<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I use IP ranges in ASA firepower ASDM ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941626#M148838</link>
    <description>&lt;P&gt;How do I use IP ranges in ASA firepower ASDM ?&lt;/P&gt;
&lt;P&gt;Individual addresses work like 192.168.1.100/32&lt;BR /&gt;Full subnets also work like 192.168.1.0/24&lt;/P&gt;
&lt;P&gt;But I cannot seem to find a way to use IP ranges in network --&amp;gt; individual objects.&lt;BR /&gt;I tried something like 192.168.1.20-192.168.1.30/24 and the rule applied for the whole 192.168.1.* class instead of the interval.&lt;/P&gt;
&lt;P&gt;Is this method of putting ranges with "-" between valid ?&lt;BR /&gt;Would the above example work if I use the same 192.168.1.20-192.168.1.30 but with /32 ?&lt;/P&gt;
&lt;P&gt;How do I actually use IP ranges as network objects ?&lt;/P&gt;
&lt;P&gt;Please provide a practical tested answer, not links towards obscure documentation.&lt;/P&gt;
&lt;P&gt;I cannot test all possibilities that I can think of because it's a server environment and wrong settings cause disruption.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:28:46 GMT</pubDate>
    <dc:creator>Infuscomus</dc:creator>
    <dc:date>2019-03-12T08:28:46Z</dc:date>
    <item>
      <title>How do I use IP ranges in ASA firepower ASDM ?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941626#M148838</link>
      <description>&lt;P&gt;How do I use IP ranges in ASA firepower ASDM ?&lt;/P&gt;
&lt;P&gt;Individual addresses work like 192.168.1.100/32&lt;BR /&gt;Full subnets also work like 192.168.1.0/24&lt;/P&gt;
&lt;P&gt;But I cannot seem to find a way to use IP ranges in network --&amp;gt; individual objects.&lt;BR /&gt;I tried something like 192.168.1.20-192.168.1.30/24 and the rule applied for the whole 192.168.1.* class instead of the interval.&lt;/P&gt;
&lt;P&gt;Is this method of putting ranges with "-" between valid ?&lt;BR /&gt;Would the above example work if I use the same 192.168.1.20-192.168.1.30 but with /32 ?&lt;/P&gt;
&lt;P&gt;How do I actually use IP ranges as network objects ?&lt;/P&gt;
&lt;P&gt;Please provide a practical tested answer, not links towards obscure documentation.&lt;/P&gt;
&lt;P&gt;I cannot test all possibilities that I can think of because it's a server environment and wrong settings cause disruption.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941626#M148838</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2019-03-12T08:28:46Z</dc:date>
    </item>
    <item>
      <title>IP ranges in object</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941627#M148839</link>
      <description>&lt;P&gt;IP ranges in object definitions are supported as of FirePOWER 6.1.&lt;/P&gt;
&lt;P&gt;You define them as shown in this practical example (open in new tab to zoom):&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/firepower_object_range_example.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The obscure documentation covers it in this section:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/Reusable_Objects.html?bookSearch=true#ID-2243-000000f2&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 13:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941627#M148839</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-11-02T13:54:52Z</dc:date>
    </item>
    <item>
      <title>Thanks for answering. After</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941628#M148841</link>
      <description>&lt;P&gt;Thanks for answering. After some more testing with ICMP as test I managed to successfully make a range. "-" is indeed used as separator. I had to use /32 though, as /24 would block the whole class no matter the IP interval. I was wondering what's the default if you just put the range and do not use any mask info.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 07:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-use-ip-ranges-in-asa-firepower-asdm/m-p/2941628#M148841</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2016-11-03T07:08:46Z</dc:date>
    </item>
  </channel>
</rss>

