cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
384
Views
0
Helpful
2
Replies

Creating Service Groups

dcrouch
Level 1
Level 1

Hello - I have a list of 'ports to open' on our ASA5510 to allow traffic to/from a remote site who will be hosting an application our users need to access.  There are 9 ports total, so should I use a Service Group?  If so, should I select only 'TCP' or 'TCP-UDP', for the type of service group I need to create?  I can provide more detail, if needed.  Thanks for your insight!

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

dcrouch@nhmg.com

Hello - I have a list of 'ports to open' on our ASA5510 to allow traffic to/from a remote site who will be hosting an application our users need to access.  There are 9 ports total, so should I use a Service Group?  If so, should I select only 'TCP' or 'TCP-UDP', for the type of service group I need to create?  I can provide more detail, if needed.  Thanks for your insight!

Davis

You can use a service group or you can just have an entry per port. If there are 9 ports then personally i would use a service group as you suggest. There is no fixed rule however as to when and when not to use them, it's just a way of organising the config and specifically the rule base.

As for whether it should be tcp or tcp-udp it depends on whether you have a mixture of tcp and udp ports or just tcp or udp.

Edit - apologies Davis, i should have been more specific about tcp-udp.  tcp-udp should be used where the service uses both tcp and udp on the same port eg. DNS which can be TCP/port 53 or UDP/port 53. As Mike says you cannot however mix different tcp and udp ports in the same group.

Jon

Maykol Rojas
Cisco Employee
Cisco Employee

Hello,

I just want to add something else to what Jon states. You can create the TCP or UDP service group, however it is not possible to create a UDP and TCP service group.

It really depends on the flavour, if you do it with service group, it will help the firewall in order to avoid going line by line trying to find the correct match.

Hope this helps.

Mike.

Mike
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card