Skip to Content
Network Warrior, 2nd Edition
book

Network Warrior, 2nd Edition

by Gary A. Donahue
May 2011
Intermediate to advanced
788 pages
23h 34m
English
O'Reilly Media, Inc.
Content preview from Network Warrior, 2nd Edition

Object Groups

Object groups allow a group of networks, IP addresses, protocols, or services to be referenced with a single name. This is extremely helpful when you’re configuring complex access lists. Take the situation shown in Figure 28-2. There are three web servers, each of which offers the same three protocols: SMTP (TCP port 25), HTTP (TCP port 80), and HTTPS (TCP port 443).

Complex access list scenario

Figure 28-2. Complex access list scenario

Note

This example shows a collocated website. On a normal enterprise network, web servers should not reside on the inside network, but rather in a DMZ. Of course, “normal” is a very subjective word.

Because the IP addresses of the three servers are not in a range that can be addressed with a single subnet mask, each server must have its own access list entry. Additionally, there must be an entry for each protocol for each server.

As a result, you must configure nine access list entries to allow each of the three protocols to these three servers:

access-list In permit tcp any host 192.168.1.101 eq smtp access-list In permit tcp any host 192.168.1.101 eq www access-list In permit tcp any host 192.168.1.101 eq https access-list In permit tcp any host 192.168.1.201 eq smtp access-list In permit tcp any host 192.168.1.201 eq www access-list In permit tcp any host 192.168.1.201 eq https access-list In permit tcp any host 192.168.1.228 eq smtp access-list In permit tcp any host ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Computer Networks, Fifth Edition

Computer Networks, Fifth Edition

David J. Wetherall, Andrew S. Tanenbaum

Publisher Resources

ISBN: 9781449307974Errata Page