Best practices regarding Service Groups in Cisco ASA

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2017 01:31 AM - edited 03-12-2019 01:55 AM
Good day,
I wonder if there is any best practice guideline regarding the use of TCP/UDP Service Groups, instead of several one-port access-rules
For example, if you have several subnets who need to talk to some domain controllers in one subnet, for AD-traffic - it quick get a lot of access-rules if you use one rule per port. On the other side, you can easily see which rules have hits, and who have no hits - and might be removed.
I'm thinking of creating a Service Group for all AD-traffic, so I only need one rule for each interface for this traffic.
Any downsides doing this? Do use of Service Groups impact performance?
Thanks.
- Labels:
-
NGFW Firewalls

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2017 01:57 AM
Please check the below link for best practices guide:-
http://www.cisco.com/c/en/us/about/security-center/firewall-best-practices.html
