Something similar to groups of objects, but for the ports? (must be used on an ACL)

Hello community!

I'm fairly new, when it comes to firewalls, but I have some experience with routers and switches, so I'm not completely lost.

Practically, we all know that a group object is a large bucket to throw things and then managing them as a single group, which is very useful for many reasons... so is there something similar that we can use in an ACL for the port?

Say so, let that I want to allow the following ports:

  • 80
  • 443
  • 25
  • 30500
  • 20500
  • 8080
  • 14600
  • 21
  • 753
  • 22

And instead of doing something like this:

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 80

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 443

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 25

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 30500

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 20500

access-list extended dmz_access_in permit tcp host WEB host WEB-EXT eq 8080

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 14600

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 21

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 753

dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 22

do something like:

dmz_access_in list extended access permit tcp host WEB host WEB-EXT eq PORT_LIST1

Thank you!!

PD: Excuse me if some port above are not TCP, if just one example. I just start typing all the numbers that came to my head.

Hey Rolando,

On a SAA, you can combine services and protocols based on the source/destination in an object-group service oriented. Your example would look like this:

 object-group service PORT_LIST1 service-object tcp destination range 21 22 service-object tcp destination eq 25 service-object tcp destination eq 80 service-object tcp destination eq 443 service-object tcp destination eq 753 service-object tcp destination eq 8080 service-object tcp-udp destination eq 14600 service-object tcp destination eq 20500 service-object tcp destination eq 30500

You can create also integrate groups:

 object-group service WEB_PORTS service-object tcp destination eq 80 service-object tcp destination eq 443 object-group service PORT_LIST1 group-object WEB_PORTS service-object ...

This type of group is going where the Protocol is specified in the ACL:

 access-list dmz_access_in extended permit object-group PORT_LIST1 object HOST object EXT-WEB

Tags: Cisco Security

Similar Questions

  • How to query the object module for the interface of the module interface specific, I need

    Hello.

    Currently using LabVIEW TestStand/2012 2012.

    I am looking to change the sequence of LabVIEW text translator, and in the CreateStep.vi I am trying to create a step of type WIS_Sequence_Call (a customized version of NI_Types.ini--> SequenceCall).

    I need set the file path, name and step sequence parameter values.  I think I need to access the SequenceCallModule class to do this.

    This will help the States of SequenceCallModule in the description of the file: "To access the properties and methods of a specific module class, ask the object Module for the specific module interface interface, you want to acquire".

    What, exactly, is "request" here?  It looks to "Clarify" might be what I'm after, but I want that result programmatically, IE no dialog box.

    See my excerpt below.

    Thank you.

    Use the connectivity-> ActiveX--> consider Variant. Define the type of SequenceCallModule, giving the interface as input Module. You must close the interfaces of the Module and the SequenceCallModule when you are finished with them.

    What he does is to call QueryInterface on the entry. The COM Module object implements the interfaces of the Module and the SequenceCallModule in this case to use.

    Hope this helps,

    -Doug

  • Very new to photoshop, I try to make changes to a photo and set up as a dynamic object, but after the selection of dynamic object, the grid appears and my photo dissppears

    Very new to photoshop, I try to make changes to a photo and set up as a dynamic object, but after the selection of dynamic object, the grid appears and my photo dissppears

    Well, something's wrong with Photoshop. Try to close Photoshop, and then press Command + Option + shift as you restart Photoshop. You will be asked to clear the Photoshop preferences. ATTENTION: you will lose all current preferences.

  • Error: you have an error in your SQL syntax; consult the manual for your version of the MySQL server for the right syntax to use near ')' at line 5

    Original title: how to solve this problem:

    System error

    You have an error in your SQL syntax; consult the manual for your version of the MySQL server for the right syntax to use near ')' at line 5

    Hi Roger,

    It seems that you have problems with the SQL syntax. The question you have posted is related to encoding and it would be better suited to the MSDN Community. Please report it in the community below.

    http://social.msdn.Microsoft.com/forums/SQLServer/en-us/home

    Hope this is useful.

  • I buy creative cloud, but forget the serial number cannot use lightroom, how do?

    I buy creative cloud, but forget the serial number cannot use lightroom, how do?

    Log, activation, or connection errors. CC, CS6, CS5.5

    Mylenium

  • Rotation at random one group of objects but binding at certain angles

    Hi all

    I'm looking to rotate a group of objects randomly, but limiting the rotation for just the right angles (90 °, 180 °, 270 °, 360 °).

    Is there a native way to do this? I don't think that there is - if there is a plugin that can do this?

    Thanks in advance!

    What you can do:

    There are random selection scripts that will choose randomly the existing objects.

    Selection of random items

    Then, there are replacement scripts that will replace the selected objects:

    Kelso cartography

    All you have to do is to have your loan of objects rotated made for replacement. Then randomly choose existing ones and replace.

    In this case to re-create the random objects is OK, try the ColliderScribe plugin, which has a mode of distribution. You can prepare a few objects and let the plugin distirbute them on a given area.

  • How to group by field derived for the field value below?

    Hi all

    I class field with the name of CLASS_FLD data item, I want to group by on left(CLASS_FLD,2).

    How to write him group by for the left(class_FLD,2) of expression above?

    I used earlier messages based on the syntax below but I am unable to make the Group

    <? for-each - group: row; xdoxslt:left(./CLASS_FLD,2)? > <? type: xdoxslt:left (current-group () / CLASS_FLD, 2); ' ascending '; data-type = "text"? >

    Thank you and best regards,

    1157496 wrote:

    Give me the syntax for the first group of lines BY expression counts.

    and also how the syntax would be if he is Businessunit group then group by expression (left(account,2)

    Mean you nested groups, first group BUSINESSUNIT and then other group ACCOUNT

    If yes then the internal group based on the ACCOUNT, we could watch as below

    for-each - Group: Current - Group (); xdoxslt:Left(./Account,2)? >

    For example

    . . . .

  • How to upgrade the Client installation from the Admin 12.1.0.2 to the most recent Group of patches available for the installation of the database.

    Hello

    We have sql client version 12.1.0.2 which has some issues in terms of sqlloader does not. This has been fixed by the patches oracle 20315685 group. Can someone help us understand how to install this group of patches on the installation of the Client. How to get on the client only the upgrade from group fixes provided by oracle.20315685 in this case.

    Concerning

    Patch 20315685 is WINDOWS BUNDLE PATCH 12.1DB. 0.2.2

    It is a bundle patch is developed to fix bugs related to 12.1.0.2.0 version on windows platform.

    This patch is common for the database server and Client.

    To apply the patch

    (1) services the customer stop like sqlplus, sqlloader

    (2) unzip the downloaded patch

    (3) cd

    (4) set as % ORACLE_HOME %path% environment variable

    (5) %ORACLE_HOME%/OPatch/opatch apply

    It will apply the necessary corrections.

  • An application like Nike Running... But for the market

    I wanted an app to walk and does not. All of you who have a few apps?

    I use MapMyWalk. I use the free version, and it does everything I want for the market.

  • Structure of the vanilla and object relationship for the Siebel complaint process.

    Hi all

    We have seibel eautomotive implementation. In this complaint, utility has been activated. We have a requirement to report on the complaint through OBIEE. Do we need a thing for the same star schema structure. If any of you have been working on it so please let me know is vanilla mappings, structure of this RPD star for this schema.


    Concerning
    Niraj

    Hi nirajkumar,

    If your vanilla 7.6 BIAPPS help or a higher version, then you would have the module eautomotive in siebel vanilla and all mappings to start the schema and the default reports required by the company would be set up. It would be built pre analytical in the vanilla version.

    Check out these could b of help: -.
    http://download.Oracle.com/docs/CD/E14223_01/BIA.796/e14217.PDF
    http://www.Oracle.com/us/support/licensecodes/Siebel/Siebel-CRM-bi-integration-166917.html#auto
    http://download.Oracle.com/docs/CD/E05555_01/PDFFiles/704auto/Auto_WhatsNewAdm.PDF

    hope helps you.

    See you soon,.
    KK

  • Hide an object displayed for the rest of the project

    I have an item I want to show for almost all of my slides.  If I use the option "Show the rest of the project", what is the best way to hide on a few slides, on that I don't want?

    Hello

    Unfortunately my crystal ball does not for the moment I'll have to ask which version of Captivate you use.

    See you soon... Rick

    Useful and practical links

    Captivate wish form/Bug report form

    Certified Adobe Captivate training

    SorcerStone blog

    Captivate eBooks

  • I am looking for a solution Server (with Te css) for the fact that Firefox uses the system DPI settings, which makes my site look (too) big.

    My site appears much too big in firefox. And I want all browsers to view my site properly.
    I know that there are settings wihtin firefox that fix this problem. But I'm looking for a solution on server side, so that visitors to my site must not be disturbed by changing their settings.

    You may need to change your site as soon as 30 Chrome and IE 11 will also use the system DPI setting (like Firefox does now).

    Possible solution:

    • Type of topic: config in the Firefox address bar and hit the Enter key.
    • If the warning that this might void your warranty , click I'll be careful, I promised.
    • Search for layout.css.devPixelsPerPx

    • Double-click layout.css.devPixelsPerPx to edit its value. The default value is - 1.0 in Firefox 22 and above. Change it to 1.0 to run as in previous versions of Firefox.

    If necessary, further adjust the value of 0.1 or 0.05. Values between 1.0 and around 0.5 to reduce the size of the elements. Use a value greater than 1.0 to increase the size. For example, a value of 1.25 will increase the font size of the 125% to account for the default DPI setting in Windows 8. Check the value that you enter. Definition of a value that is too small will take everything away and too high will explode things.

    If the web pages should always be adjusted so you can watch the extension Default FullZoom Level or NoSquint .

    To adjust the font size for the user interface, you can use the extension of theme font & size changer .

  • like firefox updates, it takes more time for the program to load, using win 7 it takes 17secs toopen window

    One of the reasons for the use of firefox is its ability to be in place and ready to use quickly (I was one of the first users.) Now, Google and dare say int explore seem to have the advantage

    One possible cause is security software (firewall) that blocks or limits Firefox or plugin-container process without informing you, possibly after the detection of changes (update) for the Firefox program.

    Delete all rules for Firefox in the list of permissions in the firewall and leave your firewall again ask permission to get full unlimited access to the internet for Firefox and the plugin-container and the update process.

    See:

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions or if hardware acceleration is the cause of the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > appearance/themes).

    Create a new profile as a test to see if your profile is the source of the problems.

    See "basic troubleshooting: a new profile:

    There may be extensions and plugins installed by default in a new profile, so check that in "tools > Modules > Extensions & Plugins" in case there are still problems.

    If this new profile works then you can transfer files from the old profile to the new profile, but make sure not to copy corrupted files.

    See:

  • What Win XP driver is required for the port DV on a Satellite Pro P100

    Which driver "specifically" is held by Win XP on a Satellite Pro P100 DV port?
    Toshiba provides this driver on the download page?

    Win XP does not recognize the camera into the DV port.
    It does not recognize the camera a few months ago but not detect it when it is connected.

    I don't know what changes have been made since then. Can I simply re - install the proper drivers?

    Thanks in advance.
    Tom

    Hello

    DV port? Do you mean the iLink (firewire port)?
    You have a camcorder?

    I can connect my camcorder to the laptop using the firewire cable and firewire port.
    There is no special driver for the firewire port. The Windows operating system contains the own drivers that control this port.

    Maybe you should remove the device and then Manager should restart the operating system. This allows to recognize the FireWire again

  • standalone application for the acquisition of data using the NI DAQ card

    I did a stand-alone application in labview GUI for data acquisition and processing of the signal. If I have to run this application in any other computer which should be all installed software other than the labview runtime engine... CD DEVICE DRIVERS OR alone must be installed or do I have to install any other software of data acquisition using the data acquisition card OR?

    Thanks and greetings

    You need only the racing of the engine, the device for the device drivers, maybe need pilots VISA if you make serial or something of this nature, you may need the channels or tasks created in the measures OR and automation if you created the it.

    There may be other things you'll need depending on what you include in your code and what tool kits that you have installed.

Maybe you are looking for