Apply Nested Object Group to ACL
Allow all inside hosts outbound
- HTTP
- HTTPS
- FTP
fw1(config)# access-list aclin permit tcp object-group Inside Networks any object-group Host Services_
Internet
172.16.0.0
Inside_Eng |
Inside_Mktg |
Inside Networks
© 2005 Cisco Systems, Inc. All rights re
The keyword object-group must precede the object group name in order to use object groups in your ACLs. An object group cannot be removed or emptied if it is currently being used in an ACL command. In the figure, all hosts in the Inside_Networks nested group are permitted to access any host via the services in the Host_Services group.
When used with object grouping, the syntax for the access-list commands is as follows:
access-list id [line line-number] [extended] {deny | permit} {tcp | udp} {host sip | sip mask | interface ifc name | object-group network obj grp id | any} [operator port] | object-group service obj grp id] {host dip | dip mask | interface ifc name | object-group network obj grp id | any} [operator port] | object-group service obj grp id] [log [[level] [interval secs] | disable | default]] [inactive | time-range time range name]
access-list id [line line-number] [extended] {deny | permit} icmp {host sip | sip mask | interface ifc name | object-group network obj grp id | any} {host dip | dip mask | interface ifc name | object-group network obj grp id | any} [icmp type | object-group icmp type obj grp id] [log [[level] [interval secs] | disable | default]] [inactive | time-range time range name]
|
deny |
This option does not allow a packet to traverse the security appliance if the conditions are matched. By default, the security appliance denies all inbound or outbound packets unless you specifically permit access. |
|
dip |
Specifies the IP address of the network or host to which the packet is being sent. Specify a destination IP address when the access-list command statement is used in conjunction with an access-group command statement or in conjunction with the aaa match access-list command and the aaa authorization command. For inbound and outbound connections, the destination IP address is the address before Network Address Translation (NAT) has been performed. |
|
dip_mask |
Netmask bits (mask) to be applied to the destination IP address. |
|
icmp_type |
(Optional) Specifies the ICMP message type. |
|
icmp_type_obj_grp_id |
(Optional) Specifies the identifier of an existing ICMP-type object group. |
|
id |
Specifies the name or number of an ACL. |
|
inactive |
Disables an access control element |
|
interface ifc_name |
Specifies the interface address as the source or destination address. |
|
interval secs |
Specifies the log interval at which to generate a 106100 syslog message; valid values are from 1 to 600 seconds. Default is 300. |
|
line line-num |
(Optional) The line number at which to insert an access control element. |
|
log disable | default | level |
(Optional) Specifies that the log option is disabled, set to default values, or set to a syslog level from 0 to 7. The default level is 6. When enabled, a syslog message 106100 is generated for the access control element. |
|
network_obj_grp_id |
Specifies the identifier of an existing network object group. |
|
object-group |
Specifies an object group. |
|
operator |
Compares source IP address or destination IP address ports. Possible operands include "lt" (less than), "gt" (greater than), "eq" (equal), "neq" (not equal), and "range" (inclusive range). |
|
permit |
The permit option selects a packet to traverse the security appliance if conditions are matched. By default, the security appliance denies all inbound or outbound packets unless you specifically permit access. |
|
port |
Specifies the decimal number or name of a TCP or UDP port. |
|
protocol |
Specifies the IP protocol name or number that will be open. For example, UDP is 17, TCP is 6, and EGP is 47. |
|
protocol_obj_grp_id |
Specifies the identifier of an existing protocol object group. |
|
service_obj_grp_id |
Specifies the identifier of an existing service object group. |
|
sip |
Specifies the IP address of the network or host from which the packet is being sent. |
|
sip_mask |
Netmask bits (mask) to be applied to the source IP address. |
|
time-range time_range_name |
(Optional) Specifies the time range used to define specific times of the day and week to allow access to the security appliance. |
|
fw1(config)# show run static |
||
|
static(dmz1,outside)192.168.1 |
.10 |
|
|
172.16.0.1 netmask 255.255 |
255 |
255 |
|
static(dmz1,outside)192.168.1 |
.12 |
|
|
172.16.0.2 netmask 255.255 |
255 |
255 |
|
static(dmz2,outside)192.168.2 |
.10 |
|
|
172.16.1.1 netmask 255.255 |
255 |
255 |

- © 2005 Cisco Systems, Inc. All rights reserved.
|
fw1(config)# show run object |
group |
|
|
object-group network REMOTES |
||
|
network-object host 172 |
30.0. |
50 |
|
network-object host 172 |
30.0. |
51 |
|
object-group network DMZ1 |
||
|
network-object host 192 |
168.1 |
.10 |
|
network-object host 192 |
168.1 |
.12 |
|
object-group network DMZ2 |
||
|
network-object host 192 |
168.2 |
.10 |
|
object-group network ALL_DMZ |
||
|
group-object DMZ1 |
||
|
group-object DMZ2 |
||
|
object-group service BASIC |
||
|
port-object eq http |
||
|
port-object eq smtp |
fw1(config)# access-list aclout permit tcp object-group REMOTES object-group ALL DMZ object-group BASIC_
fw1(config)# access-list aclout permit tcp object-group REMOTES object-group ALL DMZ object-group BASIC_
In the figure, object groups are configured so that one ACL entry enables remote hosts 172.30.0.50 and 172.30.0.51 to initiate HTTP and Simple Mail Transfer Protocol (SMTP) connections to DMZ1 and DMZ2 hosts in the ALL_DMZ nested group. With object grouping, one ACL entry is required. Without object grouping, the following ACL entries would be required:
access-list outside permit tcp host 172.30.0.50 host 192.168.1.10 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.1.10 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.1.10 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.1.10 eq smtp access-list outside permit tcp host 172.30.0.50 host 192.168.1.12 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.1.12 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.1.12 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.1.12 eq smtp access-list outside permit tcp host 172.30.0.50 host 192.168.2.10 eq http access-list outside permit tcp host 172.30.0.50 host 192.168.2.10 eq smtp access-list outside permit tcp host 172.30.0.51 host 192.168.2.10 eq http access-list outside permit tcp host 172.30.0.51 host 192.168.2.10 eq smtp firewall(config)#
show running-config [all] object-group [protocol | service | network | icmp-type | id obj_grp_id]
Continue reading here: Displays object groups in the configuration
Was this article helpful?