<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reg. ASDM Object grouping in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480424#M717518</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply ; however 8.2.1 (18) code with ASDM 6.2 (1) is also running and showing the same thing . Also i believe from the compatibilty matrix we can use ASDM 6.3.1 (which is recommended) with any of the 8.2 Versions .Can you please try this in lab or test with demo ASDM . Meanwhile i am also trying to figure out at my end . thanks a lot !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 30 May 2010 23:40:59 GMT</pubDate>
    <dc:creator>ankurs2008</dc:creator>
    <dc:date>2010-05-30T23:40:59Z</dc:date>
    <item>
      <title>Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480420#M717504</link>
      <description>&lt;P&gt;In the ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Objects -&amp;gt; Network objects/Groups&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we click on &lt;STRONG&gt;Add Network Object&lt;/STRONG&gt; then consider the name which we specify is TEST1 and IP Address Range is 10.10.0.0 255.255.255.0 and we create one more Network Object and then we specify name as TEST2 and IP Address Range is 10.10.0.0 255.255.255.192 .Once we apply , then the previous network object TEST1] is replaced with the newer name [TEST2] .That means now there are 2 Network Objects entries with the same name in ASDM as shown below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TEST2 10.10.0.0 255.255.255.0&lt;BR /&gt;TEST2 10.10.0.0 255.255.255.192&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is equivalent to name command in CLI and doing a "sh name" will give single TEST2 with no subnet information over there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence please let me know if this is normal or is it a bug . I have found this in 6.3.1 , is this same in other versions as well ? Also is there any workaround to have 2 different names for similar IP Range with different mask with the above [other than the solution of creating object-group and assigning network-object to it , which i know will obviously work]&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480420#M717504</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2019-03-11T17:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480421#M717506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Definitely sounds like a bug.&lt;/P&gt;&lt;P&gt;Which version of ASA are you running? If you are running version 8.2.x or lower, I would recommend that you downgrade your ASDM to version 6.2.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 12:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480421#M717506</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-28T12:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480422#M717508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running 8.2.1 (18) code with ASDM 6.2 (1) , found this issue in this as well as one firewall having ASA 8.2.2 with ASDM 6.3.1 .Please let me know regarding the same&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 12:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480422#M717508</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-05-28T12:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480423#M717513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASDM 6.3.1 is new and also to support ASA 8.3.1. Eventhough it is backward compatible, there seems to be a number of bugs with earlier version of ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend that you downgrade the ASDM back to 6.2.5 since you are not running ASA 8.3.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 12:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480423#M717513</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-28T12:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480424#M717518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply ; however 8.2.1 (18) code with ASDM 6.2 (1) is also running and showing the same thing . Also i believe from the compatibilty matrix we can use ASDM 6.3.1 (which is recommended) with any of the 8.2 Versions .Can you please try this in lab or test with demo ASDM . Meanwhile i am also trying to figure out at my end . thanks a lot !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 May 2010 23:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480424#M717518</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-05-30T23:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480425#M717523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ankur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested it in the lab, and realise that the ASDM network object should not have a netmask field because the "name" command does not have subnet field. That is why your test is getting overriden with the later name that you configured (TEST2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "name" command only have the following fields:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;&lt;STRONG class="cBold"&gt;name &lt;/STRONG&gt;&lt;EM class="cCi_CmdItalic" style="font-style: italic;"&gt;ip_address name&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: normal;"&gt; [description &lt;/SPAN&gt;&lt;EM class="cCi_CmdItalic" style="font-style: italic;"&gt;text&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: normal;"&gt;]] &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;Here is the command reference for "name" command for your reference:&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/no.html#wp1747000"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/no.html#wp1747000&lt;/A&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;You can open a TAC case so ASDM bug can be raised.&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;&lt;/P&gt;&lt;P class="pCE_CmdEnv"&gt;Hope that helps to clarify your concern.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2010 10:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480425#M717523</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-31T10:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480426#M717527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi halijenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried with 6.2.5 ASDM code as well and the same results . Also there is subnet mask associated with the network-object while creating via ASDM and the same can be pulled into an access-list (via ASDM Browse option) to use any of those 2 names ; hence in this case even though 2 network-object having same name we can still pull our desired network-object into it . However via command line , in the "sh names" it will only show 1 name (though actually we have made 2 ) and when we will apply it in access-list (via CLI) we can utilize that name however we have to give subnet mask in ACL at that point of time .Hence , conclusion is : subnet mask of network-object useful in ASDM ; however not in the CLI .As this is almost on all ASDM i dont think it is a bug as otherwise ,it wud by now have been known by everybody .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 00:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480426#M717527</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-01T00:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480427#M717532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi halijenn&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Please reply to my below query , thanks . &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 00:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480427#M717532</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-02T00:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. ASDM Object grouping</title>
      <link>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480428#M717539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ankur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 2 options when configuring object group via ASDM (the name is not very intuitive and does not match with CLI):&lt;/P&gt;&lt;P&gt;1) The name command on CLI --&amp;gt; Network Object&lt;/P&gt;&lt;P&gt;2) The object-group command on CLI --&amp;gt; Network Object Group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the first one, as advised earlier, the name command on CLI does not have the subnet mask entry included. You can actually check that by creating a "Network Object" with the mask on ASDM, and when you click Apply, it will come up with a pop up box on what command is actually sent to the ASA, and it will not include the mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Example (Attached)&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;ASDM configuration for Network Object: ASDM-NetworkObject-name.JPG&lt;/P&gt;&lt;P&gt;CLI that is being sent to the ASA when clicking on the Apply button: CLI-sent-to-ASA.JPG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see that on ASDM (Network Object) corresponds to the CLI (name command), and it does not include the subnet mask in the actual "name" command. On ASDM, it is more for your information on what subnet mask the object is, however, you can't really configure the same name with the same IP Subnet and differentiate between the 2 with subnet mask.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 08:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-asdm-object-grouping/m-p/1480428#M717539</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-02T08:46:06Z</dc:date>
    </item>
  </channel>
</rss>

