data:image/s3,"s3://crabby-images/277df/277dfe70d8425f1f0d34b1728481d989417c8447" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 243"
13-17
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 13 Identifying Traffic with Access Lists
Simplifying Access Lists with Object Grouping
If you make two network object groups, one for the inside hosts, and one for the web servers, then the
configuration can be simplified and can be easily modified to add more hosts:
hostname(config)#
object-group network denied
hostname(config-network)#
network-object host
10.1.1.4
hostname(config-network)#
network-object host
10.1.1.78
hostname(config-network)#
network-object host
10.1.1.89
hostname(config-network)#
object-group network web
hostname(config-network)#
network-object host
209.165.201.29
hostname(config-network)#
network-object host
209.165.201.16
hostname(config-network)#
network-object host
209.165.201.78
hostname(config-network)#
access-list ACL_IN extended deny tcp object-group denied
object-group web eq www
hostname(config)#
access-list ACL_IN extended permit ip any any
hostname(config)#
access-group ACL_IN in interface inside
Displaying Object Groups
To display a list of the currently configured object groups, enter the following command:
hostname(config)#
show
object-group
[
protocol
|
network
|
service
|
icmp-type
|
id
grp_id
]
If you enter the command without any parameters, the system displays all configured object groups.
The following is sample output from the
show object-group
command:
hostname#
show object-group
object-group network ftp_servers
description: This is a group of FTP servers
network-object host 209.165.201.3
network-object host 209.165.201.4
object-group network TrustedHosts
network-object host 209.165.201.1
network-object 192.168.1.0 255.255.255.0
group-object ftp_servers
Removing Object Groups
To remove an object group, enter one of the following commands.
Note
You cannot remove an object group or make an object group empty if it is used in an access list.
•
To remove a specific object group, enter the following command:
hostname(config)#
no object-group
grp_id
•
To remove all object groups of the specified type, enter the following command:
hostname(config)#
clear object-group
[
protocol
|
network
|
services
|
icmp-type
]
If you do not enter a type, all object groups are removed.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......