data:image/s3,"s3://crabby-images/6ca3f/6ca3f7bcd850865f98cd3aa12f258caf280c207b" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 491"
22-75
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
RTSP Inspection
Tip
If you allow RTSP SETUP messages on one port only or on a contiguous range or ports, you can skip
creating the access list and, in
Step 4
, use the
match port
command instead of the
match access-list
command.
Step 3
Create a class map or modify an existing class map to identify RTSP traffic. Use the
class-map
command
to do so, as follows.
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 4
Identify traffic sent to the RTSP ports you determined in
Step 1
. To do so, use a
match access-list
command, as follows.
hostname(config-cmap)#
match access-list
acl-name
Step 5
Create a policy map or modify an existing policy map that you want to use to apply the RTSP inspection
engine to RTSP traffic. To do so, use the
policy-map
command, as follows.
hostname(config-cmap)#
policy-map
policy_map_name
hostname(config-pmap)#
where
policy_map_name
is the name of the policy map. The CLI enters the policy map configuration
mode and the prompt changes accordingly.
Step 6
Specify the class map, created in
Step 3
, that identifies the RTSP traffic. Use the
class
command to do
so, as follows.
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
where
class_map_name
is the name of the class map you created. The CLI enters the policy map class
configuration mode and the prompt changes accordingly.
Step 7
Enable RTSP application inspection. To do so, use the
inspect rtsp
command, as follows.
hostname(config-pmap-c)#
inspect rtsp
hostname(config-pmap-c)#
Step 8
Use the
service-policy
command to apply the policy map globally or to a specific interface, as follows:
hostname(config-pmap-c)#
service-policy
policy_map_name
[
global
|
interface
interface_ID
]
hostname(config)#
where
policy_map_name
is the policy map you configured in
Step 5
. If you want to apply the policy map
to traffic on all the interfaces, use the
global
option. If you want to apply the policy map to traffic on a
specific interface, use the
interface
interface_ID
option, where
interface_ID
is the name assigned to the
interface with the
nameif
command.
The FWSM begins inspecting RTSP traffic, as specified.
Example 22-11
shows how to enable the RTSP inspection engine RTSP traffic on the default ports (554
and 8554). The service policy is then applied to the outside interface.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......