Object Lookup

Object Lookup shows the rules and groups in which an object is used - across all devices, in a device branch (a selected device with its child devices), or in a single, selected device.

In large network environments, it is common to have objects on many network devices that represent the same network resource. It is important to make sure that all of these objects follow your naming convention, that their IP addresses are correct, and that they are used in the correct rules and groups.

Note: IPv6 is supported for this feature, as follows: You can search for IPv6 objects by object name and you can search for IPv6 addresses as text in source and destination.

The search results show all of the objects in the selected devices that match either:

  • Text in the name, IP address or comment fields - You can also search for exact matches (not case-sensitive) of the search text to narrow the results. By default, the results show all matching objects in all devices, but you can select one or more specific devices to search in.
  • Subnet defined by IP address and netmask - You can show the objects that contain the subnet that you enter, objects that are contained in the subnet that you enter, or objects that match the subnet exactly.

    For example:

    Subnet that contains - If you enter the subnet 10.10.10.0/24, the results include network objects such as 10.10.0.0/16 and 10.10.10.0/24. If you enter the subnet 10.10.10.1/32, the results include host objects that have the IP address 10.10.10.1.

    Contained in subnet - If you enter the subnet 10.10.0.0/16, the results include network objects such as 10.10.10.0/24 and hosts such as 10.10.10.1/32.

Icons in the Name column indicate the following:

Icon

Represents

   Host object / Global host object
   Subnet or range / Global subnet or range
   Group object / Global group object

After you search for objects, you can select an object from the search results and see the rules or groups where the object is used, either explicitly or as part of a group object. You can click Export to save the results to a PDF file.

In Analyze > Object Lookup, to search for an object and the rules and groups where the object is used:

  1. From the device tree, select either:

    1. All devices
    2. A parent device with its child devices
    3. A single device
  2. Select the Text or Subnet search and its parameters.

    • To search in all devices, enter the text or a subnet to search for in the search field and press Enter.
    • To search in specific devices, select the devices to search in from either the Vendors or Groups tree and enter the text or a subnet to search for in the search field and press Enter.

    For text, the parameters are: All, IP, Name, Comment

    For subnet, the parameters are:

    • Subnets that contain - Shows all networks that include the specified subnet, including the subnet itself even if it is a host.
    • Contained in subnet - Shows all objects that have an IP address in the subnet, including the subnet itself.
    • Exact match - Shows only objects that are defined with the specified subnet.
  3. Select an object from the list.

    The rules where the object is used are shown. By default, the list only includes rules where the object is used explicitly. You can also select Show rules with object and related groups to show rules that include groups that contain the selected object.

  4. Click Objects to see the groups that contain the selected object, and click on a group to see the other objects that are contained in the group.

How Do I Get Here?

In SecureTrack, go to Browser > Object Lookup