Displays object groups in the configuration
|
fw1# show run object-group |
||
|
object-group network DMZ1 |
||
|
network-object host 192.168 |
1 |
10 |
|
network-object host 192.168 |
1 |
12 |
|
object-group network DMZ2 |
||
|
network-object host 192.168 |
2 |
10 |
|
object-group network ALL DMZ |
||
|
group-object DMZ1 |
||
|
group-object DMZ2 |
© 2005 Cisco Systems, Inc. All rights reserved. SNPA v4.0—6-20
© 2005 Cisco Systems, Inc. All rights reserved. SNPA v4.0—6-20
Use the show running-config object-group command to display a list of the currently configured object groups. The security appliance displays defined object groups by their group identifier when the show running-config object-group id grp_id command form is entered and by group type when the show running-config object-group command is entered with the protocol, service, icmp-type, or network option. When you enter show running-config object-group without a parameter, all defined object groups are shown.
The syntax for the show running-config object-group command is as follows:
|
icmp-type |
(Optional) Displays ICMP-type object groups. |
|
id obj_grp_id |
(Optional) Displays the specified object group. |
|
network |
(Optional) Displays network object groups. |
|
protocol |
(Optional) Displays protocol object groups. |
|
service |
(Optional) Displays service object groups. |
|
Removing Configured Object Groups |
||
|
1 ^^^^^^^^ tiiutiuuiii 1 |
||
|
firewall(config)# |
||
|
no object-group service obj grp id {tcp | udp | tcp-udp} |
||
|
• Removes a specific service object group |
||
|
firewall(config)# |
||
|
no object-group protocol | network | icmp-type obj grp id |
||
|
• Removes a specific protocol, network, or ICMP-type object group |
||
|
firewall(config)# |
||
|
clear configure object-group [{protocol | service | icmp-type | network}] |
||
|
• Removes all object groups or all object groups of a specific type |
||
|
fw1(config)# no object-group network ALL DMZ fw1(config)# clear config object-group protocol |
||
|
© 2005 Cisc |
||
Any object-group command can be removed with its no form. Use the no object-group command to remove a specific object group.
The syntax for the no object-group commands is as follows:
|
icmp-type |
Defines a group of ICMP types, such as echo and echo-reply. After entering the main object-group icmp-type command, add ICMP objects to the ICMP-type group with the icmp-object and the group-object commands. |
|
network |
Defines a group of hosts or subnet IP addresses. After entering the main object-group network command, add network objects to the network group with the network-object and the group-object commands. |
|
objgrpid |
Identifies the object group (one to 64 characters) and can be any combination of letters, digits, and the characters "_","-", and ".". |
|
protocol |
Defines a group of protocols, such as TCP and UDP. After entering the main object-group protocol command, add protocol objects to the protocol group with the protocol-object and the group-object commands. |
|
service |
Defines a group of TCP and UDP port specifications, such as "eq smtp" and "range 2000 2010." After entering the main object-group service command, add port objects to the service group with the port-object and the group-object commands. |
|
tcp |
Specifies that the service group is used for TCP. |
|
tcp-udp |
Specifies that the service group can be used for TCP and UDP. |
|
udp |
Specifies that the service group is used for UDP. |
The clear configure object-group command can be used to remove all object groups or all object groups of a specific type. When entered without a parameter, the clear configure object-group command removes all defined object groups that are not being used in a command. Using the protocol, service, icmp-type, or network parameter removes all defined object groups that are not being used in a command for that group type only. An object group cannot be removed if it is part of an active ACL and its removal would result in the ACL becoming incomplete or invalid.
The syntax for the clear configure object-group command is as follows:
|
icmp-type |
(Optional) Clears all ICMP-type groups. |
|
network |
(Optional) Clears all network groups. |
|
protocol |
(Optional) Clears all protocol groups. |
|
service |
(Optional) Clears all service groups. |
Continue reading here: Authenticate to the Security Appliance before accessing other services
Was this article helpful?