I am wondering how ASA/Firepower handles empty object groups in a rule. For example, I have a rule with an object group for destination; all working fine. I then have to make changes to the object group, and it turns out all IPs get removed from the object...so basically the object group is empty. If I did not have a chance to update the rule or rules using that object group, how does the FW handle the processing of that "empty" object group. Does it default to "any". Does it treat the rule as a "no -match" when processing and move on to the next rule.
I understand, ideally, I should remove the empty object group, but sometimes when dealing with many firewalls at once, it can briefly get overlooked and I am just concerned how a FW may react to this situation.