How to correct invalid services (from ASA)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to correct invalid services (from ASA)

L0 Member

Hi,

 

I'm migrating Cisco ASA security policies and showing some invalid services. 

icmp-echo

icmp-traceroute

Please let me know the correct services and how to replace it in service groups.

 

Thanks,

Karun

2 REPLIES 2

L1 Bithead

Hi there,

 

(edit: misspellings and additional info)

 

icmp-echo - Is this just for pings? If so, that would just be PA's "ping." You also have the option of "icmp." I frequently use both in an application group in case they're identified differently.

icmp-traceroute - This would likely just be PA's "traceroute."

 

In fact, I often use an application group that has all kinds of echo-related applications, ping, icmp, traceroute, etc. Then I can just reference that later.

 

Here's a link to their Application Research Center if you don't already have it, or "Applipedia." This way you can look through the descriptions to see if the ones listed above meet your needs.

L1 Bithead

Right click on the invalid service and select "Search & Replace"

This will bring you to the "Tools" menu

Select the service you want to replace in left pane

The right pane will show where used

Select all of the objects ( or just the ones you want to replace )

Click "Add to replace" at the bottom

Click the "Replace" tab in the right pane

Select the drop down for "Replace by" and choose what you want ( In your example could select "Applications")

Select the drop down for "To", select ICMP or similar for your example

In the "Options" menu select how you want to handle the replace.  Depending on what else is in the service-group you may need to split the rules.  By splitting the rule it will make an additional rule with just the "ICMP" application.  You would need to do this if the service group contained tcp/udp service ports as the rule won't work with both service and application defined, well at least not the way you want it to...

Click "Replace All" at bottom right to execute.

 

 

 

  • 1461 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!