Cisco PIX 525 Especificações Página 216

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 215
13-14
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 13 Identifying Traffic with Access Lists
Simplifying Access Lists with Object Grouping
You can also nest object groups in other object groups.
Note The ACE system limit applies to expanded access lists. If you use object groups in ACEs, the number of
actual ACEs that you enter is fewer, but the number of expanded ACEs is the same as without object
groups. In many cases, object groups create more ACEs than if you added them manually, because
creating ACEs manually leads you to summarize addresses more than an object group does. To view the
number of expanded ACEs in an access list, enter the show access-list access_list_name command.
Adding Object Groups
This section describes how to add object groups.
This section includes the following topics:
Adding a Protocol Object Group, page 13-14
Adding a Network Object Group, page 13-15
Adding a Service Object Group, page 13-15
Adding an ICMP Type Object Group, page 13-16
Adding a Protocol Object Group
To add or change a protocol object group, follow these steps. After you add the group, you can add more
objects as required by following this procedure again for the same group name and specifying additional
objects. You do not need to reenter existing objects; the commands you already set remain in place unless
you remove them with the no form of the command.
To add a protocol group, follow these steps:
Step 1 To add a protocol group, enter the following command:
hostname(config)# object-group protocol
grp_id
The grp_id is a text string up to 64 characters in length.
The prompt changes to protocol configuration mode.
Step 2 (Optional) To add a description, enter the following command:
hostname(config-protocol)# description
text
The description can be up to 200 characters.
Step 3 To define the protocols in the group, enter the following command for each protocol:
hostname(config-protocol)# protocol-object
protocol
The protocol is the numeric identifier of the specific IP protocol (1 to 254) or a keyword identifier (for
example, icmp, tcp, or udp). To include all IP protocols, use the keyword ip. For a list of protocols you
can specify, see the “Protocols and Applications” section on page D-11.
Vista de página 215
1 2 ... 211 212 213 214 215 216 217 218 219 220 221 ... 603 604

Comentários a estes Manuais

Sem comentários