<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSM error when adding new subnet to group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640490#M940408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you are observing is normal given the way we implemented the devices access policy. As you probably know, in cli you can specify only one access-rule per line for ssh, http telnet etc..&lt;/P&gt;&lt;P&gt;For example if you want to allow ssh access to the ASA from host 1.1.1.1 and 2.2.2.2 you will have to put two lines&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 2.2.2.2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;ssh 1.1.1.1 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In CSM we model this two lines as two different object, so the building block object of type network that refers to the object of type ssh access can ONLY have one entry. This behavior is the same for ICMP as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list is different because we model in CSM in a different way + you can use object-group to put together different networks. This is not possible for device access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope gave you a bit more insight on the reason &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also it would be great to mark this as answer if that is the case &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stefano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Feb 2011 16:16:41 GMT</pubDate>
    <dc:creator>Stefano De Crescenzo</dc:creator>
    <dc:date>2011-02-14T16:16:41Z</dc:date>
    <item>
      <title>CSM error when adding new subnet to group</title>
      <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640487#M940405</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attempting to add a new subnet to an existing group in CSM Enterprise v4.0.1 b7823.&amp;nbsp; When adding a new subnet to the group (the other contents of the group is another subnet), CSM issues several errors for each affected ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;Network BB(GROUPNAME,) referenced by the 'Http Network' on device(DEVICENAME) maps to more than one IP Addresses!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause:&lt;/P&gt;&lt;P&gt;Http is referring to a network object that maps&amp;nbsp; to more than one IpAddress on the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action:&lt;/P&gt;&lt;P&gt;Please config the policy with network object that resolve to only one IpAddress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an error for ICMP as well.&amp;nbsp; Since the contents of the group is already a /24subnet, I don't imagine it's a very accurate error.&amp;nbsp; Has anyone come up against this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640487#M940405</guid>
      <dc:creator>j.england</dc:creator>
      <dc:date>2020-02-21T12:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: CSM error when adding new subnet to group</title>
      <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640488#M940406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not recall to have hit this situation, however I would suggest we investigate a bit more.&lt;/P&gt;&lt;P&gt;First thing, if you can, I would need to know the exact steps you followed to end up in this situation so I can try to reproduce :). Also it would be great if you can send a screenshot of the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Stefano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Feb 2011 07:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640488#M940406</guid>
      <dc:creator>Stefano De Crescenzo</dc:creator>
      <dc:date>2011-02-12T07:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: CSM error when adding new subnet to group</title>
      <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640489#M940407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefano,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really appreciate your response.&amp;nbsp; I actually just had the time to sit down and investigate a bit more yesterday.&amp;nbsp; This error was referring to the Device Access Platform Policies governing access to the firewalls via HTTP, ICMP, SSH, etc.&amp;nbsp; The object causing the isses contained one subnet.&amp;nbsp; When I attempted to add another subnet, these access policies rejected it because they allow only one entry int the contents of the objects being allowed.&amp;nbsp; I simply had to create a new entry for each protocol access for each firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for following up though!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Feb 2011 18:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640489#M940407</guid>
      <dc:creator>j.england</dc:creator>
      <dc:date>2011-02-12T18:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSM error when adding new subnet to group</title>
      <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640490#M940408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you are observing is normal given the way we implemented the devices access policy. As you probably know, in cli you can specify only one access-rule per line for ssh, http telnet etc..&lt;/P&gt;&lt;P&gt;For example if you want to allow ssh access to the ASA from host 1.1.1.1 and 2.2.2.2 you will have to put two lines&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 2.2.2.2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;ssh 1.1.1.1 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In CSM we model this two lines as two different object, so the building block object of type network that refers to the object of type ssh access can ONLY have one entry. This behavior is the same for ICMP as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list is different because we model in CSM in a different way + you can use object-group to put together different networks. This is not possible for device access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope gave you a bit more insight on the reason &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also it would be great to mark this as answer if that is the case &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stefano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 16:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640490#M940408</guid>
      <dc:creator>Stefano De Crescenzo</dc:creator>
      <dc:date>2011-02-14T16:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: CSM error when adding new subnet to group</title>
      <link>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640491#M940409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the rundown, that does clarify things quite a bit.&amp;nbsp; I am definitely more enlightened, and I appreciate the response!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 17:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-error-when-adding-new-subnet-to-group/m-p/1640491#M940409</guid>
      <dc:creator>j.england</dc:creator>
      <dc:date>2011-02-14T17:31:28Z</dc:date>
    </item>
  </channel>
</rss>

