Does anyone have any thoughts on best practices for object groups. We are replaces a pix v6 with an ASA. There are several interfaces (inside, outside, dmz). I'm thinking I could have a generic service object group for windows (dns, backup, av update, backup, patch update) and another for unix (dns, syslog), one for mail (smtp). For the naming convention, i'm thinking service_interface like this "smtp_outside", "smtp_dmz", "windows_dmz", where _outside and _dmz when the services in a specific object group use the interface defined in the object group.