Views:

You can use predefined interface objects or interface groups as a source when defining policy rules.

Cloud Edge includes physical interface (including wireless interfaces in Routing Mode), and virtual interfaces such as VLANS and VPNs (L2TP and SSL) in the list of predefined interface objects. Optionally, you can define custom interface groups that contain one or more of the predefined interfaces.

Important:

You can select interface objects as a source when you have selected only a single Cloud Edge 50G2 gateway running Cloud Edge 6.0 or later in the Gateway Devices section.

If you select a standard gateway running Cloud Edge 5.x or earlier or a gateway group containing a standard gateway, Any-to-Any is preselected in the Interface Objects section, and this selection cannot be changed.

Table 1. Types of interfaces supported as Interface Objects

Interface Type

Name

Interface Type

Port Name

Supported

Physical

WAN

Physical

eth0

YES

LAN1

Physical

eth1

YES

LAN2

Physical

eth2

YES

LAN3

Physical

eth3

YES

MGMT

Physical

eth4

NO

WLAN0

Wi-Fi

wlan0

Yes in Router Mode

WLAN1

Wi-Fi

wlan1

Yes in Router Mode

Virtual

$name

L3 VLAN

$name$ID

Examples:

  • eth2.$ID

  • eth3.$ID

YES in Router Mode

User inputs name.

Interface exists when user adds a VLAN; does not exist when user deletes the VLAN.

L2TP VPN

YES in Router Mode

Always exists even if user disables L2TP VPN.

SSL VPN

YES in Router Mode

Always exists even if user disables SSL VPN.

Site–to–Site VPN

NO

Note:

Interfaces contained within object groups might be deleted if you replace the gateway, do a factory reset, or switch modes between Routing Mode and Bridge Mode.

  • If some interfaces are deleted by the user, the interfaces will continue to exist in related object groups and related policies in the back end.
  • Users cannot see the deleted interfaces on the user interface, but they will be deployed to gateways. Gateways will ignore these non-existent interfaces.
  • When a user edits and saves policy rules or interface groups again from Cloud Edge Cloud Console, the interfaces will disappear in related object groups and related policies in the back end.