Objects

In an environment where you may have cloud-based managers such as AWS or GCP interacting with on-premises datacenters, it is crucial to be able to share objects within policies to protect your environment. Shared objects make it easy to maintain policies because you can modify an object in one place and that change affects all other policies that use that object. Without shared objects, you would need to modify all the policies individually that require the same change.

Multicloud Defense shows you a combined or "flattened" view of the elements of the object in the details pane. Notice that in the details pane, the network elements are flattened into a simple list and not directly associated with a named object.

Note that sharing objects is only supported when you deploy an access control policy that allows traffic from your cloud-based datacenter. Ensure that your policy includes, or excludes, instances or attributes from your third-party datacenter.

Multicloud Defense has the capability to communicate with either a datacenter or a cloud platform, ensuring your policies for security can be managed anywhere.

Static Objects

Static objects specifies unchanging IP addresses, subnets, or specific firewall rules to provide predictable and stable configurations which can be important for compliance and security purposes. In a cloud environment, this allows you to create and share objects that maintain the same IP address or FQDN within a hybrid environment.

If you choose to delete a shared object, Multicloud Defense deletes it only from its system. The object continues to exist within Security Cloud Control.

Dynamic Objects

In contrast, dynamic objects do not have to specify an IP address at all. Dynamic objects are adaptable configurations that automatically adjust to varying conditions or environments. They allow firewalls to respond to real-time events without requiring manual intervention.

You can also tag resources and use them as objects to create a more fine-tuned ruleset within your policy. This level of fleibiltity within a cloud environment allows the system to adjust for yoou based on real-time data and can result on reduced maintenance.

Sharing Objects with Security Cloud Control

Customers who provision Multicloud Defense after August 6, 2025 and want to use Object Sharing will need to contact Cisco Technical Assistance Center (Cisco TAC) to enable this feature.

When you share objects with Security Cloud Control they are automatically translated into network objects. This does not affect the original state of the object in Multicloud Defense.

To configure object sharing between Multicloud Defense and Security Cloud Control you must create a connector in Security Cloud Control and attach the connector to an applicable policy to enable this feature and then import objects to see them in the Multicloud Defense Controller. See About the Multicloud Defense Connector for more information.

If you happen to share dynamic objects there is the option to preserve the original values of the object by creating an override value. An object override allows you to override the value of a shared network object on specific devices. See Object Overrides for more information.


Note


Objects cannot be shared with Cloud-Delivered Firewall Management Center.


About the Multicloud Defense Connector

You can optionally send address objects from Cisco Multicloud Defense to the configured Cloud-Delivered Firewall Management Center using a Cisco Secure Dynamic Attributes Connector. A connector is responsible for gathering dynamic data (such as IP addresses) and streaming them to the Cloud-Delivered Firewall Management Center so they can be used in access control policies.

For more information about Multicloud Defense objects, see the Address Objects chapter and address object API documentation.

For more information about the Multicloud Defense Connector, see the Managing Firewall Threat Defense with Cloud-delivered Firewall Management Center in Security Cloud Control.

Import Objects From Security Cloud Control


Note


You do not have to enable dynamic sharing in the Security Cloud Control dashboard to import objects to Multicloud Defense.


Use the following procedure to manually import Security Cloud Control objects into Multicloud Defense using the Multicloud Defense Controller dashboard:

Procedure


Step 1

Log into Security Cloud Control and in the left pane, click Multicloud Defense.

Step 2

Click Multicloud Defense Controller located in the upper right to cross-launch into the controller dashboard.

Step 3

Navigate to Policies > Security Policies > Addresses.

Step 4

Click Import Objects.

Step 5

From the pop-up window of Security Cloud Control objects, scroll or use the search bar to locate an individual object.

Note: Objects with names that contain "." are not supported by Multicloud Defense at this time. Attempting to share or import objects with periods in their name results in an error message.

Step 6

Select the object so it is highlighted and click Import. You can click Cancel at any point to back out of the action.


What to do next

Allow a few minutes for Multicloud Defense to communicate with Security Cloud Control and synchronize the object you imported. From the Security Cloud Control dashboard you will be able to see an updated shared object count in the "Multicloud Defense Shared Object" widget.