Created on
10-11-2019
06:41 AM
Edited on
08-08-2025
05:13 AM
By
Stephen_G
Description | This article describes the behavior and changes of the 'Create address object matching subnet' option for different Interface roles via GUI/CLI. |
Scope | FortiGate interface created with role LAN in v7.0+ via GUI/CLI. |
Solution |
The 'Create address object matching subnet' feature automatically creates a Firewall address object once an interface is created with the role LAN/DMZ.
Behavior:
Default setting via GUI:
In the GUI, this setting is controlled via the 'Create address object matching subnet' toggle as depicted in the image above.
Default setting via CLI:
The default setting via CLI is slightly different since CLI does not have the 'Create address object matching subnet' enable/disable toggle setting.
V7.0.x,v 7.2.0-7.2.3:
v7.2.4+:
The interface created automatically looks something like the below:
edit "interface_name address"
Note: If the interface address changes, the subnet of the address object will update dynamically.
Important Note: When an interface has an address object of type 'interface-subnet' automatically or manually created as above, it is not possible to assign this interface as 'ha-mgmt-interface. Remove the interface firewall address object before assigning this interface as 'ha-mgmt.-interface'.
This scenario also works similarly when adding an interface as a member in the switch-interface command. It will not be possible to add the newly created interface if that feature is enabled, as it will create a reference. Therefore, it will not be able to add that interface as a member to the switch-interface. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.