<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can mix, I thought you in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090226#M283545</link>
    <description>&lt;P&gt;You can mix, I thought you wanted to replace an existing ACE with object-group. Sorry for the confusion.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2017 14:16:20 GMT</pubDate>
    <dc:creator>cofee</dc:creator>
    <dc:date>2017-08-09T14:16:20Z</dc:date>
    <item>
      <title>Add object-group in existing ACL</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090220#M283539</link>
      <description>&lt;P&gt;I have an existing ACL that is not built using object groups but would like to create a network object group with a list of networks and add it to this ACL.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Will this work or do I need to completely rebuild the ACL using groups for all services and hosts/networks?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 16:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090220#M283539</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2019-03-05T16:58:57Z</dc:date>
    </item>
    <item>
      <title>If existing acl is not using</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090221#M283540</link>
      <description>&lt;P&gt;If existing acl is not using any object-group or objects then I don't think it's possible. But you can create a new ACL using object groups for the target nodes and services and place it on top of the existing ACL using line/sequence numbers. Once you verify that new&amp;nbsp;ACL is being used by looking at hit counters and old ACL is not getting any hit counters ( just to be on the safe side) you can remove the old ACL.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 12:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090221#M283540</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2017-08-09T12:59:58Z</dc:date>
    </item>
    <item>
      <title>So you can't mix regular</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090222#M283541</link>
      <description>&lt;P&gt;So you can't mix regular statements and group statements in a single ACL?&amp;nbsp; Looking at the documentation, there doesn't seem to be any difference in the way the ACL is created. It's just a regular extended ACL.&lt;/P&gt;
&lt;P&gt;Does something about it change once a group object has been added into it so that standard statements no longer work or vice versa?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090222#M283541</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2017-08-09T13:07:08Z</dc:date>
    </item>
    <item>
      <title>I believe as long as your</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090223#M283542</link>
      <description>&lt;P&gt;I believe as long as your current access list is an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;extended&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;one you can add entries to it using object groups if you wish. As long as your IOS supports object-groups I don't think it is any different from adding another "non object group" line to the ACL.&lt;/P&gt;
&lt;P&gt;I believe this is what you are asking..&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090223#M283542</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2017-08-09T13:10:13Z</dc:date>
    </item>
    <item>
      <title>Thanks Grant and yes that is</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090224#M283543</link>
      <description>&lt;P&gt;Thanks Grant and yes that is my question.&amp;nbsp; I've been asked to give access to a large list of networks and rather than adding 30 lines to my ACL, I'm hoping I can just create a group with these networks in it and add it to the existing extended ACL so that I can do the same thing with one new line.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090224#M283543</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2017-08-09T13:13:41Z</dc:date>
    </item>
    <item>
      <title>I have just tested on a 2911</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090225#M283544</link>
      <description>&lt;P&gt;I have just tested on a 2911 running IOS 15.1. Seems it can be done if this is what you are referring to. I think the only caveat here is it will need to be an extended ACL.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ip access-list extended NAT-TO-PLATFORMS&lt;BR /&gt; permit ip any 172.17.250.32 0.0.0.31&lt;BR /&gt; permit ip any 172.17.254.32 0.0.0.31&lt;BR /&gt; permit ip any 172.17.34.32 0.0.0.31&lt;BR /&gt; permit ip any 172.17.36.32 0.0.0.31&lt;BR /&gt; permit ip any 172.17.246.32 0.0.0.31&lt;BR /&gt; permit ip any 172.17.39.208 0.0.0.7&lt;BR /&gt; permit ip any 172.17.40.0 0.0.0.15&lt;BR /&gt; permit ip any 10.96.129.96 0.0.0.31&lt;BR /&gt; &lt;STRONG&gt;permit tcp object-group TEST any&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090225#M283544</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2017-08-09T13:14:51Z</dc:date>
    </item>
    <item>
      <title>You can mix, I thought you</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090226#M283545</link>
      <description>&lt;P&gt;You can mix, I thought you wanted to replace an existing ACE with object-group. Sorry for the confusion.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 14:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/add-object-group-in-existing-acl/m-p/3090226#M283545</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2017-08-09T14:16:20Z</dc:date>
    </item>
  </channel>
</rss>

