![Cisco ASA 5512-X Скачать руководство пользователя страница 12](http://html.mh-extra.com/html/cisco/asa-5512-x/asa-5512-x_configuration-manual_63717012.webp)
1-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 1 Service Policy Using the Modular Policy Framework
About Service Policies
Examples of Packet Matching
For example:
•
If a packet matches a class map for connection limits, and also matches a class map for an
application inspection, then both actions are applied.
•
If a packet matches a class map for HTTP inspection, but also matches another class map that
includes HTTP inspection, then the second class map actions are not applied.
•
If a packet matches a class map for HTTP inspection, but also matches another class map that
includes FTP inspection, then the second class map actions are not applied because HTTP and FTP
inspections cannot be combined.
•
If a packet matches a class map for HTTP inspection, but also matches another class map that
includes IPv6 inspection, then both actions are applied because the IPv6 inspection can be combined
with any other type of inspection.
Order in Which Multiple Feature Actions are Applied
The order in which different types of actions in a policy map are performed is independent of the order
in which the actions appear in the policy map.
Actions are performed in the following order:
1.
QoS input policing
2.
TCP normalization, TCP and UDP connection limits and timeouts, TCP sequence number
randomization, and TCP state bypass.
Note
When a the ASA performs a proxy service (such as AAA or CSC) or it modifies the TCP
payload (such as FTP inspection), the TCP normalizer acts in dual mode, where it is applied
before and after the proxy or payload modifying service.
3.
ASA CSC
4.
Application inspections that can be combined with other inspections:
a.
IPv6
b.
IP options
c.
WAAS
5.
Application inspections that cannot be combined with other inspections. See
Certain Feature Actions, page 1-7
for more information.
6.
ASA IPS
7.
ASA CX
8.
ASA FirePOWER (ASA SFR)
9.
QoS output policing
10.
QoS standard priority queue
Note
NetFlow Secure Event Logging filtering and User statistics for Identity Firewall are order-independent.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...