Добрый день.при кофигурировании пикса через АСДМ, а частности при редактировании хоста (хотя бы при изменении имени хоста) выходит ошибка:
--------------------------------
Due to a change you have made, an error occurred while validating the
Access Control for incoming traffic rule which is applied to traffic between
(Jroup:To_ASUTP_Servers and (Jroup:Servers_of_ASUTP when the
traffic type matches icmp.
A translation rule which will allow such traffic to traverse the PIX no longer exists.
When an object group is used in a rule1 ASDM must verify that each member of the group has a corresponding translation rule, if verification fails for any single member of the group, the rule validation fails.
Unless the error is corrected before proceeding, the above rule will be displayed as NULL in the rule table, indicating thatthe rule remains configured but has no or partial effect on traffic.
Do you still want to proceed?
-------------
группа To_ASUTP_Servers на интерфейсе inside
группа Servers_of_ASUTP виртуальный инт. Vlan6_ASUTP на DMZ.
хосты группы To_ASUTP_Servers статически натятся:
static (inside,Vlan6_ASUTP) h1 h1 netmask 255.255.255.255
static (inside,Vlan6_ASUTP) h2 h2 netmask 255.255.255.255
static (inside,Vlan6_ASUTP) h3 h3 netmask 255.255.255.255
static (inside,Vlan6_ASUTP) h4 h4 netmask 255.255.255.255
и общим правилом на branche:
static (inside,branche) GAS_net GAS_net netmask 255.255.255.0
хосты группы Servers_of_ASUTP статически натятся на инт-с inside и больше ни куда ибо делать там нефиг.
есть след-е правила:
access-list inside_access_in extended permit icmp object-group To_ASUTP_Servers object-group Servers_of_ASUTP
access-list inside_access_in extended permit tcp object-group To_ASUTP_Servers object-group Servers_of_ASUTP eq 3389
...
и обратно:
access-list Vlan6_ASUTP_access_in extended permit icmp object-group Servers_of_ASUTP object-group To_ASUTP_Servers_ref log debugging
access-list Vlan6_ASUTP_access_in extended deny ip any any
вроде всё просто но почему вылазиет эта и не только, практически на любое правило где хосты в группе.
подскажите куда копать.