cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
970
Views
0
Helpful
1
Replies

Service object-group in VPN encryption domain.

Baker
Level 1
Level 1

Can you add a service object group in an encryption domain when setting up a s2s on an ASA?

 

Example:


object-group network local
network-object host 10.0.1.0

object-group network remote
network-object host 10.0.2.0

object-group service ports
service tcp-udp destination eq 3389
service tcp-udp destination eq 8080

access-list 100 permit object-group ports object-group local object-group remote

 

Thanks

1 Reply 1

GioGonza
Level 4
Level 4

Hello @Baker

 

You can do it but I would recommend VPN-Filter since if you want to enable just specific ports that is a better way, if you do it on the encryption domain this can add more troubles than good when you are on troubleshooting sessions.

 

This is the link for reference: https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/99103-pix-asa-vpn-filter.html

 

HTH

Gio

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: