Networking-Blog

My WordPress Blog

ASA – Group Object

Create a Object-Group icmp-type ICMP traffic :

object-group icmp-type INBOUND
description Permit necessary inbound ICMP traffic
icmp-object echo
icmp-object echo-reply
icmp-object unreachable
icmp-object time-exceeded

Create a Object-Group service for TCP traffic :

object-group service INBOUND tcp
description Inbound Access
port-object eq 3389
port-object range 9998 9999

Cisco ASA Object-Group

Object groups on the ASA allow you to group similar types of components within a single heading.  You can use this heading for access-lists, which in turn can be used for access control, NAT, encryption, and traffic classification.

The two main object groups I use are network and service.

The network object group is where you put subnets and hosts, while the service object group is for protocols and ports.

object-group service TCP_PORTS_10038_10046 tcp
port-object eq 10038
port-object eq  10046
!
object-group network TCP_10038_10046_LAN
network-object host 172.18.192.24
network-object host 172.16.0.68
!
object-group network TCP_10038_10046_WAN
network-object host 125.215.194.223
network-object host 125.215.194.252
network-object host 125.215.194.253
network-object host 125.215.194.232
!
access-list MPLS_access_in remark Access to  TCP_PORTS_10038_10046
access-list MPLS_access_in extended permit tcp object-group TCP_10038_10046_LAN object-group TCP_10038_10046_WAN object-group TCP_PORTS_10038_10046
!
!
Configure Inspect Policy:

class-map inspection_default
match default-inspection-traffic

class-map TCP_PORTS_10038
match port tcp eq 10038
!
class-map TCP_PORTS_10046
match port tcp eq 10046
!
!
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls
!
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
inspect esmtp tls-esmtp
class TCP_PORTS_10038
class TCP_PORTS_10046
!
service-policy global_policy global

Verify:

show access-list | grep 172.18.192.24
show service-policy inspect tcp
show service-policy global