sk182252 - Dynamic Layer in Access Control Policy
Dynamic Layer in Access Control Policy
Product Multi-Domain Security Management, Security Gateways, Security Management
Version R82, R82.10
OS Gaia
Last Modified 2026-06-14
Solution
Table of Contents:
- Introduction
- Requirements
- Configuration
- Known Limitations
- Important Notes
- Documentation
Introduction
Starting from R82, it is possible to configure Access Control rules directly on the Security Gateway with the Gaia API call set-dynamic-content. This saves time and helps automate various tasks.
On the Management Server, you configure a new Policy Layer (and configure it as a Dynamic Layer). On the Security Gateway, this Dynamic Layer works as a container for all Access Control rules you configure with the Gaia API call set-dynamic-content.
Requirements
Management Server R82 and higher:
- Security Management Server
- Multi-Domain Security Management Server
Security Gateway R82 and higher:
- Security Gateway
- ElasticXL Cluster
- ClusterXL
- Security Group on Maestro or Scalable Chassis
On the Security Gateway, the user that runs the Gaia API must have this configuration in Gaia OS:
- Role: adminRole.
- Access Mechanism: Gaia API.
- Shell: /etc/cli.sh or /bin/bash
See the Gaia Administration Guide > chapter "User Management" > sections "Users" and "Roles".
Configuration
See the Security Management Administration Guide > Chapter " Creating an Access Control Policy" > section " Self-Managed Security Gateways".
Known Limitations
- It is not supported to edit or delete individual dynamic rules on the Security Gateway after you add them.
To remove dynamic rules, you must reset the Dynamic Layer that contains these rules on the Security Gateway.
VSNext Virtual Gateway is supported starting from R82.10.
Legacy VSX Virtual System (on a VSX Gateway or VSX Cluster) is not supported.
Legacy VSX Virtual Router (on a VSX Gateway or VSX Cluster) is not supported.
Important Notes
Each Policy Package supports more than one Dynamic Layer - as an Inline Layer or as an Ordered Layer. For example, different administrators can use different layers.
Security Gateway applies the Access Control rules in the order of the Policy Layers in the Policy Package.
Rules that you configure in SmartConsole in the Dynamic Layer apply until you run the Gaia API call
set-dynamic-contentfor the first time on the Security Gateway.If you delete the Dynamic Layer from the Policy Package (or clear the checkbox " Set as a Dynamic Layer, see sk182252" in the Dynamic Layer) and install the Access Control policy, then the Security Gateway removes all dynamic rules and applies only the static rules configured in SmartConsole.
SmartConsole does not show rules in the Dynamic Layer that you configure on the Security Gateway.
To see the list of the supported objects in the Dynamic Layer, refer to the API call " set-dynamic-content" > section " Request Body" > parameter " objects".
Documentation
Gaia API Reference (v1.8 and higher) > section "System" > sub-section "Dynamic Content".
Security Management Administration Guide > chapters "Managing Policies" and "Creating an Access Control Policy".
Gaia Administration Guide > chapter "User Management" > sections "Users" and "Roles".
sk143612 - Gaia REST API: Read and send information to Check Point servers
Article Properties
Access Level General
Status Approved
Date Created 2024-04-25
Last Modified 2026-06-14