
22-79
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
SIP Inspection
The CLI enters class-map configuration mode, where you can enter one or more
match
commands.
b.
(Optional) To add a description to the class map, enter the following command:
hostname(config-cmap)#
description
string
Where
string
is the description of the class map (up to 200 characters).
c.
(Optional) To match a called party, as specified in the To header or Contact header, enter the
following command:
hostname(config-cmap)#
match [not] called-party regex
{
class
class_name
|
regex_name
}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
d.
(Optional) To match a calling party, as specified in the From header, enter the following command:
hostname(config-cmap)#
match [not] calling-party regex
{
class
class_name
|
regex_name
}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
e.
(Optional) To match a content length in the SIP header, enter the following command:
hostname(config-cmap)#
match [not] content length gt
length
Where
length
is the number of bytes the content length is greater than. 0 to 65536.
f.
(Optional) To match an SDP content type or regular expression, enter the following command:
hostname(config-cmap)#
match [not] content type
{
sdp
|
regex
{
class
class_name
|
regex_name
}}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
g.
(Optional) To match a SIP IM subscriber, enter the following command:
hostname(config-cmap)#
match [not] im-subscriber regex
{
class
class_name
|
regex_name
}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
h.
(Optional) To match a SIP via header, enter the following command:
hostname(config-cmap)#
match [not] message-path regex
{
class
class_name
|
regex_name
}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
i.
(Optional) To match a SIP request method, enter the following command:
hostname(config-cmap)#
match [not] request-method
method
Where
method
is the type of method to match (ack, bye, cancel, info, invite, message, notify,
options, prack, refer, register, subscribe, unknown, update).
j.
(Optional) To match the requester of a third-party registration by matching the From header in SIP
REGISTER messages, enter the following command. This command only matches the requestor
when the contents of the To and From fields in a SIP REGISTER message are different.
hostname(config-cmap)#
match [not] third-party-registration regex
{
class
class_name
|
regex_name
}
Where the
regex
regex_name
argument is the regular expression you created in
Step 1
. The
class
regex_class_name
is the regular expression class map you created in
Step 2
.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......