In Forti-OS, you can add single IP Addresses (IPv4 or IPv6), and then create groups of these IP addresses. This is required for use in your Firewall policy.
Creating Addresses
In order to proceed with the below instructions, you will need to have access and be logged into your Fortigate Firewall.
1. Start by clicking 'Policy & Objects', followed by 'Addresses' and then 'Create New' to create a new address:
Once you're on the new address page, complete the form shown with the applicable information you'd like to enter:
| Name | Give a description of what the address is. |
| Interface | Choose if this address is to be limited to any specific interface. |
| Type | ![]() There are a few types you can set for the address. In this example we're using the 'Subnet' option. Choose the type that is right for you. |
| IP / Netmask | This can be in two different formats. "IP/CIDR" and "IP space NETMASK" for example 221.121.134.123/32 or 221.121.134.123 255.255.255.254 |
| Static Route Configuration | Tick the box if this is for a Static Route |
| Comments | Any comments you feel are required can be entered here |
Click OK once done. You can now use this address in a firewall policy, or in an address group.
Creating Address Groups
In order to proceed with the below instructions, you will need to have access and be logged into your Fortigate Firewall.
1. Start by clicking 'Policy & Objects', followed by 'Addresses' and then going to the 'Address Group' tab, we can 'Create New' to create a new address:

2. Once you're on the new address page, complete the form shown with the applicable information you'd like to enter:
| Category | Choose if this group is IPv4 or IPv6 addresses. |
| Name | Give a description of what the address is. |
| Type | You can make a group of addresses, or a folder to contain them |
| Members | Click the + button and then choose all the entries to add to the group. |
| Exclude Members | You can add exclusions to the group manually here. |
| Static Route Configuration | Allow the group to be used in a static route. |
| Comment | Any comments you feel are required can be entered here |
