<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Wildcard Address not supported in Address Groups? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ip-wildcard-address-not-supported-in-address-groups/m-p/532782#M109795</link>
    <description>&lt;P&gt;You can use a FQDN, IP address, or IP block in an Address Group, but not an IP Wildcard. The reason is that Address Objects and Groups must be resolvable to an IP or IP block. An IP Wildcard is kind of a special Address Object (selective IP masking) that breaks that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-addresses" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-addresses&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV&gt;IP Wildcard Mask&lt;/DIV&gt;
—Enter an IP wildcard address in the format of an IPv4 address followed by a slash and a mask (which must begin with a zero); for example, 10.182.1.1/0.127.248.0. In the wildcard mask, a zero (0) bit indicates that the bit being compared must match the bit in the IP address that is covered by the 0. A one (1) bit in the mask is a wildcard bit, meaning the bit being compared need not match the bit in the IP address that is covered by the 1. Convert the IP address and the wildcard mask to binary. To illustrate the matching: on binary snippet 0011, a wildcard mask of 1010 results in four matches (0001, 0011, 1001, and 1011).
&lt;DIV class="note " data-label="NOTE"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;&lt;STRONG&gt;You can use an address object of type IP Wildcard Mask only in a Security policy rule.&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 23:23:34 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2023-03-01T23:23:34Z</dc:date>
    <item>
      <title>IP Wildcard Address not supported in Address Groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-wildcard-address-not-supported-in-address-groups/m-p/532769#M109793</link>
      <description>&lt;P&gt;I am trying to make an address group that consist of wildcard addresses but I get this error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ext-mb-text"&gt; vpn30-wc -&amp;gt; static 'vpn30-v110-wc-1' is not a valid reference vpn30-wc -&amp;gt; static is invalid&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ext-mb-text"&gt;vpn30-v110-wc-1 is an IP Wildcard&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ext-mb-text"&gt;vpn30-wc is a new empty address group.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ext-mb-text"&gt;Is this not supported?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 22:15:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-wildcard-address-not-supported-in-address-groups/m-p/532769#M109793</guid>
      <dc:creator>BBartik</dc:creator>
      <dc:date>2023-03-01T22:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: IP Wildcard Address not supported in Address Groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-wildcard-address-not-supported-in-address-groups/m-p/532782#M109795</link>
      <description>&lt;P&gt;You can use a FQDN, IP address, or IP block in an Address Group, but not an IP Wildcard. The reason is that Address Objects and Groups must be resolvable to an IP or IP block. An IP Wildcard is kind of a special Address Object (selective IP masking) that breaks that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-addresses" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-addresses&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV&gt;IP Wildcard Mask&lt;/DIV&gt;
—Enter an IP wildcard address in the format of an IPv4 address followed by a slash and a mask (which must begin with a zero); for example, 10.182.1.1/0.127.248.0. In the wildcard mask, a zero (0) bit indicates that the bit being compared must match the bit in the IP address that is covered by the 0. A one (1) bit in the mask is a wildcard bit, meaning the bit being compared need not match the bit in the IP address that is covered by the 1. Convert the IP address and the wildcard mask to binary. To illustrate the matching: on binary snippet 0011, a wildcard mask of 1010 results in four matches (0001, 0011, 1001, and 1011).
&lt;DIV class="note " data-label="NOTE"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;&lt;STRONG&gt;You can use an address object of type IP Wildcard Mask only in a Security policy rule.&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 23:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-wildcard-address-not-supported-in-address-groups/m-p/532782#M109795</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-03-01T23:23:34Z</dc:date>
    </item>
  </channel>
</rss>

