We help IT Professionals succeed at work.

Cisco Pix Access list Question

inf2300
inf2300 asked
on
Medium Priority
301 Views
Last Modified: 2013-11-16
I would like to create an access list that has access to certain services. My question is the following:

Is there a way to create a group of ips (not a range) and then only have to write one access-list command. This way i could simply add ips to the group when i when to grant them access

Thanks
Comment
Watch Question

Commented:
Yes - you can use the object-group command

For example - if you want to allow www access in to several web servers on non-sequential ip addresses :

conf t
object-group network wwwservers
network-object host 200.200.200.145
network-object host 200.200.200.147
network-object host 200.200.200.149
network-object host 200.200.200.155
network-object host 200.200.200.176
network-object host 200.200.200.143

access-list fromoutside permit tcp any object-group wwwservers eq www

You can now add hosts to the object group as needed and they will be applied.

hope this helps

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.