<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Object group and access list disappear after ASA reload in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123555#M1113303</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;I have the same problem. I have also tried Write Standby, but it does not help. I can't see many objects and rules in the standby node.&lt;/P&gt;
&lt;P&gt;Any suggestions/workarounds?&amp;nbsp;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwj93921?rfs=qvlogin" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCwj93921?rfs=qvlogin&lt;/A&gt;&amp;nbsp;- this one does not helps&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 16:55:31 GMT</pubDate>
    <dc:creator>Yordan1</dc:creator>
    <dc:date>2024-06-03T16:55:31Z</dc:date>
    <item>
      <title>Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121698#M1113174</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After upgrading our FPR-2110 running as ASA version 9.12 (4) to 9.18.4.22 , an object group and access list disappeared upon reload.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We re-added them , however once again after issuing write memory and reloading the ASA again after a few days, the same object group and access list are disappearing again.&lt;/P&gt;&lt;P&gt;Has anyone faced this issue before, or any idea what may be causing this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 08:18:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121698#M1113174</guid>
      <dc:creator>jjtech</dc:creator>
      <dc:date>2024-05-31T08:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121705#M1113176</link>
      <description>&lt;P&gt;Reload' did you wr the config?&lt;/P&gt;
&lt;P&gt;It can thr startup config is different than running config or you use some backup config before you do change.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 08:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121705#M1113176</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-31T08:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121728#M1113178</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1542888"&gt;@jjtech&lt;/a&gt;&amp;nbsp;You need to look at physical console during reload. There should be error messages there.&lt;/P&gt;&lt;P&gt;In ASA 9.18 entire ACL subsystem was redesigned which also changed the way how ASA boots up and also changed running-config command order:&lt;BR /&gt;CSCvu39353 ENH: Optimize ACL / object-groups&lt;/P&gt;&lt;P&gt;For example, it is expected that access-group is lost upon downgrade from 9.18 to 9.12, but not the other way around. Still, there might be issues with the new architecture. One such issue was fixed in 9.18.4.22:&lt;BR /&gt;&lt;SPAN class=""&gt;CSCwh62731&lt;/SPAN&gt; FTD Upgrade from 6.6.5 to 7.2.5 removing OGS causing rule expansion on boot&lt;/P&gt;&lt;P&gt;There might be others.&lt;/P&gt;&lt;P&gt;Did you have "object-group-search access-control" enabled in 9.12? Is it still enabled in 9.18? ("show run all | i object-group-search" + "show run | i object-group-search" + "show asp rule-engine"). How big are your ACLs (total size of all configs on the box in MB if it runs in multiple mode)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 09:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5121728#M1113178</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-31T09:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123192#M1113262</link>
      <description>&lt;P&gt;Yes I already confirmed that write memory was already issued before the reloads.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 07:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123192#M1113262</guid>
      <dc:creator>jjtech</dc:creator>
      <dc:date>2024-06-03T07:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123197#M1113263</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt;&amp;nbsp; for the detailed answer.&lt;/P&gt;&lt;P&gt;After checking, object group search was not enabled before upgrade, neither is it enabled now.&lt;/P&gt;&lt;P&gt;The ASA is running in single mode currently. Regarding the ACLs size, I the number of elements is acceptable (Total number of access-list elements is currently 7689) and I think the ACLs count as well, but how can I accurately see how big the ACLs are ? ( I couldn't find a command that would show such statistics)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 07:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123197#M1113263</guid>
      <dc:creator>jjtech</dc:creator>
      <dc:date>2024-06-03T07:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123219#M1113266</link>
      <description>&lt;P&gt;Welcome to the club. I've upgraded from ASA&amp;nbsp;&lt;SPAN&gt;9.18.4.22 to&amp;nbsp;9.18.4.24 and had this issue. See my post of today.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/cisco-asa-9-18-4-24-don-t-install-it-it-s-buggy/td-p/5123108" target="_blank"&gt;https://community.cisco.com/t5/network-security/cisco-asa-9-18-4-24-don-t-install-it-it-s-buggy/td-p/5123108&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Object-group search is not enabled. I tried that once years ago and it was buggy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;firewall1/web1/act# show run all | i object-group-search
no object-group-search access-control
no object-group-search threshold
no object-group-search access-control interface


firewall1/web1/act# show asp rule-engine

Rule compilation Status:   Completed
Duration(ms):              288821

S.No  Start Time                - Last Complete Time        Run Time(sec)

1     08:20:44 UTC Jun 3 2024   - 08:20:45 UTC Jun 3 2024    1
2     08:20:45 UTC Jun 3 2024   - 08:20:49 UTC Jun 3 2024    4
3     08:20:49 UTC Jun 3 2024   - 08:20:58 UTC Jun 3 2024    9
4     08:20:58 UTC Jun 3 2024   - 08:21:08 UTC Jun 3 2024    10
5     08:21:56 UTC Jun 3 2024   - 08:22:06 UTC Jun 3 2024    10
6     08:24:03 UTC Jun 3 2024   - 08:24:13 UTC Jun 3 2024    10
7     08:24:33 UTC Jun 3 2024   - 08:24:39 UTC Jun 3 2024    6
8     08:24:39 UTC Jun 3 2024   - 08:24:49 UTC Jun 3 2024    10
9     08:19:00 UTC Jun 3 2024   - 08:19:05 UTC Jun 3 2024    5
10    08:19:05 UTC Jun 3 2024   - 08:19:10 UTC Jun 3 2024    5
11    08:19:10 UTC Jun 3 2024   - 08:19:20 UTC Jun 3 2024    10
12    08:19:22 UTC Jun 3 2024   - 08:19:32 UTC Jun 3 2024    10
13    08:19:53 UTC Jun 3 2024   - 08:20:03 UTC Jun 3 2024    10
14    08:20:30 UTC Jun 3 2024   - 08:20:34 UTC Jun 3 2024    4
15    08:20:34 UTC Jun 3 2024   - 08:20:44 UTC Jun 3 2024    10

Module      | Insert      | Remove      | Current     |

 NAT        | 3394        | 2792        | 602         |
 ROUTE      | 2315        | 781         | 1534        |
 IFC        | 1278        | 1030        | 248         |
 ACL        | 148570      | 123129      | 25441       |
 IDENTITY   | 589         | 404         | 185         |

 Total      |                           | 28010       |&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 08:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123219#M1113266</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2024-06-03T08:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123253#M1113270</link>
      <description>&lt;P&gt;What a pain. &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1542888"&gt;@jjtech&lt;/a&gt; , did you upgrade to 9.18.4.22 or 9.18.4.24? I mean, if you upgraded to 9.18.4.22 you could have faced with a completely different issue than &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/138411"&gt;@Network Diver&lt;/a&gt; .&lt;/P&gt;&lt;P&gt;The number of ACL elements is shown by "show access-list | i element", but in your case it is small, so this is not related to ACL size.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 09:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123253#M1113270</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-06-03T09:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123414#M1113292</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt;&amp;nbsp;We upgraded to&amp;nbsp;&lt;SPAN&gt;9.18.4.22, so yes could be unrelated to Bernd's issue&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123414#M1113292</guid>
      <dc:creator>jjtech</dc:creator>
      <dc:date>2024-06-03T13:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123514#M1113299</link>
      <description>&lt;P&gt;Ok, so once again, you either need another box for testing with access to physical console or a TAC case and TAC engineer can try to repro this issue with your configuration. Usually, an error message should be produced if something goes wrong when the firewall interprets its configuration, although &lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-aclconfig-wVK52f3z" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-aclconfig-wVK52f3z&lt;/A&gt; tells us that firewall can keep silence sometimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 16:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123514#M1113299</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-06-03T16:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123555#M1113303</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;I have the same problem. I have also tried Write Standby, but it does not help. I can't see many objects and rules in the standby node.&lt;/P&gt;
&lt;P&gt;Any suggestions/workarounds?&amp;nbsp;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwj93921?rfs=qvlogin" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCwj93921?rfs=qvlogin&lt;/A&gt;&amp;nbsp;- this one does not helps&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 16:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5123555#M1113303</guid>
      <dc:creator>Yordan1</dc:creator>
      <dc:date>2024-06-03T16:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Object group and access list disappear after ASA reload</title>
      <link>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5124148#M1113316</link>
      <description>&lt;P&gt;this way you can check if the run config is same as startup config or not&amp;nbsp;&lt;BR /&gt;show run | in check&amp;nbsp;&lt;BR /&gt;show run | in check&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;check the checksum is it same or not&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (545).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219986iFAAFB5BC66EBB65B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (545).png" alt="Screenshot (545).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 06:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-and-access-list-disappear-after-asa-reload/m-p/5124148#M1113316</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-04T06:02:58Z</dc:date>
    </item>
  </channel>
</rss>

