> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Creating Groups for Distributed Cloud Firewall

> A Distributed Cloud Firewall (DCF) SmartGroup contains one or more filters to identify cloud endpoints that map to an app domain. A filter specifies resource matching criteria.

## SmartGroups

A Distributed Cloud Firewall (DCF) SmartGroup contains one or more filters to
identify cloud endpoints that map to an app domain. A filter specifies resource
matching criteria. Matching criteria could be a cloud tag; a resource attribute
(such as account name or region); a list of IP prefixes; or a Site2Cloud
external connection. All conditions within the filter must be satisfied to be
matched. A tag or resource attribute-based filter must be associated with a
resource type (VPC/VNet, subnet, or VM).

<a href={"/docs/enterprise/" + "10.1" + "/reference/ui/groups/index#create-smartgroup"}>Creating SmartGroups</a>

## WebGroups

A DCF WebGroup contains one or more domain names or URLs that assists in
filtering (and providing security to) Internet-bound traffic.

<a href={"/docs/enterprise/" + "10.1" + "/reference/ui/groups/index#create-web-group"}>Creating WebGroups</a>

## ExternalGroups

An ExternalGroup can contain countries, threat feeds, and SaaS-based services
(Azure and GitHub).

<a href={"/docs/enterprise/" + "10.1" + "/reference/ui/groups/index#create-external-group"}>Managing the Relationship Between Feeds and ExternalGroups</a>

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/dcf/dcf-disable-feature"}>Disabling the Distributed Cloud Firewall Feature</a>
* [Creating Distributed Cloud Firewall Rules](https://legacy.docs.aviatrix.com/documentation/latest/security/dcf-create-rules.html)
