<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You're welcome.  I'm glad it in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298034#M343574</link>
    <description>&lt;P&gt;You're welcome.&amp;nbsp; I'm glad it helped to resolve your problem.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2016 13:33:18 GMT</pubDate>
    <dc:creator>Jesse Peden</dc:creator>
    <dc:date>2016-06-07T13:33:18Z</dc:date>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298021#M343551</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using a cisco ASA 5525 with 8.6 code.&amp;nbsp; I am trying to setup access list for oubound access meaning hosts accessing the internet.&amp;nbsp; I have created an access list called outbound_access and did "access-groupc outbound_access in interface inside "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to use object-groups where ever i can.&amp;nbsp; Here is an example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service obj_Meraki_outbound&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 443&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 80&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 7734&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 7752&lt;/P&gt;&lt;P&gt;service-object udp destination eq 7351&lt;/P&gt;&lt;P&gt;object-group network obj_Meraki_lan&lt;/P&gt;&lt;P&gt;network-object 10.2.11.0 255.255.255.240&lt;/P&gt;&lt;P&gt;network-object 10.5.11.0 255.255.225.240&lt;/P&gt;&lt;P&gt;object-group network obj_Meraki_pub&lt;/P&gt;&lt;P&gt;des This group lists all hosts associated with Meraki.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; network-object host 64.156.192.154&lt;/P&gt;&lt;P&gt;&amp;nbsp; network-object host 64.62.142.12&lt;/P&gt;&lt;P&gt;&amp;nbsp; network-object host 64.62.142.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; network-object host 74.50.51.16&lt;/P&gt;&lt;P&gt;&amp;nbsp; network-object host 74.50.56.218&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;object-group service obj_Meraki_outbound&lt;BR /&gt;service-object tcp destination eq 443&lt;BR /&gt;service-object tcp destination eq 80&lt;BR /&gt;service-object tcp destination eq 7734&lt;BR /&gt;service-object tcp destination eq 7752&lt;BR /&gt;service-object udp destination eq 7351&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network obj_Meraki_lan&lt;BR /&gt;network-object 10.x.x.x 255.255.255.240&lt;BR /&gt;network-object 10.x.x.x 255.255.225.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network obj_Meraki_pub&lt;BR /&gt;des This group lists all hosts associated with Meraki.&amp;nbsp; &lt;BR /&gt;&amp;nbsp; network-object host 64.156.192.154&lt;BR /&gt;&amp;nbsp; network-object host 64.62.142.12&lt;BR /&gt;&amp;nbsp; network-object host 64.62.142.2&lt;BR /&gt;&amp;nbsp; network-object host 74.50.51.16&lt;BR /&gt;&amp;nbsp; network-object host 74.50.56.218&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried tying all these groups together in multiple ways but cannot figure out how to do this.&amp;nbsp; This what i think it should be "access-list outbound_access extended permit object-group obj_Meraki_outbound object-group obj_Meraki_lan object-group obj_Meraki_pub"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i want is the use the service objects and the source network would be obj_Meraki_lan and destination would be obj_Meraki_pub.&amp;nbsp;&amp;nbsp; It seems the rules completely change when you use object groups.&amp;nbsp; Can someone explain this maybe with a few examples.&amp;nbsp; I am already using object groups in many acls but not for every element.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298021#M343551</guid>
      <dc:creator>Jason Flory</dc:creator>
      <dc:date>2019-03-12T02:33:44Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298022#M343553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you provide us with the &lt;STRONG&gt;"show accesslist outbound_access"&lt;/STRONG&gt; output and also the output of &lt;STRONG&gt;"show run access-group"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It just that it seems that the above configuration should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 06:27:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298022#M343553</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-04T06:27:16Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298023#M343556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue you are running into is that you are defining ports where you should be defining which protocol to use&lt;/P&gt;&lt;P&gt;access-list outbound_access extended permit object-group&amp;nbsp; &lt;STRONG&gt;obj_Meraki_outbound&lt;/STRONG&gt; object-group obj_Meraki_lan object-group&amp;nbsp; obj_Meraki_pub&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service obj_Meraki_outbound&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 443&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 80&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 7734&lt;/P&gt;&lt;P&gt;service-object tcp destination eq 7752&lt;/P&gt;&lt;P&gt;service-object udp destination eq 7351&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can either specify the protocol independently or you can use an object-group for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol PROTOCOLS&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then use this in the ACL and place the obj_Meraki_outbound at the end of the ACL...if these are to be destination ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outbound_access extended permit object-group PROTOCOLS object-group obj_Meraki_lan object-group&amp;nbsp; obj_Meraki_pub object-group obj_Meraki_outbound&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 20:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298023#M343556</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-09-04T20:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298024#M343559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version he posted also works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; he uses specifies both protocol and port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example from my firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outbound_access line 1 extended permit object-group obj_Meraki_outbound object-group obj_Meraki_lan object-group obj_Meraki_pub (hitcnt=0) 0x7c4d1265&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list outbound_access line 1 extended permit tcp 10.2.11.0 255.255.255.240 host 64.156.192.154 eq https (hitcnt=0) 0x18a14951&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list outbound_access line 1 extended permit tcp 10.2.11.0 255.255.255.240 host 64.62.142.12 eq https (hitcnt=0) 0x127ea116&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list outbound_access line 1 extended permit tcp 10.2.11.0 255.255.255.240 host 64.62.142.2 eq https (hitcnt=0) 0x842644a4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list outbound_access line 1 extended permit tcp 10.2.11.0 255.255.255.240 host 74.50.51.16 eq https (hitcnt=0) 0x1aba7005&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;REST of="" the="" output="" removed=""&gt;&lt;/REST&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 20:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298024#M343559</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-04T20:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298025#M343562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting.&amp;nbsp; Everytime I have tried it the way he mentions, I have never gotten it to work.&amp;nbsp; The ASA takes the commands but the ACL is never matched.&amp;nbsp; I see you have 0 hits on the ACL... have you tried generating traffic to see if it is matched?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 20:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298025#M343562</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-09-04T20:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298026#M343564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to work on my test ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached it to my current LAN interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# packet-tracer input LAN tcp 10.2.11.1 12345 64.156.192.154 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phase: 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: ROUTE-LOOKUP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Subtype: input&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result: ALLOW&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional Information:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phase: 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: ACCESS-LIST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Subtype: log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result: ALLOW&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-group outbound_access in interface LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outbound_access extended permit object-group obj_Meraki_outbound object-group obj_Meraki_lan object-group obj_Meraki_pub&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group service obj_Meraki_outbound&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq https&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq 7734&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq 7752&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object udp destination eq 7351&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network obj_Meraki_lan&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 10.2.11.0 255.255.255.240&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 10.5.11.0 255.255.255.240&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network obj_Meraki_pub&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; description: This group lists all hosts associated with Meraki.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 64.156.192.154&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 64.62.142.12&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 64.62.142.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 74.50.51.16&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 74.50.56.218&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional Information:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; access-list outbound_access line 1 extended permit tcp 10.2.11.0 255.255.255.240 host 64.156.192.154 eq www (hitcnt=1) 0x4d812691&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also have used such configuration in some special cases where the customer has insisted on allow specific TCP/UDP ports between multiple networks. And nothing is stopping from adding ICMP into the &lt;STRONG&gt;"object-group service"&lt;/STRONG&gt; also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 20:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298026#M343564</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-04T20:25:40Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298027#M343566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah i was wondering about specifying type of protocol but as you see my object-group has both TCP and UDP.&amp;nbsp; But it looks like you have addressed that as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im going to give this a shot.&amp;nbsp; I will post back with results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other question.&amp;nbsp; These ACLs are for outbound traffic to internet and just want to make sure that I should place the ACL on the inside interface.&amp;nbsp; Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 22:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298027#M343566</guid>
      <dc:creator>Jason Flory</dc:creator>
      <dc:date>2013-09-04T22:36:10Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298028#M343568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually you will have INBOUND ACL on each interface controlling traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if we take a simple example with interfaces &lt;STRONG&gt;"inside" , "dmz" &lt;/STRONG&gt;and &lt;STRONG&gt;"outside"&lt;/STRONG&gt; then we would usually configure an ACL for each interface and attached it with the &lt;STRONG&gt;"access-group"&lt;/STRONG&gt; command in the direction &lt;STRONG&gt;"in"&lt;/STRONG&gt; to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These ACLs will essentially control traffic entering that interface from networks that are located behind that interface. So for example &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interfaces ACL in this case would control traffc heading from &lt;STRONG&gt;"inside"&lt;/STRONG&gt; towards any other interface (and the networks behind it) on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the same way an ACL attached to the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface in the direction &lt;STRONG&gt;"in"&lt;/STRONG&gt; will control all traffic coming from the external network towards your local networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So yes, you should control traffic bound to Internet on the LAN/DMZ interfaces with an ACL attached to the direction &lt;STRONG&gt;"in"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 22:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298028#M343568</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-04T22:59:22Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298029#M343569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So I tried the above &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outbound_access extended permit object-group Protocols object-group obj_Meraki_lan object-group obj_Meraki_pub object-group obj_Meraki_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol Protocols &lt;/P&gt;&lt;P&gt;protocol-object TCP&lt;/P&gt;&lt;P&gt;protocol-object UDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is still barking at me.&amp;nbsp; Says ob_Meraki_oubound is not a service type which of course it is.&amp;nbsp;&amp;nbsp; I am looking at other examples of ACLs when using enhanced object groups and it seems the service-objects do not go at the end like normal.&amp;nbsp; See this &lt;A _jive_internal="true" href="https://community.cisco.com/thread/2063088"&gt;https://supportforums.cisco.com/thread/2063088&lt;/A&gt;&amp;nbsp;&amp;nbsp; When ever i see object-groups being used for service object is goes right after permit protocol type is not required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 23:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298029#M343569</guid>
      <dc:creator>Jason Flory</dc:creator>
      <dc:date>2013-09-04T23:00:05Z</dc:date>
    </item>
    <item>
      <title>Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298030#M343570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; This format worked.&amp;nbsp; At least the ASA accepted the acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outbound_access extended permit object-group obj_Meraki_outbound object-group obj_Meraki_lan object-group obj_Meraki_pub.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder why they change the complete structure of the ACL when you use service objects.&amp;nbsp; AHHG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 23:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298030#M343570</guid>
      <dc:creator>Jason Flory</dc:creator>
      <dc:date>2013-09-04T23:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Access list with multiple object groups</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298031#M343571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change the obj_Meraki_outbound object to the following and try again please. (notice the TCP-UDP keyword at the end of the object-group statement)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group service obj_Meraki_outbound tcp-udp&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq https&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq 7734&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object tcp destination eq 7752&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service-object udp destination eq 7351&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outbound_access extended permit object-group PROTOCOLS&amp;nbsp; object-group obj_Meraki_lan object-group&amp;nbsp; obj_Meraki_pub object-group&amp;nbsp; obj_Meraki_outbound&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 19:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298031#M343571</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-09-05T19:34:44Z</dc:date>
    </item>
    <item>
      <title>You can't define a protocol</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298032#M343572</link>
      <description>&lt;P&gt;You can't define a protocol on the object-group and then use service-object entries; if you want to define tcp-udp you will have to use port-object instead of service-object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group service obj_Meraki_outbound tcp-udp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port-object eq https&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port-object eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port-object eq 7734&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port-object eq 7752&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port-object eq 7351&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 19:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298032#M343572</guid>
      <dc:creator>Jesse Peden</dc:creator>
      <dc:date>2015-04-23T19:26:22Z</dc:date>
    </item>
    <item>
      <title>Jesse, funny how your</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298033#M343573</link>
      <description>&lt;P&gt;Jesse, funny how your contribution helped me solve my problem which is slightly different from Jason's problem.&lt;/P&gt;
&lt;P&gt;The problem I had was not being able to go beyond:&lt;/P&gt;
&lt;P&gt;ASA(config)# access-list problem extended permit object-group services ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA(config)# access-list problem extended permit object-group services&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Your message made me look again at my service object group configuration:&lt;/P&gt;
&lt;P&gt;object-group service services tcp&lt;BR /&gt;port-object range 3000&amp;nbsp;3500&lt;BR /&gt;port-object range 10000 10500&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I went ahead to reconfigure it like so:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object-group service service&lt;/SPAN&gt;&lt;SPAN&gt;s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;service-object tcp destination&amp;nbsp;range 3&lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;00&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;3500&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;service-object tcp destination range 1&lt;/SPAN&gt;&lt;SPAN&gt;0000&lt;/SPAN&gt;&lt;SPAN&gt; 1&lt;/SPAN&gt;&lt;SPAN&gt;0500&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Straight away, I was able to complete the access-list command and apply it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;ASA(config)# access-list problem extended permit object-group services object-group ip1 object-group ip2&lt;BR /&gt;ASA(config)#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks guys!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 12:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298033#M343573</guid>
      <dc:creator>emeka.ibeto</dc:creator>
      <dc:date>2016-06-07T12:42:28Z</dc:date>
    </item>
    <item>
      <title>You're welcome.  I'm glad it</title>
      <link>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298034#M343574</link>
      <description>&lt;P&gt;You're welcome.&amp;nbsp; I'm glad it helped to resolve your problem.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 13:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-with-multiple-object-groups/m-p/2298034#M343574</guid>
      <dc:creator>Jesse Peden</dc:creator>
      <dc:date>2016-06-07T13:33:18Z</dc:date>
    </item>
  </channel>
</rss>

