TMS zl Management and Configuration Guide ST.1.0.090213
1-31
Overview
Named Objects
Named Objects
The TMS zl Module supports named objects for greater ease of configuration.
A named object is a logical “container” that can be used in firewall access
policies, NAT policies, port triggers, and IPsec policy traffic selectors to
represent one or more addresses, one or more services, or a schedule. The
advantage to using named objects is that you can create the object, then if the
parameters of the object change, you edit the object only once, and the change
takes effect in all of the policies that include the object.
You can create the following types of named objects:
■ Address objects (maximum 500), which are configured as follows:
• Single-entry address objects:
– IP—a single IP address
– Range—a single range of IP addresses
– Network—a single network IP address and subnet mask
• Multiple-entry address objects:
– IP—a list of up to 100 non-contiguous IP addresses
– Range—a list of up to 100 ranges of IP addresses
– Network—a list of up to 100 network IP addresses and subnet
masks
– Domain name—one DNS name or a list of up to 10 names, which
the TMS zl Module dynamically resolves provided that a DNS
server is specified.
■ Address groups (maximum 1000), which contain multiple address objects
■ Service objects (maximum 500):
• Protocol and single port—one Layer 4 protocol and a single port,
such as TCP 80
• Protocol and port range object—one Layer 4 protocol and a range
of ports, such as UDP 50000–50010
• IANA-assigned Internet protocol— one predefined Layer 3 proto-
col
■ Service groups (maximum 5000), which contain multiple service objects
■ Schedule objects (maximum 25), which specify the following:
• Days of the week—one or more days during the week, which begin
and end at midnight
• Time of day—the start and end times within the day