data:image/s3,"s3://crabby-images/6ca3f/6ca3f7bcd850865f98cd3aa12f258caf280c207b" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 491"
22-75
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
RTSP Inspection
Tip
If you allow RTSP SETUP messages on one port only or on a contiguous range or ports, you can skip
creating the access list and, in
Step 4
, use the
match port
command instead of the
match access-list
command.
Step 3
Create a class map or modify an existing class map to identify RTSP traffic. Use the
class-map
command
to do so, as follows.
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 4
Identify traffic sent to the RTSP ports you determined in
Step 1
. To do so, use a
match access-list
command, as follows.
hostname(config-cmap)#
match access-list
acl-name
Step 5
Create a policy map or modify an existing policy map that you want to use to apply the RTSP inspection
engine to RTSP traffic. To do so, use the
policy-map
command, as follows.
hostname(config-cmap)#
policy-map
policy_map_name
hostname(config-pmap)#
where
policy_map_name
is the name of the policy map. The CLI enters the policy map configuration
mode and the prompt changes accordingly.
Step 6
Specify the class map, created in
Step 3
, that identifies the RTSP traffic. Use the
class
command to do
so, as follows.
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
where
class_map_name
is the name of the class map you created. The CLI enters the policy map class
configuration mode and the prompt changes accordingly.
Step 7
Enable RTSP application inspection. To do so, use the
inspect rtsp
command, as follows.
hostname(config-pmap-c)#
inspect rtsp
hostname(config-pmap-c)#
Step 8
Use the
service-policy
command to apply the policy map globally or to a specific interface, as follows:
hostname(config-pmap-c)#
service-policy
policy_map_name
[
global
|
interface
interface_ID
]
hostname(config)#
where
policy_map_name
is the policy map you configured in
Step 5
. If you want to apply the policy map
to traffic on all the interfaces, use the
global
option. If you want to apply the policy map to traffic on a
specific interface, use the
interface
interface_ID
option, where
interface_ID
is the name assigned to the
interface with the
nameif
command.
The FWSM begins inspecting RTSP traffic, as specified.
Example 22-11
shows how to enable the RTSP inspection engine RTSP traffic on the default ports (554
and 8554). The service policy is then applied to the outside interface.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......