21-14
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 21 Using Modular Policy Framework
Defining Actions Using a Layer 3/4 Policy Map
•
Supported Feature Types, page 21-14
•
Feature Directionality, page 21-14
•
Feature Matching Guidelines within a Policy Map, page 21-15
•
Feature Matching Guidelines for multiple Policy Maps, page 21-15
•
Order in Which Multiple Feature Actions are Applied, page 21-16
Policy Map Guidelines
See the following guidelines for using policy maps:
•
You can only assign one policy map per interface.
•
You can apply the same policy map to multiple interfaces.
•
You can identify multiple Layer 3/4 class maps in a Layer 3/4 policy map.
•
For each class map, you can assign multiple actions from one or more feature types.
Supported Feature Types
Feature types supported by the Modular Policy Framework that you can enable in the policy map include
the following:
•
TCP normalization, TCP and UDP connection limits and timeouts, and TCP sequence number
randomization
•
CSC
•
Application inspection
•
IPS
•
QoS input policing
•
QoS output policing
•
QoS priority queue
Feature Directionality
Actions are applied to traffic bidirectionally or unidirectionally depending on the feature. For features
that are applied bidirectionally, all traffic that enters or exits the interface to which you apply the policy
map is affected if the traffic matches the class map for both directions.
Note
When you use a global policy, all features are unidirectional; features that are normally bidirectional
when applied to a single interface only apply to the ingress of each interface when applied globally.
Because the policy is applied to all interfaces, the policy will be applied in both directions so
bidirectionality in this case is redundant.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......