Create NOG/SOG Using Standard Naming

Summary

Provide a naming standard for the creation of Network Object Groups (NOG) and Service Object Groups (SOG) in support the Palo Alto firewalls.

Body

All NOGs/SOGs shall follow the below guidelines to allow for ease of management and troubleshooting:

"HSIT- " should be used as the prefix for all of our custom NOGs and SOGs. There are some exceptions such as predefined services such as Windows Files Services, SSH and etc. Note: SSL VPN VLAN are named via the interface and consist of RC code and CDS group name.

The format should be, HSIT-PROD or TEST/DEV-<descriptor>-<clients/services/managers/etc>.

For example:

HSIT-SQLCLUSTER-PORTS

HSIT-VEEAM-BACKUP-PORTS

HSIT-ITARGET-DEVELOPER-DESKTOPS

HSIT-PROD-SQL-SERVERS

HSIT-TEST/DEV-SQL-SERVERS

HSIT-PROD-WEB-FRONT-END-SERVERS-TO-SQL-SERVERS

HSIT-TEST/DEV-WEB-FRONT-END-SERVERS-TO-SQL-SERVERS

NOTE:
CSSD security has informed us that with the migration to Palo Alto we no longer require adding locations to our NOG/SOGs

Details

Details

Article ID: 3740
Created
Mon 6/29/26 3:13 PM
Modified
Wed 9/16/26 8:07 AM