<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASDM bug with network object groups?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147174#M861197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To use object groups in an access list, replace the normal protocol (protocol), network (source_address mask, etc.), service (operator port), or ICMP type (icmp_type) parameter with object-group grp_id parameter. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, to use object groups for all available parameters in the access-list {tcp | udp} command, enter the following command: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# access-list access_list_name [line line_number] [extended] {deny | &lt;/P&gt;&lt;P&gt;permit} {tcp | udp} object-group nw_grp_id [object-group svc_grp_id] object-group &lt;/P&gt;&lt;P&gt;nw_grp_id [object-group svc_grp_id] [log [[level] [interval secs] | disable | default]] &lt;/P&gt;&lt;P&gt;[inactive | time-range time_range_name]&lt;/P&gt;&lt;P&gt;You do not have to use object groups for all parameters; for example, you can use an object group for the source address, but identify the destination address with an address and mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Apr 2009 22:17:42 GMT</pubDate>
    <dc:creator>ivillegas</dc:creator>
    <dc:date>2009-04-09T22:17:42Z</dc:date>
    <item>
      <title>ASDM bug with network object groups??</title>
      <link>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147173#M861192</link>
      <description>&lt;P&gt;I have a possible bug when creating an Access Rule that happens sporatically.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using a Network Object Group with 3 members as the Destination, the ACL blocks the source that I want to permit.  However, when I break up the Network Object Group into 3 individual destination hosts, the ACL works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced this???  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5520 Version 8.0(4) &lt;/P&gt;&lt;P&gt;ASDM 6.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147173#M861192</guid>
      <dc:creator>chendav11</dc:creator>
      <dc:date>2019-03-11T15:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM bug with network object groups??</title>
      <link>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147174#M861197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To use object groups in an access list, replace the normal protocol (protocol), network (source_address mask, etc.), service (operator port), or ICMP type (icmp_type) parameter with object-group grp_id parameter. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, to use object groups for all available parameters in the access-list {tcp | udp} command, enter the following command: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# access-list access_list_name [line line_number] [extended] {deny | &lt;/P&gt;&lt;P&gt;permit} {tcp | udp} object-group nw_grp_id [object-group svc_grp_id] object-group &lt;/P&gt;&lt;P&gt;nw_grp_id [object-group svc_grp_id] [log [[level] [interval secs] | disable | default]] &lt;/P&gt;&lt;P&gt;[inactive | time-range time_range_name]&lt;/P&gt;&lt;P&gt;You do not have to use object groups for all parameters; for example, you can use an object group for the source address, but identify the destination address with an address and mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2009 22:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147174#M861197</guid>
      <dc:creator>ivillegas</dc:creator>
      <dc:date>2009-04-09T22:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM bug with network object groups??</title>
      <link>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147175#M861200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post your object group and the access list used for that object group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2009 23:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-bug-with-network-object-groups/m-p/1147175#M861200</guid>
      <dc:creator>roshan.maskey</dc:creator>
      <dc:date>2009-04-09T23:19:45Z</dc:date>
    </item>
  </channel>
</rss>

