pjhtech Tools
Configuration & sysadmin

FortiGate Bulk Address Object Generator

Generate FortiOS address objects from IPv4 lists or name,cidr CSV, preview the batch, and copy or download the CLI configuration.

Input

UTF-8 · name,cidr header · maximum 200,000 bytes. Reading a file selects CSV mode and replaces the text above.

Reset restores the example inputs.

Local calculation · inputs are not sent to a server.

Result

Calculating the example…

Object preview

LineObject nameCanonical CIDRSubnet mask

Paste IPv4 hosts or CIDRs, optionally with name= before each entry, or choose CSV and supply name,cidr rows. Select Generate, check the Object preview, then use Copy result or Save text file for the CLI configuration.

Example: branch-lan=192.0.2.19/24 creates branch-lan for 192.0.2.0 with mask 255.255.255.0. A bare 198.51.100.9 creates NET_198_51_100_9_P32 with mask 255.255.255.255. Selecting an optional group adds those generated object names as members.

Use new names: edit can reopen an existing firewall object, and set member replaces an existing group’s membership. Apply the reviewed snippet in the intended VDOM. The output uses FortiOS 7.6.6 syntax; IPv6, FQDNs, address ranges and comments are not accepted.

Line input and CSV files

Line mode accepts one IPv4 host or CIDR per line, optionally prefixed with name=.

CSV mode requires a UTF-8 file with the exact header name,cidr; leave a name cell empty to use a generated name. Quoted CSV fields and CRLF line endings are accepted. Embedded newlines inside a CSV field are rejected. Blank lines are ignored; diagnostics use physical line numbers.

name,cidr
branch-lan,192.0.2.19/24
,198.51.100.9

Expected CLI for those two rows

config firewall address
    edit "branch-lan"
        set type ipmask
        set subnet 192.0.2.0 255.255.255.0
    next
    edit "NET_198_51_100_9_P32"
        set type ipmask
        set subnet 198.51.100.9 255.255.255.255
    next
end

Fix a rejected row or name conflict

For a reported line error, correct that physical line in the text or CSV and generate again. If one name is assigned to two different networks, give one row a different name or correct its CIDR. A group name must also differ from every generated object name.

Duplicates, names and batch limits

The same name and normalized CIDR are emitted once. Reusing a name for another network is an error. Different explicit names for the same network are retained and flagged, because other configuration may refer to either name. Host-bit normalization is always reported. A group cannot share a generated address-object name.

This helper accepts 1–63 ASCII letters, digits, dots, underscores or hyphens in names, beginning with a letter or digit. That is a deliberately restricted subset of FortiOS naming support. Quotes, whitespace and command separators are rejected, not pasted into CLI.

Up to 2,048 data rows and 200,000 characters are accepted; file size is limited to 200,000 bytes. Optional groups are limited by this helper to 256 members; actual device limits may differ.

Compare planned and existing network lists before preparing objects. For groups of objects already on the firewall, use the address group generator.

References