Jump to content

object-group network на ASR

Что-то я с наскоку не могу врубиться.



В IOS есть такие замечательные конструкции типа:

object-group network ADM
object-group network ADM_SRV
object-group network DMZ
 group-object ADM
 group-object ADM_SRV

object-group network LocalNet
object-group network Local
group-object LocalNet

ip access-list extended DMZ_IN
permit ip any object-group DMZ
deny ip object-group Local object-group Local
permit ip any any
ip access-list extended DMZ_OUT
permit ip object-group DMZ any
deny ip object-group Local object-group Local
permit ip any any



Что удобно понятно, лаконично.

А в ASR как?

Rou(config)#object-group ?
 security  Security object group
Rou(config)#object-group security DMZ
Rou(config-security-group)#group-object ?
 WORD  Nested object group name

Rou(config-security-group)#group-object ADM
Object group ADM is not configured
Security object group configuration commands:
 description     User object group description
 exit            Exit from User policy-group configuration mode
 group-object    Nested object group
 no              Negate or set default values of a command
 security-group  Security Group Tag

И все собственно.




License Level: advipservices




Security Configuration Guide: Zone-Based Policy Firewall, Cisco IOS XE Release 3S

Говорит что есть.

Собственно CFN говорит что .3.12 .3.13, но насколько оно там юзабельно и сами ветки стабильны? Вот в чем вопрос...

Edited by myst

Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this