I couldn't find a definitive answer to a question regarding the discovery of unused address objects found by Expedition. According to the manuals, unused address objects are those not referenced in a security or nat rule. However, an address object may be contained within an address group object and that group referenced in a security rule. By this definition, an address object is referenced by a rule indirectly. This would also apply to services and custom applications.
Before I go and whack a whole bunch address objects that aren't directly in rules, but in groups instead, would someone provide some clarity on exactly how the address objects are determined to be unused.
The process originally did only check Security and NAT rulebases, however it has been expanded to support the full rulebase, and includes address-group objects. The only caviat that still exists is, I believe, the limitation that an address-group that lists other address-groups does not take into account the addresses that make up the nested address-group objects (address-groups composed of address-groups).
Just to confirm... if an IP object belongs to a IP object group, and the IP object is not explicitly used in the ruleset, upon looking at unused objects within Expedition, that the IP object is still considered used as it belongs to a group that is used in a ruleset? Furthermore, an IP object that belongs to a group in which the group is not referenced in a rule, that the IP address object is also considered unused (unless of course the IP object itself belongs to a group that is referenced in a rule). This situation was not expressly answered in the any of the answers.
What if I want to show all unused objects which are not really being used by any of the device-group? Because I saw some red ones (unused) but when I look at the Panorama and did Global find I did saw the object being used in other device-group. Like for example if the object is shared and you are looking at specific device-group in expedition it will show you that the object is unused when in fact is it used by other device-group.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!