You use rule objects to define quarantine zone access rules and quarantine exceptions.
Icon/Option | Definition | |
|---|---|---|
Rule object | Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.
| |
Object Type | Filters rule objects in the list.
| |
Rule Object Type | Select the rule object type that you want to view. | |
Search | Type your search criteria in the field to find rule objects with matching elements. For example, type to list the rule objects containing google as part of their names. | |
icon | Creates a custom rule object. | |
icon | Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects. | |
icon | Deletes a custom rule object belonging to the current admin domain. | |
To view or edit a rule object | Double-click the rule object belonging to the current admin domain. |
Rule objects are mappings to one or more components related to your network traffic. However, for Quarantine you can map a rule object only to one component. So, for example, you can specify an IPv4 address as a rule object. Then you can create a quarantine zone access rule in which you specify this rule object as the destination. Every time you want to refer to this IP address in your quarantine zone access rules or quarantine exceptions, you can use this rule object.
Important
In features such as Advanced Firewall policies, you can specify multiple rule objects per component of an access rule. For example, you can specify multiple rule objects as the destination of the traffic. In case of quarantine zone access rule, you can specify only one rule object per component. Also, the rule object that you use in the quarantine zone access rule can have only one item in it. For example, the IPv4 Endpoint rule object that you want to use in quarantine zone access rule can only contain one IPv4 address in it. However, the IPv4 Endpoint rule object for quarantine exception list can contain up to 10 IPv4 addresses.
Rule objects for Quarantine | Relevant for quarantine zone? | Relevant for quarantine exception? |
|---|---|---|
IPv4 Endpoint: Use this rule object to refer to IPv4 addresses in quarantine zone access rules and quarantine exception list. | Yes | Yes |
IPv6 Endpoint: Use this rule object to refer to IPv6 addresses in quarantine exception list. | No | Yes |
IPv4 Network: Use this rule object to refer to the CIDRs to use in quarantine zone access rules and quarantine exception lists. In a quarantine zone access rule, you can specify a CIDR as the destination of traffic. For example, you might want to apply a rule on the traffic targeted for 172.16.225.0/24 network. Default IPv4 Network rule objects are available for the three reserved IPv4 ranges according to RFC 1918. You can specify up to 10 CIDRs in one rule object for quarantine exception lists. | Yes | Yes |
Service: To restrict traffic based on the IP protocol, ICMP codes, or the TCP/UDP port numbers, use the Service rule object. You can create Service rule objects or use the default ones. The well-known services on standard TCP and UDP ports, as well as ICMP codes are pre-defined. For example, telnet is predefined as TCP on port 23. Similarly, ICMP codes such as ICMP echo reply and ICMP request are pre-defined. When you create a Service rule object, the options are to specify the protocol number, TCP port, or UDP port. For custom ICMP codes, you need to specify the IP protocol number and the ICMP code in the port field. You can define only one IP protocol specification per rule object. Notes:
| Yes | No |
.png)
.png)
.png)