25-41
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 25 Configuring Application Layer Protocol Inspection
H.323 Inspection
Not all options are available for each
match
or
class
command. See the CLI help or the
Cisco
Security Appliance Command Reference
for the exact options available.
The
drop
keyword drops all packets that match.
The
send-protocol-error
keyword sends a protocol error message.
The
drop-connection
keyword drops the packet and closes the connection.
The
mask
keyword masks out the matching portion of the packet.
The
reset
keyword drops the packet, closes the connection, and sends a TCP reset to the server
and/or client.
The
log
keyword, which you can use alone or with one of the other keywords, sends a system log
message.
The
rate-limit
message_rate
argument limits the rate of messages.
You can specify multiple
class
or
match
commands in the policy map. For information about the order
of
class
and
match
commands, see the
“Defining Actions in an Inspection Policy Map” section on
page 21-11
.
Step 7
To configure parameters that affect the inspection engine, perform the following steps:
a.
To enter parameters configuration mode, enter the following command:
hostname(config-pmap)#
parameters
hostname(config-pmap-p)#
b.
To define the H.323 call duration limit, enter the following command:
hostname(config-pmap-p)#
call-duration-limit
time
Where
time
is the call duration limit in seconds. Range is from 0:0:0 ti 1163:0;0. A value of 0 means
never timeout.
c.
To enforce call party number used in call setup, enter the following command:
hostname(config-pmap-p)#
call-party-number
d.
To enforce H.245 tunnel blocking, enter the following command:
hostname(config-pmap-p)#
h245-tunnel-block action
{
drop-connection
|
log
}
e.
To define an hsi group and enter hsi group configuration mode, enter the following command:
hostname(config-pmap-p)#
hsi-group
id
Where
id
is the hsi group ID. Range is from 0 to 2147483647.
To add an hsi to the hsi group, enter the following command in hsi group configuration mode:
hostname(config-h225-map-hsi-grp)#
hsi
ip_address
Where
ip_address
is the host to add. A maximum of five hosts per hsi group are allowed.
To add an endpoint to the hsi group, enter the following command in hsi group configuration
mode:
hostname(config-h225-map-hsi-grp)#
endpoint
ip_address if_name
Where
ip_address
is the endpoint to add and
if_name
is the interface through which the endpoint
is connected to the security appliance. A maximum of ten endpoints per hsi group are allowed.
f.
To check RTP packets flowing on the pinholes for protocol conformance, enter the following
command:
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......