data:image/s3,"s3://crabby-images/798b4/798b48188bbffa810ba5ddaba08c4231cf967577" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 508"
22-92
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
Skinny (SCCP) Inspection
Step 7
Return to global configuration mode by entering the following command:
hostname(config-pmap)#
exit
hostname(config)#
Step 8
Apply the policy map globally or to a specific interface by entering the following command:
hostname(config)#
service-policy
policy_map_name
[
global
|
interface
interface_ID
Replace policy_map_name with the policy map you configured in
Step 3
, and identify all the interfaces
with the
global
option or a specific interface using the name assigned with the
nameif
command.
For example, the following command applies the sample_policy to the outside interface:
hostname(config)#
service-policy sample_policy interface outside
The following command applies the sample_policy to the all the FWSM interfaces:
hostname(config)#
service-policy sample_policy global
You enable the SCCP inspection engine as shown in
Example 22-12
, which creates a class map to match
SCCP traffic on the default port (2000). The service policy is then applied to the outside interface.
Example 22-12 Enabling SCCP Application Inspection
hostname(config)#
class-map sccp_port
hostname(config-cmap)#
match port tcp eq 2000
hostname(config-cmap)#
exit
hostname(config)#
policy-map sample_policy
hostname(config-pmap)#
class sccp_port
hostname(config-pmap-c)#
inspect skinny
hostname(config-pmap-c)#
exit
hostname(config)#
service-policy sample_policy interface outside
Verifying and Monitoring SCCP Inspection
The
show skinny
command assists in troubleshooting SCCP (Skinny) inspection engine issues. The
following is sample output from the
show skinny
command under the following conditions. There are
two active Skinny sessions set up across the FWSM. The first one is an audio connection established
between an internal Cisco IP Phone at local address 10.0.0.11 and an external Cisco CallManager at
172.18.1.33. TCP port 2000 is the CallManager. The second one is a video connection established
between another internal Cisco IP Phone at local address 10.0.0.22 and the same Cisco CallManager.
hostname#
show skinny
LOCAL FOREIGN STATE
---------------------------------------------------------------
1 10.0.0.11/52238 172.18.1.33/2000 1
AUDIO 10.0.0.11/22948 172.18.1.22/20798
2 10.0.0.22/52232 172.18.1.33/2000 1
VIDEO 10.0.0.22/20798 172.18.1.11/22948
The output indicates that a call has been established between two internal Cisco IP Phones. The RTP
listening ports of the first and second phones are UDP 22948 and 20798 respectively.
The following is sample output from the
show xlate debug
command for these Skinny connections:
hostname#
show xlate debug
2 in use, 2 most used
Flags: D - DNS, d - dump, I - identity, i - inside, n - no random,
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......