Cisco ASA 5505 Configuration Manual page 604

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Information About Service Policies
Order in Which Multiple Feature Actions are Applied
The order in which different types of actions in a service policy are performed is independent of the order
in which the actions appear in the table.
Note
NetFlow Secure Event Logging filtering is order-independent.
Actions are performed in the following order:
1.
2.
Note
3.
4.
Cisco ASA 5500 Series Configuration Guide using ASDM
29-4
QoS input policing
TCP normalization, TCP and UDP connection limits and timeouts, TCP sequence number
randomization, and TCP state bypass.
When a the adaptive security appliance performs a proxy service (such as AAA or CSC) or it
modifies the TCP payload (such as FTP inspection), the TCP normalizer acts in dual mode,
where it is applied before and after the proxy or payload modifying service.
CSC
Application inspection (multiple types)
The order of application inspections applied when a class of traffic is classified for multiple
inspections is as follows. Only one inspection type can be applied to the same traffic. WAAS
inspection is an exception, because it can be applied along with other inspections for the same
traffic. See the
"Incompatibility of Certain Feature Actions" section on page 29-5
information.
CTIQBE
a.
DNS
b.
FTP
c.
GTP
d.
H323
e.
HTTP
f.
ICMP
g.
ICMP error
h.
ILS
i.
MGCP
j.
k.
NetBIOS
l.
PPTP
Sun RPC
m.
RSH
n.
RTSP
o.
SIP
p.
Skinny
q.
SMTP
r.
Chapter 29
Configuring a Service Policy
for more
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents