EasyManuals Logo
Home>Cisco>Firewall>FirePOWER ASA 5500 series

Cisco FirePOWER ASA 5500 series User Manual

Cisco FirePOWER ASA 5500 series
989 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #360 background imageLoading...
Page #360 background image
21-2
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Chapter 21 Using Modular Policy Framework
Identifying Traffic Using a Layer 3/4 Class Map
3. Apply actions to the Layer 3 and 4 traffic. See the “Defining Actions Using a Layer 3/4 Policy Map”
section on page 21-13.
4. Activate the actions on an interface. See the Applying a Layer 3/4 Policy to an Interface Using a
Service Policy” section on page 21-17.
Default Global Policy
By default, the configuration includes a policy that matches all default application inspection traffic and
applies certain inspections to the traffic on all interfaces (a global policy). Not all inspections are enabled
by default. You can only apply one global policy, so if you want to alter the global policy, you need to
either edit the default policy or disable it and apply a new one. (An interface policy overrides the global
policy.)
The default policy configuration includes the following commands:
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
service-policy global_policy global
Identifying Traffic Using a Layer 3/4 Class Map
A Layer 3/4 class map identifies Layer 3 and 4 traffic to which you want to apply actions. The maximum
number of Layer 3/4 class maps is 255 in single mode or per context in multiple mode. The configuration
includes a default Layer 3/4 class map that the security appliance uses in the default global policy. It is
called inspection_default and matches the default inspection traffic:
class-map inspection_default
match default-inspection-traffic
You can create multiple Layer 3/4 class maps for each Layer 3/4 policy map. You can create the
following types of class maps:
Creating a Layer 3/4 Class Map for Through Traffic, page 21-3
Creating a Layer 3/4 Class Map for Management Traffic, page 21-5

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco FirePOWER ASA 5500 series and is the answer not in the manual?

Cisco FirePOWER ASA 5500 series Specifications

General IconGeneral
BrandCisco
ModelFirePOWER ASA 5500 series
CategoryFirewall
LanguageEnglish

Related product manuals