A real-life situation
The web server in the DMZ moves from 10.0.2.10 to 10.0.2.20. On a firewall where every policy contains the raw address, someone must find and edit each one, and will miss one. On FGT1 every policy points at the object WEB1, so one edit to that object moves all of them.
Address objects
| Type | Example | Use it for |
|---|---|---|
| Subnet | 10.0.1.0/24, or 10.0.2.10/32 for one host | Most internal networks and servers |
| IP range | 10.0.1.100–10.0.1.150 | Ranges that aren't a clean subnet |
| FQDN | update.example.com | External services whose IPs change |
| Geography | a country | Allowing or blocking traffic by country |
| MAC address | a device's MAC | Matching a device regardless of its IP (same Layer 2 network only) |
| Dynamic | cloud or SDN tags | Addresses learned from cloud platforms and connectors |
config firewall address
edit LAN-subnet
set subnet 10.0.1.0 255.255.255.0
next
edit WEB1
set subnet 10.0.2.10 255.255.255.255
set comment "DMZ web server"
next
edit Admin-PCs
set type iprange
set start-ip 10.0.1.20
set end-ip 10.0.1.29
next
edit Vendor-Update
set type fqdn
set fqdn "update.example.com"
next
end
config firewall addrgrp
edit DMZ-Servers
set member WEB1
next
endA /32 subnet is a single host. Groups can contain addresses and other groups; using a group in policies means adding a second server later is a one-line change.
Services
FortiOS ships with predefined services (HTTP, HTTPS, DNS, SSH, PING, ALL…). Create custom ones for anything else:
config firewall service custom
edit TCP-8443
set tcp-portrange 8443
next
edit App-Ports
set tcp-portrange 9000-9010
set udp-portrange 5060
next
end
config firewall service group
edit Web-Access
set member HTTP HTTPS
next
endA port range is low-high. One custom service can hold TCP and UDP ports together. A service matches the destination port; the source port is normally left as any.
Schedules
config firewall schedule recurring
edit work-hours
set day monday tuesday wednesday thursday friday
set start 08:00
set end 18:00
next
endA policy with schedule work-hours only matches during that window; the predefined schedule always matches all the time. One-time schedules (config firewall schedule onetime) cover a date range, for example temporary access for a contractor.
Internet Service Database objects
Large cloud services use thousands of addresses that change constantly. Instead of maintaining them, a policy can use an Internet Service object as its destination, for example a Microsoft 365 or Google service. FortiGuard keeps the addresses and ports up to date, and the object supplies both, so the policy doesn't need its own list of addresses and services for that destination.
Why it works this way
Objects separate what a policy means ("the LAN may reach the web servers") from the details (which addresses those are today). The rule base stays readable, changes happen in one place, and the reference count shows exactly what a change will affect.
Common mistakes
- Creating a new object for every policy instead of reusing one, until there are five objects for the same server.
- Using
ALLas the service when only HTTPS is needed. - Using FQDN objects for sites behind a CDN whose addresses differ for each client query.
- Naming objects by IP (
10.0.2.10) instead of by role (WEB1): the name stops making sense when the address changes.
Key takeaways
- Policies reference objects, never raw addresses or ports; change the object, change every policy.
- Address types: subnet, range, FQDN, geography, MAC, dynamic; groups combine them.
- Services match protocol and destination port; schedules limit when a policy is active.
- Internet Service objects let FortiGuard maintain cloud services' addresses for you.
Check yourself
Which address type fits a single server, 10.0.2.10?
A contractor needs access only from 1 to 14 March. What limits the policy to those dates?
Staff must reach Microsoft 365, whose addresses change often. What is the easiest destination to maintain?