<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM add host into object-group issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627510#M595141</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That seems to be just fine.&lt;/P&gt;&lt;P&gt;It seems to be that you are hitting one or both the bugs that you mentioned earlier. Please upgrade the FWSM to at least the latest version of 3.2.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Jan 2011 11:13:04 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-01-06T11:13:04Z</dc:date>
    <item>
      <title>FWSM add host into object-group issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627507#M595128</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used FWSM on 6500 with software 3.1(3)&lt;/P&gt;&lt;P&gt;When i add hosts or services into exising object-group, firewall don't perform process on exisiting ACL involve that object-group.&lt;/P&gt;&lt;P&gt;I have to remove ACL and re-insert once to activate. I tested on 10 times found issue 7-8 times. I'm sure this is bug or not but i found some bug may be related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H6 class="alt-2"&gt;CSCtd78604&lt;/H6&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="padding: 8px; font-size: 88%;"&gt;&lt;SPAN&gt;&lt;STRONG&gt;FWSM: ACLs missing after adding items to object-groups &lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 0px 8px 8px; font-size: 88%;" valign="top"&gt;&lt;SPAN&gt; &lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt;If adding additional network-objects to object-groups fails with the following error, "access-list" lines may be missing from the config afterwards:&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;H6 class="alt-2"&gt;CSCse60868&lt;/H6&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="padding: 8px; font-size: 88%;"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Modifying an ACL with an object-group could cause ACL corruption &lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 0px 8px 8px; font-size: 88%;" valign="top"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627507#M595128</guid>
      <dc:creator>Rojer-bkk</dc:creator>
      <dc:date>2019-03-11T19:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM add host into object-group issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627508#M595133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FWSM version 3.1.3 is quite an old version of code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please check if ACL count has hit the hardware limit? Please share the output of "show np 3 acl stats" from the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, it does seem to match bugID CSCtd78604, but it might be a good idea to open a TAC case to further investigate the issue, OR/ I would recommend upgrading the FWSM to at least the latest version of 3.2.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 09:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627508#M595133</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-06T09:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM add host into object-group issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627509#M595137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your advised. Here is output from internal-server context&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh np 3 acl stats &lt;BR /&gt;----------------------------&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACL Tree Statistics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;----------------------------&lt;BR /&gt;Rule count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp; 496&lt;BR /&gt;Bit nodes (PSCB's):&amp;nbsp;&amp;nbsp;&amp;nbsp; 464&lt;BR /&gt;Leaf nodes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp; 465&lt;BR /&gt;Total nodes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp; 929 (max&amp;nbsp; 28356)&lt;BR /&gt;Leaf chains&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 42&lt;BR /&gt;Total stored rules:&amp;nbsp;&amp;nbsp;&amp;nbsp; 496&lt;BR /&gt;Max rules in leaf :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;BR /&gt;Node depth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&lt;BR /&gt;----------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is output from admin context&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh np 3 acl stats &lt;BR /&gt;----------------------------&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACL Tree Statistics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;----------------------------&lt;BR /&gt;Rule count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45&lt;BR /&gt;Bit nodes (PSCB's):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40&lt;BR /&gt;Leaf nodes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41&lt;BR /&gt;Total nodes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 81 (max&amp;nbsp; 28356)&lt;BR /&gt;Leaf chains&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&lt;BR /&gt;Total stored rules:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55&lt;BR /&gt;Max rules in leaf :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;BR /&gt;Node depth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9&lt;BR /&gt;----------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 10:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627509#M595137</guid>
      <dc:creator>Rojer-bkk</dc:creator>
      <dc:date>2011-01-06T10:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM add host into object-group issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627510#M595141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That seems to be just fine.&lt;/P&gt;&lt;P&gt;It seems to be that you are hitting one or both the bugs that you mentioned earlier. Please upgrade the FWSM to at least the latest version of 3.2.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 11:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627510#M595141</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-06T11:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM add host into object-group issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627511#M595148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The one that you found CSCse60868 is ONE reason why you should upgrade.&lt;/P&gt;&lt;P&gt;This one jumbles the acl and puts the implicit deny on the top of the acl thereby denying all permit traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There was a PSIRT on this one that you can read here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/warp/public/707/cisco-sa-20070214-fwsm.shtml"&gt;http://www.cisco.com/warp/public/707/cisco-sa-20070214-fwsm.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM code download link:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/cgi-bin/tablebuild.pl/cat6000-fwsm"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/cat6000-fwsm&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt; Click on the All new releases will be available "here"&lt;BR /&gt; &lt;BR /&gt; The latest in the 3.1.x train 3.1.(19)&lt;BR /&gt; The latest in the 4.0 train is 4.0.13&lt;BR /&gt; The latest in the 3.2 train is 3.2.(19)&lt;BR /&gt; The latest in the 4.1 train is 4.1(3)&lt;BR /&gt; ASDM is asdm-62(1)f.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 15:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-add-host-into-object-group-issue/m-p/1627511#M595148</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-06T15:20:05Z</dc:date>
    </item>
  </channel>
</rss>

