Symptom
On the GUI of the Secure Firewall Management Center (FMC), a search/filtering for a specific object group within a prefilter rule in a prefilter policy does not return the expected object group.
Searching for the same object group on the Object Management page of the FMC GUI (Objects > Object Management) does return the object group. Additionally, searches for the object group within rules of other policy types (for example, within access control or decryption policies) will return the object group.
Without a search/filter present, the object group of interest will appear on the list of objects and object groups, but one will need to manually scroll through the list to find it.
Conditions
The FMC runs software version 7.3.1.
The FMC has a larger number of objects and object groups of all kinds (e.g network, port, etc.) present.
The creation or editing of a rule within the prefilter policy, and then the use of a search/filter to find a specific object group for the purpose of selecting it to add as a condition to the rule.
The object group that was expected to be returned in the search/filter results contains a higher number of items directly within the group (the number will vary depending on the total number of objects and object groups configured on the FMC).
Workaround
1. Confirm that the object group of interest (one that will have a larger number of items within it; we will call it the "large group") can be found when searching for it under the respective object type on the Object Management page of the FMC GUI (Objects > Object Management), but that the same object group cannot be found when searching for it when editing a prefilter rule within a prefilter policy.
2. Create a new object group for the object type (for example, a new network object group). Add only the "large group" to the new object group. Give the new group a name. Optionally, add a note to the Description field of the new group that indicates that the group is intended for use with prefilter rules. Save the group.
3. Use the new object group (created in step 2) in the prefilter policy wherever the "large group" would otherwise be employed.
4. Deploy to the FTDs that make use of the prefilter policy (as configured in access control policies).
5. Continue to make modifications to the "large group" as needed.
Further Problem Description