<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Common groups across multiple firewalls in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184956#M351345</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if there is an easy way to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following command to view all "object-group" on the firewall (both service and network type object-groups)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following commands to show all the certain types of "object-group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show&amp;nbsp; run object-group network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group service&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group protocol&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know a name of an "object-group" you can view its configuration with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group id &lt;OBJECT-GROUP name=""&gt;&lt;/OBJECT-GROUP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest of the commands to my understanding would be using some search string to filter the search results&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example to just get the names names of the "object-group" configured on the firewall you could use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group | inc object-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though this would also show the ACLs where the "object-group" are used too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And naturally there is multitude of different versions of the above according to what search string you use after the "| inc" parf of the above commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are just trying to find same named "object-group" on the firewalls then you can just filter the configurations with the name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh run object-group | inc &lt;OBJECT-GROUP name=""&gt;&lt;/OBJECT-GROUP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searching for object-groups which contain the same objects under them would be a bit harder. Especially if we are talking about "object-group" which contain multiple objects under them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Apr 2013 06:07:02 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-20T06:07:02Z</dc:date>
    <item>
      <title>Common groups across multiple firewalls</title>
      <link>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184955#M351343</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;I need to review network objects groups&amp;nbsp; in the firewalls for some project work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;Then i need to find common group across all the firewalls&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;as well as objects in those common groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;Need to undertsand&amp;nbsp; how can i start this work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;What commands should i run on the firewalls?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: Calibri;"&gt;Mahesh&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184955#M351343</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:32:08Z</dc:date>
    </item>
    <item>
      <title>Common groups across multiple firewalls</title>
      <link>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184956#M351345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if there is an easy way to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following command to view all "object-group" on the firewall (both service and network type object-groups)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following commands to show all the certain types of "object-group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show&amp;nbsp; run object-group network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group service&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group protocol&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know a name of an "object-group" you can view its configuration with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group id &lt;OBJECT-GROUP name=""&gt;&lt;/OBJECT-GROUP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest of the commands to my understanding would be using some search string to filter the search results&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example to just get the names names of the "object-group" configured on the firewall you could use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group | inc object-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though this would also show the ACLs where the "object-group" are used too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And naturally there is multitude of different versions of the above according to what search string you use after the "| inc" parf of the above commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are just trying to find same named "object-group" on the firewalls then you can just filter the configurations with the name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh run object-group | inc &lt;OBJECT-GROUP name=""&gt;&lt;/OBJECT-GROUP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searching for object-groups which contain the same objects under them would be a bit harder. Especially if we are talking about "object-group" which contain multiple objects under them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Apr 2013 06:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184956#M351345</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-20T06:07:02Z</dc:date>
    </item>
    <item>
      <title>Re:Common groups across multiple firewalls</title>
      <link>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184957#M351347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;You can use rancid to grap the configs and then some perl, Python magic Tod compare the object groups .&lt;BR /&gt;&lt;BR /&gt;Hth&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Apr 2013 10:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/common-groups-across-multiple-firewalls/m-p/2184957#M351347</guid>
      <dc:creator>patrick.preuss</dc:creator>
      <dc:date>2013-04-20T10:07:35Z</dc:date>
    </item>
  </channel>
</rss>

