For quarantine zone access rules, only IPv4 Endpoint rule objects are supported. Also, only one rule member per rule object is applicable for quarantine zone.
The steps to add IPv4 Endpoint and IPv6 Endpoint rule objects are identical. Follow these steps to add IPv4 Endpoint or IPv6 Endpoint rule objects:
Upon specifying the options in the Properties tab and selecting IPv4 Endpoint or IPv6 Endpoint from the rule object Type drop-down, click Next.
Create an IPv4 Endpoint or IPv6 Endpoint rule object.png)
The Rule Members tab is displayed.
Add Rule Members.png)
Following are the details of the columns displayed in the Rule Members tab:
Column details in the Rule Members tab - IPv4/IPv6 Endpoint rule objectColumn
Description
State
Specifies whether a rule member (in this case, IPv4 or IPv6 endpoint based on the rule object type selected) is Enabled or Disabled
Value
Displays the IPv4 or IPv6 addresses
Last Updated
Time — Specifies the time when the rule member was last modified
By — Displays the user who modified the rule member
Comment
Displays any additional comment specified for the rule member
You can rearrange/resize the columns to view the details according to your preference.
The following table explains the options in the Rule Members tab.
Option
Definition
.png)
Click this icon to add an IPv4 or IPv6 address.
.png)
Click this icon to delete single or multiple IPv4 or IPv6 addresses.
Save as CSV
Click this button to export all the rule members displayed in the grid to a CSV file.
Other Actions
Import — Allows you to import a file containing a list of IPv4 or IPv6 addresses
Export All — Allows you to export all the IP addresses from the Manager to the local system
There are two ways to add the IP addresses — add individual IP addresses using the
icon or import a list of IP addresses from a CSV file using the Other Actions → Import option.To add an individual IPv4 or IPv6 address:
Click the
icon.A Details window is displayed on the right-hand side of the Rule Members tab.
For details of the options displayed in the window, refer the table Column details in the Rule Members tab - IPv4/IPv6 Endpoint rule object.
Select the State, enter the IPv4 or IPv6 address in the Value field, enter a Comment if required and click Add.
Note
Do not specify the CIDR prefix (32) when entering an IPv4 address.
You can enter an IPv6 address such as 5507:c0d0:2002:0071:0000:0000:0000:0003. The same address can be represented as 5507:c0d0:2002:0071::0003.
You can enter up to 140000 IPv4 or 140000 IPv6 addresses in a single rule object.
The above rule member count is applicable only for Firewall policy. For QoS policy, Ignore Rules, SSL Decryption Exclusions, and NTBA Communication Rules, the maximum rule member count applicable for each rule object type is 10. For Quarantine Zones, only one rule member should be assigned per rule object. So, you need to add rule members to a rule object accordingly.
If the Manager is on or before version 10.1.7.55 and the Sensor is on or before 10.1.5.153, you can add a maximum of 10 IPv4/IPv6 addresses in any rule object.
Add individual IP addresses.png)
Upon adding all the required IP addresses, click Next.
Adaptive (Ignore Rules only) tab is displayed. This is an optional tab.
The following table explains the options in the Adaptive (Ignore Rules only) tab.
Option
Definition
Customization
Select Disabled to disable customization or select Use custom values per resource to customize values
Resource to Customize
Select the resource to customize from the drop-down list
Note
This option is displayed only if you select the customization option as Use custom values per resource
Add
Click this button to add an IP address to the Customizations list
Search
Type the search criteria to search for a resource
.png)
Click this icon to remove an IP address from the list
Based on the above options, make any configuration changes if required, and click Save. The rule object will be created.
To import a list of IP addresses from a CSV file using the Import option:
Click Other Actions → Import.
Note
You cannot import the file while adding individual entries. In case you plan to import a file along with the individual entries, add the entries first, save the rule object and re-open the rule object to import the file. Make sure that total rule member count (sum of CSV file entries and individual entries) does not exceed 140000.
Note
If you are assigning the rule object to QoS policy, Ignore Rules, SSL Decryption Exclusions, and NTBA Communication Rules, make sure that total rule member count (sum of CSV file entries and individual entries) does not exceed 10 entries.
Import IP addresses from a CSV file.png)
Import from CSV window appears. Use the Append option to add a new list of IP addresses or to append a list of IP addresses to an existing list. Use the Replace option to remove the existing list of IP addresses and add a new list from the file being imported.
Note
If any duplicate entries exist while appending, the Manager replaces the existing entries with the entries being imported.
Click Browse to locate the CSV file that contains the list of IP addresses that you plan to import.
Import IP addresses from a CSV file.png)
The file to be imported should be in the following CSV format: <IPv4 or IPv6 address>,<Comment>
Example file format: 10.10.1.1,textual description
The following is a sample for a CSV file with multiple IPv4 addresses:
CSV file format for IPv4 or IPv6 Endpoints.png)
The following table describes the details of the IP addresses to be imported in the CSV file format.
Format
Description
<IPv4 or IPv6 address>
Specifies the IP address to be imported
<Comment>
Specifies the description of the IP address to be imported. If you do not want to specify a comment for an entry, add comma (
,) next to the entry and leave it.Click Import upon selecting the CSV file.
All the entries in the CSV file will be imported and the rule object will be saved automatically.
Note
The State of the rule members will be set to Enabled by default. You may change the state of a rule member by accessing the rule object.
Rule object for IPv4/IPv6 endpoint successfully created.png)
Note
If there are any invalid entries in the CSV file, the Manager displays an Informational dialog-box stating about the invalid entries. All such entries will also be collected to a CSV file. This file will either download onto the local machine automatically or require you to choose a download location, based on your web browser's download settings. Upon downloading the file, click OK to close the Informational dialog-box. In this case, the rule object will be created upon closing the dialog-box.
Information dialog-box for invalid entries.png)