<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic object-group? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313171#M311659</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say I have an internal server with IP address of 2.2.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service TEST&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8888&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8081&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Out-In extended permit object-group TEST any host 2.2.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group Out-In in interface Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input outside tcp 4.2.2.2 1025&amp;nbsp; 2.2.2.3 8888&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 2.2.2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; Inside_1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group Out-In in interface Outside&lt;/P&gt;&lt;P&gt;access-list Out-In extended permit object-group TEST any host 2.2.2.3&lt;/P&gt;&lt;P&gt;object-group service TEST&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8888&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8081&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 2, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: Inside_1&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's it!! And remember to register on my website for more information &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information about Core and Security Networking follow my website at &lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Oct 2013 17:27:42 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-10-02T17:27:42Z</dc:date>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313169#M311657</link>
      <description>&lt;P&gt;Thanks for reading!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to organize these tcp ports into an object group on my ASA5520.&amp;nbsp; The ACLs are organized and I want to keep it that way.&amp;nbsp; The only option I know of is to enter the rule 7 times - doh!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8443&lt;BR /&gt;8888&lt;BR /&gt;9000&lt;BR /&gt;8081&lt;BR /&gt;8000&lt;BR /&gt;1099&lt;BR /&gt;9011&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Seems &lt;/EM&gt;like it should be easy but I'm just not getting the right search string to find an answer.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313169#M311657</guid>
      <dc:creator>Bob Greer</dc:creator>
      <dc:date>2019-03-12T02:46:16Z</dc:date>
    </item>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313170#M311658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not quiet understanding your question… so you have an acl applied on an interface already and you don’t want it to be changed? By change you mean the order of actual acls entries?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 17:16:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313170#M311658</guid>
      <dc:creator>Saqib Raza</dc:creator>
      <dc:date>2013-10-02T17:16:45Z</dc:date>
    </item>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313171#M311659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say I have an internal server with IP address of 2.2.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service TEST&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8888&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8081&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Out-In extended permit object-group TEST any host 2.2.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group Out-In in interface Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input outside tcp 4.2.2.2 1025&amp;nbsp; 2.2.2.3 8888&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 2.2.2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; Inside_1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group Out-In in interface Outside&lt;/P&gt;&lt;P&gt;access-list Out-In extended permit object-group TEST any host 2.2.2.3&lt;/P&gt;&lt;P&gt;object-group service TEST&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8888&lt;/P&gt;&lt;P&gt; service-object tcp destination eq 8081&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 2, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: Inside_1&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's it!! And remember to register on my website for more information &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information about Core and Security Networking follow my website at &lt;STRONG&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 17:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313171#M311659</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-02T17:27:42Z</dc:date>
    </item>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313172#M311660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Saqib,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for taking the time to read and answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm trying to do is add a new rule allowing a DMZ server (x.x.x.x) to connect to an internal server (b.b.b.b) over a handful of tcp ports.&amp;nbsp; I could enter&amp;nbsp; (basically) the same command 7 times,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_DMZ-INET_IN extended permit tcp host x.x.x.x host b.b.b.b eq 8443&lt;BR /&gt;access-list ACL_DMZ-INET_IN extended permit tcp host x.x.x.x host b.b.b.b eq 8888&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;access-list ACL_DMZ-INET_IN extended permit tcp host x.x.x.x host b.b.b.b eq 9011&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only changing the permitted port.&amp;nbsp; I'm hoping there's an option to aggregate the tcp ports into some kind of group and then invoke the group in only one new ACL rule.&amp;nbsp; That way, I keep the list 6 lines shorter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's really my goal (apart from making the stuff work - heh): adding fewer lines to the ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;BR /&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 18:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313172#M311660</guid>
      <dc:creator>Bob Greer</dc:creator>
      <dc:date>2013-10-02T18:59:55Z</dc:date>
    </item>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313173#M311661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for taking time to generate this example.&amp;nbsp; Sorry to be obtuse: could you dumb this down a little?&lt;/P&gt;&lt;P&gt;I think I'm seeeing object-group service TEST is where I'd create 7 service objects?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 8443&lt;BR /&gt;service-object tcp destination eq 8888&lt;BR /&gt;service-object tcp destination eq 9000&lt;BR /&gt;service-object tcp destination eq 8081&lt;BR /&gt;service-object tcp destination eq 8000&lt;BR /&gt;service-object tcp destination eq 1099&lt;BR /&gt;service-object tcp destination eq 9011&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then invoke the object-group like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MY_NAMED_ACL extended permit object-group TEST DMZ_SERVER host 2.2.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I correct?&lt;/P&gt;&lt;P&gt;Thanks again!&lt;BR /&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 19:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313173#M311661</guid>
      <dc:creator>Bob Greer</dc:creator>
      <dc:date>2013-10-02T19:14:04Z</dc:date>
    </item>
    <item>
      <title>object-group?</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/2313174#M311662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No problem that's what we are here to help &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly you got it my friend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes and remember to subscribe to my website for future documentation such as the one I exposed here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 19:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/2313174#M311662</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-02T19:18:47Z</dc:date>
    </item>
  </channel>
</rss>

