Export a network object by navigating to Objects, selecting your object, and using the export option in the menu

To export a network object from Cisco Firewall Management Center (FMC), you open the Objects section, find the network object you want to export, and use the built-in export function. The exported file saves as an XML document that you can move to another FMC instance, share with your team, or back up for safekeeping. The process takes about two minutes and requires only that you have read access to the object.

Network objects in FMC are reusable definitions — IP addresses, subnets, address ranges, or groups of addresses — that you reference in access control policies and other rules. Exporting them lets you duplicate your network definitions across multiple FMC instances without manually re-entering each one, or preserve them before a system change.

Key Takeaways

  • Network objects export as XML files that contain only the object definition, not the policies that reference it.
  • You must have read access to the object and write access to the destination folder to export successfully.
  • Exported objects can be imported into another FMC instance, but you will need to re-link them to policies manually.
  • The export function is located in the object's context menu, not in a separate export tool.

Open the Objects section and locate your network object

Log into your FMC instance with an account that has at least read permissions. In the top navigation menu, click Objects. A dropdown menu appears with several object types: Network, Port, URL, DNS, and others. Click Network Objects to see the full list of network objects in your system.

The Network Objects page displays all objects you have created or imported. Use the search bar at the top of the list to find the specific object you want to export. Type the object name or part of it, and the list filters in real time. Once you locate the object, note its exact name — you will need to select it in the next step.

Right-click the object and select the export option

Find your network object in the list and right-click directly on its name. A context menu appears with several options. Look for Export in this menu and click it. If you do not see an Export option, verify that your user account has read access to the object. Objects you created yourself always have the necessary permissions.

After you click Export, FMC prepares the object for download. A dialog box may appear asking you to confirm the export or choose a destination folder on your computer. The default location is usually your Downloads folder. Accept the default or navigate to a folder where you want to store the XML file, then click the button to complete the download.

Verify the exported file and check its contents

Once the download finishes, open your file manager and navigate to the folder where the file was saved. The exported file has a name like NetworkObject_[ObjectName].xml or similar, depending on your FMC version. Right-click the file and open it with a text editor such as Notepad, Notepad++, or VS Code to verify its contents.

The XML file contains the object definition: its name, description, IP address or subnet, and any tags or comments you added. It does not include policies that reference the object, access control lists, or any configuration outside the object itself. This is normal and expected. If the file is empty or contains only XML headers, the export may have failed — try the process again or contact your FMC administrator.

Import the exported object into another FMC instance

To use the exported object in a different FMC system, log into that instance and navigate to Objects > Network Objects. Look for an Import button or option, usually located near the top of the page or in a menu. Click it and select the XML file you exported from the first FMC instance.

FMC imports the object with the same name and configuration as the original. If an object with that name already exists in the destination FMC, the system will either skip the import or ask you to rename it — the behavior depends on your FMC version. After import, the object appears in your Network Objects list and is ready to use in policies. You will need to manually add it to any access control rules or other policies where you want it to apply.

Troubleshoot common export problems

If the Export option does not appear in the context menu, you may not have read access to the object. Contact your FMC administrator and ask them to grant you read permissions on that specific object, or ask them to perform the export on your behalf. Permissions are assigned at the object level, so you may have access to some objects but not others.

If the exported file is very small (less than 1 kilobyte) or contains only XML structure with no data, the export may have been incomplete. Delete the file and try exporting again. If the problem persists, check that the object itself is not corrupted by editing it in FMC — open the object, verify its settings are correct, save it, and then attempt the export once more.

If you are importing into another FMC and the import fails, verify that the XML file is not corrupted by opening it in a text editor and checking that it contains valid XML syntax (opening and closing tags, proper nesting). If the file looks correct but the import still fails, the two FMC instances may be running different software versions. Check that both systems are running compatible versions of FMC, or contact Cisco support for version-specific guidance.

Back up network objects regularly

Exporting network objects is a simple way to create backups before you make major changes to your FMC configuration. If you have many objects to export, you can select multiple objects at once — most FMC versions allow you to check a box next to each object name and then use a bulk export option. This saves time compared to exporting objects one at a time.

Store exported XML files in a version-controlled system or cloud storage so you can track changes over time and recover a previous version if needed. Label each export with the date and the FMC instance it came from, so you know which file belongs to which system. This practice is especially useful if you manage multiple FMC instances across different locations or departments.

Frequently Asked Questions

Can I export a group of network objects at once?

Most versions of FMC allow you to select multiple objects by checking the box next to each name, then use a bulk export option from a menu or toolbar button. This is faster than exporting one object at a time. Check your FMC version's documentation to confirm whether bulk export is available in your release.

Will the exported object include the policies that use it?

No. The exported XML file contains only the object definition — its name, IP address, subnet, and metadata. Policies that reference the object are not included. You must manually add the imported object to policies in the destination FMC instance.

What happens if I import an object with a name that already exists?

FMC will either skip the import or prompt you to rename the object, depending on your version. If prompted, you can give it a new name or cancel the import. Check your FMC version's behavior before importing to avoid surprises.

Can I edit the XML file before importing it?

Yes, you can open the XML file in a text editor and change the object name, description, or IP address before importing. Make sure you maintain valid XML syntax — if you introduce errors, the import will fail. Only edit the file if you are comfortable with XML structure.

Do I need special permissions to export a network object?

You need at least read access to the object. If you created the object yourself, you have the necessary permissions. If another administrator created it, ask them to grant you read access, or ask them to perform the export for you.