Object groups on the ASA allow you to group similar types of components within a single heading. You can use this heading for access-lists, which in turn can be used for access control, NAT, encryption, and traffic classification.
The two main object groups I use are network and service.
The network object group is where you put subnets and hosts, while the service object group is for protocols and ports.
object-group service TCP_PORTS_10038_10046 tcp
port-object eq 10038
port-object eq 10046
!
object-group network TCP_10038_10046_LAN
network-object host 172.18.192.24
network-object host 172.16.0.68
!
object-group network TCP_10038_10046_WAN
network-object host 125.215.194.223
network-object host 125.215.194.252
network-object host 125.215.194.253
network-object host 125.215.194.232
!
access-list MPLS_access_in remark Access to TCP_PORTS_10038_10046
access-list MPLS_access_in extended permit tcp object-group TCP_10038_10046_LAN object-group TCP_10038_10046_WAN object-group TCP_PORTS_10038_10046
!
!
Configure Inspect Policy:
class-map inspection_default
match default-inspection-traffic
class-map TCP_PORTS_10038
match port tcp eq 10038
!
class-map TCP_PORTS_10046
match port tcp eq 10046
!
!
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls
!
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
inspect esmtp tls-esmtp
class TCP_PORTS_10038
class TCP_PORTS_10046
!
service-policy global_policy global
Verify:
show access-list | grep 172.18.192.24
show service-policy inspect tcp
show service-policy global