Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Create and Manage Addresses or Address Groups

Use the Addresses page to create addresses and address groups. Addresses and address groups are used in firewall and NAT services. After you create an address, you can combine it with other addresses to form an address group. Address groups are useful when you want to apply the same policy to multiple services.

Create Addresses or Address Groups

  1. Click Security > Shared Objects > Addresses.

    The Addresses page is displayed.

  2. Click the plus icon (Blue plus symbol suggesting an action like adding or expanding content.).

    The Create Addresses page is displayed.

  3. Complete the configuration according to the guidelines in Table 1.
    Table 1: Fields on the Create Addresses Page

    Field

    Description

    Name

    Enter a unique name containing maximum 63 characters.

    The name must begin with an alphanumeric character and can contain alphanumeric characters and some special characters such as colons (:), hyphens (-), forward slashes (/), periods (.), and underscores (_).

    Description

    Enter a description containing maximum 900 characters. Ensure that description is useful for all administrators.

    The description can contain alphanumeric characters and special characters such as less-than sign (<) and greater-than sign (>).

    Object Type

    Select the address object to create.

    • Address

    • Address Group—A list of addresses is displayed for you to select the addresses to include in the address group. Select the addresses and click the arrow (>) to move the selected devices to the Selected column.

    Type

    Select the address type and complete the configuration according to the guidelines in Address Object Configuration.

    Table 2: Address Object Configuration
    Field Description

    Host

    • Host IP—Enter the IPv4 or IPv6 host IP address.

      If you do not know the IP address, enter the hostname and click Look up hostname.

    • Hostname—Enter a host name containing maximum 63 characters. The name must begin with an alphanumeric character and can contain hyphens (-) and underscores (_).

      If you do not know the host name, enter the IP address and click Look up IP address. For example, enter www.company.com and click Look up IP address. The host name lookup supports IPv4 addresses.

    Range

    • Start Address—Enter a starting IPv4 or IPv6 address along with the classless inter-domain routing (CIDR) for the address range.

    • End Address—Enter an ending IPv4 or IPv6 address for the address range.

    The address range is validated after you enter the ending address.

    An address range is configured on devices as an address set, using network address objects that collectively cover the specified range.

    Network

    • Network—Enter the IPv4 or IPv6 network IP address. For example, 192.0.2.0 or 2001:db8:4136:e378:8000:63bf:3fff:fdd2.

    • Subnet Mask—Enter the IPv4 or IPv6 subnet mask for the network range. For example, 192.0.2.0/24 or 2001:db8::/32. The subnet mask is validated as you type. It must match the network address you’ve entered.

    DNS Host

    • DNS Name—Enter the DNS name containing maximum 63 alphanumeric characters. The name must end with an alphanumeric character and can contain hyphens (-) and periods (.) For example, company.com.

    • DNS Type—Select IPv4-only or IPv6-only.

    Variable

    • Default address—Select the default address. This default address is replaced with the mapped device-specific address when applied to the group firewall policy.

    • Variable address—Create a new variable address.

      1. Click the plus icon (Blue plus symbol suggesting an action like adding or expanding content.). The Create Variable page is displayed.
      2. Select the devices to map the variable address. Click the arrow (>) to move the selected devices to the Selected column. Only devices from the current and child domain are listed. Click to search the device list.
      3. Select an address. This device-specific address replaces the default address when applied to a security policy.
      4. Click OK. A new variable address is created.

    Variables addresses are used in group security policies only.

  4. Click OK.

A new address or address group is created. You can use this object in security policies or NAT policies.

Manage Addresses or Address Groups

You cannot edit or delete predefined addresses. You can edit or delete GeoIP feeds only from Security > Shared Objects > GEO Fencing.

  • Edit—Select the address or address group, and click the pencil icon (Blue pencil icon indicating edit functionality.).

    When you edit an address that is a deployed as part of a policy, you will need to redeploy that policy in order for the changes to take effect. You cannot edit Address Name and Object Type.

  • Clone—Select the address or address group, and click More > Clone.

  • Delete—Select the address or address group, and click the trash can icon (Blue trash can icon representing delete or remove function.).

    You cannot delete addresses or address groups that are referenced in a policy. If you try to delete such an address or address group, an error message is displayed.