<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: object-group acl example in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804944#M987161</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that looks fine to me. I agree that it is best that you test this out of hours just in case you have missed anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how you get on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2007 06:20:54 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-06-14T06:20:54Z</dc:date>
    <item>
      <title>object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804938#M987100</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm just converting my ACLs to use object-groups and just wanted ti check the ACLs I have written are OK.  To start with I have some ACLs of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list example permit ip 192.x.x.0 255.255.255.0 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list example permit ip 192.x.x.0 255.255.255.0 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list example permit ip 192.x.x.0 255.255.255.0 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list example permit ip 192.x.x.0 255.255.255.0 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and some object-groups of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network UK_Network&lt;/P&gt;&lt;P&gt;description subnets in use on UK LAN&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network Canada_Network&lt;/P&gt;&lt;P&gt;network-object 10.x.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the access-list I have written to use the object-groups is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list example permit ip object-group UK_Network object-group Canada_Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does this look right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804938#M987100</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2019-03-11T10:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804939#M987115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks fine other than the 10.x.0.0 entry in the UK_Network object-group. Do you need this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 13:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804939#M987115</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-13T13:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804940#M987131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my fault with the notation of the subnets- should read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network UK_Network&lt;/P&gt;&lt;P&gt;description subnets in use on UK LAN&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.20.x.x 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network Canada_Network&lt;/P&gt;&lt;P&gt;network-object 10.1.x.x 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the network object-group acl's seem easy enough- would it be Ok if I ran some port, protocol and icmp ACLs past you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 13:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804940#M987131</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-13T13:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804941#M987141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, no problem at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 13:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804941#M987141</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-13T13:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804942#M987149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here are some object-groups I've written and i'm juts writing the access-lists currently.  Also wondering about best testing and implementation method- presumably one access-list at a time and out of hours!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol proto_grp_1&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service OWA_AD TCP&lt;/P&gt;&lt;P&gt;description TCP ports for Outlook Web Access and Active Directory&lt;/P&gt;&lt;P&gt;port-object eq ldap &lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq domain&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;port-object eq 42&lt;/P&gt;&lt;P&gt;port-object eq 88&lt;/P&gt;&lt;P&gt;port-object eq 135&lt;/P&gt;&lt;P&gt;port-object eq 445&lt;/P&gt;&lt;P&gt;port-object eq 3268&lt;/P&gt;&lt;P&gt;port-object eq 3269&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service OWA_AD UDP&lt;/P&gt;&lt;P&gt;description UDP ports for Outlook Web Access and Active Directory&lt;/P&gt;&lt;P&gt;port-object eq ldap&lt;/P&gt;&lt;P&gt;port-object eq domain&lt;/P&gt;&lt;P&gt;port-object eq 42&lt;/P&gt;&lt;P&gt;port-object eq 88&lt;/P&gt;&lt;P&gt;port-object eq 135&lt;/P&gt;&lt;P&gt;port-object eq 445&lt;/P&gt;&lt;P&gt;port-object eq 3268&lt;/P&gt;&lt;P&gt;port-object eq 3269&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service External_Addresses TCP&lt;/P&gt;&lt;P&gt;description TCP ports for External Addresses&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;port-object eq pop3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service External_Addresses UDP&lt;/P&gt;&lt;P&gt;description UDP ports for External Addresses&lt;/P&gt;&lt;P&gt;port-object eq 10000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol TCP&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 14:07:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804942#M987149</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-13T14:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804943#M987156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi J&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my original access-lists are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.232 eq www&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.235 eq pop3&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.234 eq smtp&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.234 eq www&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.235 eq www&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.235 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;new object-groups:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network External_Addresses&lt;/P&gt;&lt;P&gt;description External Addresses&lt;/P&gt;&lt;P&gt;network-object host 62.x.x.234&lt;/P&gt;&lt;P&gt;network-object host 62.x.x.235&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;updated access-lists:&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.232 eq www&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any host 62.x.x.235 eq pop3&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any object-group External_Addresses eq smtp&lt;/P&gt;&lt;P&gt;access-list if-out permit tcp any object-group External_Addresses eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how's that look? cheers for help- been sidetracked on to some other stuff unfortunately&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2007 14:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804943#M987156</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-13T14:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804944#M987161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that looks fine to me. I agree that it is best that you test this out of hours just in case you have missed anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how you get on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 06:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804944#M987161</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-14T06:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804945#M987163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have multiple examples of pairs of rules in separate access-lists which reference the same source and destination networks that are both getting hit- how does this work- do I need both lines?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 07:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804945#M987163</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-14T07:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804946#M987166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you send an exmaple of what you mean. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 07:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804946#M987166</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-14T07:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804947#M987168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yup sure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 1 permit ip object-group UK_Network object-group Canada_Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 2 permit ip object-group UK_Network object-group Canada_Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both getting hit- why are both needed- wouldn't just one do the job?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 07:39:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804947#M987168</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-14T07:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804948#M987171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are these access-lists applied ie. which interfaces on they applied to and in which direction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ordinarily you don't need to have the same access-lists but without some context it's difficult to say. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 08:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804948#M987171</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-14T08:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804949#M987174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;neither are applied with an access-group command.  UK_Network is on inside and Canada on outside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 09:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804949#M987174</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-14T09:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804950#M987177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, i'm confused now. How are you getting hits on them if you have not applied them on any interfaces ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 09:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804950#M987177</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-14T09:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: object-group acl example</title>
      <link>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804951#M987179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good-  sort of as that had been confusing me too! this config is something I have inherited and I'm just coming to terms with (and the counters have been cleared recently).  I've bene taske dwith cleaning up a config which has had numerous people working on it over last few years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two access-lists applied to interfaces as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group if-out-owa in interface outside&lt;/P&gt;&lt;P&gt;access-group inside_access_out in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list if-out-owa permit tcp any host 62.x.x.x eq www&lt;/P&gt;&lt;P&gt;access-list if-out-owa permit tcp any host 62.x.x.x eq https&lt;/P&gt;&lt;P&gt;access-list inside_access_out deny ip any host ip_of_some_virus_server&lt;/P&gt;&lt;P&gt;access-list inside_access_out permit ip any any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2007 14:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-acl-example/m-p/804951#M987179</guid>
      <dc:creator>w.halliday</dc:creator>
      <dc:date>2007-06-14T14:32:44Z</dc:date>
    </item>
  </channel>
</rss>

