cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
391
Views
0
Helpful
1
Replies
Highlighted
Beginner

Service object-group in VPN encryption domain.

Can you add a service object group in an encryption domain when setting up a s2s on an ASA?

 

Example:


object-group network local
network-object host 10.0.1.0

object-group network remote
network-object host 10.0.2.0

object-group service ports
service tcp-udp destination eq 3389
service tcp-udp destination eq 8080

access-list 100 permit object-group ports object-group local object-group remote

 

Thanks

1 REPLY 1
Enthusiast

Re: Service object-group in VPN encryption domain.

Hello @Baker

 

You can do it but I would recommend VPN-Filter since if you want to enable just specific ports that is a better way, if you do it on the encryption domain this can add more troubles than good when you are on troubleshooting sessions.

 

This is the link for reference: https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/99103-pix-asa-vpn-filter.html

 

HTH

Gio