Concept of object grouping is used in firewall to have the group of host/services involved in logically single rules instead of varied lines.
Now it is seen that ACE uses only single line no. to define each object grouped rule until there is a change.
But even this way, the actual no. of lines would still be large enough degtermined by the no. of hosts or services in the object group.
Does this have any bearing on the extra lines firewall will have to parse thru.or is it simply for easier admin control.