05-07-2020 11:16 AM
Can I get some clarification on what is considered an unused object?
For example is an Address or Service Object considered unused if it is not part of any rules if it is listed individually and that is it?
How about if the object is not listed individually in any rules, but it is part of an object group that is also not part of any rules?
And finally, how about if the object is not listed individually in any rules, but is part of an object group and that object group is in fact included in a rule?
Thanks for the clarification.
05-07-2020 11:53 AM
Hello BOkay,
Unused objects simply means address or service objects that's not being referenced in address group , service group , nat rules, and security rules. If the address object is member of address group object , it will shows as "used" regardless if address group object is being referenced in any of the security or nat rules.
05-07-2020 11:53 AM
Hello BOkay,
Unused objects simply means address or service objects that's not being referenced in address group , service group , nat rules, and security rules. If the address object is member of address group object , it will shows as "used" regardless if address group object is being referenced in any of the security or nat rules.
05-08-2020 12:09 AM
Let me correct one thing.
If an address object is solely being used in address groups but those address groups are not used, the address object is not user as well.
We do a recursion to see if the object is actually needed for the security policy in place, including security rules, NAT rules, custom application rules, interfaces, etc. whether directly consumed of indirectly consumed by groups the object belongs to.
01-24-2023 07:46 AM
What about objects with tags that are a part of a dynamic address group?
Does Expedition take hit counts into account? I noticed a shared object that is added to a rule that is targeted to numerous firewalls in our Panorama shows as unused. It's very possible the rule doesn't have hit counts but going by the explanation above, it is used.
01-24-2023 08:36 AM - edited 01-24-2023 08:36 AM
Hi @Alex_Kalbfell If the object is used in the dynamic objects , expedition would not know the reference , so it will show unused even it is tag and reference in the dynamic objects. If you have dynamic objects, please review them carefully.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!