An easier way to input a large list of blocked IPs

Zyxel_James Posts: 630  Zyxel Employee
First Anniversary 10 Comments Friend Collector First Answer

If you want to block a large list of addresses to access your firewall, but don't want to create the address object one by one, we can do it by directly adjusting the configuration.

a. Download the startup-config.conf and open the .conf file with txt notebook
b. Find the configuration of address-object and object-group address
c. Add the IP address in this format:
address-object <object_address1> x.x.x.x
address-object <object_address2> y.y.y.y

d. Create an address group including the address objects.
object-group address <address_group_object_name>
address-object address name1
address-object address name2

e. Apply the address group object to the blocked security policy