Dynamic objects

A dynamic object is a network object that

  • specifies one or many IP addresses retrieved using REST API calls or the Dynamic Attributes Connector from cloud sources,

  • can be used in access control or DNS rules without deploying dynamic changes, and

  • automatically updates object values on managed devices after being pushed by the Dynamic Attributes Connector.

Kinds of dynamic objects

There are these kinds of dynamic objects:

  • Connector-created dynamic objects: The system pushes dynamic objects created using the dynamic attributes connector to the Cloud-Delivered Firewall Management Center as soon as you create them. The system updates them at regular intervals.

  • API-created dynamic objects have the following characteristics:

    • Are IP addresses, with or without classless inter-domain routing (CIDR), that can be used in access control rules much like a network object.

    • Do not support fully-qualified domain names or address ranges.

    • You must update these objects using an API.

    For more information about API-created dynamic objects, see API-created dynamic objects.

Note

Unlike most other objects, dynamic objects do not have to be deployed to managed devices to take effect. Add a dynamic object to the Dynamic Attributes tab in a rule and deploy the rule. The object values are automatically updated on the managed device as soon as possible after being pushed by the Dynamic Attributes Connector.