Create dynamic objects with Cloud-Delivered Firewall Management Center

This page appears if you indicated that you are configuring the Dynamic Attributes Connector with Cloud-Delivered Firewall Management Center in Security Cloud Control.

To configure cloud-delivered FMC with dynamic attributes connector included in Security Cloud Control, you must onboard the FMC to Security Cloud Control then create an adapter in the dynamic attributes connector that communicates with the FMC

A dynamic object is a firewall configuration element that

  • enables automatic retrieval of IP addresses from cloud services,

  • allows for dynamic updates within access control rules, and

  • provides integration with external systems for adaptive security policies.

To deploy this feature:

  1. Configure connectors: Retrieve IP addresses from supported cloud services for automatic policy updates.

    For more details, see Create a connector.

  2. Configure dynamic attributes filters: Specify which IP addresses should be sent to the management center.

    For more details, see Create dynamic attributes filters.

  3. Configure a Cloud-Delivered Firewall Management Center adapter: Ensure that the retrieved IP addresses are sent to the correct device.

  4. Access Administration > Firewall Management Center: Use the Tools menu to select Cloud-Delivered FMC.

  5. View your dynamic objects: Navigate to Objects > External Attributes > Dynamic Object to see the list.

  6. Use dynamic objects in access control rules: In access control policies, use the Dynamic Attributes tab to add dynamic objects.

    You can also use the objects in DNS rules.