Forcepoint Security Management Center
Forcepoint SMC provides unified, centralized management of all models of Forcepoint engines whether physical, virtual or cloud—across large, geographically distributed enterprise environments.
Network Security · Forcepoint Security Management Center
Details
| ID | Forcepoint Security Management Center |
|---|---|
| Provider | Francisco Partners |
| Category | Network Security |
| From Version | 6.8.0 |
| Docker Image | demisto/vendors-sdk:1.0.0.10120494 |
| Supported Modules | Agentix XSIAM |
README
Forcepoint SMC provides unified, centralized management of all models of Forcepoint engines whether physical, virtual or cloud—across large, geographically distributed enterprise environments.
This integration was integrated and tested with version 6.10 of Forcepoint Security Management Center
Configure Forcepoint Security Management Center in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| API Key | The API Key to use for connection | True |
| Port | True | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
forcepoint-smc-ip-list-create
Creates an IP list.
Base Command
forcepoint-smc-ip-list-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the IP list to create. | Required |
| addresses | A comma-separated list of IP addresses. | Optional |
| comment | The comment to add to the IP List. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.IPList.Name | String | The name of the IP list. |
| ForcepointSMC.IPList.Addresses | Unknown | The list of addresses in the IP list. |
| ForcepointSMC.IPList.Comment | String | The comment for the IP list. |
Command example
!forcepoint-smc-ip-list-create name="name" addresses="1.1.1.1" comment="test"
Context Example
{
"ForcepointSMC": {
"IPList": {
"Addresses": [
"1.1.1.1"
],
"Comment": "test",
"Name": "name"
}
}
}
Human Readable Output
IP List name was created successfully.
forcepoint-smc-ip-list-update
Updates an IP list.
Base Command
forcepoint-smc-ip-list-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the IP list. | Required |
| addresses | A comma-separated list of addresses to update. | Optional |
| is_override | If false, the list of addresses will be appended to the existing one. Else, the list will be overwritten. Default is False. Possible values are: False, True. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.IPList.Name | String | The name of the IP list. |
| ForcepointSMC.IPList.Addresses | Unknown | The list of addresses in the IPList |
| ForcepointSMC.IPList.Comment | String | The comment for the IP list. |
Command example
!forcepoint-smc-ip-list-update name="name" addresses="1.2.3.4" comment="test" is_override=True
Context Example
{
"ForcepointSMC": {
"IPList": {
"Addresses": [
"1.2.3.4"
],
"Comment": "test",
"Name": "name"
}
}
}
Human Readable Output
IP List name was updated successfully.
forcepoint-smc-ip-list-list
Lists the IP Lists in the system.
Base Command
forcepoint-smc-ip-list-list
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of a specific IP list to fetch. Overrides the other arguments if used. | Optional |
| limit | The maximum number of IP lists to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results or not. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.IPList.Name | String | The name of the IP list. |
| ForcepointSMC.IPList.Addresses | Unknown | The list of addresses in the IP list. |
| ForcepointSMC.IPList.Comment | String | The comment of the IPList |
Command example
!forcepoint-smc-ip-list-list name="name"
Context Example
{
"ForcepointSMC": {
"IPList": {
"Addresses": [
"1.2.3.4"
],
"Comment": "test",
"Name": "name"
}
}
}
Human Readable Output
IP Lists
Name Addresses Comment name 1.2.3.4 test
forcepoint-smc-ip-list-delete
Deletes an IP list.
Base Command
forcepoint-smc-ip-list-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the IP list to delete. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.IPList.Name | String | The name of the IP list. |
| ForcepointSMC.IPList.Deleted | Boolean | Whether the IP list was deleted. |
Command example
!forcepoint-smc-ip-list-delete name="name"
Context Example
{
"ForcepointSMC": {
"IPList": {
"Deleted": true,
"Name": "name"
}
}
}
Human Readable Output
IP List name was deleted successfully.
forcepoint-smc-host-list
Lists the hosts in the system.
Base Command
forcepoint-smc-host-list
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of a specific host to fetch. | Optional |
| limit | The maximum number of hosts to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results. Overrides the other arguments if used. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Host.Name | String | The name of the host. |
| ForcepointSMC.Host.Address | String | The address of the host. |
| ForcepointSMC.Host.IPv6_address | String | The IPv6 address of the host. |
| ForcepointSMC.Host.Secondary_address | String | The secondary address of the host. |
| ForcepointSMC.Host.Comment | String | The comment for the host. |
Command example
!forcepoint-smc-host-list name="name"
Context Example
{
"ForcepointSMC": {
"Host": {
"Address": "1.1.1.1",
"Comment": null,
"IPv6_address": "",
"Name": "name",
"Secondary_address": []
}
}
}
Human Readable Output
Hosts
Name Address name 1.1.1.1
forcepoint-smc-host-create
Creates a new host.
Base Command
forcepoint-smc-host-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of a specific host to fetch. | Required |
| address | The address of the host. Cannot be combined with the ipv6_address argument. | Optional |
| ipv6_address | The IPv6 address of the host. Cannot be combined with the address argument. | Optional |
| secondary_address | A comma-separated list of secondary addresses of the host. | Optional |
| comment | The comment to add to the host. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Host.Name | String | The name of the host. |
| ForcepointSMC.Host.Address | String | The address of the host. |
| ForcepointSMC.Host.IPv6_address | String | The IPv6 address of the host. |
| ForcepointSMC.Host.Secondary_address | Unknown | The secondary address of the host. |
| ForcepointSMC.Host.Comment | String | The comment for the host. |
Command example
!forcepoint-smc-host-create name="name" address="1.1.1.1"
Context Example
{
"ForcepointSMC": {
"Host": {
"Address": "1.1.1.1",
"Comment": "",
"IPv6_address": "",
"Name": "name",
"Secondary_address": []
}
}
}
Human Readable Output
Host name was created successfully.
forcepoint-smc-host-update
Updates a host.
Base Command
forcepoint-smc-host-update
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the host to update. | Required |
| address | The address of the host. Cannot be combined with the ipv6_address argument. | Optional |
| ipv6_address | The IPv6 address of the host. Cannot be combined with the address argument. | Optional |
| secondary_address | comma-separated list of secondary addresses of the host. | Optional |
| comment | The comment to add to the host. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Host.Name | String | The name of the host. |
| ForcepointSMC.Host.Address | String | The address of the host. |
| ForcepointSMC.Host.IPv6_address | String | The IPv6 address of the host. |
| ForcepointSMC.Host.Secondary_address | String | The secondary address of the host. |
| ForcepointSMC.Host.Comment | String | The comment for the host. |
Command example
!forcepoint-smc-host-update name="name" address="1.2.3.4"
Context Example
{
"ForcepointSMC": {
"Host": {
"Address": "1.2.3.4",
"Comment": null,
"IPv6_address": "",
"Name": "name",
"Secondary_address": []
}
}
}
Human Readable Output
Host name was updated successfully.
forcepoint-smc-host-delete
Deletes a host.
Base Command
forcepoint-smc-host-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the host to delete. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Host.Name | String | The name of the host. |
| ForcepointSMC.Host.Deleted | Boolean | Whether the host was deleted. |
Command example
!forcepoint-smc-host-delete name="name"
Context Example
{
"ForcepointSMC": {
"Host": {
"Deleted": true,
"Name": "name"
}
}
}
Human Readable Output
Host name was deleted successfully.
forcepoint-smc-domain-create
Creates a new domain.
Base Command
forcepoint-smc-domain-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the domain to create. | Required |
| comment | The comment to add to the domain. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Domain.Name | String | The name of the host. |
| ForcepointSMC.Domain.Comment | String | The comment of the host. |
Command example
!forcepoint-smc-domain-create name="name"
Context Example
{
"ForcepointSMC": {
"Domain": {
"Comment": "",
"Name": "name"
}
}
}
Human Readable Output
Domain name was created successfully.
forcepoint-smc-domain-list
Lists the domains in the system.
Base Command
forcepoint-smc-domain-list
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of a specific domain to fetch. | Optional |
| limit | The maximum number of hosts to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results. Overrides the other arguments if used. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Domain.Name | String | The name of the domain. |
| ForcepointSMC.Domain.Comment | String | The comment for the domain. |
Command example
!forcepoint-smc-domain-list name="name"
Context Example
{
"ForcepointSMC": {
"Domain": {
"Comment": null,
"Name": "name"
}
}
}
Human Readable Output
Domains
Name name
forcepoint-smc-domain-delete
Deletes a domain.
Base Command
forcepoint-smc-domain-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the domain to delete. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Domain.Name | String | The name of the domain. |
| ForcepointSMC.Domain.Deleted | Boolean | Whether the domain was deleted. |
Command example
!forcepoint-smc-domain-delete name="name"
Context Example
{
"ForcepointSMC": {
"Domain": {
"Deleted": true,
"Name": "name"
}
}
}
Human Readable Output
Domain name was deleted successfully.
forcepoint-smc-policy-template-list
Lists the policy templates in the system.
Base Command
forcepoint-smc-policy-template-list
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of policy templates to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results. Overrides the other arguments if used. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.PolicyTemplate.Name | String | The name of the firewall policy template. |
| ForcepointSMC.PolicyTemplate.Comment | String | The comment for the firewall policy. |
Command example
!forcepoint-smc-policy-template-list limit=1
Context Example
{
"ForcepointSMC": {
"PolicyTemplate": {
"Comment": "Firewall Template Policy that uses Inspection rules from the No Inspection Policy.",
"Name": "Firewall Template"
}
}
}
Human Readable Output
Policy template
Name Comment Firewall Template Firewall Template Policy that uses Inspection rules from the No Inspection Policy.
forcepoint-smc-firewall-policy-list
Lists the firewall policies in the system.
Base Command
forcepoint-smc-firewall-policy-list
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of firewall policies to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results. Overrides the other arguments if used. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Policy.Name | String | The name of the firewall policy. |
| ForcepointSMC.Policy.Comment | String | The comment for the firewall policy. |
Command example
!forcepoint-smc-firewall-policy-list limit=1
Context Example
{
"ForcepointSMC": {
"FirewallPolicy": {
"Comment": null,
"Name": "Policy For May To Test PC"
}
}
}
Human Readable Output
Firewall policies
Name Policy For May To Test PC
forcepoint-smc-firewall-policy-create
Creates a firewall policy.
Base Command
forcepoint-smc-firewall-policy-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the firewall policy. | Required |
| template | The template name to use to create the firewall policy. Run the forcepoint-smc-policy-template-list command to get the list of policy templates. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Policy.Name | String | The name of the firewall policy. |
| ForcepointSMC.Policy.Comment | String | The comment for the firewall policy. |
Command example
!forcepoint-smc-firewall-policy-create name="name" template="Firewall Template"
Context Example
{
"ForcepointSMC": {
"Policy": {
"Comment": null,
"Name": "name"
}
}
}
Human Readable Output
Firewall policy name was created successfully.
forcepoint-smc-firewall-policy-delete
Deletes a firewall policy.
Base Command
forcepoint-smc-firewall-policy-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The name of the policy to delete. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Policy.Name | String | The name of the firewall policy. |
| ForcepointSMC.Policy.Deleted | Boolean | Whether the policy was deleted. |
Command example
!forcepoint-smc-firewall-policy-delete name="name"
Context Example
{
"ForcepointSMC": {
"Policy": {
"Deleted": true,
"Name": "name"
}
}
}
Human Readable Output
Firewall policy name was deleted successfully.
forcepoint-smc-rule-create
Creates a rule.
Base Command
forcepoint-smc-rule-create
Input
| Argument Name | Description | Required |
|---|---|---|
| policy_name | The name of the firewall policy. | Required |
| rule_name | The name of the rule to create. | Required |
| ip_version | The ip_version of the rule. Possible values are: V4, V6. | Required |
| source_ip_list | A comma-separated list of source ip-list names to use to create the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. | Optional |
| source_host | A comma-separated list of source host names to use to create the rule. Run the forcepoint-host-list command to get the list of hosts. | Optional |
| source_domain | A comma-separated list of source domain names to use to create the rule. Run the forcepoint-domain-list command to get the list of domains. | Optional |
| destination_ip_list | A comma-separated list of destination ip-list names to use to create the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. | Optional |
| destination_host | A comma-separated list of destination host names to use to create the rule. Run the forcepoint-host-list command to get the list of hosts. | Optional |
| destination_domain | A comma-separated list of destination domain names to use to create the rule. Run the forcepoint-domain-list command to get the list of domains. | Optional |
| action | The action of the rule. Possible values are: allow, continue, discard, refuse, enforce_vpn, apply_vpn, forward_vpn, blacklist, forced_next_hop. | Required |
| comment | The comment to add to the rule. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Rule.Name | String | The name of the rule. |
| ForcepointSMC.Rule.ID | String | The ID of the rule. |
| ForcepointSMC.Rule.IP_version | String | The IP version of the rule. |
| ForcepointSMC.Rule.Action | String | The action of the rule. |
| ForcepointSMC.Rule.Comment | String | The comment for the rule. |
Command example
!forcepoint-smc-rule-create policy_name="name" action=allow rule_name="test" destination_ip_list="test" ip_version="V4"
Context Example
{
"ForcepointSMC": {
"Rule": {
"Action": [
"allow"
],
"Comment": "",
"Destinations": [
"test"
],
"ID": "2097186.0",
"IP_version": "V4",
"Name": "test",
"Services": [],
"Sources": []
}
}
}
Human Readable Output
The rule test to the policy name was created successfully.
forcepoint-smc-rule-update
Updates a rule.
Base Command
forcepoint-smc-rule-update
Input
| Argument Name | Description | Required |
|---|---|---|
| policy_name | The name of the firewall policy. | Required |
| rule_name | The name of the rule to update. | Required |
| is_override | Whether to override the existing values. Default value is False. Possible values are: False, True. | Optional |
| ip_version | The ip_version of the rule. Possible values are: V4, V6. | Required |
| source_ip_list | A comma-separated list of source ip-list names to use to update the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. | Optional |
| source_host | A comma-separated list of source host names to use to update the rule. Run the forcepoint-host-list command to get the list of hosts. | Optional |
| source_domain | A comma-separated list of source domain names to use to update the rule. Run the forcepoint-domain-list command to get the list of domains. | Optional |
| destination_ip_list | A comma-separated list of destination ip-list names to use to update the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. | Optional |
| destination_host | A comma-separated list of destination host names to use to update the rule. Run the forcepoint-host-list command to get the list of hosts. | Optional |
| destination_domain | A comma-separated list of destination domain names to use to update the rule. Run the forcepoint-domain-list command to get the list of domains. | Optional |
| action | The action of the rule. Possible values are: allow, continue, discard, refuse, enforce_vpn, apply_vpn, forward_vpn, blacklist, forced_next_hop. | Optional |
| comment | The comment to add to the rule. | Optional |
Context Output
There is no context output for this command.
Command example
!forcepoint-smc-rule-update policy_name="name" action=continue rule_name="test" source_ip_list="test" ip_version="V4"
Human Readable Output
The rule test to the policy name was updated successfully.
forcepoint-smc-rule-list
Lists the rules in a specific policy.
Base Command
forcepoint-smc-rule-list
Input
| Argument Name | Description | Required |
|---|---|---|
| policy_name | The name of the firewall policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Rule.Name | String | The name of the rule. |
| ForcepointSMC.Rule.ID | String | The ID of the rule. |
| ForcepointSMC.Rule.IP_version | String | The IP version of the rule. |
| ForcepointSMC.Rule.Sources | Unknown | The sources of the rule. |
| ForcepointSMC.Rule.Destinations | Unknown | The destinations of the rule. |
| ForcepointSMC.Rule.Services | Unknown | The services of the rule. |
| ForcepointSMC.Rule.Actions | Unknown | The actions of the rule. |
| ForcepointSMC.Rule.Comment | String | The comment of the rule. |
Command example
!forcepoint-smc-rule-list policy_name="name"
Context Example
{
"ForcepointSMC": {
"Rule": {
"Actions": [
"continue"
],
"Comment": "",
"Destinations": [
"test"
],
"ID": "2097186.1",
"IP_version": "V4",
"Name": "test",
"Services": [],
"Sources": [
"test"
]
}
}
}
Human Readable Output
Rules
Name ID IP_version Sources Destinations Actions test 2097186.1 V4 test test continue
forcepoint-smc-rule-delete
Deletes a rule.
Base Command
forcepoint-smc-rule-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| policy_name | The name of the firewall policy. | Required |
| rule_name | The name of the rule to delete. | Required |
| ip_version | The ip_version of the rule. Possible values are: V4, V6. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Rule.ID | String | The ID of the rule. |
| ForcepointSMC.Rule.Deleted | Boolean | Whether the rule was deleted. |
Command example
!forcepoint-smc-rule-delete policy_name="name" rule_name="test" ip_version=V4
Context Example
{
"ForcepointSMC": {
"Rule": {
"Deleted": true,
"Name": "test"
}
}
}
Human Readable Output
Rule test was deleted successfully.
forcepoint-smc-engine-list
Lists the engines in the system.
Base Command
forcepoint-smc-engine-list
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of engines to return. Default value is 50. | Optional |
| all_results | Whether to return all of the results or not, overrides the other arguments if used. Default value is False. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ForcepointSMC.Engine.Name | String | The name of the engine. |
| ForcepointSMC.Engine.Comment | String | The comment for the engine. |
Command example
!forcepoint-smc-engine-list limit=1
Context Example
{
"ForcepointSMC": {
"Engine": {
"Comment": "Forcepoint Engine element pre-populated by installer",
"Name": "Forcepoint Engine"
}
}
}
Human Readable Output
Engines
Name Comment Forcepoint Engine Forcepoint Engine element pre-populated by installer
forcepoint-smc-engine-refresh
Refreshes the specified engines. Use the forcepoint-smc-engine-list command to list the engines in the system.
Base Command
forcepoint-smc-engine-refresh
Input
| Argument Name | Description | Required |
|---|---|---|
| engine_name | A comma-separated list of engine names to refresh. | Required |
| interval_in_seconds | The interval in seconds between polling attempts. To prevent search timeouts, set this value within the 60-90 second range. Default is 60. | Optional |
| timeout_in_seconds | The timeout for polling in seconds. Default is 600. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
url— Server URL (required)credentials— (required)port— Port (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (21)
-
forcepoint-smc-domain-createCreates a new domain.
-
forcepoint-smc-domain-deleteDeletes a domain.
-
forcepoint-smc-domain-listLists the domains in the system.
-
forcepoint-smc-engine-listLists the engines in the system.
-
forcepoint-smc-engine-refreshRefreshes the specified engines. Use the forcepoint-smc-engine-list command to list the engines in the system.
-
forcepoint-smc-firewall-policy-createCreates a firewall policy.
-
forcepoint-smc-firewall-policy-deleteDeletes a firewall policy.
-
forcepoint-smc-firewall-policy-listLists the firewall policies in the system.
-
forcepoint-smc-host-createCreates a new host.
-
forcepoint-smc-host-deleteDeletes a host.
-
forcepoint-smc-host-listLists the hosts in the system.
-
forcepoint-smc-host-updateUpdates a host.
-
forcepoint-smc-ip-list-createCreates an IP list.
-
forcepoint-smc-ip-list-deleteDeletes an IP list.
-
forcepoint-smc-ip-list-listLists the IP Lists in the system.
-
forcepoint-smc-ip-list-updateUpdates an IP list.
-
forcepoint-smc-policy-template-listLists the policy templates in the system.
-
forcepoint-smc-rule-createCreates a rule.
-
forcepoint-smc-rule-deleteDeletes a rule.
-
forcepoint-smc-rule-listLists the rules in a specific policy.
-
forcepoint-smc-rule-updateUpdates a rule.
category: Network Security sectionorder: - Connect provider: Francisco Partners commonfields: id: Forcepoint Security Management Center version: -1 configuration: - display: Server URL name: url required: true type: 0 section: Connect - displaypassword: API Key additionalinfo: The API Key to use for connection name: credentials required: true hiddenusername: true type: 9 section: Connect - defaultvalue: '8082' display: Port name: port required: true type: 0 section: Connect - display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - display: Use system proxy settings name: proxy required: false type: 8 section: Connect description: Forcepoint SMC provides unified, centralized management of all models of Forcepoint engines whether physical, virtual or cloud—across large, geographically distributed enterprise environments. display: 'Forcepoint Security Management Center' name: Forcepoint Security Management Center script: commands: - arguments: - default: false description: The name of the IP list to create. isArray: false name: name required: true secret: false - default: false description: A comma-separated list of IP addresses. isArray: false name: addresses required: false - default: false description: The comment to add to the IP List. isArray: false name: comment required: false description: Creates an IP list. execution: false name: forcepoint-smc-ip-list-create outputs: - contextPath: ForcepointSMC.IPList.Name description: The name of the IP list. type: String - contextPath: ForcepointSMC.IPList.Addresses description: The list of addresses in the IP list. type: Unknown - contextPath: ForcepointSMC.IPList.Comment description: The comment for the IP list. type: String - arguments: - default: false description: The name of the IP list. isArray: false name: name required: true secret: false - default: false description: A comma-separated list of addresses to update. isArray: true name: addresses required: false - default: false auto: PREDEFINED description: If false, the list of addresses will be appended to the existing one. Else, the list will be overwritten. Default is False. isArray: false name: is_override predefined: - 'False' - 'True' required: false description: Updates an IP list. execution: false name: forcepoint-smc-ip-list-update outputs: - contextPath: ForcepointSMC.IPList.Name description: The name of the IP list. type: String - contextPath: ForcepointSMC.IPList.Addresses description: 'The list of addresses in the IPList.' type: Unknown - contextPath: ForcepointSMC.IPList.Comment description: The comment for the IP list. type: String - arguments: - default: false description: The name of a specific IP list to fetch. Overrides the other arguments if used. isArray: false name: name required: false secret: false - default: false description: The maximum number of IP lists to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results or not. Default value is False. isArray: false name: all_results required: false description: Lists the IP Lists in the system. execution: false name: forcepoint-smc-ip-list-list outputs: - contextPath: ForcepointSMC.IPList.Name description: The name of the IP list. type: String - contextPath: ForcepointSMC.IPList.Addresses description: The list of addresses in the IP list. type: Unknown - contextPath: ForcepointSMC.IPList.Comment description: The comment for the IP list. type: String - arguments: - default: false description: The name of the IP list to delete. isArray: false name: name required: true secret: false description: Deletes an IP list. execution: false name: forcepoint-smc-ip-list-delete outputs: - contextPath: ForcepointSMC.IPList.Name description: The name of the IP list. type: String - contextPath: ForcepointSMC.IPList.Deleted description: Whether the IP list was deleted. type: Boolean - arguments: - default: false description: The name of a specific host to fetch. isArray: false name: name required: false secret: false - default: false description: The maximum number of hosts to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results. Overrides the other arguments if used. Default value is False. isArray: false name: all_results required: false description: Lists the hosts in the system. execution: false name: forcepoint-smc-host-list outputs: - contextPath: ForcepointSMC.Host.Name description: The name of the host. type: String - contextPath: ForcepointSMC.Host.Address description: The address of the host. type: String - contextPath: ForcepointSMC.Host.IPv6_address description: The IPv6 address of the host. type: String - contextPath: ForcepointSMC.Host.Secondary_address description: The secondary address of the host. type: String - contextPath: ForcepointSMC.Host.Comment description: The comment for the host. type: String - arguments: - default: false description: The name of a specific host to fetch. isArray: false name: name required: true secret: false - default: false description: The address of the host. Cannot be combined with the ipv6_address argument. isArray: false name: address required: false - default: false description: The IPv6 address of the host. Cannot be combined with the address argument. isArray: false name: ipv6_address required: false - default: false description: A comma-separated list of secondary addresses of the host. isArray: true name: secondary_address required: false - default: false description: The comment to add to the host. isArray: false name: comment required: false description: Creates a new host. execution: false name: forcepoint-smc-host-create outputs: - contextPath: ForcepointSMC.Host.Name description: The name of the host. type: String - contextPath: ForcepointSMC.Host.Address description: The address of the host. type: String - contextPath: ForcepointSMC.Host.IPv6_address description: The IPv6 address of the host. type: String - contextPath: ForcepointSMC.Host.Secondary_address description: The secondary address of the host. type: Unknown - contextPath: ForcepointSMC.Host.Comment description: The comment for the host. type: String - arguments: - default: false description: The name of the host to update. isArray: false name: name required: true secret: false - default: false description: The address of the host. Cannot be combined with the ipv6_address argument. isArray: false name: address required: false - default: false description: The IPv6 address of the host. Cannot be combined with the address argument. isArray: false name: ipv6_address required: false - default: false description: comma-separated list of secondary addresses of the host. isArray: true name: secondary_address required: false - default: false description: The comment to add to the host. isArray: false name: comment required: false description: Updates a host. execution: false name: forcepoint-smc-host-update outputs: - contextPath: ForcepointSMC.Host.Name description: The name of the host. type: String - contextPath: ForcepointSMC.Host.Address description: The address of the host. type: String - contextPath: ForcepointSMC.Host.IPv6_address description: The IPv6 address of the host. type: String - contextPath: ForcepointSMC.Host.Secondary_address description: The secondary address of the host. type: String - contextPath: ForcepointSMC.Host.Comment description: The comment for the host. type: String - arguments: - default: false description: The name of the host to delete. isArray: false name: name required: true secret: false description: Deletes a host. execution: false name: forcepoint-smc-host-delete outputs: - contextPath: ForcepointSMC.Host.Name description: The name of the host. type: String - contextPath: ForcepointSMC.Host.Deleted description: Whether the host was deleted. type: Boolean - arguments: - default: false description: The name of the domain to create. isArray: false name: name required: true secret: false - default: false description: The comment to add to the domain. isArray: false name: comment required: false description: Creates a new domain. execution: false name: forcepoint-smc-domain-create outputs: - contextPath: ForcepointSMC.Domain.Name description: The name of the host. type: String - contextPath: ForcepointSMC.Domain.Comment description: The comment of the host. type: String - arguments: - default: false description: The name of a specific domain to fetch. isArray: false name: name required: false secret: false - default: false description: The maximum number of hosts to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results. Overrides the other arguments if used. Default value is False. isArray: false name: all_results required: false description: Lists the domains in the system. execution: false name: forcepoint-smc-domain-list outputs: - contextPath: ForcepointSMC.Domain.Name description: The name of the domain. type: String - contextPath: ForcepointSMC.Domain.Comment description: The comment for the domain. type: String - arguments: - default: false description: The name of the domain to delete. isArray: false name: name required: true secret: false description: Deletes a domain. execution: false name: forcepoint-smc-domain-delete outputs: - contextPath: ForcepointSMC.Domain.Name description: The name of the domain. type: String - contextPath: ForcepointSMC.Domain.Deleted description: Whether the domain was deleted. type: Boolean - arguments: - default: false description: The maximum number of policy templates to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results. Overrides the other arguments if used. Default value is False. isArray: false name: all_results required: false description: Lists the policy templates in the system. execution: false name: forcepoint-smc-policy-template-list outputs: - contextPath: ForcepointSMC.PolicyTemplate.Name description: The name of the firewall policy template. type: String - contextPath: ForcepointSMC.PolicyTemplate.Comment description: The comment for the firewall policy. type: String - arguments: - default: false description: The maximum number of firewall policies to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results. Overrides the other arguments if used. Default value is False. isArray: false name: all_results required: false description: Lists the firewall policies in the system. execution: false name: forcepoint-smc-firewall-policy-list outputs: - contextPath: ForcepointSMC.Policy.Name description: The name of the firewall policy. type: String - contextPath: ForcepointSMC.Policy.Comment description: The comment for the firewall policy. type: String - arguments: - default: false description: The name of the firewall policy. isArray: false name: name required: true - default: false description: The template name to use to create the firewall policy. Run the forcepoint-smc-policy-template-list command to get the list of policy templates. isArray: false name: template required: true description: Creates a firewall policy. execution: false name: forcepoint-smc-firewall-policy-create outputs: - contextPath: ForcepointSMC.Policy.Name description: The name of the firewall policy. type: String - contextPath: ForcepointSMC.Policy.Comment description: The comment for the firewall policy. type: String - arguments: - default: false description: The name of the policy to delete. isArray: false name: name required: true secret: false description: Deletes a firewall policy. execution: false name: forcepoint-smc-firewall-policy-delete outputs: - contextPath: ForcepointSMC.Policy.Name description: The name of the firewall policy. type: String - contextPath: ForcepointSMC.Policy.Deleted description: Whether the policy was deleted. type: Boolean - arguments: - default: false description: The name of the firewall policy. isArray: false name: policy_name required: true - default: false description: The name of the rule to create. isArray: false name: rule_name required: true - default: false description: The ip_version of the rule. auto: PREDEFINED isArray: false name: ip_version required: true predefined: - "V4" - "V6" - default: false description: A comma-separated list of source ip-list names to use to create the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. isArray: true name: source_ip_list required: false - default: false description: A comma-separated list of source host names to use to create the rule. Run the forcepoint-host-list command to get the list of hosts. isArray: true name: source_host required: false - default: false description: A comma-separated list of source domain names to use to create the rule. Run the forcepoint-domain-list command to get the list of domains. isArray: true name: source_domain required: false - default: false description: A comma-separated list of destination ip-list names to use to create the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. isArray: true name: destination_ip_list required: false - default: false description: A comma-separated list of destination host names to use to create the rule. Run the forcepoint-host-list command to get the list of hosts. isArray: true name: destination_host required: false - default: false description: A comma-separated list of destination domain names to use to create the rule. Run the forcepoint-domain-list command to get the list of domains. isArray: true name: destination_domain required: false - default: false auto: PREDEFINED description: The action of the rule. isArray: false name: action required: true predefined: - allow - continue - discard - refuse - enforce_vpn - apply_vpn - forward_vpn - blacklist - forced_next_hop - default: false description: The comment to add to the rule. isArray: false name: comment required: false description: Creates a rule. execution: false name: forcepoint-smc-rule-create outputs: - contextPath: ForcepointSMC.Rule.Name description: The name of the rule. type: String - contextPath: ForcepointSMC.Rule.ID description: The ID of the rule. type: String - contextPath: ForcepointSMC.Rule.IP_version description: The IP version of the rule. type: String - contextPath: ForcepointSMC.Rule.Action description: The action of the rule. type: String - contextPath: ForcepointSMC.Rule.Comment description: The comment for the rule. type: String - arguments: - default: false description: The name of the firewall policy. isArray: false name: policy_name required: true - default: false description: The name of the rule to update. isArray: false name: rule_name required: true - default: false auto: PREDEFINED description: Whether to override the existing values. Default value is False. isArray: false name: is_override required: false predefined: - 'False' - 'True' - default: false description: The ip_version of the rule. isArray: false auto: PREDEFINED name: ip_version required: true predefined: - 'V4' - 'V6' - default: false description: A comma-separated list of source ip-list names to use to update the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. isArray: true name: source_ip_list required: false - default: false description: A comma-separated list of source host names to use to update the rule. Run the forcepoint-host-list command to get the list of hosts. isArray: true name: source_host required: false - default: false description: A comma-separated list of source domain names to use to update the rule. Run the forcepoint-domain-list command to get the list of domains. isArray: true name: source_domain required: false - default: false description: A comma-separated list of destination ip-list names to use to update the rule. Run the forcepoint-ip-list-list command to get the list of ip lists. isArray: true name: destination_ip_list required: false - default: false description: A comma-separated list of destination host names to use to update the rule. Run the forcepoint-host-list command to get the list of hosts. isArray: true name: destination_host required: false - default: false description: A comma-separated list of destination domain names to use to update the rule. Run the forcepoint-domain-list command to get the list of domains. isArray: true name: destination_domain required: false - default: false auto: PREDEFINED description: The action of the rule. isArray: true name: action required: false predefined: - allow - continue - discard - refuse - enforce_vpn - apply_vpn - forward_vpn - blacklist - forced_next_hop - default: false description: The comment to add to the rule. isArray: false name: comment required: false description: 'Updates a rule.' execution: false name: forcepoint-smc-rule-update - arguments: - default: false description: The name of the firewall policy. isArray: false name: policy_name required: true description: 'Lists the rules in a specific policy.' execution: false name: forcepoint-smc-rule-list outputs: - contextPath: ForcepointSMC.Rule.Name description: 'The name of the rule.' type: String - contextPath: ForcepointSMC.Rule.ID description: 'The ID of the rule.' type: String - contextPath: ForcepointSMC.Rule.IP_version description: 'The IP version of the rule.' type: String - contextPath: ForcepointSMC.Rule.Sources description: 'The sources of the rule.' type: Unknown - contextPath: ForcepointSMC.Rule.Destinations description: 'The destinations of the rule.' type: Unknown - contextPath: ForcepointSMC.Rule.Services description: 'The services of the rule.' type: Unknown - contextPath: ForcepointSMC.Rule.Actions description: 'The actions of the rule.' type: Unknown - contextPath: ForcepointSMC.Rule.Comment description: 'The comment of the rule.' type: String - arguments: - default: false description: The name of the firewall policy. isArray: false name: policy_name required: true - default: false description: The name of the rule to delete. isArray: false name: rule_name required: true - default: false auto: PREDEFINED description: The ip_version of the rule. isArray: false name: ip_version required: true predefined: - 'V4' - 'V6' description: Deletes a rule. execution: false name: forcepoint-smc-rule-delete outputs: - contextPath: ForcepointSMC.Rule.ID description: The ID of the rule. type: String - contextPath: ForcepointSMC.Rule.Deleted description: Whether the rule was deleted. type: Boolean - arguments: - default: false description: The maximum number of engines to return. Default value is 50. isArray: false name: limit required: false - default: false description: Whether to return all of the results or not, overrides the other arguments if used. Default value is False. isArray: false name: all_results required: false description: Lists the engines in the system. execution: false name: forcepoint-smc-engine-list outputs: - contextPath: ForcepointSMC.Engine.Name description: The name of the engine. type: String - contextPath: ForcepointSMC.Engine.Comment description: The comment for the engine. type: String - arguments: - description: A comma-separated list of engine names to refresh. isArray: true name: engine_name required: true - description: A comma-separated list of polling refresh task IDs. isArray: true name: task_ids required: false hidden: true - name: interval_in_seconds description: The interval in seconds between polling attempts. To prevent search timeouts, set this value within the 60-90 second range. defaultValue: '60' - name: timeout_in_seconds description: The timeout for polling in seconds. defaultValue: '600' description: Refreshes the specified engines. Use the forcepoint-smc-engine-list command to list the engines in the system. name: forcepoint-smc-engine-refresh polling: true isfetch: false runonce: false script: '-' type: python subtype: python3 dockerimage: demisto/vendors-sdk:1.0.0.10120494 fromversion: 6.8.0 tests: - No tests