<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Use of TCP-UDP-Service Groups in ASDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975257#M918241</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use a Cisco ASDM 5.2F for ASDM.&lt;/P&gt;&lt;P&gt;There is the possibility of defining TCP-UDP Service Groups. What's the use of this? I've tried it out and failed. Whenever you create an access rule you have to define either whether it's TCP or UDP (or IP, or ICMP). If you define an access rule for TCP then the UDP protocols won't work and vice versa. &lt;/P&gt;&lt;P&gt;I've successfully been using TCP-UDP-Groups on Checkpoint Firewalls, but in Cisco ASDM it seems futile. &lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:40:17 GMT</pubDate>
    <dc:creator>Beat.Traber</dc:creator>
    <dc:date>2019-03-26T00:40:17Z</dc:date>
    <item>
      <title>Use of TCP-UDP-Service Groups in ASDM</title>
      <link>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975257#M918241</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use a Cisco ASDM 5.2F for ASDM.&lt;/P&gt;&lt;P&gt;There is the possibility of defining TCP-UDP Service Groups. What's the use of this? I've tried it out and failed. Whenever you create an access rule you have to define either whether it's TCP or UDP (or IP, or ICMP). If you define an access rule for TCP then the UDP protocols won't work and vice versa. &lt;/P&gt;&lt;P&gt;I've successfully been using TCP-UDP-Groups on Checkpoint Firewalls, but in Cisco ASDM it seems futile. &lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975257#M918241</guid>
      <dc:creator>Beat.Traber</dc:creator>
      <dc:date>2019-03-26T00:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Use of TCP-UDP-Service Groups in ASDM</title>
      <link>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975258#M918242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This feature was introduced 'in parity' of Checkpoint only, as per the ASA 8.0 TAC training.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not really that good with ASDM, but here is how you can configure them on the CLI (and no there are not futile, pretty useful actually):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml#serv" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml#serv&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Enhanced service object-groups were introduced with the release of software version 8.0. Enhanced service object-groups enable the ASA/PIX to combine IP protocols together in the same service group, which eliminates the need for protocol and icmp-type specific object groups. The protocol type must not be specified in order to configure an enhanced service object-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw are you using an ASA or a FWSM? Is'nt ASDM 5.2F supposed to be for the FWSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975258#M918242</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-17T09:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Use of TCP-UDP-Service Groups in ASDM</title>
      <link>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975259#M918243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, and yes, of course I'm using ASDM on top of a FWSM.&lt;/P&gt;&lt;P&gt;I'll try and configure it on the CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975259#M918243</guid>
      <dc:creator>Beat.Traber</dc:creator>
      <dc:date>2008-06-17T09:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Use of TCP-UDP-Service Groups in ASDM</title>
      <link>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975260#M918244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry I did not read your post carefully the first time. I don't think the feature mentioned in the link is supported on the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regard what you are trying to achive, this is from one of my earlier posts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you define the object-group using both the tcp-udp keyword, there is no real security issue here. Because service type object-group is just defining the ports, you would still need two seperate ACLs here, for example: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any host 5.5.5.5 object-group ntp&lt;/P&gt;&lt;P&gt;access-list 100 permit udp any host 5.5.5.5 object-group ntp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course you could make a separate protocol object-group to combine both tcp and udp into one (I do this at work), for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol TCP-UDP&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would make above ACL like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit object-group tcp-udp any host 5.5.5.5 object-group ntp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 10:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/use-of-tcp-udp-service-groups-in-asdm/m-p/975260#M918244</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-17T10:32:34Z</dc:date>
    </item>
  </channel>
</rss>

