Network wildcard masks

A network wildcard mask is an IP address mask that

  • uses a discontinuous mask of bits to define network objects,

  • enables you to create network objects with expanded subnet IP addresses, and

  • appears as Network Wildcard in the Type column of the network object list.

Network wildcard mask usage and support

You can create and manage wildcard mask objects from the Network Wildcard Mask page in Objects .

Standard network objects use contiguous masks, while wildcard network objects use discontinuous masks.

This table shows examples of IP addresses and indicates whether they are considered network wildcard objects:

Network wildcard mask examples

Example IP address

Network wildcard?

Object type

192.0.0.0/8

No

Network

10.10.0.0/255.255.0.0

No

Network

10.10.0.10/255.255.0.255

Yes

Network Wildcard

72.0.240.10/255.255.240.255

Yes

Network Wildcard

Note

Network wildcard objects and groups containing network wildcard objects are allowed only when configuring these policies:

  • Prefilter policy

  • Access control policy

  • NAT policy

Guidelines and limitations

  • To create network wildcard objects, in the Cloud-Delivered Firewall Management Center UI, choose Objects > Network and click Add Network and then Add Object. Select the Network option and enter the value as expanded subnet mask fotmat, such as 10.0.10.10 or 255.255.0.255.

  • Features supported: Object override, group object support, group object override, wildcard literals, and wildcard object import.

  • Network wildcard objects are supported only for IPv4 addresses.

  • Network wildcard objects are supported from Cloud-Delivered Firewall Management Center and Firewall Threat Defense versions 7.1 onwards.

  • Network wildcard objects are supported only for Snort-3.