11-02-2017 09:11 AM - edited 03-05-2019 09:25 AM
Hey guys,
I have a simple question. I do have an object-group with 4 IP's in it, and on access list I'm allowing these IP's (object-group) to access 4 different servers.
On one server I need access from only 2 of the 4 IP's. Is there a way on access-list to exclude 2 IP's or something like that. I know I can just add an access-list specifically for these IP's, I was just wondering if there is an easier way.
Thanks
Solved! Go to Solution.
11-02-2017 10:18 AM
Agree. If you need them in a different rule, is better split the object group so that you avoid permit unnecessary traffic to host.
-If I helped you somehow, please, rate it as useful.-
11-02-2017 10:05 AM
Hi @aliabuklam
You should edit your object group and rip off those hosts you don't need anymore.
object-group network object-group-name
no host {host-address | host-name}
-If I helped you somehow, please, rate it as useful.-
11-02-2017 10:12 AM
Thanks for your response Flavio.
I still need this all the hosts for other servers though. I guess I will just create a new object-group and use it specifically for this that one server.
Thank you.
11-02-2017 10:18 AM
Agree. If you need them in a different rule, is better split the object group so that you avoid permit unnecessary traffic to host.
-If I helped you somehow, please, rate it as useful.-
11-02-2017 01:03 PM
Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide