data:image/s3,"s3://crabby-images/9a1f2/9a1f2f2bea96c5a089b32fe26d374ae860f376df" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 413"
21-13
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 21 Configuring Advanced Connection Features
Configuring TCP State Bypass
Connection Timeout
If there is no traffic on a given connection for 2 minutes, the connection times out. You can override this
default using the
set connection timeout tcp
command. Normal TCP connections timeout by default
after 60 minutes.
Enabling TCP State Bypass
To enable TCP state bypass, perform the following steps:
Step 1
To identify the traffic for which you want to disable stateful firewall inspection, add a class map using
the
class-map
command. See the
“Identifying Traffic (Layer 3/4 Class Map)” section on page 20-4
for
more information.
For example, you can match an access list:
hostname(config)#
access list bypass extended
permit tcp any 10.1.1.1 255.255.255.255
hostname(config)#
class-map bypass_traffic
hostname(config-cmap)#
match access-list bypass
Step 2
To add or edit a policy map that sets the actions to take with the class map traffic, enter the following
commands:
hostname(config)#
policy-map
name
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
where the
class_map_name
is the class map from
Step 1
.
For example:
hostname(config)#
policy-map tcp_bypass_policy
hostname(config-pmap)#
class bypass_traffic
hostname(config-pmap-c)#
Step 3
Enable TCP state bypass by entering the following command:
hostname(config-pmap-c)#
set connection advanced-options tcp-state-bypass
Step 4
Activate the policy map on one or more interfaces by entering the following command:
hostname(config)#
service-policy
policymap_name
{
global
|
interface
interface_name
}
Where
global
applies the policy map to all interfaces, and
interface
applies the policy to one interface.
Only one global policy is allowed. You can override the global policy on an interface by applying a
service policy to that interface. You can only apply one policy map to each interface.
Note
If you use the
show conn
command, the display for connections that use TCP state bypass includes the
flag “b.”
The following is an example configuration for TCP state bypass:
hostname(config)#
access-list tcp_bypass extended permit tcp 10.1.1.0 255.255.255.0
10.2.1.0 255.255.255.0
hostname(config)#
class-map tcp_bypass
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......