint\_management\_access\_rule" "in-policy-FWL\_VS1" {

for\_each = local.clients

name = "${each.key}"

layer = "FWLVS1\_policy Network"

position = { top = "top" }

source = \["existing\_group"\]

destination = \["host\_${each.key}"\]

service = \["tcp\_${each.key}"\]

action = "Accept"

track = {

accounting = true

type = "Log"

per\_connection = "true"

}

depends\_on = \[ checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_service\_tcp.tcp\_service \]

action\_settings = {

enable\_identity\_captive\_portal = false

}

content = \[\]

custom\_fields = {}

time = \[\]

}

resource "checkpoint\_management\_access\_rule" "in-policy-FWL\_VS2" {

for\_each = local.clients

name = "${each.key}"

layer = "FWLVS2\_policy Network"

position = { top = "top" }

source = \["existing\_group"\]

destination = \["host\_${each.key}"\]

service = \["tcp\_${each.key}"\]

action = "Accept"

track = {

accounting = true

type = "Log"

per\_connection = "true"

}

depends\_on = \[ checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_service\_tcp.tcp\_service \]

action\_settings = {

enable\_identity\_captive\_portal = false

}

content = \[\]

custom\_fields = {}

time = \[\]

}

resource "checkpoint\_management\_publish" "unstable\_lab" {

triggers = toset(\[sha1(jsonencode(\[\
\
checkpoint\_management\_host.hosts\_lab,\
\
checkpoint\_management\_access\_rule.in-policy-FWL\_VS1,\
\
checkpoint\_management\_access\_rule.in-policy-FWL\_VS2,\
\
checkpoint\_management\_service\_tcp.tcp\_service,\
\
\]))\])

depends\_on = \[checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_access\_rule.in-policy-FWL\_VS1, checkpoint\_management\_access\_rule.in-policy-FWL\_VS2, checkpoint\_management\_service\_tcp.tcp\_service\]

}

resource "checkpoint\_management\_install\_policy" "FWL\_VS1" {

policy\_package = "FWLVS1\_policy"

targets = \["FWLVS1"\]

depends\_on = \[checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_access\_rule.in-policy-FWL\_VS1, checkpoint\_management\_access\_rule.in-policy-FWL\_VS2, checkpoint\_management\_service\_tcp.tcp\_service, checkpoint\_management\_publish.unstable\_lab \]

}

resource "checkpoint\_management\_install\_policy" "FWL\_VS2" {

policy\_package = "FWLVS2\_policy"

targets = \["FWLVS2"\]

depends\_on = \[checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_access\_rule.in-policy-FWL\_VS1, checkpoint\_management\_access\_rule.in-policy-FWL\_VS2, checkpoint\_management\_service\_tcp.tcp\_service, checkpoint\_management\_publish.unstable\_lab, checkpoint\_management\_install\_policy.FWL\_VS1 \]

}

resource "checkpoint\_management\_logout" "unstable\_lab" {

triggers = \["${timestamp()}"\]

depends\_on = \[checkpoint\_management\_host.hosts\_lab, checkpoint\_management\_access\_rule.in-policy-FWL\_VS1, checkpoint\_management\_access\_rule.in-policy-FWL\_VS2, checkpoint\_management\_service\_tcp.tcp\_service, checkpoint\_management\_publish.unstable\_lab, checkpoint\_management\_install\_policy.FWL\_VS1, checkpoint\_management\_install\_policy.FWL\_VS2\]

}

\`\`

Terraform used the selected providers to generate the following execution

plan. Resource actions are indicated with the following symbols:

~ update in-place

\- destroy

\-/\+ destroy and then create replacement

Terraform will perform the following actions:

# checkpoint\_management\_access\_rule.in-policy-FWL\_VS1\["client\_3"\] will be destroyed

# (because key \["client\_3"\] is not in for\_each map)

- resource "checkpoint\_management\_access\_rule" "in-policy-FWL\_VS1" {
  - action = "Accept" -> null
  - action\_settings = {
    - "enable\_identity\_captive\_portal" = "false"

} -\> null
  - content = \[\] -> null
  - content\_direction = "any" -> null
  - content\_negate = false -> null
  - custom\_fields = {} -> null
  - destination = \[\
    - "host\_client\_3",\
\
      \] -\> null
  - destination\_negate = false -> null
  - enabled = true -> null
  - id = "60df76ab-952c-4a81-9242-f811fc712003" -> null
  - ignore\_errors = false -> null
  - ignore\_warnings = false -> null
  - install\_on = \[\] -> null
  - layer = "FWL-BE-DMZINT\_policy Network" -> null
  - name = "client\_3" -> null
  - position = {
    - "top" = "top"

} -\> null
  - service = \[\
    - "tcp\_client\_3",\
\
      \] -\> null
  - service\_negate = false -> null
  - source = \[\
    - "existing\_group",\
\
      \] -\> null
  - source\_negate = false -> null
  - time = \[\] -> null
  - track = {
    - "accounting" = "true"
    - "per\_connection" = "true"
    - "type" = "Log"

} -\> null
  - vpn = "Any" -> null

}

# checkpoint\_management\_access\_rule.in-policy-FWL\_VS2\["client\_3"\] will be destroyed

# (because key \["client\_3"\] is not in for\_each map)

- resource "checkpoint\_management\_access\_rule" "in-policy-FWL\_VS2" {
  - action = "Accept" -> null
  - action\_settings = {
    - "enable\_identity\_captive\_portal" = "false"

} -\> null
  - content = \[\] -> null
  - content\_direction = "any" -> null
  - content\_negate = false -> null
  - custom\_fields = {} -> null
  - destination = \[\
    - "host\_client\_3",\
\
      \] -\> null
  - destination\_negate = false -> null
  - enabled = true -> null
  - id = "0fee58d6-0f04-43c7-96eb-4acdddbccc43" -> null
  - ignore\_errors = false -> null
  - ignore\_warnings = false -> null
  - install\_on = \[\] -> null
  - layer = "FWL-BE-DMZPRV\_policy Network" -> null
  - name = "client\_3" -> null
  - position = {
    - "top" = "top"

} -\> null
  - vpn = "Any" -> null

}

# checkpoint\_management\_group.groups\_lab will be updated in-place

~ resource "checkpoint\_management\_group" "groups\_lab" {

id = "cb645dd5-5221-445a-ab4b-d12d8bab0a61"

~ members = \[\
\
\- "host\_client\_3",\
\
\# (2 unchanged elements hidden)\
\
\]

name = "group\_terraformed"

tags = \[\]

\# (3 unchanged attributes hidden)

}

# checkpoint\_management\_host.hosts\_lab\["client\_3"\] will be destroyed

# (because key \["client\_3"\] is not in for\_each map)

- resource "checkpoint\_management\_host" "hosts\_lab" {
  - color = "black" -> null
  - id = "c2605a4c-6800-4654-909c-f98b7e3fe1d0" -> null
  - ignore\_errors = false -> null
  - ignore\_warnings = true -> null
  - ipv4\_address = "10.100.200.3" -> null
  - name = "host\_client\_3" -> null
  - nat\_settings = {} -> null
  - tags = \[\] -> null

}

# checkpoint\_management\_install\_policy.FWL\_VS1 must be replaced

\-/\+ resource "checkpoint\_management\_install\_policy" "FWL\_VS1" {

~ id = "install-policy-nrqihmvykd" -> (known after apply)

~ task\_id = "1ccf9d30-b246-43f4-8ce8-1c8cc2b5bb49" -> (known after apply)

~ triggers = \[ # forces replacement\
\
\+ "00634fa4a304ad78e0d01badc15de0e3859b95e1",\
\
\- "b9d1295431895bedb0005b1b1a877bed2f451200",\
\
\]

\# (4 unchanged attributes hidden)

}

# checkpoint\_management\_install\_policy.FWL\_VS2 must be replaced

\-/\+ resource "checkpoint\_management\_install\_policy" "FWL\_VS2" {

~ id = "install-policy-br8oh3nykd" -> (known after apply)

~ task\_id = "95c7efda-2ac7-48ed-a72f-235fa835e0d8" -> (known after apply)

~ triggers = \[ # forces replacement\
\
\+ "00634fa4a304ad78e0d01badc15de0e3859b95e1",\
\
\- "b9d1295431895bedb0005b1b1a877bed2f451200",\
\
\]

\# (4 unchanged attributes hidden)

}

# checkpoint\_management\_logout.unstable\_lab must be replaced

\-/\+ resource "checkpoint\_management\_logout" "unstable\_lab" {

~ id = "logout-ypdyzdj9kg" -> (known after apply)

~ triggers = \[\
\
\- "2023-01-03T18:20:43Z",\
\
\] -\> (known after apply) # forces replacement

}

# checkpoint\_management\_publish.unstable\_lab must be replaced

\-/\+ resource "checkpoint\_management\_publish" "unstable\_lab" {

~ id = "publish-vgndg6ldby" -> (known after apply)

~ task\_id = "01234567-89ab-cdef-8d12-8c39b51d80ed" -> (known after apply)

~ triggers = \[ # forces replacement\
\
\+ "00634fa4a304ad78e0d01badc15de0e3859b95e1",\
\
\- "b9d1295431895bedb0005b1b1a877bed2f451200",\
\
\]

}

# checkpoint\_management\_service\_tcp.tcp\_service\["client\_3"\] will be destroyed

# (because key \["client\_3"\] is not in for\_each map)

- resource "checkpoint\_management\_service\_tcp" "tcp\_service" {
  - aggressive\_aging = {
    - "enable" = "true"
    - "timeout" = "360"
    - "use\_default\_timeout" = "false"

} -\> null
  - color = "black" -> null
  - id = "6fe11bfc-2659-47f8-a04e-80fec5593c50" -> null
  - ignore\_errors = false -> null
  - ignore\_warnings = true -> null
  - keep\_connections\_open\_after\_policy\_installation = true -> null
  - match\_by\_protocol\_signature = false -> null
  - match\_for\_any = true -> null
  - name = "tcp\_client\_3" -> null
  - override\_default\_settings = false -> null
  - port = "3003" -> null
  - session\_timeout = 3600 -> null
  - sync\_connections\_on\_cluster = true -> null
  - tags = \[\] -> null
  - use\_default\_session\_timeout = true -> null

}

Plan: 4 to add, 1 to change, 8 to destroy.

checkpoint\_management\_logout.unstable\_lab: Destroying... \[id=logout-ypdyzdj9kg\]

checkpoint\_management\_logout.unstable\_lab: Destruction complete after 0s

checkpoint\_management\_install\_policy.FWL\_VS2: Destroying... \[id=install-policy-br8oh3nykd\]

checkpoint\_management\_install\_policy.FWL\_VS2: Destruction complete after 0s

checkpoint\_management\_install\_policy.FWL\_VS1: Destroying... \[id=install-policy-nrqihmvykd\]

checkpoint\_management\_install\_policy.FWL\_VS1: Destruction complete after 0s

checkpoint\_management\_publish.unstable\_lab: Destroying... \[id=publish-vgndg6ldby\]

checkpoint\_management\_publish.unstable\_lab: Destruction complete after 0s

checkpoint\_management\_access\_rule.in-policy-FWL\_VS1\["client\_3"\]: Destroying... \[id=60df76ab-952c-4a81-9242-f811fc712003\]

checkpoint\_management\_access\_rule.in-policy-FWL\_VS2\["client\_3"\]: Destroying... \[id=0fee58d6-0f04-43c7-96eb-4acdddbccc43\]

checkpoint\_management\_access\_rule.in-policy-FWL\_VS1\["client\_3"\]: Destruction complete after 0s

checkpoint\_management\_access\_rule.in-policy-FWL\_VS2\["client\_3"\]: Destruction complete after 0s

checkpoint\_management\_host.hosts\_lab\["client\_3"\]: Destroying... \[id=c2605a4c-6800-4654-909c-f98b7e3fe1d0\]

checkpoint\_management\_service\_tcp.tcp\_service\["client\_3"\]: Destroying... \[id=6fe11bfc-2659-47f8-a04e-80fec5593c50\]

checkpoint\_management\_service\_tcp.tcp\_service\["client\_3"\]: Destruction complete after 0s

╷

│ Error: failed to execute API call

│ Status: 400 Bad Request

│ Code: err\_validation\_failed

│ Message: Validation failed with 1 warning

│ Warnings:

│ 1\. Object host\_client\_3 is used by the following objects: group\_terraformed

│

│

╵

Cleaning up project directory and file based variables

00:00

ERROR: Job failed: exit code 1

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166612?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

- [All forum topics](https://community.checkpoint.com/t5/DevSecOps/bd-p/DevSecOps "DevSecOps")
- [Previous Topic](https://community.checkpoint.com/t5/DevSecOps/Terraform-Azure-CloudGuardIaaS-Deployment/td-p/183922 "Terraform - Azure CloudGuardIaaS Deployment")
- [Next Topic](https://community.checkpoint.com/t5/DevSecOps/How-to-create-a-new-ServiceAccount-via-API/td-p/148847 "How to create a new ServiceAccount via API?")

1 Solution

Accepted Solutions

[alexproca](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48689)

Participant

‎2023-01-0612:47 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=DevSecOps&message.id=115)
- [Permalink](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889/highlight/true#M115)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/DevSecOps/message-id/115/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/166889)

[In response to the\_rock](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166800/highlight/true#M113)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

It's a terraform provider problem, not a management or api problem.

Also posted this on the provider github page and a developer acknowledged the bug and promised to solve in the next release.

[https://github.com/CheckPointSW/terraform-provider-checkpoint/issues/135](https://github.com/CheckPointSW/terraform-provider-checkpoint/issues/135)

The version i tried is v2.1.0 so look for the bug fix in the release notes of future versions.

[View solution in original post](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/DevSecOps/message-id/115/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166889?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[(1)](https://community.checkpoint.com/t5/ratings/ratingdetailpage/message-uid/166889/rating-system/message_ratings#userlist "5 Average Rating")

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

5 Replies

[alexproca](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48689)

Participant

‎2023-01-0501:48 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=DevSecOps&message.id=111)
- [Permalink](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166762/highlight/true#M111)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/DevSecOps/message-id/111/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/166762)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

Another note, I tried ignore\_warnings/errors but it did not work also, the checkpoint api/gui does not allow you to delete a host that is part of a group.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166762?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

[PhoneBoy](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7)

Admin

‎2023-01-0505:10 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=DevSecOps&message.id=112)
- [Permalink](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166788/highlight/true#M112)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/DevSecOps/message-id/112/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/166788)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

What is the version/JHF of management?

What does a where-used on the relevant object show?

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/DevSecOps/message-id/112/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166788?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

[alexproca](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48689)

Participant

‎2023-01-0612:45 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=DevSecOps&message.id=114)
- [Permalink](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166888/highlight/true#M114)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/DevSecOps/message-id/114/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/166888)

[In response to PhoneBoy](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166788/highlight/true#M112)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

HOTFIX\_R81\_10\_JUMBO\_HF\_MAIN Take: 66

The relevant object showed up in the group I created with terraform. Process.

1\. create host x with terraform

2\. create group y with members host x with terraform

at this point host x was used in group y.

3\. when trying to delete host x, terraform does two things:

3a. delete: host x

3b. update-in-place: remove host x from group y

Since terraform is trying to do 3a before 3b, API gives error that the group is used.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166888?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

[the\_rock](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213)

MVP Diamond

‎2023-01-0506:09 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=DevSecOps&message.id=113)
- [Permalink](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166800/highlight/true#M113)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/DevSecOps/message-id/113/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/166800)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

I once had hell of a time with trying to delete identity provider object that was referenced with a specific gateway. I must have spent close to 3 hours with TAC on the phone until we finally got it...had to re-log back into Guidbedit close to 20 times and remove every single reference of it.I hope your case is not going to be like mine, but Gudbedit is always good place to start, because once removed from database, you will not have any issues with smart console.

Best,

Andy

"Have a great day and if its not, change it"

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/166800?t:ac=board-id/DevSecOps/message-id/110/thread-id/110&t:cp=kudos/contributions/tapletcontributionspage&ticket=BqBJ5XYK7vmS_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

[alexproca](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48689)

Participant

‎2023-01-0612:47 AM

[Show option menu](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612# "Show option menu")

[In response to the\_rock](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166800/highlight/true#M113)

[Jump to solution](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166889#M115)

It's a terraform provider problem, not a management or api problem.

Also posted this on the provider github page and a developer acknowledged the bug and promised to solve in the next release.

[https://github.com/CheckPointSW/terraform-provider-checkpoint/issues/135](https://github.com/CheckPointSW/terraform-provider-checkpoint/issues/135)

The version i tried is v2.1.0 so look for the bug fix in the release notes of future versions.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[(1)](https://community.checkpoint.com/t5/ratings/ratingdetailpage/message-uid/166889/rating-system/message_ratings#userlist "5 Average Rating")

[Reply](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

Post Reply

Upcoming Events

Sort by:

- [All](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612#)
- [Virtual](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612#)
- [In-Person](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612#)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats](https://community.checkpoint.com/t5/CheckMates-Events/Under-the-Hood-Check-Point-and-Illumio-Modern-Network-Defense/ev-p/279701)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280019)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280021)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280020)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

Thu 30 Jul 2026 @ 11:30 AM (CDT)

[CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/CheckMates-Live-DFW-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279920)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Thu 30 Jul 2026 @ 10:00 AM (PDT)

[AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Masters-E12-READY-OR-NOT-Securing-the-AI-Enterprise/ev-p/277411)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Tue 11 Aug 2026 @ 11:30 AM (EDT)

[New York City: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/New-York-City-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279476)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 13 Aug 2026 @ 11:30 AM (EDT)

[Waltham, MA: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/Waltham-MA-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279475)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 08:30 AM (COT)

[Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Evolution-Hybrid-Mesh-Management-Visibilidad/ev-p/280003)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 06:00 PM (COT)

[Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Intelligence-IA-Generativa-en-Acci%C3%B3n-para/ev-p/280004)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 27 Aug 2026 @ 09:00 AM (CEST)

[Check Point Hands-On SASE and Cloud Workshop - Zurich](https://community.checkpoint.com/t5/CheckMates-Events/Check-Point-Hands-On-SASE-and-Cloud-Workshop-Zurich/ev-p/279914)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Wed 21 Oct 2026 @ 09:00 AM (BST)

[AI Security Workshop - Glasgow](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Workshop-Glasgow/ev-p/278505)

[CheckMates Events](https://community.checkpoint.com/t5/CheckMates-Events/eb-p/events)

[Top](https://community.checkpoint.com/t5/DevSecOps/checkpoint-management-group-cannot-delete-host/m-p/166612)

About CheckMates

- [Getting Started & FAQ](https://community.checkpoint.com/t5/help/faqpage)
- [Community Guidelines](https://community.checkpoint.com/t5/user/TermsOfServicePage)

Learn Check Point

- [Check Point for Beginners](https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/bg-p/check-point-for-beginners-2-0)
- [Check Point Trivia](https://community.checkpoint.com/t5/Check-Point-Trivia/bg-p/trivia)
- [CheckFlix Videos](https://community.checkpoint.com/t5/CheckFlix/ct-p/checkflix)

Advanced Learning

- [Check Point Security Masters](https://community.checkpoint.com/t5/Check-Point-Security-Masters/gp-p/ccsm)
- [Tip of the Week](https://community.checkpoint.com/t5/SecureKnowledge-Tip-of-the-Week/bg-p/secureknowledge)
- [TechTalks](https://community.checkpoint.com/t5/TechTalks/ct-p/techtalks%20role=)
- [Training and Certification](https://community.checkpoint.com/t5/Training-and-Certification/bd-p/training-and-certification)

Resources

- [CheckMates Toolbox](https://community.checkpoint.com/t5/CheckMates-Toolbox/ct-p/CheckMatesToolbox)
- [Developers (Code Hub)](https://community.checkpoint.com/t5/Developers-API-CLI/bd-p/codehub)
- [Product Announcements](https://community.checkpoint.com/t5/Product-Announcements/bg-p/products-blog)
- [Upcoming Events](https://community.checkpoint.com/t5/Upcoming-Events/bg-p/checkmates-live)

Non-English Discussions

- [Español](https://community.checkpoint.com/t5/Espa%C3%B1ol/bd-p/spanish)
- [French](https://community.checkpoint.com/t5/Fran%C3%A7ais/bd-p/francais)
- [Japanese](https://community.checkpoint.com/t5/Japanese-%E6%97%A5%E6%9C%AC%E8%AA%9E/bd-p/Japanese)
- [Português](https://community.checkpoint.com/t5/Portugu%C3%AAs/bd-p/portuguese)
- [Russian](https://community.checkpoint.com/t5/Russian/bd-p/russian)
- [Chinese](https://community.checkpoint.com/t5/Chinese/bd-p/taiwan)

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us [CheckMates on LinkedIn](http://linkedin.com/company/cpcheckmates)  [Check Point on YouTube](https://www.youtube.com/user/CPGlobal) [CheckMates on Facebook](https://www.facebook.com/cpcheckmates/) [CheckMates on Instagram](https://www.instagram.com/cpcheckmates/)

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. [Copyright](https://www.checkpoint.com/copyright/) [Privacy Policy](https://www.checkpoint.com/privacy/) [About Us](https://www.checkpoint.com/about-us/) [UserCenter](https://usercenter.checkpoint.com/)

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
