Cisco Cisco Firepower Management Center 4000
5-12
FireSIGHT System User Guide
Chapter 5 Managing Reusable Objects
Working with VLAN Tag Objects
Step 3
Click
Add Port
.
The Port Objects pop-up window appears.
Step 4
Type a
Name
for the port object. You can use any printable standard ASCII characters except curly braces
(
{}
).
Step 5
Select a
Protocol
.
You can quickly select
TCP
,
UDP
,
IP
,
ICMP
, or
IPv6-ICMP
, or you can use the
Other
drop-down list to select
either a different protocol or
All
protocols.
Step 6
Optionally, restrict a TCP or UDP port object using a
Port
or port range.
You can specify any port from 1 to 65535 or
any
to match all ports. Use a hyphen to specify a range of
ports.
Step 7
Optionally, restrict a ICMP or IPV6-ICMP port object using a
Type
and, if appropriate, a related
Code
.
When you create an ICMP or IPv6-ICMP object, you can specify the type and, if applicable, the code.
For more information on ICMP types and codes, see
http://www.iana.org/assignments/icmp-parameters/icmp-parameters.xml and
http://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xml. You can set the type to
any to match any type or set the code to any to match any code for the specified type.
For more information on ICMP types and codes, see
http://www.iana.org/assignments/icmp-parameters/icmp-parameters.xml and
http://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xml. You can set the type to
any to match any type or set the code to any to match any code for the specified type.
Step 8
Optionally, select
Other
and a protocol from the drop-down list. If you select
All
protocols, type a port
number in the
Port
field.
Step 9
Click
Save
.
The port object is added.
Working with VLAN Tag Objects
License:
Any
Each VLAN tag object you configure represents a VLAN tag or range of tags. You can use VLAN tag
objects and groups (see
objects and groups (see
) in various places in the system’s web interface,
including access control policies and event searches. For example, you could write an access control rule
that applies only to a specific VLAN.
that applies only to a specific VLAN.
You cannot delete a VLAN tag object that is in use. Additionally, after you edit a VLAN tag object used
in an access control policy, you must reapply the policy for your changes to take effect.
in an access control policy, you must reapply the policy for your changes to take effect.
To add a VLAN tag object:
Access:
Admin/Access Admin/Network Admin
Step 1
Select
Objects > Object Management
.
The Object Management page appears.
Step 2
Under
VLAN Tag
, select
Individual Objects
.
Step 3
Click
Add VLAN Tag
.
The VLAN Tag pop-up window appears.
Step 4
Type a
Name
for the VLAN tag. You can use any printable standard ASCII characters except curly braces
(
{}
).