data:image/s3,"s3://crabby-images/8a15e/8a15e60b2aabd9e767f79d6bbd1e5390725495dd" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 398"
20-22
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 20 Using Modular Policy Framework
Modular Policy Framework Examples
Applying Inspection and Connection Limits to HTTP Traffic to Specific Servers
In this example (see
Figure 20-2
), any HTTP connection destined for Server A (TCP traffic on port 80)
that enters the FWSM through the outside interface is classified for HTTP inspection and maximum
connection limits.
Any HTTP connection destined for Server B that enters the FWSM through the inside interface is
classified for HTTP inspection.
Figure 20-2
HTTP Inspection and Connection Limits to Specific Servers
See the following commands for this example:
hostname(config)#
access-list serverA extended permit tcp any host 192.168.1.1 eq 80
hostname(config)#
access-list ServerB extended permit tcp any host 10.1.1.2 eq 80
hostname(config)#
class-map http_serverA
hostname(config-cmap)#
match access-list serverA
hostname(config)#
class-map http_serverB
hostname(config-cmap)#
match access-list serverB
hostname(config)#
policy-map policy_serverA
hostname(config-pmap)#
class http_serverA
hostname(config-pmap-c)#
inspect http http_map_serverA
hostname(config-pmap-c)#
set connection conn-max 100
hostname(config)#
policy-map policy_serverB
hostname(config-pmap)#
class http_serverB
hostname(config-pmap-c)#
inspect http http_map_serverB
hostname(config)#
service-policy policy_serverB interface inside
hostname(config)#
service-policy policy_serverA interface outside
Applying Inspection to HTTP Traffic with NAT
In this example, the Host on the inside network has two addresses: one is the real IP address 10.1.1.1,
and the other is a mapped IP address used on the outside network, 209.165.200.225 (see
Figure 20-3
).
Because the policy is applied to the inside interface, where the real address is used, then you must use
the real IP address in the access list in the class map. If you applied it to the outside interface, you would
use the mapped addresses.
132872
inside
outside
Server A
192.168.1.1
Host B
192.168.1.1
Host A
10.1.1.1
Server B
10.1.1.2
FWSM
port 80
port 80
insp.
insp.
set conns
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......