<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Have you tried adding the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480478#M267228</link>
    <description>&lt;P&gt;Have you tried adding the commands manually in the CLI? if not, could you try a couple object-groups to see if you get an error there also?&lt;/P&gt;&lt;P&gt;If you do not get an error there then I think this could be an issue with ASDM version and would suggest downgrading (if you absolutely have to do this in ASDM). If you get an error when entering the commands in CLI then it would seem that there is an issue with the configuration...perhaps naming convention(?), in any case we would need to see more of your configuration to help you further in this case.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2014 11:30:26 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-04-29T11:30:26Z</dc:date>
    <item>
      <title>ASA5505 got Network objects group and network objects problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480475#M267219</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ASA5505 start acts strangely in the ASDM. When i starts create Network objects and Network objects group, it often failed -&lt;/P&gt;&lt;P&gt;Actually what i am trying to do is to deny connection&amp;nbsp; to/from Adverstment servers, it is supposed to an easy task to do.&lt;/P&gt;&lt;P&gt;This is the error message from the asdm when i edit the network object group:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[OK] object network ADS.ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object network ADS.ds.serving-sys.com&lt;BR /&gt;[OK] fqdn v4 ds.serving-sys.com&lt;BR /&gt;[OK] description ds.serving-sys.com&lt;BR /&gt;[OK] object-group network ADS_BLOCK&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network ADS_BLOCK&lt;BR /&gt;[ERROR] network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister b.voicefive.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister cmh.hk.overture.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister ds.serving-sys.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.i.l.networld.hk&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister i.l.networld.hk lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister pagead2.googlesyndication.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.pubads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister pubads.g.doubleclick.net lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister s3-ap-southeast-1.amazonaws.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.servedby.adsfactor.net&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister servedby.adsfactor.net lookup service (10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ASA5505 is running ASA9.2, ASDM 7.2.1 . How can i solve this problem? My ACL of this network-group also disappear after i created it with the network group object again and again. It just doesn't work now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480475#M267219</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2019-03-12T04:08:06Z</dc:date>
    </item>
    <item>
      <title>If you enable preview</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480476#M267222</link>
      <description>&lt;P&gt;If you enable preview commands under preferences before deploying, review the commands to see if there might be some issues with the commands the ASDM is trying to deploy.&lt;/P&gt;&lt;P&gt;Have you tried to add the object groups and ACLs using the CLI.&amp;nbsp; Has this been successful?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 10:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480476#M267222</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-29T10:17:23Z</dc:date>
    </item>
    <item>
      <title>Hi Marius,Thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480477#M267225</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion - I have enabled the option you mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see it is trying to do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;object-group network ADS_BLOCK&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object ADS.cmh.hk.overture.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then it came back:&lt;/P&gt;&lt;P&gt;[OK] object-group network ADS_BLOCK&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network ADS_BLOCK&lt;BR /&gt;[ERROR] network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister b.voicefive.com lookup service (10)&lt;/P&gt;&lt;P&gt;[ERROR] network-object object ADS.cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Adding obj to object-group (ADS_BLOCK) failed; cause access-list error&lt;BR /&gt;ERROR: unable to deregister cmh.hk.overture.com lookup service (10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know what is going on, any suggestion can debug this are welcome and i will try to do the suggestion as i can.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 11:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480477#M267225</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-04-29T11:14:27Z</dc:date>
    </item>
    <item>
      <title>Have you tried adding the</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480478#M267228</link>
      <description>&lt;P&gt;Have you tried adding the commands manually in the CLI? if not, could you try a couple object-groups to see if you get an error there also?&lt;/P&gt;&lt;P&gt;If you do not get an error there then I think this could be an issue with ASDM version and would suggest downgrading (if you absolutely have to do this in ASDM). If you get an error when entering the commands in CLI then it would seem that there is an issue with the configuration...perhaps naming convention(?), in any case we would need to see more of your configuration to help you further in this case.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 11:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480478#M267228</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-29T11:30:26Z</dc:date>
    </item>
    <item>
      <title>I found another problem. I</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480479#M267230</link>
      <description>&lt;P&gt;I found another problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see what ASDM is doing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;access-list inside_access_in line 9 extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/P&gt;&lt;P&gt;then write mem&lt;/P&gt;&lt;P&gt;The asdm will actualy list this acl for a moment.&lt;/P&gt;&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;But in the actual runnning config, i cannot see anything actually is related to this.&lt;/P&gt;&lt;P&gt;And interestingly , after write mem and checked running config from CLI, i run asdm again, and, acl disappear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, seems this &amp;nbsp;access-list inside_access_in line 9 extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable no use at all.&lt;/P&gt;&lt;P&gt;btw, i used command created this newly ADS1_BLOCK group , no problem at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AS i am not very familiar CLI, would you suggest is there another&amp;nbsp; way to rewrite this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;access-list inside_access_in line 9 extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/P&gt;&lt;P&gt;? i suspected this command messed up things in my ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 11:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480479#M267230</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-04-29T11:56:48Z</dc:date>
    </item>
    <item>
      <title>I don't see how that ACL</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480480#M267231</link>
      <description>&lt;P&gt;I don't see how that ACL entry would mess things up as it is disabled.&amp;nbsp; But there really isn't any other way of writing it, other than creating separate entries for all the objects in the ADS1_BLOCK group.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 12:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480480#M267231</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-29T12:01:46Z</dc:date>
    </item>
    <item>
      <title>I tried this: access-list</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480481#M267232</link>
      <description>&lt;P&gt;I tried this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as i found in the running config.&lt;/P&gt;&lt;P&gt;I typed this in CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa(config)# aaccess-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;BR /&gt;asa(config)# write&lt;BR /&gt;Building configuration...&lt;BR /&gt;Cryptochecksum: 793b2277 64859db5 0966c319 439447e6&lt;/P&gt;&lt;P&gt;28366 bytes copied in 1.420 secs (28366 bytes/sec)&lt;BR /&gt;[OK]&lt;BR /&gt;asa(config)#&lt;/P&gt;&lt;P&gt;But i run sh run i cannot find this entry in my running config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My running config have this:&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny tcp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny udp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny tcp object my-host object-group wp-block log disable&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Monitor-remote-tcp log alerts&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Internet-tcp log disable&lt;BR /&gt;access-list inside_access_in extended permit udp any4 any4 object-group Internet-udp log disable&lt;BR /&gt;access-list inside_access_in extended permit icmp any4 any4 object-group ICMP-Service-Group log disable&lt;BR /&gt;access-list inside_access_in extended permit ip any4 any4 log disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really don't know what is going on, no complain in CLI, can write to mem but just not exist in the running config&lt;/P&gt;&lt;P&gt;Any suggestion?&lt;/P&gt;&lt;P&gt;Should i downgrade ASA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 12:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480481#M267232</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-04-29T12:13:28Z</dc:date>
    </item>
    <item>
      <title>Could you post the</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480482#M267233</link>
      <description>&lt;P&gt;Could you post the configuration output for ADS1_BLOCK please?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 12:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480482#M267233</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-29T12:15:57Z</dc:date>
    </item>
    <item>
      <title>I post my running config here</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480483#M267234</link>
      <description>&lt;P&gt;I post my running config here - hope you can give me any suggestion.&lt;/P&gt;&lt;P&gt;asa# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;: Serial Number:&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5505, 1024 MB RAM, CPU Geode 500 MHz&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.2(1)&lt;BR /&gt;!&lt;BR /&gt;hostname asa&lt;BR /&gt;enable password&amp;nbsp; encrypted&lt;BR /&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;multicast-routing&lt;BR /&gt;names&lt;BR /&gt;name 10.71.0.50 my-host&lt;BR /&gt;ip local pool vpn-pool 10.71.1.230-10.71.1.254 mask 255.255.0.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;description Private-interface&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.71.0.1 255.255.255.0&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;description Public-interface&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa921-k8.bin&lt;BR /&gt;boot system disk0:/asa915-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST 8&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;name-server 8.8.8.8&lt;BR /&gt;&amp;nbsp;name-server 8.8.4.4&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj-10.71.0.224&lt;BR /&gt;&amp;nbsp;subnet 10.71.0.224 255.255.255.224&lt;BR /&gt;object network my-host&lt;BR /&gt;&amp;nbsp;host 10.71.0.50&lt;BR /&gt;object service obj-tcp-source-eq-57706&lt;BR /&gt;&amp;nbsp;service tcp source eq 57706&lt;BR /&gt;object service obj-tcp-source-eq-7777&lt;BR /&gt;&amp;nbsp;service tcp source eq 7777&lt;BR /&gt;object network obj-10.71.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.71.0.0 255.255.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.71.0.224_27&lt;BR /&gt;&amp;nbsp;subnet 10.71.0.224 255.255.255.224&lt;BR /&gt;object service obj-tcp-source-eq-80&lt;BR /&gt;&amp;nbsp;service tcp source eq www&lt;BR /&gt;object network vpnpool&lt;BR /&gt;&amp;nbsp;range 10.71.1.230 10.71.1.254&lt;BR /&gt;&amp;nbsp;description vpnpool&lt;BR /&gt;object service obj-tcp-source-eq-443&lt;BR /&gt;&amp;nbsp;service tcp source eq https&lt;BR /&gt;object service 1443&lt;BR /&gt;&amp;nbsp;service tcp destination eq 1443&lt;BR /&gt;object network block-NEOTEL&lt;BR /&gt;&amp;nbsp;range 41.160.0.0 41.175.255.255&lt;BR /&gt;&amp;nbsp;description 255.255.0.0&lt;BR /&gt;object network block-190.123.0.0&lt;BR /&gt;&amp;nbsp;range 190.123.0.0 190.123.255.255&lt;BR /&gt;object network block-level3&lt;BR /&gt;&amp;nbsp;range 4.26.0.0 4.26.255.255&lt;BR /&gt;object network block-110.164.191.179&lt;BR /&gt;&amp;nbsp;range 110.164.0.0 110.164.255.255&lt;BR /&gt;object network block-87.106.0.0_16&lt;BR /&gt;&amp;nbsp;range 87.106.0.0 87.106.255.255&lt;BR /&gt;object network block-80.86.80.0_16&lt;BR /&gt;&amp;nbsp;range 80.86.80.0 80.86.84.255&lt;BR /&gt;object network ADS.bdaz.adsfactor.net&lt;BR /&gt;&amp;nbsp;fqdn v4 bdaz.adsfactor.net&lt;BR /&gt;&amp;nbsp;description bdaz.adsfactor.net&lt;BR /&gt;object network ADS.googleads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;fqdn v4 googleads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;description googleads.g.doubleclick.net&lt;BR /&gt;object network ADS.i.l.networld.hk&lt;BR /&gt;&amp;nbsp;fqdn v4 i.l.networld.hk&lt;BR /&gt;&amp;nbsp;description i.l.networld.hk&lt;BR /&gt;object network ADS.servedby.adsfactor.net&lt;BR /&gt;&amp;nbsp;fqdn v4 servedby.adsfactor.net&lt;BR /&gt;&amp;nbsp;description servedby.adsfactor.net&lt;BR /&gt;object network ADS.pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;fqdn v4 pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;description pagead2.googlesyndication.com&lt;BR /&gt;object network ADS.s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;&amp;nbsp;fqdn v4 s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;&amp;nbsp;description s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;object network ADS.cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;fqdn v4 cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;description cmh.hk.overture.com&lt;BR /&gt;object network ADS.pubads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;fqdn v4 pubads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;description pubads.g.doubleclick.net&lt;BR /&gt;object network ADS.ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;fqdn v4 ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;description ds.serving-sys.com&lt;BR /&gt;object network ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;fqdn b.voicefive.com&lt;BR /&gt;object network ADS1.test.abc.com&lt;BR /&gt;&amp;nbsp;fqdn test.abc.com&lt;BR /&gt;object-group network ADS_BLOCK&lt;BR /&gt;&amp;nbsp;network-object object ADS.bdaz.adsfactor.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.googleads.g.doubleclick.net&lt;BR /&gt;object-group service Internet-udp udp&lt;BR /&gt;&amp;nbsp;description UDP Standard Internet Services&lt;BR /&gt;&amp;nbsp;port-object eq domain&lt;BR /&gt;&amp;nbsp;port-object eq ntp&lt;BR /&gt;&amp;nbsp;port-object eq isakmp&lt;BR /&gt;&amp;nbsp;port-object eq 4500&lt;BR /&gt;&amp;nbsp;port-object eq snmp&lt;BR /&gt;&amp;nbsp;port-object eq snmptrap&lt;BR /&gt;object-group service Internet-tcp tcp&lt;BR /&gt;&amp;nbsp;description TCP Standard Internet Services&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;&amp;nbsp;port-object eq smtp&lt;BR /&gt;&amp;nbsp;port-object eq 465&lt;BR /&gt;&amp;nbsp;port-object eq pop3&lt;BR /&gt;&amp;nbsp;port-object eq 995&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq ftp-data&lt;BR /&gt;&amp;nbsp;port-object eq domain&lt;BR /&gt;&amp;nbsp;port-object eq ssh&lt;BR /&gt;&amp;nbsp;port-object eq 57706&lt;BR /&gt;object-group icmp-type ICMP-Service-Group&lt;BR /&gt;&amp;nbsp;description ICMP Service Group&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group service Monitor-remote-tcp tcp&lt;BR /&gt;&amp;nbsp;description Monitor-remote-tcp&lt;BR /&gt;&amp;nbsp;port-object eq 5938&lt;BR /&gt;&amp;nbsp;port-object eq 7777&lt;BR /&gt;object-group network DMZ_Group&lt;BR /&gt;&amp;nbsp;network-object 10.80.0.0 255.255.0.0&lt;BR /&gt;object-group network wp-block&lt;BR /&gt;&amp;nbsp;network-object object block-NEOTEL&lt;BR /&gt;&amp;nbsp;network-object object block-190.123.0.0&lt;BR /&gt;&amp;nbsp;network-object object block-level3&lt;BR /&gt;&amp;nbsp;network-object object block-110.164.191.179&lt;BR /&gt;&amp;nbsp;network-object object block-87.106.0.0_16&lt;BR /&gt;&amp;nbsp;network-object object block-80.86.80.0_16&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;&amp;nbsp;service-object object obj-tcp-source-eq-443&lt;BR /&gt;&amp;nbsp;service-object object obj-tcp-source-eq-57706&lt;BR /&gt;&amp;nbsp;service-object object obj-tcp-source-eq-7777&lt;BR /&gt;&amp;nbsp;service-object object obj-tcp-source-eq-80&lt;BR /&gt;object-group network ADS1_BLOCK&lt;BR /&gt;&amp;nbsp;network-object object ADS1.test.abc.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.bdaz.adsfactor.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.googleads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.i.l.networld.hk&lt;BR /&gt;&amp;nbsp;network-object object ADS.pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.pubads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.servedby.adsfactor.net&lt;BR /&gt;object-group-search access-control&lt;BR /&gt;access-list NAT-ACLs extended permit ip 10.71.0.0 255.255.255.0 any4&lt;BR /&gt;access-list inside-in extended deny ip any 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside-in remark -=[Access Lists For Outgoing Packets from Inside interface]=-&lt;BR /&gt;access-list inside-in extended permit udp 10.71.0.0 255.255.255.0 any4 object-group Internet-udp&lt;BR /&gt;access-list inside-in extended permit tcp 10.71.0.0 255.255.255.0 any4 object-group Internet-tcp&lt;BR /&gt;access-list inside-in extended permit icmp 10.71.0.0 255.255.255.0 any4&lt;BR /&gt;access-list outside-in remark -=[Access Lists For Incoming Packets on OUTSIDE interface]=-&lt;BR /&gt;access-list outside-in extended permit icmp any4 any4 echo-reply&lt;BR /&gt;access-list outside-in extended deny tcp any 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny tcp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny udp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny tcp object my-host object-group wp-block log disable&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Monitor-remote-tcp log alerts&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Internet-tcp log disable&lt;BR /&gt;access-list inside_access_in extended permit udp any4 any4 object-group Internet-udp log disable&lt;BR /&gt;access-list inside_access_in extended permit icmp any4 any4 object-group ICMP-Service-Group log disable&lt;BR /&gt;access-list inside_access_in extended permit ip any4 any4 log disable&lt;BR /&gt;access-list outside_access_in extended deny tcp object-group wp-block object my-host log alerts&lt;BR /&gt;access-list outside_access_in remark gov&lt;BR /&gt;access-list outside_access_in extended deny object-group DM_INLINE_SERVICE_3 202.128.224.0 255.255.224.0 object my-host log alerts&lt;BR /&gt;access-list outside_access_in remark gov&lt;BR /&gt;access-list outside_access_in extended deny tcp 202.128.224.0 255.255.224.0 object my-host log alerts&lt;BR /&gt;access-list outside_access_in extended permit tcp any4 any4 object-group Monitor-remote-tcp log alerts&lt;BR /&gt;access-list outside_access_in extended permit tcp any4 any4 object-group Internet-tcp log disable&lt;BR /&gt;access-list outside_access_in extended permit udp any4 any4 object-group Internet-udp log disable&lt;BR /&gt;access-list outside_access_in extended permit ip any4 any4 log disable&lt;BR /&gt;access-list outside_access_in extended permit icmp any4 any4 object-group ICMP-Service-Group log disable&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip any4 10.71.0.224 255.255.255.224&lt;BR /&gt;access-list split-tunnel standard permit 10.71.0.0 255.255.255.0&lt;BR /&gt;access-list DMZ_access_in extended permit tcp any any object-group Internet-tcp&lt;BR /&gt;access-list DMZ_access_in extended permit ip any any&lt;BR /&gt;access-list DMZ_access_in extended permit udp any any object-group Internet-udp&lt;BR /&gt;access-list DMZ_access_in extended permit icmp any any object-group ICMP-Service-Group&lt;BR /&gt;access-list global_access extended permit tcp any any object-group Internet-tcp&lt;BR /&gt;access-list global_access extended permit udp any any object-group Internet-udp&lt;BR /&gt;access-list global_access extended permit icmp any any object-group ICMP-Service-Group&lt;BR /&gt;access-list global_access extended deny ip 202.128.224.0 255.255.224.0 object my-host log alerts&lt;BR /&gt;access-list global_access extended deny ip object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list filter level warnings&lt;BR /&gt;logging buffer-size 999999&lt;BR /&gt;logging buffered filter&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging flash-bufferwrap&lt;BR /&gt;logging flash-minimum-free 30760&lt;BR /&gt;logging flash-maximum-allocation 30240&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-721.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source static my-host interface service obj-tcp-source-eq-80 obj-tcp-source-eq-80&lt;BR /&gt;nat (inside,outside) source static my-host interface service obj-tcp-source-eq-443 obj-tcp-source-eq-443&lt;BR /&gt;nat (inside,outside) source static my-host interface service obj-tcp-source-eq-57706 obj-tcp-source-eq-57706&lt;BR /&gt;nat (inside,outside) source static my-host interface service obj-tcp-source-eq-7777 obj-tcp-source-eq-7777&lt;BR /&gt;nat (inside,outside) source dynamic obj-10.71.0.0 interface&lt;BR /&gt;nat (inside,outside) source static any any destination static obj-10.71.0.0 obj-10.71.0.0 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network obj-10.71.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;nat (any,outside) after-auto source static vpnpool vpnpool&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group global_access global&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-192-SHA ESP-AES-256-SHA ESP-3DES-SHA ESP-DES-SHA ESP-AES-128-SHA-TRANS ESP-AES-192-SHA-TRANS ESP-AES-256-SHA-TRANS ESP-3DES-SHA-TRANS ESP-DES-SHA-TRANS&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto map inside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map inside_map interface inside&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;subject-name CN=my-asa&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate map DefaultCertificateMap 10&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 21 20 19 24 14 5&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable inside client-services port 443&lt;BR /&gt;crypto ikev2 enable outside&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh scopy enable&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh timeout 60&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpnclient server 1.2.3.4&lt;BR /&gt;vpnclient mode client-mode&lt;BR /&gt;vpnclient vpngroup vpn password *****&lt;BR /&gt;dhcpd lease 1048575&lt;BR /&gt;!&lt;BR /&gt;dhcpd address my-host-10.71.0.128 inside&lt;BR /&gt;dhcpd dns 8.8.8.8 8.8.4.4 interface inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;dynamic-filter updater-client enable&lt;BR /&gt;dynamic-filter use-database&lt;BR /&gt;dynamic-filter enable interface outside&lt;BR /&gt;ntp authenticate&lt;BR /&gt;ntp server 118.143.17.82 prefer&lt;BR /&gt;ssl encryption 3des-sha1 aes256-sha1&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 inside&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;port 8443&lt;BR /&gt;&amp;nbsp;enable inside&lt;BR /&gt;&amp;nbsp;enable outside&lt;BR /&gt;&amp;nbsp;character-encoding unicode&lt;BR /&gt;&amp;nbsp;anyconnect-essentials&lt;BR /&gt;&amp;nbsp;csd image disk0:/csd_3.6.6210-k9.pkg&lt;BR /&gt;&amp;nbsp;csd enable&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-3.1.03103-k9.pkg 1 regex "Windows NT"&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-linux-3.1.03103-k9.pkg 2 regex "Linux"&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macosx-i386-3.1.03103-k9.pkg 3 regex "Intel Mac OS X"&lt;BR /&gt;&amp;nbsp;anyconnect profiles vpn disk0:/vpn.xml&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;mus password *****&lt;BR /&gt;group-policy DefaultRAGroup internal&lt;BR /&gt;group-policy DefaultRAGroup attributes&lt;BR /&gt;&amp;nbsp;dns-server value 8.8.8.8 8.8.4.4&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol l2tp-ipsec&lt;BR /&gt;group-policy DefaultRAGroup_1 internal&lt;BR /&gt;group-policy DefaultRAGroup_1 attributes&lt;BR /&gt;&amp;nbsp;dns-server value 8.8.8.8 8.8.4.4&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:793b227764859db50966c319439447e6&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 12:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480483#M267234</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-04-29T12:30:30Z</dc:date>
    </item>
    <item>
      <title>is this a typo or copy error.</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480484#M267236</link>
      <description>&lt;P&gt;is this a typo or copy error...? (two a's in access)&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;aaccess-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If it is a typo, I do not have a good explanation as to why it is not showing up in the running configuration.&amp;nbsp; I plugged you config into my ASA and got no error and see the entry when I issue &lt;STRONG&gt;show run access-list.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Try removing the ADS1_BLOCK group and the ACL, refresh ASDM and make sure the commands are not present in the ASDM or CLI, then re-add the commands using the CLI only and see if the command is now present.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no access-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no object-group network ADS1_BLOCK&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;refresh ASDM and check that configs are gone.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network ADS1_BLOCK&lt;BR /&gt;&amp;nbsp;network-object object ADS1.test.abc.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.bdaz.adsfactor.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.cmh.hk.overture.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.ds.serving-sys.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.googleads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.i.l.networld.hk&lt;BR /&gt;&amp;nbsp;network-object object ADS.pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.pubads.g.doubleclick.net&lt;BR /&gt;&amp;nbsp;network-object object ADS.s3-ap-southeast-1.amazonaws.com&lt;BR /&gt;&amp;nbsp;network-object object ADS.servedby.adsfactor.net&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If that doesn't work then perhaps it is best to contact TAC, if you have a support contract with Cisco.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 13:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480484#M267236</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-29T13:03:49Z</dc:date>
    </item>
    <item>
      <title>Hi I am geeting into a loop..</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480485#M267239</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am geeting into a loop...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa(config)# no object network ADS.googleads.g.doubleclick.net&lt;BR /&gt;ERROR: unable to delete object (ADS.googleads.g.doubleclick.net). object is being used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa(config)# no object-group network ADS1_BLOCK&lt;BR /&gt;Removing object-group (ADS1_BLOCK) not allowed, it is being used.&lt;/P&gt;&lt;P&gt;Any idea how to solve ???&lt;/P&gt;&lt;P&gt;It is driving me crazy .....-_-"&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 13:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480485#M267239</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-04-29T13:51:55Z</dc:date>
    </item>
    <item>
      <title>You need to remove the access</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480486#M267240</link>
      <description>&lt;P&gt;You need to remove the access-list first.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no access-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Enter this command even though the ACL is not visible in the running configuration.&amp;nbsp; You might want to try the following command to see if the access-list shows up there: &lt;STRONG&gt;show run all &lt;/STRONG&gt;and &lt;STRONG&gt;more system:running-config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;After you have removed the access-list remove the object-group:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no object-group network ADS1_BLOCK&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;--&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 06:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480486#M267240</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-30T06:41:26Z</dc:date>
    </item>
    <item>
      <title>yeah, all the ADS are not</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480487#M267241</link>
      <description>&lt;P&gt;yeah, all the ADS are not resolving to anything, since they don't resolve you are getting this error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Users\jumora&amp;gt;nslookup ADS.cmh.hk.overture.com&lt;BR /&gt;Server:&amp;nbsp; UnKnown&lt;BR /&gt;Address:&amp;nbsp; 10.198.4.30&lt;/P&gt;&lt;P&gt;*** UnKnown can't find ADS.cmh.hk.overture.com: Non-existent domain&lt;/P&gt;&lt;P&gt;C:\Users\jumora&amp;gt;nslookup ADS.googleads.g.doubleclick.net&lt;BR /&gt;Server:&amp;nbsp; UnKnown&lt;BR /&gt;Address:&amp;nbsp; 10.198.4.30&lt;/P&gt;&lt;P&gt;*** UnKnown can't find ADS.googleads.g.doubleclick.net: Non-existent domain&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 21:58:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480487#M267241</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2014-04-30T21:58:43Z</dc:date>
    </item>
    <item>
      <title>thanks - seems no use. Even i</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480488#M267242</link>
      <description>&lt;P&gt;thanks - seems no use. Even i run &lt;STRONG&gt;show run all &lt;/STRONG&gt;and &lt;STRONG&gt;more system:running-config still cannot see the access-list with ADS1_block&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And this is what i have tried:&lt;/P&gt;&lt;P&gt;asa# conf t&lt;BR /&gt;asa(config)# no access-list inside_access_in extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;BR /&gt;Specified access-list does not exist&lt;BR /&gt;asa(config)# no&amp;nbsp; access-list inside_access_in line 9 extended deny ip any object-group ADS1_BLOCK&amp;nbsp; log disable&lt;BR /&gt;Specified access-list does not exist at that line&lt;BR /&gt;asa(config)# show run access-list&lt;BR /&gt;access-list NAT-ACLs extended permit ip 10.71.0.0 255.255.255.0 any4&lt;BR /&gt;access-list inside-in extended deny ip any 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside-in remark -=[Access Lists For Outgoing Packets from Inside interface]=-&lt;BR /&gt;access-list inside-in extended permit udp 10.71.0.0 255.255.255.0 any4 object-group Internet-udp&lt;BR /&gt;access-list inside-in extended permit tcp 10.71.0.0 255.255.255.0 any4 object-group Internet-tcp&lt;BR /&gt;access-list inside-in extended permit icmp 10.71.0.0 255.255.255.0 any4&lt;BR /&gt;access-list outside-in remark -=[Access Lists For Incoming Packets on OUTSIDE interface]=-&lt;BR /&gt;access-list outside-in extended permit icmp any4 any4 echo-reply&lt;BR /&gt;access-list outside-in extended deny tcp any 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny tcp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny udp object my-host 202.128.224.0 255.255.224.0 log alerts&lt;BR /&gt;access-list inside_access_in extended deny tcp object my-host object-group wp-block log disable&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Monitor-remote-tcp log alerts&lt;BR /&gt;access-list inside_access_in extended permit tcp any4 any4 object-group Internet-tcp log disable&lt;BR /&gt;access-list inside_access_in extended permit udp any4 any4 object-group Internet-udp log disable&lt;BR /&gt;access-list inside_access_in extended permit icmp any4 any4 object-group ICMP-Service-Group log disable&lt;BR /&gt;access-list inside_access_in extended permit ip any4 any4 log disable&lt;BR /&gt;access-list outside_access_in extended deny tcp object-group wp-block object pigpigpig-host log alerts&lt;BR /&gt;access-list outside_access_in remark gov&lt;BR /&gt;access-list outside_access_in extended deny object-group DM_INLINE_SERVICE_3 202.128.224.0 255.255.224.0 object my-host log alerts&lt;BR /&gt;access-list outside_access_in remark gov&lt;BR /&gt;access-list outside_access_in extended deny tcp 202.128.224.0 255.255.224.0 object pigpigpig-host log alerts&lt;BR /&gt;access-list outside_access_in extended permit tcp any4 any4 object-group Monitor-remote-tcp log alerts&lt;BR /&gt;access-list outside_access_in extended permit tcp any4 any4 object-group Internet-tcp log disable&lt;BR /&gt;access-list outside_access_in extended permit udp any4 any4 object-group Internet-udp log disable&lt;BR /&gt;access-list outside_access_in extended permit ip any4 any4 log disable&lt;BR /&gt;access-list outside_access_in extended permit icmp any4 any4 object-group ICMP-Service-Group log disable&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip any4 10.71.0.224 255.255.255.224&lt;BR /&gt;access-list split-tunnel standard permit 10.71.0.0 255.255.255.0&lt;BR /&gt;access-list DMZ_access_in extended permit tcp any any object-group Internet-tcp&lt;BR /&gt;access-list DMZ_access_in extended permit ip any any&lt;BR /&gt;access-list DMZ_access_in extended permit udp any any object-group Internet-udp&lt;BR /&gt;access-list DMZ_access_in extended permit icmp any any object-group ICMP-Service-Group&lt;BR /&gt;access-list global_access extended permit tcp any any object-group Internet-tcp&lt;BR /&gt;access-list global_access extended permit udp any any object-group Internet-udp&lt;BR /&gt;access-list global_access extended permit icmp any any object-group ICMP-Service-Group&lt;BR /&gt;access-list global_access extended deny ip 202.128.224.0 255.255.224.0 object pigpigpig-host log alerts&lt;BR /&gt;access-list global_access extended deny ip object my-host 202.128.224.0 255.255.224.0 log alerts&lt;/P&gt;&lt;P&gt;asa(config)#&lt;BR /&gt;asa(config)# no object-group network ADS1_BLOCK&lt;BR /&gt;Removing object-group (ADS1_BLOCK) not allowed, it is being used.&lt;BR /&gt;asa(config)# show run object-group network ADS1_BLOCK&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;asa(config)# show run object-group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;object-group network ADS1_BLOCK&lt;BR /&gt;&amp;nbsp;network-object object ADS.b.voicefive.com&lt;/P&gt;&lt;P&gt;asa(config)#&lt;BR /&gt;asa(config)# no network-object object ADS.b.voicefive.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;asa(config)# object-group network ADS1_BLOCK&lt;BR /&gt;asa(config-network-object-group)# no network-object object ADS.b.voicefive.com&lt;BR /&gt;Removing obj from object-group not allowed;&lt;BR /&gt;object-group (ADS1_BLOCK),&amp;nbsp; being used in access-list or threat-detection or NAT, would become empty&lt;BR /&gt;asa(config-network-object-group)#&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 04:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480488#M267242</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-05-01T04:01:38Z</dc:date>
    </item>
    <item>
      <title>HI jumora, But i don't know</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480489#M267243</link>
      <description>&lt;P&gt;HI jumora,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i don't know if a object name will also used to resolve - -_-"&lt;/P&gt;&lt;P&gt;In the running config:&lt;/P&gt;&lt;P&gt;object network ADS.pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;fqdn v4 pagead2.googlesyndication.com&lt;BR /&gt;&amp;nbsp;description pagead2.googlesyndication.com&lt;/P&gt;&lt;P&gt;In fqdn i defined the proper domain name...&lt;/P&gt;&lt;P&gt;Anyway , do you have suggestion of how can i remove this troubleshome network-groups and network objects?i am running in a loop....thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put ADS.(domain name) is just for easy for me to classify they are ads server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 04:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-got-network-objects-group-and-network-objects-problem/m-p/2480489#M267243</guid>
      <dc:creator>danielchau</dc:creator>
      <dc:date>2014-05-01T04:06:43Z</dc:date>
    </item>
  </channel>
</rss>

