Description | This article describes how to create three address objects (Class A, B, and C) and add them to an address group. |
Scope | FortiGate. |
Solution |
Sometimes, the address group 'all' or 'g_all' is not used on firewall policies, but the user wants to cover a large range of IP addresses.
Step 1: Create the address object by selecting Policy & Objects -> Addresses -> Create New.
Step 2: Create the address object class A. Class_A can be used as a name, select IP Range and add the range 1.0.0.0-127.0.0.
Step 3: Repeat the steps above to create the address objects for classes B and C. Use the following commands via CLI:
config firewall address
Step 4: Create a group and add the three members to classes A, B, and C.
Commands to create the group via CLI:
config firewall addrgrp
Note: v5.0 up to 6.4 are out of engineering support. These commands might be different on higher versions. Consider upgrading the firmware level on the device to a supported version (7.0 up to 7.6). Check the firmware path and compatibility depending on the hardware: Upgrade tool. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.