Object overrides

An object override is a configuration mechanism that

  • enables the definition of alternate values for objects, which the system applies to specified devices,

  • lets administrators create a smaller set of shared policies that can be used across devices without losing the flexibility to modify policies for individual devices, and

  • allows modifications to an object for devices or domains that require different definitions.

Object override usage and supported object types

Administrators can create an object whose definition works for most devices and use overrides to specify modifications for those devices needing different definitions. You may also need to override an object for all devices. This approach allows you to create a single policy that applies everywhere. Object overrides allow you to use fewer shared policies and customize them for individual devices when necessary.

You can target overrides to a specific domain. The override value applies to all devices in that domain unless you set a device-specific override. The object manager enables selection of objects that can be overridden and allows listing device-level or domain-level overrides for each object.

Supported object types for overrides include:

  • Network

  • Port

  • VLAN tag

  • URL

  • SLA Monitor

  • Prefix List

  • Route Map

  • Access List

  • AS Path

  • Community List

  • Policy List

  • Cert Enrollment (PKI)

  • Key Chain

In the object manager, the Override column flags objects that support overrides:

  • Green checkmark: Overrides can be created, and none have been added yet.

  • Red X: Overrides are not supported for the object.

  • Number: Indicates the count of overrides added for the object (for example, "2" means two overrides have been defined).

Object override example

For example, to deny ICMP traffic to different departments, each connected to a different network, you can define an access control policy that includes a network object called Departmental Network. By enabling overrides for this object, it's possible to create policy variations on each relevant device that specify the actual network associated with that device.