You can reference a predefined region in a policy directly without modification, unless the IP address information in predefined regions is not up-to-date.
Mismatch between regions and IP addresses can be identified during fault location. For example, you have configured a security policy allowing region A to access the enterprise server, but a PC in region A cannot access the server. The PC IP address may be added to another region that is not allowed to access the intranet. In this case, you can add the IP address to region A.
Add an IP address to a predefined region.
Run the geo-location pre-defined geo-location-name command to access the predefined region view.
Run the add address { ip-address mask { mask-address | mask-length } | range start-ip-address end-ip-address } command to add an IP address.
If the IP address you are adding to a predefined region has been added to a user-defined region or predefined region, the addition takes effect and the IP address is removed from the predefined or user-defined region to which the IP address belonged.
Exclude an IP address from a predefined region.
You can exclude a predefined IP address from a predefined region by adding it to another predefined region. The undo add address command does not delete the predefined IP address from the predefined region. If you know the region of the IP address, you can add the IP address to the region. If not, you can add the IP address to region unknown-zone.
For example, if you find an IP address belonging to region B is in region A, you can add the IP address to region B. If you do not know which region the IP address belongs to, add it to region unknown-zone.
You can add an IP address to region unknown-zone as follows:
Run the geo-location unknown-zone command to access the unknown zone view.
Run the add address { ip-address mask { mask-address | mask-length } | range start-ip-address end-ip-address } command to add an IP address.