- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-06-2012 08:35 AM
I'm trying to find more details about the differences between address groups and regions.
I added some regions to get a better reporting when I include src and dst countries.
Initially I made a mistake of naming a region the same as an existing address group. I couldn't delete it, got the error message that this object is used in a rule.
I know that in rules one can use regions also as src or dst, similar to an address group.
I imported some 100+ subnets and didn't check all of them in detail and after a commit I got an error message about subnets being already defined in other regions or overlapping subnets. Did only complain about that for the regions, not for the address groups ?
Is there a document available describing in more details the differences between these two object types?
Regards,
Andreas
09-06-2012 09:16 AM
Yes. The predefined regions we have contain the networks per the ARIN database.
09-06-2012 08:58 AM
Andreas,
Address groups let you to group a bunch of addresses to be part of a group - say all the networks used for Sales are in Sales address group and for Accounting can be part of Accounting address group. A overlap of networks in address groups is permitted as this is custom defined. When usign Regions, we are grouping the IPs that are allocated for a particular country and these networks cannot overlap with each other. Say you have 1.1.0.0/16 in CN(China), you cannot have 1.1.1.0/24 in CL(Chile).
From your description, looks like you have an overlapping subnet between 2 countries. Verify and make sure to not have any overlapping networks between the regions.
Thanks,
Sri
09-06-2012 09:06 AM
Hi Sri,
thanks for the fast answer.
So to summarize:
- the way one defines address groups and regions is slightly different, but in the end they both contain IP address ranges
- both can be used in security rules as src or dst
- regions are checked for overlapping addresses, adress groups not
Is my understanding correct?
Regards,
Andreas
09-06-2012 09:16 AM
Yes. The predefined regions we have contain the networks per the ARIN database.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!