Objects

An object is a configuration element that

  • associates a name with a value for increased flexibility and ease of use in the web interface,

  • enables reuse of configurations across policies, rules, event searches, reports, and dashboards, and

  • can be managed, grouped, and overridden as needed within the system.

Object management and usage

The system uses named objects to simplify configuration and management. Use the object manager to create and manage objects. Many configurations that use objects also allow you to create objects as needed. The object manager enables you to:

  • View the policies, settings, and other objects where a network, port, VLAN, or URL object is used; see View objects and their usage.

  • Group objects to reference multiple objects with a single configuration; see Object groups.

  • Override object values for selected devices; see Object overrides.

After editing an object used in an active policy, you must redeploy the changed configuration for your changes to take effect. You cannot delete an object that is in use by an active policy.

Note

The system configures an object on a managed device only when a policy assigned to that device uses the object. If you remove an object from all policies assigned to a given device, the object is also removed from the device configuration on the next deployment, and subsequent changes to the object are not reflected in the device configuration.

This table lists the objects you can create in the system, and indicates whether each object type can be grouped or configured to allow overrides.

Object type

Groupable?

Allows overrides?

Network

yes

yes

Port

yes

yes

Interface:

  • Security Zone

  • Interface Group

no

no

Tunnel Zone

no

no

Application Filter

no

no

VLAN Tag

yes

yes

External Attribute: Security Group Tag (SGT) and Dynamic Object

no

no

URL

yes

yes

Geolocation

no

no

Time Range

no

no

Variable Set

no

no

Security Intelligence: Network, DNS, and URL lists and feeds

no

no

Sinkhole

no

no

File List

no

no

Cipher Suite List

no

no

Distinguished Name

yes

no

Public Key Infrastructure (PKI):

  • Internal and Trusted CA

  • Internal and External Certs

yes

no

Key Chain no yes

DNS Server Group

no

no

SLA Monitor

no

no

Prefix List: IPv4 and IPv6

no

yes

Route Map

no

yes

Access List: Standard and Extended

no

yes

AS Path

no

yes

Community List

no

yes

Policy List

no

yes

FlexConfig: Text and FlexConfig objects

no

yes