data:image/s3,"s3://crabby-images/4a73c/4a73cf31d0bc9d6f858f7821b85a31ff9bc91dae" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 453"
22-37
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
GTP Inspection
Enabling and Configuring GTP Inspection
GTP application inspection is disabled by default, so you need to complete the procedures described in
this section to enable GTP inspection.
Note
GTP inspection requires a special license. If you enter GTP-related commands on a FWSM without the
required license, the FWSM displays an error message.
To enable or change GTP configuration, perform the following steps:
Step 1
Define an access list with ACEs that identify the ports required for GTP traffic. The standard ports are
UDP ports 2123 and 3386. To create the access list, use the
access-list extended
command once for each
ACE, as follows.
hostname(config)#
access-list
acl-name
permit
{
udp
|
tcp
}
any any eq
port
where
acl-name
is the name you assign to the access list and
port
is the GTP port that the ACE identifies.
Step 2
Create a class map or modify an existing class map to identify GTP traffic. Use the
class-map
command
to do so, as follows.
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 3
Use a
match access-list
command to identify GTP traffic with the access list you created in
Step 1
.
hostname(config-cmap)#
match access-list
acl-name
Step 4
(Optional) If you want to enforce additional parameters on GTP traffic, create and configure a GTP map.
For more information about GTP maps and the default values enforced if you do not specify GTP map,
see
“GTP Maps and Commands” section on page 22-36
. To create and configure a GTP map, perform
the following steps.
a.
Create a GTP map that will contain the additional parameters of GTP inspection. Use the
gtp-map
command to do so, as follows.
hostname(config-cmap)#
gtp-map
map_name
hostname(config-gtp-map)#
where
map_name
is the name of the GTP map. The CLI enters GTP map configuration mode.
permit response
Specifies an object group allowed to receive responses from another
object group.
request-queue
Specifies the maximum requests allowed in the queue.
timeout (gtp-map)
Specifies the idle timeout for the GSN, PDP context, requests,
signaling connections, and tunnels.
tunnel-limit
Specifies the maximum number of tunnels allowed.
Table 22-4
GTP Map Configuration Commands
Command
Description
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......