You can use rule objects to create ignore rules. You can use common rule objects across other features in the Manager such as Firewall.
Rule objects, in ignore rules, can be customized to override any settings made at the parent domain level. They can be customized at the admin domain level, child domain level or the Sensor level.
Note
The ability to customize a rule object is only available for ignore rules. Firewall, which also uses rule objects, does not support rule object customization.
Icon/Option | Definition |
|---|---|
Rule object | Displays the rule objects according to the filter criteria. Click a column heading to sort the table in ascending or descending order.
|
Object Type | Filters rule objects in the list.
|
Rule Object Type | Select the rule object type that you want to view. |
Search | Type your search criteria in the field to find rule objects with matching elements. For example, type to list the rule objects containing google as part of their names. |
![]() icon | Creates a custom rule object. |
![]() icon | Clones a rule object. You cannot clone default rule objects other than the IPv4 network rule objects. |
![]() icon | Deletes a custom rule object belonging to the current admin domain. |
To view or edit a rule object | Double-click the rule object belonging to the current admin domain. |
The following table lists the available rule objects and the corresponding icons.
Icon | Rule Object |
|---|---|
![]() | IPv4 Endpoint |
![]() | IPv6 Endpoint |
![]() | IPv4 Address Range |
![]() | IPv6 Address Range |
![]() | Network Group for ignore rule |
![]() | IPv4 Network |
![]() | IPv6 Network |
Note
IPv6 Address Range and Network Group for Ignore Rule are two new types of rule objects that are only applicable to ignore rules.
By default, a Sensor inherits the rule object definitions from the domain that owns the Sensor (when the rule object is not customized at the Sensor level). If there is no customized definition present in this domain, the Sensor inherits the object definition from its parent domains in the hierarchy until a valid definition is found.
You can customize rule object definitions at the child domain level, only if the resources belong to the child domain. Such changes, made at the child domain level, will be visible in the parent admin domain level and can also be modified here.
If you delegate an interface (say G0/1) belonging to a Sensor to a child domain, all the rule objects assigned to that interface (through ignore rules) inherit their definition from the customization at the physical Sensor level. If there is no Sensor level definition, the specific rule object inherits its definition from the admin domain to which the Sensor belongs.
.png)
.png)
.png)
.png)
.png)
.png)
.png)