Apply Nested Object Group to ACL

Allow all inside hosts outbound

- HTTP

- HTTPS

- FTP

fw1(config)# access-list aclin permit tcp object-group Inside Networks any object-group Host Services_

Internet

172.16.0.0

Inside_Eng |

Inside_Mktg |

Inside Networks

© 2005 Cisco Systems, Inc. All rights re

The keyword object-group must precede the object group name in order to use object groups in your ACLs. An object group cannot be removed or emptied if it is currently being used in an ACL command. In the figure, all hosts in the Inside_Networks nested group are permitted to access any host via the services in the Host_Services group.

When used with object grouping, the syntax for the access-list commands is as follows:

access-list id [line line-number] [extended] {deny | permit} {tcp | udp} {host sip | sip mask | interface ifc name | object-group network obj grp id | any} [operator port] | object-group service obj grp id] {host dip | dip mask | interface ifc name | object-group network obj grp id | any} [operator port] | object-group service obj grp id] [log [[level] [interval secs] | disable | default]] [inactive | time-range time range name]

access-list id [line line-number] [extended] {deny | permit} icmp {host sip | sip mask | interface ifc name | object-group network obj grp id | any} {host dip | dip mask | interface ifc name | object-group network obj grp id | any} [icmp type | object-group icmp type obj grp id] [log [[level] [interval secs] | disable | default]] [inactive | time-range time range name]

deny

This option does not allow a packet to traverse the security appliance if the conditions are matched. By default, the security appliance denies all inbound or outbound packets unless you specifically permit access.

dip

Specifies the IP address of the network or host to which the packet is being sent. Specify a destination IP address when the access-list command statement is used in conjunction with an access-group command statement or in conjunction with the aaa match access-list command and the aaa authorization command. For inbound and outbound connections, the destination IP address is the address before Network Address Translation (NAT) has been performed.

dip_mask

Netmask bits (mask) to be applied to the destination IP address.

icmp_type

(Optional) Specifies the ICMP message type.

icmp_type_obj_grp_id

(Optional) Specifies the identifier of an existing ICMP-type object group.

id

Specifies the name or number of an ACL.

inactive

Disables an access control element

interface ifc_name

Specifies the interface address as the source or destination address.

interval secs

Specifies the log interval at which to generate a 106100 syslog message; valid values are from 1 to 600 seconds. Default is 300.

line line-num

(Optional) The line number at which to insert an access control element.

log disable | default |

level

(Optional) Specifies that the log option is disabled, set to default values, or set to a syslog level from 0 to 7. The default level is 6. When enabled, a syslog message 106100 is generated for the access control element.

network_obj_grp_id

Specifies the identifier of an existing network object group.

object-group

Specifies an object group.

operator

Compares source IP address or destination IP address ports. Possible operands include "lt" (less than), "gt" (greater than), "eq" (equal), "neq" (not equal), and "range" (inclusive range).

permit

The permit option selects a packet to traverse the security appliance if conditions are matched. By default, the security appliance denies all inbound or outbound packets unless you specifically permit access.

port

Specifies the decimal number or name of a TCP or UDP port.

protocol

Specifies the IP protocol name or number that will be open. For example, UDP is 17, TCP is 6, and EGP is 47.

protocol_obj_grp_id

Specifies the identifier of an existing protocol object group.

service_obj_grp_id

Specifies the identifier of an existing service object group.

sip

Specifies the IP address of the network or host from which the packet is being sent.

sip_mask

Netmask bits (mask) to be applied to the source IP address.

time-range time_range_name

(Optional) Specifies the time range used to define specific times of the day and week to allow access to the security appliance.

fw1(config)# show run static

static(dmz1,outside)192.168.1

.10

172.16.0.1 netmask 255.255

255

255

static(dmz1,outside)192.168.1

.12

172.16.0.2 netmask 255.255

255

255

static(dmz2,outside)192.168.2

.10

172.16.1.1 netmask 255.255

255

255

© 2005 Cisco Systems, Inc. All rights reserved.

fw1(config)# show run object

group

object-group network REMOTES

network-object host 172

30.0.

50

network-object host 172

30.0.

51

object-group network DMZ1

network-object host 192

168.1

.10

network-object host 192

168.1

.12

object-group network DMZ2

network-object host 192

168.2

.10

object-group network ALL_DMZ

group-object DMZ1

group-object DMZ2

object-group service BASIC

port-object eq http

port-object eq smtp

fw1(config)# access-list aclout permit tcp object-group REMOTES object-group ALL DMZ object-group BASIC_

fw1(config)# access-list aclout permit tcp object-group REMOTES object-group ALL DMZ object-group BASIC_

In the figure, object groups are configured so that one ACL entry enables remote hosts 172.30.0.50 and 172.30.0.51 to initiate HTTP and Simple Mail Transfer Protocol (SMTP) connections to DMZ1 and DMZ2 hosts in the ALL_DMZ nested group. With object grouping, one ACL entry is required. Without object grouping, the following ACL entries would be required:

access-list outside permit tcp host 172.30.0.50 host 192.168.1.10 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.1.10 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.1.10 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.1.10 eq smtp access-list outside permit tcp host 172.30.0.50 host 192.168.1.12 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.1.12 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.1.12 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.1.12 eq smtp access-list outside permit tcp host 172.30.0.50 host 192.168.2.10 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.2.10 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.2.10 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.2.10 eq smtp firewall(config)#

show running-config [all] object-group [protocol | service | network | icmp-type | id obj_grp_id]

Continue reading here: Displays object groups in the configuration

Was this article helpful?

0 0