<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL object-group 6509 VSS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-object-group-6509-vss/m-p/3185518#M1066029</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm new in this support forum and almost new in networking field.&lt;/P&gt;&lt;P&gt;I'm working to migrate extended ACL to Object-group using IP ADDRESS group and IP PORT group.&lt;/P&gt;&lt;P&gt;But I don't know how to proceed implementing the new ACL. An example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this&lt;/P&gt;&lt;P&gt;ip access-list extended &lt;STRONG&gt;from X to Y&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1890 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 80&lt;BR /&gt;1900 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 443&lt;BR /&gt;1910 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 8443&lt;BR /&gt;1920 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 22443&lt;BR /&gt;1930 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 22443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to implement this using&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group ip address &lt;STRONG&gt;to Y (connection srv)&lt;/STRONG&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object-group ip port&amp;nbsp;&lt;STRONG&gt;to Y&lt;/STRONG&gt;&lt;BR /&gt;eq 80&lt;BR /&gt;eq 443&lt;BR /&gt;eq 8443&lt;BR /&gt;eq 22443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ACL as following&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;permit tcp addrgroup 10.x.x.x 0.0.1.255 addrgroup &lt;STRONG&gt;to&amp;nbsp;Y (connection srv)&lt;/STRONG&gt;&amp;nbsp;portgroup &lt;STRONG&gt;to Y&lt;/STRONG&gt;&lt;BR /&gt;permit udp addrgroup 10.x.x.x 0.0.1.255 addrgroup &lt;STRONG&gt;to&amp;nbsp;Y (connection srv)&lt;/STRONG&gt; eq 22443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to use the same ACL Extended name.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The question is: Do I have to create Object group first, and next? Have I to go line by line in order to cancel the old ACL and copy the new one?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Most probably it has to be performed outside working hours, but what the best way to mswap from old ACL to the new one?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank in advance for your help, I'm a bit confused.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:19:05 GMT</pubDate>
    <dc:creator>alessandro.derobertis</dc:creator>
    <dc:date>2020-02-21T14:19:05Z</dc:date>
    <item>
      <title>ACL object-group 6509 VSS</title>
      <link>https://community.cisco.com/t5/network-security/acl-object-group-6509-vss/m-p/3185518#M1066029</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm new in this support forum and almost new in networking field.&lt;/P&gt;&lt;P&gt;I'm working to migrate extended ACL to Object-group using IP ADDRESS group and IP PORT group.&lt;/P&gt;&lt;P&gt;But I don't know how to proceed implementing the new ACL. An example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this&lt;/P&gt;&lt;P&gt;ip access-list extended &lt;STRONG&gt;from X to Y&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1890 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 80&lt;BR /&gt;1900 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 443&lt;BR /&gt;1910 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 8443&lt;BR /&gt;1920 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 22443&lt;BR /&gt;1930 permit tcp 10.xxx.xx.0 0.0.1.255 host 10.xxx.xxx.xxx eq 22443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to implement this using&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group ip address &lt;STRONG&gt;to Y (connection srv)&lt;/STRONG&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;BR /&gt;host-info 10.&lt;SPAN&gt;xxx.xxx.xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object-group ip port&amp;nbsp;&lt;STRONG&gt;to Y&lt;/STRONG&gt;&lt;BR /&gt;eq 80&lt;BR /&gt;eq 443&lt;BR /&gt;eq 8443&lt;BR /&gt;eq 22443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ACL as following&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;permit tcp addrgroup 10.x.x.x 0.0.1.255 addrgroup &lt;STRONG&gt;to&amp;nbsp;Y (connection srv)&lt;/STRONG&gt;&amp;nbsp;portgroup &lt;STRONG&gt;to Y&lt;/STRONG&gt;&lt;BR /&gt;permit udp addrgroup 10.x.x.x 0.0.1.255 addrgroup &lt;STRONG&gt;to&amp;nbsp;Y (connection srv)&lt;/STRONG&gt; eq 22443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to use the same ACL Extended name.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The question is: Do I have to create Object group first, and next? Have I to go line by line in order to cancel the old ACL and copy the new one?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Most probably it has to be performed outside working hours, but what the best way to mswap from old ACL to the new one?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank in advance for your help, I'm a bit confused.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-object-group-6509-vss/m-p/3185518#M1066029</guid>
      <dc:creator>alessandro.derobertis</dc:creator>
      <dc:date>2020-02-21T14:19:05Z</dc:date>
    </item>
  </channel>
</rss>

