Course menu

Module 2: Firewall PoliciesLesson 2.2 (2 of 5 in this module)7 of 18 in the FortiGate Administrator course

Addresses, services and schedules

Subnet, range, FQDN and geography addresses, groups, predefined and custom services, schedules and Internet Service objects.

Intermediate · 11 min read

What you will learn

After this lesson, you can create address, service and schedule objects and groups, choose the right address type, and know when an Internet Service object is better than an address.

  • Address objects
  • Service objects
  • Schedules
  • ISDB objects

Firewall objects are the named building blocks that FortiGate policies reference: addresses (who or where), services (which protocol and port), schedules (when) and Internet Service Database entries (well-known cloud services). Policies never contain raw IP addresses or ports; they point at objects, so one change to an object updates every policy that uses it.

In simple terms: Instead of typing addresses and ports into every rule, you give them names once and use the names everywhere.

A real-life situation

The web server in the DMZ moves from 10.0.2.10 to 10.0.2.20. On a firewall where every policy contains the raw address, someone must find and edit each one, and will miss one. On FGT1 every policy points at the object WEB1, so one edit to that object moves all of them.

Address objects

TypeExampleUse it for
Subnet10.0.1.0/24, or 10.0.2.10/32 for one hostMost internal networks and servers
IP range10.0.1.100–10.0.1.150Ranges that aren't a clean subnet
FQDNupdate.example.comExternal services whose IPs change
Geographya countryAllowing or blocking traffic by country
MAC addressa device's MACMatching a device regardless of its IP (same Layer 2 network only)
Dynamiccloud or SDN tagsAddresses learned from cloud platforms and connectors
config firewall address edit LAN-subnet set subnet 10.0.1.0 255.255.255.0 next edit WEB1 set subnet 10.0.2.10 255.255.255.255 set comment "DMZ web server" next edit Admin-PCs set type iprange set start-ip 10.0.1.20 set end-ip 10.0.1.29 next edit Vendor-Update set type fqdn set fqdn "update.example.com" next end config firewall addrgrp edit DMZ-Servers set member WEB1 next end

A /32 subnet is a single host. Groups can contain addresses and other groups; using a group in policies means adding a second server later is a one-line change.

Services

FortiOS ships with predefined services (HTTP, HTTPS, DNS, SSH, PING, ALL…). Create custom ones for anything else:

config firewall service custom edit TCP-8443 set tcp-portrange 8443 next edit App-Ports set tcp-portrange 9000-9010 set udp-portrange 5060 next end config firewall service group edit Web-Access set member HTTP HTTPS next end

A port range is low-high. One custom service can hold TCP and UDP ports together. A service matches the destination port; the source port is normally left as any.

Schedules

config firewall schedule recurring edit work-hours set day monday tuesday wednesday thursday friday set start 08:00 set end 18:00 next end

A policy with schedule work-hours only matches during that window; the predefined schedule always matches all the time. One-time schedules (config firewall schedule onetime) cover a date range, for example temporary access for a contractor.

Internet Service Database objects

Large cloud services use thousands of addresses that change constantly. Instead of maintaining them, a policy can use an Internet Service object as its destination, for example a Microsoft 365 or Google service. FortiGuard keeps the addresses and ports up to date, and the object supplies both, so the policy doesn't need its own list of addresses and services for that destination.

Why it works this way

Objects separate what a policy means ("the LAN may reach the web servers") from the details (which addresses those are today). The rule base stays readable, changes happen in one place, and the reference count shows exactly what a change will affect.

Common mistakes

  • Creating a new object for every policy instead of reusing one, until there are five objects for the same server.
  • Using ALL as the service when only HTTPS is needed.
  • Using FQDN objects for sites behind a CDN whose addresses differ for each client query.
  • Naming objects by IP (10.0.2.10) instead of by role (WEB1): the name stops making sense when the address changes.

Key takeaways

✅ Key takeaways
  • Policies reference objects, never raw addresses or ports; change the object, change every policy.
  • Address types: subnet, range, FQDN, geography, MAC, dynamic; groups combine them.
  • Services match protocol and destination port; schedules limit when a policy is active.
  • Internet Service objects let FortiGuard maintain cloud services' addresses for you.

Check yourself

Predict · scenario 1

Which address type fits a single server, 10.0.2.10?

Predict · scenario 2

A contractor needs access only from 1 to 14 March. What limits the policy to those dates?

Predict · scenario 3

Staff must reach Microsoft 365, whose addresses change often. What is the easiest destination to maintain?

FAQ

Why can't I delete an address object?
Because something still uses it: a policy, a group, a route or a VIP. The Ref. column in the GUI shows how many references it has, and clicking the number lists them. Remove the references first.
How does an FQDN address work if the site's IP changes?
The FortiGate resolves the name itself and refreshes the result regularly, updating the policy match. It works best when clients use the same DNS servers as the FortiGate, so both see the same addresses.