> Source: [sk182252](https://support.checkpoint.com/results/sk/sk182252)

# sk182252 - Dynamic Layer in Access Control Policy

| Property | Value |
|----------|-------|
| Solution ID | sk182252 |
| Date Created | 2024-04-25 |
| Last Modified | 2026-06-14 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R82.10, R82, R82.10, R82 |
| OS | Gaia |

## Solution

**Table of Contents:**

* Introduction
* Requirements
* Configuration
* Known Limitations
* Important Notes
* Documentation

### Introduction {#1}

Starting from R82, it is possible to configure Access Control rules directly on the Security Gateway with the Gaia API call "`set-dynamic-content`". This saves time and helps automate various tasks.

On the Management Server, you configure a new Policy Layer (and configure it as a Dynamic Layer). On the Security Gateway, this Dynamic Layer works as a container for all Access Control rules you configure with the Gaia API call "`set-dynamic-content`".

### Requirements {#2}

1. Management Server R82 and higher:

   * Security Management Server

   * Multi-Domain Security Management Server

2. Security Gateway R82 and higher:

   * Security Gateway

   * ElasticXL Cluster

   * ClusterXL

   * Security Group on Maestro or Scalable Chassis

3. On the Security Gateway, the user that runs the Gaia API must have this configuration in Gaia OS:

   1. Role: **adminRole**.

   2. Access Mechanism: **Gaia API**.

   3. Shell: **/etc/cli.sh** or **/bin/bash**

   See the [Gaia Administration Guide](https://support.checkpoint.com/product/73#f-commonsource=C.%20Documentation) \> chapter "User Management" \> sections "Users" and "Roles".

### Configuration {#3}

See the [Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Default.htm#cshid=ID136) \> Chapter "**Creating an Access Control Policy** " \> section "**Self-Managed Security Gateways**".

### Known Limitations {#4}

* It is not supported to edit or delete individual dynamic rules on the Security Gateway after you add them.

  To remove dynamic rules, you must reset the Dynamic Layer that contains these rules on the Security Gateway.
* VSNext Virtual Gateway is supported starting from R82.10.

* Legacy VSX Virtual System (on a VSX Gateway or VSX Cluster) is not supported.

* Legacy VSX Virtual Router (on a VSX Gateway or VSX Cluster) is not supported.

### Important Notes {#5}

* Each Policy Package supports more than one Dynamic Layer - as an Inline Layer or as an Ordered Layer. For example, different administrator can use different layers.

* Security Gateway applies the Access Control rules in the order of the Policy Layers in the Policy Package.

* Rules that you configure in SmartConsole in the Dynamic Layer apply until you run the Gaia API call "`set-dynamic-content`" for the first time on the Security Gateway.

* If you delete the Dynamic Layer from the Policy Package (or clear the checkbox "**Set as a Dynamic Layer, see sk182252**" in the Dynamic Layer) and install the Access Control policy, then the Security Gateway removes all dynamic rules and applies only the static rules configured in SmartConsole.

* SmartConsole does not show rules in the Dynamic Layer that you configure on the Security Gateway.

* To see the list of the supported objects in the Dynamic Layer, refer to the API call "**set-dynamic-content** " \> section "**Request Body** " \> parameter "**objects**".

### Documentation {#6}

* [Gaia API Reference](https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html#introduction) (v1.8 and higher) \> section "System" \> sub-section "Dynamic Content".

* [Security Management Administration Guide](https://support.checkpoint.com/product/184#f-commonsource=C.%20Documentation) \> chapters "Managing Policies" and "Creating an Access Control Policy".

* [Gaia Administration Guide](https://support.checkpoint.com/product/73#f-commonsource=C.%20Documentation) \> chapter "User Management" \> sections "Users" and "Roles".

* [sk143612 - Gaia REST API: Read and send information to Check Point servers](https://support.checkpoint.com/results/sk/sk143612)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
