25-9
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 25 Configuring Application Layer Protocol Inspection
Configuring Application Inspection
Step 6
To activate the policy map on one or more interfaces, enter the following command:
hostname(config)#
service-policy
policymap_name
{
global
|
interface
interface_name
}
Where
global
applies the policy map to all interfaces, and
interface
applies the policy to one interface.
By default, the default policy map, “global_policy,” is applied globally. Only one global policy is
allowed. You can override the global policy on an interface by applying a service policy to that interface.
You can only apply one policy map to each interface.
radius-accounting
[
map_name
]
The
radius-accounting
keyword is only available for a
management class map. See the
“Creating a Layer 3/4 Class
Map for Management Traffic” section on page 21-5
for more
information about creating a management class map.
If you added a RADIUS accounting inspection policy map
according to
“Configuring a RADIUS Inspection Policy
Map for Additional Inspection Control” section on
page 25-61
, identify the map name in this command.
rsh
—
rtsp
[
map_name
]
If you added a NetBIOS inspection policy map according to
“Configuring an RTSP Inspection Policy Map for Additional
Inspection Control” section on page 25-63
, identify the map
name in this command.
sip
[
map_name
]
If you added a SIP inspection policy map according to
“Configuring a SIP Inspection Policy Map for Additional
Inspection Control” section on page 25-67
, identify the map
name in this command.
skinny
[
map_name
]
If you added a Skinny inspection policy map according to
“Configuring a Skinny (SCCP) Inspection Policy Map for
Additional Inspection Control” section on page 25-73
,
identify the map name in this command.
snmp
[
map_name
]
If you added an SNMP inspection policy map according to
“SNMP Inspection” section on page 25-76
, identify the map
name in this command.
sqlnet
—
sunrpc
The default class map includes UDP port 111; if you want to
enable Sun RPC inspection for TCP port 111, you need to
create a new class map that matches TCP port 111, add the
class to the policy, and then apply the
inspect sunrpc
command to that class.
tftp
—
xdmcp
—
Table 25-2
Protocol Keywords
Keywords
Notes
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......