data:image/s3,"s3://crabby-images/1055e/1055ef02c0ad2915779db38895c1eb46f539c059" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 507"
22-91
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
Skinny (SCCP) Inspection
To enable SCCP inspection or change the default port used for receiving SCCP traffic, perform the
following steps:
Step 1
Name the traffic class by entering the following command in global configuration mode:
hostname(config)#
class-map
class_map_name
Replace
class_map_name
with the name of the traffic class, for example:
hostname(config)#
class-map sccp_port
When you enter the
class-map
command, the CLI enters the class map configuration mode, and the
prompt changes, as in the following example:
hostname(config-cmap)#
Step 2
In the class map configuration mode, define the
match
command, as in the following example:
hostname(config-cmap)#
match port tcp eq 2000
hostname(config-cmap)#
exit
hostname(config)#
To assign a range of continuous ports, enter the
range
keyword, as in the following example:
hostname(config-cmap)#
match port tcp range 2000-2010
To assign more than one non-contiguous port for SCCP inspection, enter the
access-list extended
command and define an ACE to match each port. Then enter the
match
command to associate the access
lists with the SCCP traffic class.
Step 3
Name the policy map by entering the following command:
hostname(config)#
policy-map
policy_map_name
Replace
policy_map_name
with the name of the policy map, as in the following example:
hostname(config)#
policy-map sample_policy
The CLI enters the policy map configuration mode and the prompt changes accordingly, as follows:
hostname(config-pmap)#
Step 4
Specify the traffic class defined in
Step 1
to be included in the policy map by entering the following
command:
hostname(config-pmap)#
class
class_map_name
For example, the following command assigns the sccp_port traffic class to the current policy map:
hostname(config-pmap)#
class sccp_port
The CLI enters the policy map class configuration mode and the prompt changes accordingly, as follows:
hostname(config-pmap-c)#
Step 5
(Optional) To change the default port used by the FWSM for receiving SCCP traffic, enter the following
command:
hostname(config-pmap-c)#
inspect skinny
Step 6
Return to policy map configuration mode by entering the following command:
hostname(config-pmap-c)#
exit
hostname(config-pmap)#
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......