<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between Address groups and regions ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45475#M33426</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andreas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address groups let you to group a bunch of addresses to be part of a group - say all the networks used for Sales are in Sales address group and for Accounting can be part of Accounting address group. A overlap of networks in address groups is permitted as this is custom defined. When usign Regions, we are grouping the IPs that are allocated for a particular country and these networks cannot overlap with each other. Say you have 1.1.0.0/16 in CN(China), you cannot have 1.1.1.0/24 in CL(Chile). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your description, looks like you have an overlapping subnet between 2 countries. Verify and make sure to not have any overlapping networks between the regions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Sep 2012 15:58:03 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2012-09-06T15:58:03Z</dc:date>
    <item>
      <title>Difference between Address groups and regions ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45474#M33425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to find more details about the differences between address groups and regions.&lt;/P&gt;&lt;P&gt;I added some regions to get a better reporting when I include src and dst countries.&lt;/P&gt;&lt;P&gt;Initially I made a mistake of naming a region the same as an existing address group. I couldn't delete it, got the error message that this object is used in a rule.&lt;/P&gt;&lt;P&gt;I know that in rules one can use regions also as src or dst, similar to an address group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imported some 100+ subnets and didn't check all of them in detail and after a commit I got an error message about subnets being already defined in other regions or overlapping subnets. Did only complain about that for the regions, not for the address groups ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a document available describing in more details the differences between these two object types?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 15:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45474#M33425</guid>
      <dc:creator>AndreasB</dc:creator>
      <dc:date>2012-09-06T15:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between Address groups and regions ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45475#M33426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andreas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address groups let you to group a bunch of addresses to be part of a group - say all the networks used for Sales are in Sales address group and for Accounting can be part of Accounting address group. A overlap of networks in address groups is permitted as this is custom defined. When usign Regions, we are grouping the IPs that are allocated for a particular country and these networks cannot overlap with each other. Say you have 1.1.0.0/16 in CN(China), you cannot have 1.1.1.0/24 in CL(Chile). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your description, looks like you have an overlapping subnet between 2 countries. Verify and make sure to not have any overlapping networks between the regions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 15:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45475#M33426</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-09-06T15:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between Address groups and regions ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45476#M33427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the fast answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to summarize:&lt;/P&gt;&lt;P&gt;- the way one defines address groups and regions is slightly different, but in the end they both contain IP address ranges&lt;/P&gt;&lt;P&gt;- both can be used in security rules as src or dst&lt;/P&gt;&lt;P&gt;- regions are checked for overlapping addresses, adress groups not&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my understanding correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Andreas&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 16:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45476#M33427</guid>
      <dc:creator>AndreasB</dc:creator>
      <dc:date>2012-09-06T16:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between Address groups and regions ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45477#M33428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. The predefined regions we have contain the networks per the ARIN database. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 16:16:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difference-between-address-groups-and-regions/m-p/45477#M33428</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-09-06T16:16:02Z</dc:date>
    </item>
  </channel>
</rss>

