<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,Try the following in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-access-object-groups-not-working/m-p/2565712#M921753</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try the following configuration:&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-IN-V1&lt;BR /&gt;&amp;nbsp;permit tcp&amp;nbsp; object-group GG-CDE object-group RemoteConsole object-group GG-Internal&lt;/P&gt;&lt;P&gt;// from servers tcp ports vnc/rdp to clients&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-OUT-V1&lt;BR /&gt;&amp;nbsp;permit tcp&amp;nbsp; object-group GG-Internal object-group GG-CDE object-group RemoteConsole&lt;/P&gt;&lt;P&gt;//from clients to servers on tcp ports rdp/vnc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pedro Lereno&lt;/P&gt;</description>
    <pubDate>Wed, 15 Oct 2014 12:46:27 GMT</pubDate>
    <dc:creator>Pedro Lereno</dc:creator>
    <dc:date>2014-10-15T12:46:27Z</dc:date>
    <item>
      <title>Ip access object groups not working</title>
      <link>https://community.cisco.com/t5/network-security/ip-access-object-groups-not-working/m-p/2565711#M921751</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a Cisco 2901 router running 15.3 (M3) that I am trying to setup a basic firewall on.&amp;nbsp; I want to remote console into computers from only certain IP addresses.&amp;nbsp;&amp;nbsp; I've created the objects and rules below and applied&amp;nbsp; then to the subinterface, but when I do that it cuts off all data from the subinterface.&amp;nbsp; There are a lot more rules, but I just cut it down so I can figure out where I went wrong.&amp;nbsp; Basiclly, I want anyone on the 192.168 subnet to be able to VNC, or RDP into a machine on the 10.100 network.&amp;nbsp; I'm hoping someone can point out where I went wrong.&amp;nbsp;&amp;nbsp; Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group network GG-Internal&lt;BR /&gt;&amp;nbsp;192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object-group network GG-CDE&lt;BR /&gt;&amp;nbsp;10.100.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object-group service RemoteConsole&lt;BR /&gt;&amp;nbsp;tcp eq 3389&lt;BR /&gt;&amp;nbsp;tcp eq 5900&lt;BR /&gt;&amp;nbsp;tcp eq 5902&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-IN-V1&lt;BR /&gt;&amp;nbsp;permit object-group RemoteConsole object-group GG-CDE object-group GG-Internal&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-OUT-V1&lt;BR /&gt;&amp;nbsp;permit object-group RemoteConsole object-group GG-Internal object-group GG-CDE&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.5&lt;BR /&gt;&amp;nbsp;encapsulation dot1Q 5&lt;BR /&gt;&amp;nbsp;ip address 10.100.3.252 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip policy route-map clear-df&lt;BR /&gt;&amp;nbsp;service-policy input INGRESS_MARKING&lt;BR /&gt;&amp;nbsp;ip access-group CDE-IN-V1 in&lt;BR /&gt;&amp;nbsp;ip access-group CDE-OUT-V1 out&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-access-object-groups-not-working/m-p/2565711#M921751</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2020-02-21T13:18:19Z</dc:date>
    </item>
    <item>
      <title>Hi,Try the following</title>
      <link>https://community.cisco.com/t5/network-security/ip-access-object-groups-not-working/m-p/2565712#M921753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try the following configuration:&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-IN-V1&lt;BR /&gt;&amp;nbsp;permit tcp&amp;nbsp; object-group GG-CDE object-group RemoteConsole object-group GG-Internal&lt;/P&gt;&lt;P&gt;// from servers tcp ports vnc/rdp to clients&lt;/P&gt;&lt;P&gt;ip access-list extended CDE-OUT-V1&lt;BR /&gt;&amp;nbsp;permit tcp&amp;nbsp; object-group GG-Internal object-group GG-CDE object-group RemoteConsole&lt;/P&gt;&lt;P&gt;//from clients to servers on tcp ports rdp/vnc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pedro Lereno&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2014 12:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-access-object-groups-not-working/m-p/2565712#M921753</guid>
      <dc:creator>Pedro Lereno</dc:creator>
      <dc:date>2014-10-15T12:46:27Z</dc:date>
    </item>
  </channel>
</rss>

