Add variables

Add variables to a variable set so you can define reusable network or port values for use in policies.

Use variables in device policies to enable flexible, reusable configurations that simplify network management.

Before you begin

Ensure you have the IPS license (for Firewall Threat Defense devices) or the Protection license (all other device types).

Procedure


Step 1

In the variable set editor, click Add.

Step 2

Enter a unique variable Name.

Step 3

From the Type drop-down list, choose either Network or Port.

Step 4

Define the values for the variable:

  • To include or exclude specific networks or ports, select them and click Include or Exclude. If there is overlap, excluded addresses or ports always take precedence over included ones.
  • To add literal values, enter a single IP address, address block, port, or port range. If you need to add more than one value, repeat this action.
  • To remove any items from included or excluded lists, select the item and click Delete (delete icon) next to the item.
  • You may use a combination of literal values, existing variables, objects, or network object groups when specifying included or excluded items for network variables.

Step 5

Save the variable.

  • If adding a new variable from a custom set, choose whether to add it as a customized value in the default set or as a default value of any in the default and other custom sets.

Step 6

Save the variable set.

  • Any access control policy linked to the variable set will display an out-of-date status until changes are deployed.


The variable is added to the variable set and is available for use in policies. Any access control policy linked to the variable set displays an out-of-date status until you deploy the changes.

What to do next

  • If an active policy references your object, deploy configuration changes.