Networks
A network object is a network entity that
-
represents one or more IP addresses,
-
can be used in access control policies, network variables, identity rules, network discovery rules, event searches, and reports, and
-
is filtered automatically to show only valid objects for each configuration option.
Network object types
You can define a network object as one of these types:
-
Host: A single IP address.
IPv4 example:
209.165.200.225IPv6 example:
2001:DB8::0DB8:800:200C:417Aor2001:DB8:0:0:0DB8:800:200C:417A -
Range: A range of IP addresses.
IPv4 example:
209.165.200.225-209.165.200.250IPv6 example:
2001:db8:0:cd30::1-2001:db8:0:cd30::1000 -
Network: An address block, also known as a subnet.
IPv4 example:
209.165.200.224/27IPv6 example:
2001:DB8:0:CD30::/60NoteSecurity Intelligence ignores IP address blocks using a
/0netmask. -
FQDN: A single fully-qualified domain name (FQDN). You can limit FQDN resolution to IPv4 address only, IPv6 address only, or both types. FQDNs must begin and end with a digit or letter. They can contain only letters, digits, and hyphens internally.
Example:
www.example.comNoteYou can use FQDN objects in access control rules and prefilter rules, or manual NAT rules, only. The rules match the IP address obtained for the FQDN through a DNS lookup. To use an FQDN network object, ensure you have configured the DNS server settings in DNS server groups and the DNS platform settings in Configure DNS server settings.
You cannot use FDQN network objects in identity rules.
-
Group: A group of network objects or other network object groups. You can create nested groups by adding a network object group to another. Nesting is supported up to 10 levels.
NoteYou can add up to 100 network literals in a network object. Each nested network object group contains up to 100 network literals.
If you are using Cloud-Delivered Firewall Management Center
When you create a network object or group, it is replicated in the Objects > FTD Network Objects page in Security Cloud Control and vice-versa.
You can use the objects when specifying networks while configuring other Security Cloud Control-managed products, such as ASA or FDM.
Changes made to network objects or groups in either list are reflected in both. Deleting an object or group from either list also deletes its corresponding object or group from the other list.
Exception: If an object created on the Security Cloud Control list has the same name as an existing object on the Cloud-Delivered Firewall Management Center list, the object will not be replicated on the Cloud-Delivered Firewall Management Center list.