1-4
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Special Actions for Application Inspections (Inspection Policy Map)
Defining Actions in an Inspection Policy Map
Note
There are other default inspection policy maps such as
_default_esmtp_map
. For example,
inspect
esmtp
implicitly uses the policy map “_default_esmtp_map.” All the default policy maps can be shown
by using the
show running-config all policy-map
command.
Defining Actions in an Inspection Policy Map
When you enable an inspection engine in the Layer 3/4 policy map, you can also optionally enable
actions as defined in an inspection policy map.
Detailed Steps
Command Purpose
Step 1
(Optional)
Create an inspection class map.
“Identifying Traffic in an Inspection Class Map” section
Alternatively, you can identify the traffic directly within the
policy map.
Step 2
(Optional)
Create a regular expression.
For policy map types that support regular expressions, see the
“Defining Actions in an Inspection Policy Map” section on
page 1-4
in the general operations configuration guide.
Step 3
policy-map type inspect
application
policy_map_name
Example:
hostname(config)# policy-map type inspect
http http_policy
Creates the inspection policy map. See the
Application Layer Protocol Inspection” section on page 1-7
for a
list of applications that support inspection policy maps.
The
policy_map_name
argument is the name of the policy map up
to 40 characters in length. All types of policy maps use the same
name space, so you cannot reuse a name already used by another
type of policy map. The CLI enters policy-map configuration
mode.
Step 4
Specify the traffic on which you want to perform actions using one of the following methods:
class
class_map_name
Example:
hostname(config-pmap)# class http_traffic
hostname(config-pmap-c)#
Specifies the inspection class map that you created in the
“Identifying Traffic in an Inspection Class Map” section on
page 1-5
.
Not all applications support inspection class maps.
Specify traffic directly in the policy map using
one of the
match
commands described for each
application in the inspection chapter.
Example:
hostname(config-pmap)# match req-resp
content-type mismatch
hostname(config-pmap-c)#
If you use a
match not
command, then any traffic that matches the
criterion in the
match not
command does not have the action
applied.
For policy map types that support regular expressions, see the
“Defining Actions in an Inspection Policy Map” section on
page 1-4
in the general operations configuration guide.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......