Creating A Network Object Group; Adding A Description To A Network Object Group; Configuring A Network Ip Address For A Network Object Group; Configuring A Host Ip Address - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 1
Configuring Security Access Control Lists
Note
Configuring Network Object Groups
OL-16202-01
For example, consider the following three object groups:
MyServices—Includes the TCP and UDP port numbers of the service
requests that are allowed access to the internal network
TrustedHosts—Includes the host and network addresses that are allowed
access to the greatest range of services and servers
PublicServers—Includes the host addresses of servers to which the greatest
access is provided
After you create these groups, you can use a single ACL entry to allow trusted
hosts to make specific service requests to a group of public servers.
You can configure a maximum of 4 K object groups in an ACE. Each object group
can have up to 40,000 elements. The maximum number of ACL entries in an ACE
is 40,000.
The system-wide ACL entry limit of 40,000 entries applies to expanded ACL
entries. An expanded ACL entry is the individually entered entry equivalent of an
object-group element. If you use object groups in an ACL, you enter fewer actual
ACL entries. When the ACE expands an ACL that references an object group,
internally, multiple ACL entries will exist based on the number of elements
present in the object group. To view the number of expanded ACL entries in an
ACL, enter the show access-list name command. For details, see the
ACL Configuration Information and Statistics"
This section describes how to configure object groups to streamline the creation
of ACL entries in an ACL. It includes the following topics:

Creating a Network Object Group

Adding a Description to a Network Object Group

Configuring a Network IP Address for a Network Object Group

Configuring a Host IP Address

Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Simplifying Access Control Lists with Object Groups
section.
"Displaying
1-21

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents