01-18-2011 12:25 PM - edited 03-11-2019 12:36 PM
Solved! Go to Solution.
01-18-2011 12:36 PM
Hello,
Since your object-group Web-Ports consists of service objects, the way it is configured seems to be correct. You can check the access-list by issuing "show access-list CORP-IN" command.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml#serv
Hope this helps.
Regards,
NT
01-18-2011 01:09 PM
In your case, you are not getting any advantage. The enhanced service object is used when you need to group multiple protocols and ports into one group.
Hope this helps.
Regards,
NT
01-18-2011 12:36 PM
Hello,
Since your object-group Web-Ports consists of service objects, the way it is configured seems to be correct. You can check the access-list by issuing "show access-list CORP-IN" command.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml#serv
Hope this helps.
Regards,
NT
01-18-2011 01:07 PM
So in this case, what benefit do I get from using enhanced service objects? Since I am only using port 80, 443 I could have used a protocol specific service object as indicated below, correct?
object-group service test tcp
port-object eq 80
port-object eq 443
So now I know the configuration I listed in my original post works, but again, am I really deriving any benefit from doing it that way? My guess is no. What do you think?
01-18-2011 01:09 PM
In your case, you are not getting any advantage. The enhanced service object is used when you need to group multiple protocols and ports into one group.
Hope this helps.
Regards,
NT
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide