ASA Object-Group Access-Lists

In this lab you create three different service object groups using 2 different methods. I am wondering if there is a difference in the behavior between the two. I am guessing no. The first method seems to offer a bit more flexible as it allows you use as a source or destination port. But to me they seem the same.

 

object-group service TELNET tcp

Comments

  • Hi,

       The lab is trying to show you the different ways you can achieve the requirements. About this statement "I have read that in the lab it is best to perform ACLs in the least amount of lines possible." , i disagree. In the lab you do what you're told to do, nothing else.

    Regards,

    Cristian.

  • I figured you were just trying to show the different possibilities
    it just didn’t say that in the configuration explanation.

    Doing exactly what they ask makes sense. In your example you
    created an extra object group not required by the task :) ALL_DESTINATIONS. I just took
    it a step further to summarize everything into one set of object groups.

  • Hi,

       I changed the task requiements to match with the solution. In general, with the "Technologies Workbook", wording of the task is not that important, as the solution may just show multiple/different solutions just to show your options. In "Practice Labs", wording is very important, so solution should match he tak wording and requirements, plus fixing caveats which are NOT visible from the task requirements.

    Regards,

    Cristian.

  • Ok. I am treating the workbook just like a lab. Haven taken the R&S lab 4 times I know I will get tripped up on wording so trying to practice that.

Sign In or Register to comment.