data:image/s3,"s3://crabby-images/a1306/a1306ca070eccf6a8c1fe36c77d4373737a1441e" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 395"
20-19
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 20 Using Modular Policy Framework
Defining Actions (Layer 3/4 Policy Map)
The
policy_map_name
argument is the name of the policy map up to 40 characters in length. All types
of policy maps use the same name space, so you cannot reuse a name already used by another type of
policy map. The CLI enters policy-map configuration mode.
Step 2
(Optional) Specify a description for the policy map:
hostname(config-pmap)#
description
text
Step 3
Specify a previously configured Layer 3/4 class map using the following command:
hostname(config-pmap)#
class
class_map_name
where the
class_map_name
is the name of the class map you created earlier. See the
“Identifying Traffic
(Layer 3/4 Class Map)” section on page 20-4
to add a class map.
Step 4
Specify one or more actions for this class map.
•
TCP and UDP connection limits and timeouts, and TCP sequence number randomization. See the
“Configuring Connection Limits and Timeouts” section on page 21-1
.
•
TCP state bypass. See the
“Configuring TCP State Bypass” section on page 21-10
.
•
Application inspection. See
Chapter 22, “Applying Application Layer Protocol Inspection.”
•
Permitting or Denying Application Types with PISA Integration—See the
“Permitting or Denying
Application Types with PISA Integration” section on page 21-4
.
Note
If there is no
match default_inspection_traffic
command in a class map, then at most one
inspect
command is allowed to be configured under the class.
Step 5
Repeat
Step 3
and
Step 4
for each class map you want to include in this policy map.
The following is an example of a
policy-map
command for connection policy. It limits the number of
connections allowed to the web server 10.1.1.1:
hostname(config)#
access-list http-server permit tcp any host 10.1.1.1
hostname(config)#
class-map http-server
hostname(config-cmap)#
match access-list http-server
hostname(config)#
policy-map global-policy
hostname(config-pmap)#
description This policy map defines a policy concerning connection
to http server.
hostname(config-pmap)#
class http-server
hostname(config-pmap-c)#
set connection conn-max 256
The following example shows how multi-match works in a policy map:
hostname(config)#
class-map inspection_default
hostname(config-cmap)#
match default-inspection-traffic
hostname(config)#
class-map http_traffic
hostname(config-cmap)#
match port tcp eq 80
hostname(config)#
policy-map outside_policy
hostname(config-pmap)#
class inspection_default
hostname(config-pmap-c)#
inspect http http_map
hostname(config-pmap-c)#
inspect sip
hostname(config-pmap)#
class http_traffic
hostname(config-pmap-c)#
set connection timeout tcp 0:10:0
The following example shows how traffic matches the first available class map, and will not match any
subsequent class maps that specify actions in the same feature domain:
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......