<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASDM multiple network objects vs group for rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845513#M492151</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, it will be better because the processing that the ASA is going to use to determine witch rule to match would be decremented, also it would take less space on the configuration file (memory). those are some of the pros regarding creating groups for particular rules.&lt;/P&gt;&lt;P&gt;Sometimes a huge configuration file can increment the CPU usage,etc,etc. so it is better to keep it as small and organized as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Nov 2011 21:51:42 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-11-29T21:51:42Z</dc:date>
    <item>
      <title>ASDM multiple network objects vs group for rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845512#M492149</link>
      <description>&lt;P&gt;I was just curious if there are any performance benefits of using multiple network objects on multiple rules vs consolidating them into fewer rules by grouping them?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have about 10 lines of NAT exempt rules from the same source to multiple destinations.&amp;nbsp; Is there anything to be gained if I consolidated those into a single rule using an object group for the multiple destinations aside from cleaning up the clutter in ASDM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:57:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845512#M492149</guid>
      <dc:creator>Tony Kan</dc:creator>
      <dc:date>2019-03-11T21:57:02Z</dc:date>
    </item>
    <item>
      <title>ASDM multiple network objects vs group for rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845513#M492151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, it will be better because the processing that the ASA is going to use to determine witch rule to match would be decremented, also it would take less space on the configuration file (memory). those are some of the pros regarding creating groups for particular rules.&lt;/P&gt;&lt;P&gt;Sometimes a huge configuration file can increment the CPU usage,etc,etc. so it is better to keep it as small and organized as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 21:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845513#M492151</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-11-29T21:51:42Z</dc:date>
    </item>
    <item>
      <title>ASDM multiple network objects vs group for rules</title>
      <link>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845514#M492153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well using object group is easy for sure no performance benifit but easy to manage things also less configuration is required . Consider it like if you need to same ACL -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source is A &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination B C D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total 4 ACL right instead of doing that you can create two object groups Object A and B and you can add networks over there . When you will look at actual lines added would be 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so nothing but it makes job easy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 21:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-multiple-network-objects-vs-group-for-rules/m-p/1845514#M492153</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-11-29T21:53:32Z</dc:date>
    </item>
  </channel>
</rss>

