25-74
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 25 Configuring Application Layer Protocol Inspection
Skinny (SCCP) Inspection
Where the
policy_map_name
is the name of the policy map. The CLI enters policy-map configuration
mode.
Step 4
(Optional) To add a description to the policy map, enter the following command:
hostname(config-pmap)#
description
string
Step 5
To apply actions to matching traffic, perform the following steps.
a.
Specify the traffic on which you want to perform actions using one of the following methods:
•
Specify the SCCP class map that you created in
Step 3
by entering the following command:
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
•
Specify traffic directly in the policy map using one of the
match
commands described in
Step 3
.
If you use a
match not
command, then any traffic that does not match the criterion in the
match
not
command has the action applied.
b.
Specify the action you want to perform on the matching traffic by entering the following command:
hostname(config-pmap-c)# {[
drop
[
send-protocol-error
] |
drop-connection
[
send-protocol-error
]|
mask
|
reset
] [
log
] |
rate-limit
message_rate
}
Not all options are available for each
match
or
class
command. See the CLI help or the
Cisco
Security Appliance Command Reference
for the exact options available.
The
drop
keyword drops all packets that match.
The
send-protocol-error
keyword sends a protocol error message.
The
drop-connection
keyword drops the packet and closes the connection.
The
mask
keyword masks out the matching portion of the packet.
The
reset
keyword drops the packet, closes the connection, and sends a TCP reset to the server
and/or client.
The
log
keyword, which you can use alone or with one of the other keywords, sends a system log
message.
The
rate-limit
message_rate
argument limits the rate of messages.
Step 6
You can specify multiple
class
or
match
commands in the policy map. For information about the order
of
class
and
match
commands, see the
“Defining Actions in an Inspection Policy Map” section on
page 21-11
.To configure parameters that affect the inspection engine, perform the following steps:
a.
To enter parameters configuration mode, enter the following command:
hostname(config-pmap)#
parameters
hostname(config-pmap-p)#
b.
To enforce registration before calls can be placed, enter the following command:
hostname(config-pmap-p)#
enforce-registration
c.
To set the maximum SCCP station message ID allowed, enter the following command:
hostname(config-pmap-p)#
message-ID max
hex_value
Where the
hex_value
argument is the station message ID in hex.
d.
To check RTP packets flowing on the pinholes for protocol conformance, enter the following
command:
hostname(config-pmap-p)#
rtp-conformance
[
enforce-payloadtype
]
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......