Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Service objects

Want to summarize with AI?

Log in

Learn how service objects represent protocols and ICMP values that Security Cloud Control Firewall Management recognizes and manages in supported device configurations.


Firepower service objects

FTD service objects, service groups, and port groups are reusable components that contain protocols or ports considered part of the IP protocol suite.

FTD service groups are collections of service objects. A service group may contain objects for one or more protocols. You can use the objects and groups in security policies for purposes of defining network traffic matching criteria, for example, to use access rules to allow traffic to specific TCP ports. The system includes several pre-defined objects for common services. You can use these objects in your policies; however, you cannot edit or delete system-defined objects.

Firepower Device Manager and Firepower Management Center refer to service objects as port objects and service groups and port groups.

See Create and Edit Firepower Threat Defense Service Objects for more information.

Protocol objects

Protocol objects are a type of service object that contain less-commonly used or legacy protocols. Protocol objects are identified by a name and protocol number. Security Cloud Control recognizes these objects in ASA and Firepower (FDM-managed device) configurations and gives them their own filter of "Protocols" so you can find them easily.

See Create and Edit Firepower Threat Defense Service Objects for more information.

ICMP objects

An Internet Control Message Protocol (ICMP) object is a service object specifically for ICMP and IPv6-ICMP messages. Security Cloud Control recognizes these objects in ASA and Firepower configurations when those devices are onboarded and Security Cloud Control gives them their own filter of "ICMP" so you can find the objects easily.

Using Security Cloud Control, you can rename or remove ICMP objects from an ASA configuration. You can use Security Cloud Control to create, update, and delete ICMP and ICMPv6 objects in a Firepower configuration.

Note

For the ICMPv6 protocol, AWS does not support choosing specific arguments. Only rules that allow all ICMPv6 messages are supported.

See Create and Edit Firepower Threat Defense Service Objects for more information.


Create and edit Firepower service objects

To create a firepower service object, follow these steps:

Firewall Device Manager (FDM-managed) service objects are reusable components that specify a TCP/IP protocol and a port. The Firewall Device Manager, On-Premises Firewall Management Center and Cloud-Delivered Firewall Management Center refer to these objects as "Port Objects."

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click > FTD > Service.

4.

Enter an object name and description.

5.

Select Create a service object.

6.

Click the Service Type button and select the protocol for which you want to create an object.

7.

Configure the protocol as follows:

8.

Click Add.

9.

Review and deploy the changes you made now, or wait and deploy multiple changes at once.


Create a Firepower Service Group

A service group can be made up of one or more service objects representing one or more protocols. The service objects need to be created before they can be added to the group. The Firepower Device Manager and Firepower Management Center refer to these objects as "Port Objects."

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click > FTD > Service.

4.

Enter an object name and description.

5.

Select Create a service group.

6.

Add an object to the group by clicking Add Object.

  • Click Create to create a new object as you did above in Create a Firepower Service Object above.

  • Click Choose to add an existing service object to the group. Repeat this step to add more objects.

7.

Click Add when you are done adding service objects to the service group.

8.

Review and deploy the changes you made now, or wait and deploy multiple changes at once.


Edit a Firepower service object or service group

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Filter the objects to find the object you want to edit and then select the object in the object table.

4.

In the Actions pane, click Edit .

5.

Edit the values in the dialog box in the same fashion that you created them in the procedures above.

6.

Click Save.

7.

Security Cloud Control displays the policies that will be affected by the change. Click Confirm to finalize the change to the object and any policy affected by it.

8.

Review and deploy the changes you made now, or wait and deploy multiple changes at once.