Contents
How to create nested object groups in ACLS?
(Optional) Specifies a nested (child) object group to be included in the current (parent) object group. The type of child object group must match that of the parent (for example, if you are creating a network object group, you must specify another network object group as the child).
What are the two types of ACL object groups?
This feature supports two types of object groups for grouping ACL parameters: network object groups and service object groups. These object groups can be used to group IP addresses, protocols, protocol services (ports), and Internet Control Message Protocol (ICMP) types.
Why are Cisco ACLs based on object groups?
Object-group-based ACLs simplify static ACL deployments for large user access environments on Cisco IOS routers. The zone-based firewall benefits from object groups, because object groups simplify policy creation (for example, group A has access to group A services).
Is the object group based ACL supported by IPsec?
Object group-based ACLs are not supported with IPsec. The highest number of object group-based ACEs supported in an ACL is 2048. You can configure conventional ACEs and ACEs that refer to object groups in the same ACL.
Why do you need an object group for an ACL?
A typical ACE could allow a group of users to have access only to a specific group of servers. In an object group-based ACL, you can create a single ACE that uses an object group name instead of creating many ACEs (which would require each one to have a different IP address).
Where can I find object groups for Cisco ACLs?
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. You can use object groups only in extended named and numbered ACLs.
How are object groups used in access control lists?
Object Groups for ACLs. The Object Groups for ACLs feature lets you classify users, devices, or protocols into groups and apply those groups to access control lists (ACLs) to create access control policies for those groups.