Object Groups
An Object Group is a group of Address groups and Service groups. Address groups are a collection of IP addresses, range of IP addresses and domain names. Service groups are a collection of ports, range of ports, service types, and codes. When you create business policies and firewall rules, you can define the rules for a range of IP addresses or a range of TCP/UDP/ICMPv4/ICMPv6 ports, by including the object groups in the rule definitions.
You can create Address groups to save the range of valid IP addresses and Service groups for the range of port numbers or service type and range of codes. You can simplify the policy management by creating object groups of specific types and reusing them in policies and rules.
- Manage policies easily
- Modularize and reuse the policy components
- Update all referenced business and firewall policies easily
- Reduce the number of policies
- Improve the policy debugging and readability
NETWORK_SERVICE object. You can only view the object groups if you have Read permission on NETWORK_SERVICE and ENTERPRISE_PROFILE objects.Configure Object Groups
This section discusses how to configure Object Groups and Service Groups (formerly known as Port Groups).
For additional information on Object Groups, see Object Groups.
In the SD-WAN service of the Enterprise portal, to configure Object Groups, select .
The Object Groups screen appears. You can configure Address Group and Service Group from this screen.

Address Groups
To create and configure Address Groups, perform the following steps:
Service Groups (Formerly known as Port Groups)
Configure Business Policies with Object Group
While configuring business policies at Profile and Edge level, you can select the existing object groups to match the source or destination. You can define the rules for a range of IPv4 and IPv6 addresses or port numbers available in the object groups.
At the Profile level, to configure a business policy with Object Group, perform the following steps:

Configure Firewall Rule with Object Group
While configuring firewall rules at Profile and Edge level, you can select the existing object groups to match the source or destination. You can define the rules for a range of IP addresses or a range of TCP/UDP/ICMPv4/ICMPv6 ports, by including the object groups in the rule definitions.
At the Profile level, to configure Firewall Rule with Object Group, perform the following steps:






