10-28-2013 03:17 PM - edited 03-11-2019 07:57 PM
We have an ASA 5540 running ASA v 8.4(7). I am attempting to edit an existing service object-group, to add a few additional ports. However, when I attempt to do so, I get one of two problems.
If I type 'object-group service FOO' and enter it, I get:
An object-group with the same id but different type (service) exists
If I type 'object-group service FOO tcp and enter it, the ASA accepts the command, and the cursor drops to the next line, but I receive no prompt, and whatever I type in does not echo on the screen. It's like the ASA goes into the Twilight Zone.
I can log into the ASA with another SSH session, so it's not like the ASA is locked up.
Any ideas about this one?
Thanks in advance,
-rb
Solved! Go to Solution.
10-29-2013 10:39 AM
Thank you for the update!!!
10-31-2013 10:49 AM
Please update the ticket as resolved or answered so we can close out followup.
10-28-2013 06:30 PM
Please run the next command:
show run object id FOO
Please send the output so I can understand what is going on.
10-28-2013 06:30 PM
And also:
show run object-g id FOO
10-29-2013 07:39 AM
I found what the problem was. The primary and secondary ASAs were no longer in sync with the configuration, so it wouldn't let me change anything. But it didn't warn me either.
I failed over to the secondary, and rebooted the primary, and they re-synced configurations. Then I was able to change the object-group, as expected.
Thanks for your assistance.
-rb
10-29-2013 10:39 AM
Thank you for the update!!!
10-31-2013 10:49 AM
Please update the ticket as resolved or answered so we can close out followup.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide