6-10
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 6 Getting Started with Application Layer Protocol Inspection
Configure Application Layer Protocol Inspection
applications. For some applications, you can perform special actions when you enable inspection. See
Chapter 1, “Service Policy Using the Modular Policy Framework,”
for information about service
policies in general.
Inspection is enabled by default for some applications. See
Default Inspections and NAT Limitations,
section for more information. Use this section to modify your inspection policy.
Procedure
Step 1
Unless you are adding inspection to an existing class map, identify the traffic to which you want to apply
inspections in a Layer 3/4 class map either for through traffic or for management traffic.
See
Create a Layer 3/4 Class Map for Through Traffic, page 1-13
and
Create a Layer 3/4 Class Map for
for detailed information. The management Layer 3/4 class map can be
used only with the RADIUS accounting inspection.
There are important implications for the class map that you choose. You can have more than one
inspection on the inspection_default class only, and you might want to simply edit the existing global
policy that applies the inspection defaults. For detailed information on which class map to choose, see
Choosing the Right Traffic Class for Inspection, page 6-14
.
Step 2
(Optional) Some inspection engines let you control additional parameters when you apply the inspection
to the traffic. The table later in this procedure shows which protocols allow inspection policy maps, with
pointers to the instructions on configuring them.
Step 3
Add or edit a Layer 3/4 policy map that sets the actions to take with the class map traffic.
hostname(config)#
policy-map
name
hostname(config-pmap)#
The default policy map is called “global_policy.” This policy map includes the default inspections listed
in
Default Inspections and NAT Limitations, page 6-6
. If you want to modify the default policy (for
example, to add or delete an inspection, or to identify an additional class map for your actions), then
enter
global_policy
as the name.
Step 4
Identify the class map to which you want to assign an action.
hostname(config-pmap)#
class
class_map_name
hostname(config-pmap-c)#
If you are editing the default policy map, it includes the inspection_default class map. You can edit the
actions for this class by entering
inspection_default
as the name. To add an additional class map to this
policy map, identify a different name.
You can combine multiple class maps in the same policy if desired, so you can create one class map to
match certain traffic, and another to match different traffic. However, if traffic matches a class map that
contains an inspection command, and then matches another class map that also has an inspection
command, only the first matching class is used. For example, SNMP matches the inspection_default
class map.To enable SNMP inspection, enable SNMP inspection for the default class. Do not add another
class that matches SNMP.
Step 5
Enable application inspection.
hostname(config-pmap-c)#
inspect
protocol
The
protocol
is one of the following values:
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...