cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
418
Views
0
Helpful
3
Replies

Removing the Network Objects in Firewall

mahesh18
Level 6
Level 6

 

Hi Everyone,

 

I need to do cleanup on the firewalls.

I found few network objects which i need to remove from the firewall are used in many ACL's.

If i delete those Network Objects will then those ACL's will also be deleted automaticall ?

Whats the best way to do this clean up?

 

Regards

MAhesh

2 Accepted Solutions

Accepted Solutions

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

You would not be allowed to remove an object-group from the configuration when it is being used in an acl.

I would suggest you to replace the Object groups with the subnet before hand and then proceed with removing the object group.

You can also use the "where used" option on the ASDM to find where that specific Object group is being used.

Thanks and Regards,

Vibhor Amrodia

View solution in original post

Hi,

Yes , Finding the Object-groups which are being used and then removing the object-group would be the best way.

Thanks and Regards,

Vibhor Amrodia

View solution in original post

3 Replies 3

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

You would not be allowed to remove an object-group from the configuration when it is being used in an acl.

I would suggest you to replace the Object groups with the subnet before hand and then proceed with removing the object group.

You can also use the "where used" option on the ASDM to find where that specific Object group is being used.

Thanks and Regards,

Vibhor Amrodia

 

Hi Vibhor,

 

How can i replace object group with subnet?

I checked where used give me list of ACL lines where it is used.

So i can do this way also find where the object is used then delete the ACL then in the

end i can delete the ACL?

 

Regards

MAhesh

Hi,

Yes , Finding the Object-groups which are being used and then removing the object-group would be the best way.

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card