21-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 21 Using Modular Policy Framework
Identifying Traffic Using a Layer 3/4 Class Map
3.
Apply actions to the Layer 3 and 4 traffic. See the
“Defining Actions Using a Layer 3/4 Policy Map”
section on page 21-13
.
4.
Activate the actions on an interface. See the
“Applying a Layer 3/4 Policy to an Interface Using a
Service Policy” section on page 21-18
.
Default Global Policy
By default, the configuration includes a policy that matches all default application inspection traffic and
applies certain inspections to the traffic on all interfaces (a global policy). Not all inspections are enabled
by default. You can only apply one global policy, so if you want to alter the global policy, you need to
either edit the default policy or disable it and apply a new one. (An interface policy overrides the global
policy.)
The default policy configuration includes the following commands:
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
service-policy global_policy global
Identifying Traffic Using a Layer 3/4 Class Map
A Layer 3/4 class map identifies Layer 3 and 4 traffic to which you want to apply actions. The maximum
number of Layer 3/4 class maps is 255 in single mode or per context in multiple mode. The configuration
includes a default Layer 3/4 class map that the security appliance uses in the default global policy. It is
called
inspection_default
and matches the default inspection traffic:
class-map inspection_default
match default-inspection-traffic
You can create multiple Layer 3/4 class maps for each Layer 3/4 policy map. You can create the
following types of class maps:
•
Creating a Layer 3/4 Class Map for Through Traffic, page 21-3
•
Creating a Layer 3/4 Class Map for Management Traffic, page 21-5
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......