cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
798
Views
0
Helpful
1
Replies

5-tuple match on source group, or just IP

csbowser
Level 1
Level 1

Can someone confirm: When a service hits the CSS, the match made to a source group is ONLY on the IP address, not port/protocol/IP..right?

In other words, I can't specify

service www1-tcp

protocol tcp

ip address 1.1.1.1

and

service www1-udp

protocol udp

ip address 1.1.1.1

then put service www1-tcp in a source group and not expect outbound udp traffic to succeed also.

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

what kind of source group ?

If this is a 'add destination service' it applies only to the service configured.

For 'add service' we can only check the ip source and the group will be applied to both services even if only one configured.

Gilles.

Review Cisco Networking for a $25 gift card