data:image/s3,"s3://crabby-images/8819b/8819b414b465552f8b6318f64666df6015818692" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 480"
22-64
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
ICMP Inspection
Where the
string
argument is the string to substitute for the server header field. Note: WebVPN
streams are not subject to the
spoof-server
command.
The following example shows how to define an HTTP inspection policy map that will allow and log any
HTTP connection that attempts to access “www\.example.com/.*\.asp" or
"www\.example[0-9][0-9]\.com" with methods "GET" or "PUT." All other URL/Method combinations
will be silently allowed.
hostname(config)#
regex url1 “www\.example.com/.*\.asp”
hostname(config)#
regex url2 “www\.example[0-9][0-9]\.com”
hostname(config)#
regex get “GET”
hostname(config)#
regex put “PUT”
hostname(config)#
class-map type regex match-any url_to_log
hostname(config-cmap)#
match regex url1
hostname(config-cmap)#
match regex url2
hostname(config-cmap)#
exit
hostname(config)#
class-map type regex match-any methods_to_log
hostname(config-cmap)#
match regex get
hostname(config-cmap)#
match regex put
hostname(config-cmap)#
exit
hostname(config)#
class-map type inspect http http_url_policy
hostname(config-cmap)#
match request uri regex class url_to_log
hostname(config-cmap)#
match request method regex class methods_to_log
hostname(config-cmap)#
exit
hostname(config)#
policy-map type inspect http http_policy
hostname(config-pmap)#
class http_url_policy
hostname(config-pmap-c)#
log
ICMP Inspection
ICMP inspection is disabled by default.
For information about ICMP inspection, see the
inspect icmp
and
inspect icmp error
command pages
in the
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Command
Reference
.
ILS Inspection
ILS inspection is disabled by default.
For information about ILS inspection, see the
inspect ils
command page in the
Catalyst 6500 Series
Switch and Cisco 7600 Series Router Firewall Services Module Command Reference
.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......