10-28-2010 11:16 AM - edited 03-11-2019 12:01 PM
Hello - I have a list of 'ports to open' on our ASA5510 to allow traffic to/from a remote site who will be hosting an application our users need to access. There are 9 ports total, so should I use a Service Group? If so, should I select only 'TCP' or 'TCP-UDP', for the type of service group I need to create? I can provide more detail, if needed. Thanks for your insight!
10-28-2010 04:41 PM
Hello - I have a list of 'ports to open' on our ASA5510 to allow traffic to/from a remote site who will be hosting an application our users need to access. There are 9 ports total, so should I use a Service Group? If so, should I select only 'TCP' or 'TCP-UDP', for the type of service group I need to create? I can provide more detail, if needed. Thanks for your insight!
Davis
You can use a service group or you can just have an entry per port. If there are 9 ports then personally i would use a service group as you suggest. There is no fixed rule however as to when and when not to use them, it's just a way of organising the config and specifically the rule base.
As for whether it should be tcp or tcp-udp it depends on whether you have a mixture of tcp and udp ports or just tcp or udp.
Edit - apologies Davis, i should have been more specific about tcp-udp. tcp-udp should be used where the service uses both tcp and udp on the same port eg. DNS which can be TCP/port 53 or UDP/port 53. As Mike says you cannot however mix different tcp and udp ports in the same group.
Jon
10-28-2010 09:27 PM
Hello,
I just want to add something else to what Jon states. You can create the TCP or UDP service group, however it is not possible to create a UDP and TCP service group.
It really depends on the flavour, if you do it with service group, it will help the firewall in order to avoid going line by line trying to find the correct match.
Hope this helps.
Mike.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide