11-4
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 11 Service Policy Using the Modular Policy Framework
About Service Policies
Features Configured with Service Policies
The following table lists the features you configure using service policies.
Feature Directionality
Actions are applied to traffic bidirectionally or unidirectionally depending on the feature. For features
that are applied bidirectionally, all traffic that enters or exits the interface to which you apply the policy
map is affected if the traffic matches the class map for both directions.
Note
When you use a global policy, all features are unidirectional; features that are normally bidirectional
when applied to a single interface only apply to the ingress of each interface when applied globally.
Because the policy is applied to all interfaces, the policy will be applied in both directions so
bidirectionality in this case is redundant.
Table 11-1
Features Configured with Service Policies
Feature
For Through
Traffic?
For Management
Traffic?
See:
Application inspection (multiple
types)
All
except
RADIUS
accounting
RADIUS
accounting
only
•
Chapter 12, “Getting Started with Application
Layer Protocol Inspection.”
•
Chapter 13, “Inspection of Basic Internet
Protocols.”
•
Chapter 14, “Inspection for Voice and Video
Protocols.”
•
Chapter 15, “Inspection of Database, Directory,
and Management Protocols.”
•
Chapter 8, “ASA and Cisco Cloud Web Security.”
ASA IPS
Yes
No
See the ASA IPS quick start guide.
ASA CX
Yes
No
See the ASA CX quick start guide.
ASA FirePOWER (ASA SFR)
Yes
No
Chapter 7, “ASA FirePOWER Module.”
NetFlow Secure Event Logging
filtering
Yes
Yes
See the general operations configuration guide.
QoS input and output policing
Yes
No
Chapter 17, “Quality of Service.”
QoS standard priority queue
Yes
No
Chapter 17, “Quality of Service.”
TCP and UDP connection limits
and timeouts, and TCP sequence
number randomization
Yes
Yes
Chapter 16, “Connection Settings.”
TCP normalization
Yes
No
Chapter 16, “Connection Settings.”
TCP state bypass
Yes
No
Chapter 16, “Connection Settings.”
User statistics for Identity
Firewall
Yes
Yes
See the
user-statistics
command in the command
reference.
Содержание ASA 5508-X
Страница 11: ...P A R T 1 Access Control ...
Страница 12: ......
Страница 60: ...4 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 4 Access Rules History for Access Rules ...
Страница 157: ...P A R T 2 Network Address Translation ...
Страница 158: ......
Страница 204: ...9 46 Cisco ASA Series Firewall CLI Configuration Guide Chapter 9 Network Address Translation NAT History for NAT ...
Страница 232: ...10 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 10 NAT Examples and Reference DNS and NAT ...
Страница 233: ...P A R T 3 Service Policies and Application Inspection ...
Страница 234: ......
Страница 379: ...P A R T 4 Connection Management and Threat Detection ...
Страница 380: ......
Страница 400: ...16 20 Cisco ASA Series Firewall CLI Configuration Guide Chapter 16 Connection Settings History for Connection Settings ...
Страница 414: ...17 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 Quality of Service History for QoS ...