<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Object groups creation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918626#M5620</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a question in creating most effective way on object-groups.&lt;/P&gt;&lt;P&gt;I have two hosts in different public cloud coming into my onprem network and talking to two hosts in same network behind firewall, what would be the best way to create object-groups and make acls.&lt;/P&gt;&lt;P&gt;options:&lt;/P&gt;&lt;P&gt;1. should i create separate object-group for each host and make an acl accordingly.&lt;/P&gt;&lt;P&gt;2. should i create a single object-group for hosts in public cloud and another object-group for hosts in internal work and map them with acl.&lt;/P&gt;&lt;P&gt;3. should i create separate object-group for each host on public cloud, single object-group for internal hosts and create 2 acl's mapping first public object-group with internal object-group and second object-group with internal object-group.&lt;/P&gt;&lt;P&gt;Please provide me suggestions, as connections coming from public network i want firewall rules to be more precise.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:27:22 GMT</pubDate>
    <dc:creator>venkat_n7</dc:creator>
    <dc:date>2020-02-21T17:27:22Z</dc:date>
    <item>
      <title>Object groups creation</title>
      <link>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918626#M5620</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a question in creating most effective way on object-groups.&lt;/P&gt;&lt;P&gt;I have two hosts in different public cloud coming into my onprem network and talking to two hosts in same network behind firewall, what would be the best way to create object-groups and make acls.&lt;/P&gt;&lt;P&gt;options:&lt;/P&gt;&lt;P&gt;1. should i create separate object-group for each host and make an acl accordingly.&lt;/P&gt;&lt;P&gt;2. should i create a single object-group for hosts in public cloud and another object-group for hosts in internal work and map them with acl.&lt;/P&gt;&lt;P&gt;3. should i create separate object-group for each host on public cloud, single object-group for internal hosts and create 2 acl's mapping first public object-group with internal object-group and second object-group with internal object-group.&lt;/P&gt;&lt;P&gt;Please provide me suggestions, as connections coming from public network i want firewall rules to be more precise.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918626#M5620</guid>
      <dc:creator>venkat_n7</dc:creator>
      <dc:date>2020-02-21T17:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Object groups creation</title>
      <link>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918678#M5621</link>
      <description>&lt;P&gt;Personally i would go with One Object Group for external one, and one for internal one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since most of the traffic coming from outside interface and going to inside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Until you have different nameif and different context in place.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 07:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918678#M5621</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-09-04T07:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Object groups creation</title>
      <link>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918753#M5623</link>
      <description>&lt;P&gt;The question is more what your security-policy mandates here. If you use the host-to-host approach (probably also including services) that it is more precise, but also more work. But typically this is the way to go to only allow the traffic that is really needed.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 09:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-groups-creation/m-p/3918753#M5623</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-09-04T09:42:47Z</dc:date>
    </item>
  </channel>
</rss>

