If I was a competing firewall vendor I'd copy paste the thread starters opening question onto my own firewalls testimonial page.

Enclose it in quotes?

Just a guess, this is clearly an idiotic bug.

ASA CLI is horrible, but give it to me any time over the GUI!

I might look at the GUI, the day Cisco stops using Java.

Yes i have a special hate for any developer making guis like that. WebGui only https, and don't use fucking flash either.. Fuck..

To be fair, given the current Javascript (I mean ECMAScript, don't sue me Oracle!) ecosystem, I can see the draw of using Applets :P

My favorite stack has always been JSF/PrimeFaces.

Take a look at the FTD GUI, I imagine ASA isn't long for this world anymore.

The FMC GUI is actually pretty sweet. There's some strangeness if you're using Chrome, maximized, and try to increase the width of a column (like in the ACL), but other than that one weird bug it's infinitely better than the fuckin ASA Java GUI.

Yeah, except that whole part where on ASDM you hit "Apply" and it's done. On ASDM you hit "Deploy", select your device(s), then wait 5-8 minutes for it to be applied. That part of FMC drives me up a fucking wall. Especially when it's "Oops, I forgot to add a host to the Access Policy" - wait, make the change, deploy, wait 5-8 minutes again. It's fucking ridiculous.

Yeah that part is annoying. It gets to 80% in ~30 seconds, then just sits there for ~6 minutes and just chills, as far as I can tell.

Still better than the conversation that happens at least once a week

"Hey, is anybody else in the ASA?"
"Yeah what's up"
"Dammit, I'm trying to apply this change. Did you make a change?"
"Uh... I don't remember if I applied it."
"OK let me know when you're done and I'll re-do my change."


I'm not sure if this is still a thing, but I remember years ago I needed to do something on an ASA, but a co-worker was doing a show access-list and was stopped halfway down. I pulled up the same access-list and it wouldn't let me browse it further than he was paused at.

Some of their guis use flash...

ASA CLI is horrible, but give it to me any time over the GUI!

I might look at the GUI once Cisco stops using Java

Within context, I was confused.

ISE isn't any better though. :P

I tried quotes and paranthesis

Try quotes and parenthesis with an escape? Maybe try an apostrophe?

I couldn't find a way to solve that bug. CLI is all you got I think.

Sounds stupid, but maybe try a different key on the keyboard for the - symbol?

Oh it's weird, like the source port works fine. I can do source port 775-776 and that works. Destination Port I get -1 because I guess it's adding them together, same symbol used. I even copied and pasted from source port.

Try just putting the first destination port

oh like and then doing the second after I save it?

On some firewalls if you put a range in the public port you only put the first port on the private and it will just do the range math for you since a range has to match sizes no matter what.

oh I see, I'll give that a shot thanks

asdm you mean?

Happened to me today. Had to use CLI.

I know you said GUI but have you tried the CLI? If it still subtracts then maybe try preceding the - with a \ to escape the subtraction? I can't remember if Cisco does that but a lot of command lines do. It can't hurt to try.

Edit: give it a shot in the GUI too. Again, can't hurt to try.

... yea, no.

We use the CLI for initial setup and detailed troubleshooting. We use the ASDM for routine object, NAT, and ACL changes. They each have their benefits. Use the right tool for your needs I say.

Yeah, how dare anyone use the tools Cisco designed and distributed to perform exactly what the OP is trying to accomplish. Shame!

You used the word "designed".

designed would imply that any amount of forethought and consideration went into the construction of the gui management tools for ASA, which it clearly did not.

I get your point, but I suspect the design team behind it wouldn't appreciate it much.

LOL dude are you a Cisco shill?

If they designed a good GUI we wouldn't have this thread right now.

Yeah, that's me.

It's a pretty garbage gui.

I don't disagree, but the CLI gatekeeping nonsense needs to stop.

Even when it's a garbage CLI? I don't think he was gatekeeping, especially because the thread is about the ASA GUI, which you agree is garbage.

Low effort comment, yeah but not gatekeeping, IMO

It's a pretty garbage CLI too...

Yea you right

Wait, if he is not generating the config in Ruby and then converting it and applying via python, then he is dead to me.

And barely a Jr Engineer at that.


What you don’t like dm inlines?

You only get DM_INLINE if you try and do impossible things like put multiple objects in a single rule instead of using an object group. The ASA creates that group on your behalf because you couldn't be bothered to make one yourself.

In the time I managed ASAs using ASDM I never once had a problem with DM_INLINE appearing in the config.

We’re doing a migration and we have a strict no DM in line policy

Yeah... until that one tech is told to add rules to allow a new monitoring system and has to allow 15 different tcp and udp ports throughout your DMZ environment. Get ready to unwind that fucking mess when you get back.

hahahaha, always good for a laugh isn't it