Cisco PIX 500 Series Configuration Manual page 1064

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Configuring an External LDAP Server
Table E-3
Field
Prefix
Action
Protocol
Source
Source Wildcard Mask
Destination
Destination Wildcard
Mask
Log
Operator
Port
For example:
ip:inacl#1=deny ip 10.155.10.0 0.0.0.255 10.159.2.0 0.0.0.255 log
ip:inacl#2=permit TCP any host 10.160.0.1 eq 80 log
webvpn:inacl#1=permit url http://www.website.com
webvpn:inacl#2=deny smtp any host 10.1.3.5
webvpn:inacl#3=permit url cifs://mar_server/peopleshare1
Note
Use Cisco-AV pair entries with the ip:inacl# prefix to enforce ACLs for remote IPSec and SSL VPN
Client (SVC) tunnels.
Use Cisco-AV pair entries with the webvpn:inacl# prefix to enforce ACLs for WebVPN clientless
(browser-mode) tunnels.
Table E-4
Table E-4
Security Appliance-Supported Tokens
Token
Syntax Field
ip:inacl#Num=
N/A (Identifier)
webvpn:inacl#Num=
N/A (Identifier)
Cisco Security Appliance Command Line Configuration Guide
E-14
AV-Pair Attribute Syntax Rules
Description
A unique identifier for the AV pair. For example:
standard ACLs) or
only appears when the filter has been sent as an AV pair.
Action to perform if rule matches: deny, permit.
Number or name of an IP protocol. Either an integer in the range 0 - 255 or
one of the following keywords: icmp, igmp, ip, tcp, udp.
Network or host that sends the packet. It is specified as an IP address, a
hostname, or the keyword "any". If specified as an IP address, the source
wildcard mask must follow.
The wildcard mask applied to the source address.
Network or host that receives the packet. It is specified as an IP address, a
hostname, or the keyword "any." If specified as an IP address, the source
wildcard mask must follow.
The wildcard mask applied to the destination address.
Generates a FILTER log message. You must use this keyword to generate
events of severity level 9.
Logic operators: greater than, less than, equal to, not equal to.
The number of a TCP or UDP port in the range 0 - 65535.
lists the tokens for the Cisco-AV-pair attribute:
Description
(Where Num is a unique integer.) Starts all AV pair access control lists. Enforces
ACLs for remote IPSec and SSL VPN (SVC) tunnels.
(Where Num is a unique integer.) Starts all WebVPN AV pair access control lists.
Enforces ACLs for WebVPN clientless (browser-mode) tunnels.
Appendix E
Configuring an External Server for Authorization and Authentication
(used for WebVPN ACLs). This field
webvpn:inacl#
(used for
ip:inacl#1=
OL-12172-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents