Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Service objects

Want to summarize with AI?

Log in

Learn how service objects represent protocols and ICMP values that Security Cloud Control Firewall Management recognizes and manages in supported device configurations.


ASA service objects

ASA service objects, service groups, and port groups are reusable components that contain protocols or ports considered part of the IP protocol suite. In a service object you can specify a single protocol and assign it to a source port, destination port, or both source and destination ports. A service group contains many service objects and can include a mix of protocols.

A port group is a kind of ASA service object. Port groups contain port objects that pair a service type, such as TCP or UDP, and a port number or a range of port numbers. You can then use the objects in security policies for the purposes of defining traffic matching criteria. For example, you can use them in access control rules to allow traffic to a specific range of TCP ports.

See Create and Edit ASA Service Objects for more information.

Protocol objects

Protocol objects are a type of service object that contain less-commonly used or legacy protocols. Protocol objects are identified by a name and protocol number. Security Cloud Control recognizes these objects in ASA and Firepower (FDM-managed device) configurations and gives them their own filter of "Protocols" so you can find them easily.

ICMP objects

An Internet Control Message Protocol (ICMP) object is a service object specifically for ICMP and IPv6-ICMP messages. Security Cloud Control recognizes these objects in ASA and Firepower configurations when those devices are onboarded and Security Cloud Control gives them their own filter of "ICMP" so you can find the objects easily.

Using Security Cloud Control, you can rename or remove ICMP objects from an ASA configuration. You can use Security Cloud Control to create, update, and delete ICMP and ICMPv6 objects in a Firepower configuration.

Note

For the ICMPv6 protocol, AWS does not support choosing specific arguments. Only rules that allow all ICMPv6 messages are supported.


Create and Edit ASA Service Objects

In a service object, you can specify a single protocol and assign it to a source port, destination port, or both source and destination ports.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click Create Object > ASA > Service.

4.

Enter an object name.

5.

Select Create a service object

6.

Click the Service Type button and select the protocol for which you want to make an object.

  • For TCP, UDP, and TCP-UDP service types, enter a source port, destination port, or both:

    • The source port identifier allows you to match traffic originating from a particular numbered port. In the source port identifier, select an operator: equal to, range, less than, greater than, or not equal to and provide the appropriate port number or range.

    • The destination port identifier allows you to match traffic arriving at a particular numbered port. In the destination port identifier, select an operator: equal to, range, less than, greater than, or not equal to and provide the appropriate port number or range.

  • For Protocol service types, enter a protocol number between 0-255, or a well-known name, such as ip, tcp, udp, gre, and so forth.

7.

Click Add.

Examples

  • A service object that identifies incoming FTP traffic would be one with a TCP Service type and a destination port range of 21.

  • A service object that identifies outgoing DNS and DNS over TCP traffic would be one with a tcp-udb service type and a source port equal to 53.


Create an ASA Service Group

A service group can be made up of one or more service objects representing one or more protocols.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

Choose Objects.

3.

Choose Create Object > ASA > Service.

4.

Enter an object name.

5.

Select Create a service group.

6.

Add an existing object by clicking Add Object, selecting an object, and clicking Select. Repeat this step to add more objects.

7.

If needed, add an extra individual service type value to the service group

  • For TCP, UDP, and TCP-UDP service types, enter a source port, destination port, or both:

    • The source port identifier allows you to match traffic originating from a particular numbered port. In the source port identifier, select an operator: equal to, range, less than, greater than, or not equal to and provide the appropriate port number or range.

    • The destination port identifier allows you to match traffic arriving at a particular numbered port. In the destination port identifier, select an operator: equal to, range, less than, greater than, or not equal to and provide the appropriate port number or range.

  • For Protocol service types, enter a protocol number between 0-255, or a well-known name, such as ip, tcp, udp, gre, and so forth.

8.

To add more individual port values, click Add Another Value and repeat step 6.

9.

Click Add when you are done adding service objects and service values to the service group.


Edit an ASA Service Object or Service Group

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Filter the objects to find the object you want to edit and then select the object in the object table.

4.

In the details pane, click edit .

5.

Edit the values in the dialog box in the same fashion that you created them in the procedures above.

6.

Click Save.

7.

Security Cloud Control displays the policies that will be affected by the change. Click Confirm to finalize the change to the object and any policy affected by it.