cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
849
Views
0
Helpful
2
Replies

ASA 5510 Object-group & Range option

sadik.bash
Level 1
Level 1

Hello,

I have 3 ASA 5510s; two of which are in production and the 3rd one is new. I inherited the two in production and was trying to configure that 3rd one using some of the existing object-group network statements.  The problem is that when I try to create a range of IPs in one of the object-groups; the range command is not available. Here is one of the statements extracted from one of the production ASAs:  object network REMOTE
range 62.77.130.14 62.77.130.208

Both ASAs have the same image ver (asa842-k8).  Is there something that I am missing to be able to enable the range option on the new ASA?

Thanks in advance,

~sK 

1 Accepted Solution

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Are you sure the new ASA has booted to the new software 8.4(2)?

There are

  • object-group network
    • accepts networks and host addresses under it
  • object network
    • accepts subnet, range and host addresses under it

The "object network" configuration came available in the 8.3 software. Before that in software 8.2 and earlier only the "object-group network" (and other types of object-groups") existed.

Maybe you have several boot images set on the new ASA and its actually booting to the old software still?

What does the "show run boot" say?

If it lists both the command for old and new software then remove the old "boot system" command, save the configuration and reboot.

Hopefully the above information was helpful

- Jouni

View solution in original post

2 Replies 2

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Are you sure the new ASA has booted to the new software 8.4(2)?

There are

  • object-group network
    • accepts networks and host addresses under it
  • object network
    • accepts subnet, range and host addresses under it

The "object network" configuration came available in the 8.3 software. Before that in software 8.2 and earlier only the "object-group network" (and other types of object-groups") existed.

Maybe you have several boot images set on the new ASA and its actually booting to the old software still?

What does the "show run boot" say?

If it lists both the command for old and new software then remove the old "boot system" command, save the configuration and reboot.

Hopefully the above information was helpful

- Jouni

Thanks much for the quick and correct answer. My issue was that I would use the object-group network command rather than using the object network command.

Problem solved. Much appreciated.

Best, ~sK

Review Cisco Networking products for a $25 gift card