O'Reilly logo

Network Warrior by Gary A. Donahue

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Object Groups

Object groups allow a group of networks, IP addresses, protocols, or services to be referenced with a single name. This is extremely helpful when configuring complex access lists. Take the situation shown in Figure 26-2. There are three web servers, each of which offers the same three protocols: SMTP (TCP port 25), HTTP (TCP port 80), and HTTPS (TCP port 443).

Complex access-list scenario

Figure 26-2. Complex access-list scenario

Tip

This example shows a collocated web site. On a normal enterprise network, web servers should not reside on the inside network, but rather in a DMZ.

Because the IP addresses of the three servers are not in a range that can be addressed with a single subnet mask, each of the servers must have its own access-list entry. Additionally, there must be an entry for each protocol for each server.

As a result, nine access-list entries must be configured to allow each of the three protocols to these three servers:

access-list In permit tcp any host 192.168.1.101 eq smtp access-list In permit tcp any host 192.168.1.101 eq www access-list In permit tcp any host 192.168.1.101 eq https access-list In permit tcp any host 192.168.1.201 eq smtp access-list In permit tcp any host 192.168.1.201 eq www access-list In permit tcp any host 192.168.1.201 eq https access-list In permit tcp any host 192.168.1.228 eq smtp access-list In permit tcp any host 192.168.1.228 eq www access-list In permit ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required