Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

using an access-group in an access-list statement

I'm trying to use access-groups in my access lists and I keep getting an error the general format is as follows

access-list acl_in permit ip host 10.10.12.5 object-group bkup object-group legato

I get an error stating extra-argument(s)

3 REPLIES
Cisco Employee

Re: using an access-group in an access-list statement

Impossible for us to tell the problem without seeing how you've configured the bkup and legato object-groups.

Make sure you follow http://www.cisco.com/warp/public/707/pix_obj_grp.html and see how you go, if you're still having problems please at least show us the individual object groups you've configured and EXACTLY what error you're getting.

New Member

Re: using an access-group in an access-list statement

I think I've figured it out. It appears that the pix dosen't like me using "ip" for protocol. If I define the access list using tcp or udp it is fine. Not sure why I'm seeing this behavior but at least I have a work around.

Cisco Employee

Re: using an access-group in an access-list statement

If "object-group legato" is a service-type group, then you definately have to specify either tcp or udp, since that is exactly what you're telling the PIX. You can't have an access-list that includes TCP/UDP ports and then just say that's an IP access-list.

103
Views
3
Helpful
3
Replies
CreatePlease to create content