Create an Address List
Create a list of IPv4 addresses, IPv6 addresses, or fully qualified domain names (FQDNs) you can use to build rules in a firewall policy.
You can specify individual IPv4 or IPv6 IP addresses, or use CIDR blocks in an IP address list. Each address is entered on its own line within the list.
- Publicly resolvable FQDNs are supported. Private FQDNs aren't supported.
- Regex support isn't available for FQDNs.
- FQDN based filtering is supported when the count of IP addresses that an FQDN can resolve is less than or equal to 32.
- Fast flux DNS names can return different IP addresses in rapid succession. The firewall and a client might therefore resolve the same FQDN to different IP addresses. A security rule that uses the FQDN address list might then fail to match the client's connection. See FQDN-based address filtering limitations for more information.
You can configure a maximum of 20,000 IP addresses (or CIDRs) and 2,000 FQDNs across all address lists within a policy. Each individual address list can hold up to 1,000 addresses, but the total IP addresses across all lists must not exceed 20,000, and the total FQDNs must not exceed 2,000. You can create up to 20,000 address lists, as long as you adhere to these specified address limits.
To import multiple address lists using a .json file, see Import Firewall Policy Components.
Use the network-firewall address-list create command and required parameters to create an address list:
oci network-firewall address-list create --network-firewall-policy-id network firewall policy OCID --compartment-id compartment OCID --total-addresses integer --addresses '["address_1", "address_2"]' [OPTIONS]For a complete list of parameters and values for CLI commands, see the CLI Command Reference.
Run the CreateAddressList operation to create an address list.