Object Groups
An Object Group is a group of Address groups and Service groups. Address groups are a collection of IP addresses, range of IP addresses and domain names. Service groups are a collection of ports, range of ports, service types, and codes. When you create business policies and firewall rules, you can define the rules for a range of IP addresses or a range of TCP/UDP/ICMPv4/ICMPv6 ports, by including the object groups in the rule definitions.
You can create Address groups to save the range of valid IP addresses and Service groups for the range of port numbers or service type and range of codes. You can simplify the policy management by creating object groups of specific types and reusing them in policies and rules.
- Manage policies easily.
- Modularize and reuse the policy components.
- Update all referenced business and firewall policies easily.
- Reduce the number of policies.
- Improve the policy debugging and readability.
- Maximum allowed number of object groups per Enterprise is 2000.
- Maximum allowed number of object group associations per Edge and its Profile is 1000.
Configure Object Groups
This section discusses how to configure Object Groups and Service Groups (formerly known as Port Groups).
For additional information on Object Groups, see Object Groups.
In the SD-WAN service of the Enterprise portal, to configure Object Groups, select .
The Object Groups screen appears. You can configure Address Group and Service Group from this screen.

Address Groups
- In the Address Groups tab, select Add. The Configure Address Group window appears.
Figure 2. Configure Address Group 
- Enter a Name and Description for the Address Group.
- Under IP Address Ranges, select +ADD and enter the range of IPv4 or IPv6 Addresses by selecting the Prefix or Mask options as: CIDR prefix, Subnet mask, or Wildcard Mask, as required.
- Under Domains, select +ADD and enter the domain names or FQDNs for the Address Group. The domain names defined in the Address Group can be used as a matching criteria for Business policies or Firewall rules.
Note: When configuring domains as match criteria for an Address Group, the SD-WAN service first checks for an IP address match. If a match is found, then the service skips domain name matching. However, if no match is found for an IP address, then the service performs a domain name match in the Address Group.Important: The matching criteria may match basic wildcard patterns. For example, if you configure a domain in an Address Group as google.com, then mail.google.com and/or http://www.google.com may also match this criteria. However, if you configure http://www.google.com as the domain in an Address Group, then mail.google.com will not match this policy.
- Select Save Changes.
Service Groups (Formerly known as Port Groups)
- In the Service Groups tab, select Add. The Configure Service Group window appears.
Figure 3. Configure Service Group 
- Enter a Name and Description for the Service Group.
- Under Service Ranges, select +ADD and add Service ranges with the protocol as TCP or UDP or ICMPv4 and ICMPv6, as required.
Note: For TCP and UDP, you must enter a single port number or port range from 0 through 65535. For ICMP and ICMPv6, you can optionally enter the Type and Code. The Type and Code value ranges from 0 through 254. The Code can be a single value or range.
- Select Save Changes.
Select the link to the Address or Service Group to modify the settings. To delete an Address or Service Group, select the check box before the group and select Delete.
Configure Business Policies with Object Group
While configuring business policies at Profile and Edge level, you can select the existing object groups to match the source or destination. You can define the rules for a range of IPv4 and IPv6 addresses or port numbers available in the object groups.
At the Profile level, to configure a business policy with Object Group, perform the following steps:

Configure Firewall Rule with Object Group
While configuring firewall rules at Profile and Edge level, you can select the existing object groups to match the source or destination. You can define the rules for a range of IP addresses or a range of TCP/UDP/ICMPv4/ICMPv6 ports, by including the object groups in the rule definitions.
At the Profile level, to configure Firewall Rule with Object Group, perform the following steps:



