10-01-2013 09:11 AM - edited 03-11-2019 07:45 PM
Hi Everyone,
I need to config port-object eq 17800 etc in ASA.
I tried command object-group service xyz
but there is no option for port-object eq ?
Regards
Mahesh
Solved! Go to Solution.
10-01-2013 09:24 AM
Hi,
I think you have probably configured the "object-group service
For example
ASA(config)# object-group service TEST
ASA(config-service-object-group)# ?
description Specify description text
group-object Configure an object group as an object
help Help for service object-group configuration commands
no Remove an object or description from object-group
service-object Configure a service object
ASA(config-service-object-group)#
However if we specify the "object-group service
ASA(config)# object-group service TEST tcp-udp
ASA(config-service-object-group)# ?
description Specify description text
group-object Configure an object group as an object
help Help for service object-group configuration commands
no Remove an object or description from object-group
port-object Configure a port object
ASA(config-service-object-group)#
Though even if you used the original "object-group service
For example the following would group TCP/17800 and UDP/17800 in one "object-group" and use them in an ACL
object-group service TEST
service-object tcp destination eq 17800
service-object udp destination eq 17800
access-list TEST extended permit object-group TEST any any
When we look how the actual ACL looks like we see the following
ASA(config)# show access-list TEST
access-list TEST; 2 elements; name hash: 0xd37fdb2b
access-list TEST line 1 extended permit object-group TEST any any (hitcnt=0) 0x0abc0954
access-list TEST line 1 extended permit tcp any any eq 17800 (hitcnt=0) 0x25ac5419
access-list TEST line 1 extended permit udp any any eq 17800 (hitcnt=0) 0xc6e32e33
Hope this helps
- Jouni
10-01-2013 09:24 AM
Hi,
I think you have probably configured the "object-group service
For example
ASA(config)# object-group service TEST
ASA(config-service-object-group)# ?
description Specify description text
group-object Configure an object group as an object
help Help for service object-group configuration commands
no Remove an object or description from object-group
service-object Configure a service object
ASA(config-service-object-group)#
However if we specify the "object-group service
ASA(config)# object-group service TEST tcp-udp
ASA(config-service-object-group)# ?
description Specify description text
group-object Configure an object group as an object
help Help for service object-group configuration commands
no Remove an object or description from object-group
port-object Configure a port object
ASA(config-service-object-group)#
Though even if you used the original "object-group service
For example the following would group TCP/17800 and UDP/17800 in one "object-group" and use them in an ACL
object-group service TEST
service-object tcp destination eq 17800
service-object udp destination eq 17800
access-list TEST extended permit object-group TEST any any
When we look how the actual ACL looks like we see the following
ASA(config)# show access-list TEST
access-list TEST; 2 elements; name hash: 0xd37fdb2b
access-list TEST line 1 extended permit object-group TEST any any (hitcnt=0) 0x0abc0954
access-list TEST line 1 extended permit tcp any any eq 17800 (hitcnt=0) 0x25ac5419
access-list TEST line 1 extended permit udp any any eq 17800 (hitcnt=0) 0xc6e32e33
Hope this helps
- Jouni
10-01-2013 09:47 AM
Hi Jouni,
Yes i config object-group service
I used tcp in the end now and it worked great.
Best Regards
Mahesh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide