Cisco Security Cloud Control: Secure Firewall Management

PDF

Cisco Security Cloud Control: Secure Firewall Management

Geolocation objects

Want to summarize with AI?

Log in

An overview of geolocation objects, including translated addresses, rule behavior, interface scope, and policy impact.


A geolocation object defines countries and continents that host the device that is the source or destination of traffic. You can use these objects in policies to control traffic instead of using IP addresses. For example, using geographical location, you could easily restrict access to a particular country without needing to know all of the potential IP addresses used there.

You can usually select geographical locations directly in a policy without using geolocation objects. Use an object when several policies need the same countries or continents.

Update the geolocation database

To use current geographical location data to filter traffic, Cisco recommends that you regularly update the geolocation database (GeoDB). You cannot update the GeoDB in Security Cloud Control. Refer to the following sections of the Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager for the version your device is running to learn more about the GeoDB and how to update it.

  • Updating System Databases and Feeds

  • Updating System Databases


Create and Edit a Firepower Geolocation Filter Object

You can create a geolocation object by itself on the object page or when creating a security policy. This procedure creates a geolocation object from the object page.

To create a geolocation object, follow these steps:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click > FTD > Geolocation.

4.

Enter an object name for the object and optionally, a description.

5.

In the filter bar, start typing the name of a country or a region and you are presented with a list of possible matches.

6.

Check the country, countries, or regions that you want to add to the object.

7.

Click Add.


Edit a Geolocation Object

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, choose Objects.

3.

Use the filter panes and search field to locate your object.

4.

In the Actions pane, click Edit.

5.

You can change the name of the object and add or remove countries and regions to your object.

6.

Click Save.

7.

You will be notified if any devices are impacted. Click Confirm.

8.

If a device or policy was impacted, open the Security Devices page and Preview and Deploy the changes to the device.