Why do you need an object group for an ACL?
A typical ACE could allow a group of users to have access only to a specific group of servers. In an object group-based ACL, you can create a single ACE that uses an object group name instead of creating many ACEs (which would require each one to have a different IP address).
Why do you need an access control list ( ACL )?
The main idea of using an ACL is to provide security to your network. Without it, any traffic is either allowed to enter or exit, making it more vulnerable to unwanted and dangerous traffic. To improve security with an ACL you can, for example, deny specific routing updates or provide traffic flow control.
Where can I find object groups for Cisco ACLs?
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. You can use object groups only in extended named and numbered ACLs.
Where is the best place to configure an ACL?
So, one of the best places to configure an ACL is on the edge routers. A routing device with an ACL can be placed facing the Internet and connecting the DMZ (De-Militarized Zone), which is a buffer zone that divides the public Internet and the private network.
How to create nested object groups in ACLS?
(Optional) Specifies a nested (child) object group to be included in the current (parent) object group. The type of child object group must match that of the parent (for example, if you are creating a network object group, you must specify another network object group as the child).
Is the object group based ACL supported by IPsec?
Object group-based ACLs are not supported with IPsec. The highest number of object group-based ACEs supported in an ACL is 2048. You can configure conventional ACEs and ACEs that refer to object groups in the same ACL.