see an example using object-group service

Posted on 2005-04-07
Last Modified: 2010-04-08
see an example using object-group service

I would like to see an example using object-group service command with  the following

object service name: management

for services : ssh,dns,ntp,ldap,syslog,snmp,smtp

ACL: then apply it from lower security30 (dmz1) on to a higher (inside) security100
Question by:cogit
    LVL 79

    Expert Comment


    name XX.XX.XX.25 APROHEAT02
    name XX.XX.XX.24 APROHEAT01
    object-group service HEAT tcp
      port-object eq www
      port-object eq https
      port-object eq 491
    object-group network HEAT_SRVRS
      network-object APROHEAT01
      network-object APROHEAT02
    access-list inbound permit tcp any object-group HEAT_SRVRS object-group HEAT
    access-group inbound in interface outside
    LVL 79

    Expert Comment

    Here's one the reverse:

    object-group service User_Outbound tcp
      port-object eq telnet
      port-object eq www
      port-object eq ssh
      port-object eq ftp-data
      port-object eq https
      port-object eq ftp
    access-list outbound permit tcp any any object-group User_Outbound
    access-list outbound permit udp host <dns server> any eq domain
    access-group outbound in interface inside

    Author Comment

    this work?

    object-group protocol typeofprotocol
    protocol-object tcp
     protocol-object udp
    S# exit
    S# object-group service management tcp-udp
    port-object eq 22
    port-object eq 53
    port-object eq 123
    port-object eq 389
    port-object eq 514
    port-object eq 161
    port-object eq 25
    (config-service)#  exit

    access-list vlan32_out permit object-group typeofprotocol  object-group  management
    access-list vlan33_out permit object-group typeofprotocol  object-group  management
    access-list vlan34_out permit object-group typeofprotocol  object-group  management
    access-list v44_out permit object-group typeofprotocol  object-group  management
    access-list v54_out permit object-group typeofprotocol  object-group  management
    access-list v64_out permit object-group typeofprotocol  object-group  management
    access-group vlan32_out in interface vlan32
    access-group vlan33_out in interface vlan33
    access-group vlan34_out in interface vlan34
    access-group v44_out in interface v44
    access-group v54_out in interface v54
    access-group v64_out in interface v64

    LVL 79

    Accepted Solution

    I don't know why that would not work.
    You can also group your networks. This is just an example only:

    name DOT32
    name DOT33
    name DOT34
    name DOT54
    name DOT64

    object-group network LOWSECURITY
      network-object DOT32
      network-object DOT33
      network-object DOT34

    object-group network HIGHSECURITY
      network-object DOT54
      network-object DOT64

    access-list dmz_in permit object-group typeofprotocol object-group LOWSECURITY object-group HIGHSECURITY object-group management


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    6 Surprising Benefits of Threat Intelligence

    All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

    Suggested Solutions

    Title # Comments Views Activity
    Opening Port 80 10 56
    Firewall vs WYSIWYG editor 5 72
    Sonicwall 7 67
    iPhone6s - Installing Malwarebytes and/or Norton Security Deluxe 3 96
    To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
    This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
    how to add IIS SMTP to handle application/Scanner relays into office 365.
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    760 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now