data:image/s3,"s3://crabby-images/e74cd/e74cd6bb66e4cbcad9c18f80e959ce370b0a5a20" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 433"
22-17
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
DCERPC Inspection
Configuring a DCERPC Inspection Policy Map for Additional Inspection Control
To specify additional DCERPC inspection parameters, create a DCERPC inspection policy map. You can
then apply the inspection policy map when you enable DCERPC inspection according to the
“Configuring Application Inspection” section on page 22-6
.
To create a DCERPC inspection policy map, perform the following steps:
Step 1
Create a DCERPC inspection policy map, enter the following command:
hostname(config)#
policy-map type inspect dcerpc
policy_map_name
hostname(config-pmap)#
Where the
policy_map_name
is the name of the policy map. The CLI enters policy-map configuration
mode.
Step 2
(Optional) To add a description to the policy map, enter the following command:
hostname(config-pmap)#
description
string
Step 3
To configure parameters that affect the inspection engine, perform the following steps:
a.
To enter parameters configuration mode, enter the following command:
hostname(config-pmap)#
parameters
hostname(config-pmap-p)#
b.
To configure the timeout for DCERPC pinholes and override the global system pinhole timeout of
two minutes, enter the following command:
hostname(config-pmap-p)#
timeout pinhole
hh:mm:ss
Where the
hh:mm:ss
argument is the timeout for pinhole connections. Value is between 0:0:1 and
1193:0:0.
c.
To configure options for the endpoint mapper traffic, enter the following command:
hostname(config-pmap-p)#
endpoint-mapper
[
epm-service-only
] [
lookup-operation
[
timeout
hh:mm:ss]]
Where the
hh:mm:ss
argument is the timeout for pinholes generated from the lookup operation. If
no timeout is configured for the lookup operation, the timeout pinhole command or the default is
used. The
epm-service-only
keyword enforces endpoint mapper service during binding so that only
its service traffic is processed. The
lookup-operation
keyword enables the lookup operation of the
endpoint mapper service.
The following example shows how to define a DCERPC inspection policy map with the timeout
configured for DCERPC pinholes.
hostname(config)#
policy-map type inspect dcerpc dcerpc_map
hostname(config-pmap)#
timeout pinhole 0:10:00
hostname(config)#
class-map dcerpc
hostname(config-cmap)#
match port tcp eq 135
hostname(config)#
policy-map global-policy
hostname(config-pmap)#
class dcerpc
hostname(config-pmap-c)#
inspect dcerpc dcerpc-map
hostname(config)#
service-policy global-policy global
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......