Create a network object

Create network objects to define network addresses, address ranges, or groups that can be used in security policies and access rules.

Network objects allow you to efficiently manage and reuse network definitions across your security policies. This task is relevant when you need to add, clone, or modify network objects in your management center.

Procedure


Step 1

If you are accessing network objects from Security Cloud Control, choose Objects.

Step 2

Choose Objects, and then Choose Network from the list of object types.

Step 3

Choose Add Object from the Add Network drop-down menu.

Step 4

Alternatively, you can clone an existing network object and edit the parameters to create a new network object. Click the Clone icon on the existing network object that you want to clone.

Step 5

Enter a Name and optionally, enter a Description.

Step 6

In the Network field, select the required option and enter an appropriate value; see Networks.

Note

You can add up to 100 network literals in a network object. Additionally, each nested network object group can contain a maximum of 100 network literals.

Step 7

(FQDN objects only) Select the DNS resolution from the Lookup drop-down menu to determine whether you want the IPv4, IPv6, or both IPv4 and IPv6 addresses associated with the FQDN.

Step 8

Manage overrides for the object:

  • If you want to allow overrides for this object, check the Allow Overrides check box; see Allow object overrides.
  • If you want to add override values to this object, expand the Override section and click Add; see Add object overrides.

Step 9

Click Save.


What to do next

  • If an active policy references your object, deploy configuration changes.