I'm migrating configuration from ASA version 8.2 and I noticed that quite a lot of objects are doubled and also some rules are doubled.
If I look at doubled objects 1 of them has 'default' under 'src File' coloumn and the other has config file name in that coloumn (filename matching the one i imported). I only imported this named config file. Where does 'default' come from?
And both objcts of this doubled pir are used so I'm assuming rules have been doubled for the same reason.
Anyone had similar issues?
Now I noticed it also didn't change destination zone to post DNAT zone in FW rules. Maybe cause the object isn't correct; it seems it created 2 same objects out of 1 object with no mask and also left the orginal one
And FW rules (connected with above post DNAT problem) allowing known services on TCP ports (www, smtp) have ipsec-esp as application:
Corresponding NAT rule:
I know this is old but I believe the reason for Default is that the object is already part of a group in the ASA. If the SrcFile is equal to the filename, that means expedition has created the objects based on a rule.
Example: TCP port 9060 is part of an object group already. When you import the ASA config, Expedition creates a new object and SrcFile shows up as "Default". TCP 9061 is not in an object group but used in a rule. Expedition creates the object and marks the SrcFile as the filename.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!