data:image/s3,"s3://crabby-images/3b8dd/3b8ddd0f4c2192913fbf0ca536c411cd1d1b04be" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 512"
22-96
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
SMTP and Extended SMTP Inspection
Configuring and Enabling SMTP and Extended SMTP Application Inspection
SMTP inspection is enabled by default.
To enable SMTP or extended SMTP inspection, perform the following steps:
Step 1
Determine the ports that SMTP servers behind the FWSM listen to for SMTP traffic. The default port is
TCP port 25 but your SMTP servers may be configured to listen to other ports.
Step 2
Create a class map or modify an existing class map to identify SMTP traffic. Use the
class-map
command to do so, as follows:
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 3
Use a match command to identify traffic sent to the SMTP ports you determined in
Step 1
.
If the port mapper process listens to a single port, you can use the
match port
command to identify
traffic sent to that port, as follows:
hostname(config-cmap)#
match port tcp eq
port_number
where
port_number
is the port to which the port mapper process listens. If you need to assign a range of
contiguous ports, use the
range
keyword, as in the following example:
hostname(config-cmap)#
match port tcp range
begin_port_number
end_port_number
Tip
To identify two or more non-contiguous ports, enter the
access-list extended
command and
define an ACE to match each port. Then, rather than the
match port
command, use the
match
access-list
command to associate the access list with the SMTP traffic class.
Step 4
Create a policy map that you want to use to apply the SMTP inspection engine to the SMTP traffic. To
do so, use the
policy-map
command, as follows:
hostname(config-cmap)#
policy-map
policy_map_name
hostname(config-pmap)#
where
policy_map_name
is the name of the policy map. The CLI enters the policy map configuration
mode and the prompt changes accordingly.
Step 5
Specify the class map, created in
Step 2
, that identifies the SMTP traffic. Use the
class
command to do
so, as follows:
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
where
class_map_name
is the name of the class map you created in
Step 2
. The CLI enters the policy
map class configuration mode and the prompt changes accordingly.
Step 6
Do one of the following:
a.
To enable extended SMTP application inspection, enter the following command:
hostname(config-pmap-c)#
inspect esmtp
b.
To enable SMTP application inspection, enter the following command:
hostname(config-pmap-c)#
inspect smtp
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......