Preview Tool

Cisco Bug: CSCup22022 - IOS-XE ZBFW does not properly process service type object-groups

Last Modified

Jan 12, 2019

Products (21)

  • Cisco IOS
  • Cisco ASR 901-6CZ-FS-D Router
  • Cisco ASR 901-6CZ-F-D Router
  • Cisco ASR 901S-4SG-F-D Router
  • Cisco ASR 901-4C-FT-D Router
  • Cisco ME 3600X-24TS-M Switch
  • Cisco ASR 901S-2SG-F-D Router
  • Cisco ASR 901-6CZ-F-A Router
  • Cisco ASR 901S-2SG-F-AH Router
  • Cisco ASR 901-6CZ-FT-A Router
View all products in Bug Search Tool Login Required

Known Affected Releases


Description (partial)

Symptom:ASR using ZBFW may not properly classify traffic when class-maps of type inspect reference an ACL that uses a service-type object-group.

Conditions:A sample configuration that does not work:

object-group service ICMP_OG
 icmp echo
 icmp echo-reply
 icmp traceroute
 icmp unreachable
 icmp time-exceeded
ip access-list extended ICMP_ACL
 permit object-group ICMP_OG any any
class-map type inspect match-all ICMP_CMAP
 match protocol icmp
 match access-group name ICMP_ACL
policy-map type inspect ICMP_PMAP
 class type inspect ICMP_CMAP
 class class-default
zone-pair security INSIDE2OUTSIDE source INSIDE destination OUTSIDE
 service-policy type inspect ICMP_PMAP
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.