<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I didn't use both ACLs at the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924322#M171659</link>
    <description>&lt;P&gt;I didn't use both ACLs at the same time, it is just copy.&lt;/P&gt;
&lt;P&gt;ACL with service-object was used first. I found that use of this ACL is wrong.&lt;/P&gt;
&lt;P&gt;So, I am looking to figure out why first ACL is wrong?&lt;/P&gt;</description>
    <pubDate>Sat, 14 May 2016 18:22:22 GMT</pubDate>
    <dc:creator>Ritter Rs</dc:creator>
    <dc:date>2016-05-14T18:22:22Z</dc:date>
    <item>
      <title>ACL using service-object vs. port-object</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924320#M171656</link>
      <description>&lt;P&gt;Hi, I have some misunderstanding with ACL using service-object and port-object.&lt;BR /&gt;Device is Cisco ASA ASA5510 Software Version 8.2(5).&lt;BR /&gt;&lt;BR /&gt;1 ACL using service-object&lt;BR /&gt;access-list PAT-all extended permit object-group Site-LAN-serObj-tcp object-group Site-LAN any&lt;BR /&gt;&lt;BR /&gt;object-group service Site-LAN-serObj-tcp&lt;BR /&gt;&amp;nbsp;service-object tcp eq ssh&lt;BR /&gt;&amp;nbsp;service-object tcp eq 3690&lt;BR /&gt;&lt;BR /&gt;sh access-list&lt;BR /&gt;...&lt;BR /&gt;access-list PAT-all line 7 extended permit object-group Site-LAN-serObj-tcp object-group Site-LAN any 0x86266726&lt;BR /&gt;&amp;nbsp; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq ssh (hitcnt=0) 0x1cda44f6&lt;BR /&gt;&amp;nbsp; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 3690 (hitcnt=0) 0x5e3f9947&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2 ACL using port-object&lt;BR /&gt;access-list PAT-all extended permit tcp object-group Site-LAN any object-group Site-LAN-portObj-tcp&lt;BR /&gt;&lt;BR /&gt;object-group service Site-LAN-portObj-tcp tcp&lt;BR /&gt;&amp;nbsp;port-object eq ssh&lt;BR /&gt;&amp;nbsp;port-object eq 3690&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;sh access-list&lt;BR /&gt;...&lt;BR /&gt;access-list PAT-all line 5 extended permit tcp object-group Site-LAN any object-group Site-LAN-portObj-tcp 0xac4dsdf&lt;BR /&gt;&amp;nbsp; access-list PAT-all line 5 extended permit tcp 10.55.0.0 255.255.0.0 any eq ssh (hitcnt=0) 0x1cwcrcf6&lt;BR /&gt;&amp;nbsp; access-list PAT-all line 5 extended permit tcp 10.55.0.0 255.255.0.0 any eq 3690 (hitcnt=0) 0x5g5efg607&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;&lt;BR /&gt;This two access-list should do same thing, but one (with service-object) is wrong. Could someone explain why, please?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924320#M171656</guid>
      <dc:creator>Ritter Rs</dc:creator>
      <dc:date>2019-03-12T07:45:12Z</dc:date>
    </item>
    <item>
      <title>Hi -</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924321#M171657</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;How are you testing this ACL?&lt;/P&gt;
&lt;P&gt;From what I see the 2 ACL entries do exactly the same thing. In this case ACL order would cause a precedence of line 5 over line 7, so line 7 will never get a match.&lt;/P&gt;
&lt;P&gt;PSC&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2016 16:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924321#M171657</guid>
      <dc:creator>Paul Chapman</dc:creator>
      <dc:date>2016-05-14T16:58:37Z</dc:date>
    </item>
    <item>
      <title>I didn't use both ACLs at the</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924322#M171659</link>
      <description>&lt;P&gt;I didn't use both ACLs at the same time, it is just copy.&lt;/P&gt;
&lt;P&gt;ACL with service-object was used first. I found that use of this ACL is wrong.&lt;/P&gt;
&lt;P&gt;So, I am looking to figure out why first ACL is wrong?&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2016 18:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924322#M171659</guid>
      <dc:creator>Ritter Rs</dc:creator>
      <dc:date>2016-05-14T18:22:22Z</dc:date>
    </item>
    <item>
      <title>Hi -</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924323#M171662</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;Honestly I don't see a problem with it.&amp;nbsp; As shown in your original question, "show access-list" shows&amp;nbsp;the exact same ACEs in the ACL.&lt;/P&gt;
&lt;P&gt;Where is this ACL being used? (Access-Group, Crypto Map, VPN Filter, etc...)&lt;/P&gt;
&lt;P&gt;PSC&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2016 20:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924323#M171662</guid>
      <dc:creator>Paul Chapman</dc:creator>
      <dc:date>2016-05-14T20:38:32Z</dc:date>
    </item>
    <item>
      <title>It was used on ASA FW, for</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924324#M171665</link>
      <description>&lt;P&gt;It was used on ASA FW, for inside lan, to permit inside hosts to reach outside networks.&lt;/P&gt;
&lt;P&gt;I have tried with ACL using service-object to define ports that are allowed:&lt;BR /&gt;- as you can see syntax is somehow different than usual&lt;BR /&gt;acl acl-name object-group service-group-name object-group network-group-name any&lt;/P&gt;
&lt;P&gt;But it did not work, it was allowed access on non-listed ports, after I have switched from service-object &lt;BR /&gt;to port-object i didn't have access to ports that are not listed in the ACL.&lt;/P&gt;
&lt;P&gt;This is entire ACL:&lt;/P&gt;
&lt;P&gt;access-list PAT-all line 7 extended permit object-group Site-LAN-serObj-tcp object-group Site-LAN any&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq ssh (hitcnt=0) 0x1cda0cf6&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 3690 (hitcnt=0) 0x5e3f6607&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 2401 (hitcnt=0) 0x8ff4d66f&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq https (hitcnt=0) 0x6128371d&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 9418 (hitcnt=0) 0x1d56c202&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 873 (hitcnt=0) 0x1dd68fc8&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq www (hitcnt=0) 0x0c554949&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq ftp (hitcnt=0) 0xfab58087&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq rtsp (hitcnt=0) 0x81c0aca8&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 1755 (hitcnt=0) 0x39f04fcc&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 7999 (hitcnt=0) 0x075f88f8&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq sip (hitcnt=0) 0xba32cf2c&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 3000 (hitcnt=0) 0x6f781a3a&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 8443 (hitcnt=0) 0xa5cee280&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 5062 (hitcnt=0) 0x89a82da4&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 29418 (hitcnt=0) 0xa0393f09&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 3389 (hitcnt=0) 0x409bd1dd&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 10000 (hitcnt=0) 0x73039ac8&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any eq 9443 (hitcnt=0) 0x37672c98&lt;BR /&gt; access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any neq smtp (hitcnt=0) 0x6f599db4&lt;/P&gt;
&lt;P&gt;And I was able to access on one remote host with port 82, but i should not!?!&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2016 22:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924324#M171665</guid>
      <dc:creator>Ritter Rs</dc:creator>
      <dc:date>2016-05-14T22:34:28Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924325#M171667</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;The syntax is different because you don't specify "tcp" at the end of the service object-group:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object-group service Site-LAN-serObj-tcp&lt;BR /&gt;&amp;nbsp;service-object tcp eq ssh&lt;BR /&gt;&amp;nbsp;service-object tcp eq 3690&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;object-group service Site-LAN-portObj-tcp &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;tcp&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;port-object eq ssh&lt;BR /&gt;&amp;nbsp;port-object eq 3690&lt;/PRE&gt;
&lt;P&gt;What happends when you run packet tracer on the two different ACLs?&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input tcp 10.55.5.5 12345 8.8.8.8 82 detail&lt;/PRE&gt;</description>
      <pubDate>Sun, 15 May 2016 16:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924325#M171667</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-05-15T16:14:48Z</dc:date>
    </item>
    <item>
      <title>I think that I found mistake</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924326#M171670</link>
      <description>&lt;P&gt;I think that I found mistake in the first ACL,&lt;/P&gt;
&lt;P&gt;access-list PAT-all line 7 extended permit tcp 10.55.0.0 255.255.0.0 any neq smtp&lt;/P&gt;
&lt;P&gt;This line open all tcp ports including 82, (except smtp)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 13:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924326#M171670</guid>
      <dc:creator>Ritter Rs</dc:creator>
      <dc:date>2016-05-16T13:49:10Z</dc:date>
    </item>
    <item>
      <title>Hi -</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924327#M171674</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;Yes.&amp;nbsp; You found the problem alright.&amp;nbsp; Actually SMTP is on TCP/25.&amp;nbsp; The rule states all other ports are allowed.&amp;nbsp; Since it is the last entry, it will match on all non-SMTP traffic and the ASA will stop rule processing.&lt;/P&gt;
&lt;P&gt;If you post to the forums in the future, please include more complete configurations for the members to review.&lt;/P&gt;
&lt;P&gt;Good Luck!&lt;/P&gt;
&lt;P&gt;PSC&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 14:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924327#M171674</guid>
      <dc:creator>Paul Chapman</dc:creator>
      <dc:date>2016-05-16T14:17:45Z</dc:date>
    </item>
    <item>
      <title>Ok. Sorry and thank you.</title>
      <link>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924328#M171676</link>
      <description>&lt;P&gt;Ok. Sorry and thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 14:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-using-service-object-vs-port-object/m-p/2924328#M171676</guid>
      <dc:creator>Ritter Rs</dc:creator>
      <dc:date>2016-05-16T14:57:20Z</dc:date>
    </item>
  </channel>
</rss>

