data:image/s3,"s3://crabby-images/0f656/0f656a2ed70016c26ca3a42940d70e9a77d99a44" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 514"
22-98
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
SNMP Inspection
Enabling and Configuring SNMP Application Inspection
To change the default configuration for SNMP inspection, perform the following steps:
Step 1
Determine the ports that network devices behind the FWSM listen to for SNMP traffic. The default ports
are TCP ports 161 and 162.
Step 2
Create a class map or modify an existing class map to identify SNMP traffic. Use the
class-map
command to do so, as follows:
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 3
Use a match command to identify traffic sent to the SNMP ports you determined in
Step 1
.
If you need to assign a range of contiguous ports, use the
range
keyword, as in the following example:
hostname(config-cmap)#
match port tcp range
begin_port_number
end_port_number
where
begin_port_number
is the lowest port in the range of SNMP ports and
end_port_number
is the
highest port.
Tip
To identify two or more non-contiguous ports, enter the
access-list extended
command and
define an ACE to match each port. Then, rather than the
match port
command, use the
match
access-list
command to associate the access list with the SNMP traffic class.
Step 4
Create an SNMP map that will contain the parameters of SNMP inspection. Use the
snmp-map
command to do so, as follows:
hostname(config-cmap)#
snmp-map
map_name
hostname(config-snmp-map)#
where
map_name
is the name of the SNMP map. The CLI enters SNMP map configuration mode.
Step 5
Specify the versions of SNMP permitted by the SNMP map. To do so, use the
deny version
command
to disallow the versions that you do not want to permit, as follows:
hostname(config-snmp-map)#
deny version
version
hostname(config-snmp-map)#
where
version
with an SNMP version that you want to restrict. Valid values of
version
are 1, 2, 2c, and
3. You can enter as many
deny version
commands as needed.
Step 6
Create a policy map or modify an existing policy map that you want to use to apply the SNMP inspection
engine to the SNMP traffic. To do so, use the
policy-map
command, as follows:
hostname(config-cmap)#
policy-map
policy_map_name
hostname(config-pmap)#
where
policy_map_name
is the name of the policy map. The CLI enters the policy map configuration
mode and the prompt changes accordingly.
Step 7
Specify the class map, created in
Step 2
, that identifies the SNMP traffic. Use the
class
command to do
so, as follows:
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......