Interface subnet
Interface subnet address type enables an address object to be created automatically for the interface with which it is associated. Once created, the address object is updated when the interface IP/netmask changes on the associated interface.
To create the interface subnet address type object, create or edit an interface under Network > Interfaces, and enable the Create address object matching subnet option.
The Create address object matching subnet option is automatically enabled and displayed in the GUI when Role is set to LAN or DMZ. When you disable the Create address object matching subnet option, the feature is disabled, and the associated firewall address is deleted. |
To create an interface subnet:
-
Go to Network > Interfaces.
-
Select Create New > Interface or select existing interface and Edit.
-
Set Role to either LAN or DMZ.
-
Verify that Create address object matching subnet is available and automatically enabled.
-
Click OK.
The following is an example of how to configure an interface subnet firewall address on the CLI:
config firewall address edit "port1 address" set type interface-subnet set interface "port1" next end
Interface subnet addresses are automatically created when Role is set to LAN or DMZ in the Interface page, or you can manually configure interface subnet addresses in the CLI. You cannot choose Interface Subnet in the GUI when creating the address, but after the address is created, Interface Subnet displays in the GUI. However, all the settings are grayed out, except Name and Comments, which can be edited.
When Role is set to LAN or DMZ in the Interface page, the new address object displays on the Policy & Objects > Address page.
After the address is created, the subnet is dynamically assigned to the address object, which can be seen in both GUI and CLI. If the interface address changes, the subnet will update dynamically.
config firewall address edit "port1 address" set type interface-subnet set subnet 172.16.200.0 255.255.255.0 set interface "port1" next end