Cisco 4700M Configuration Manual page 147

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 3
Configuring Application Protocol Inspection
Table 3-2
Task and Command Example
7.
8.
9.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
OL-16202-01
Application Protocol Inspection Configuration Quick Start Procedures
Layer 7 FTP Request Command Inspection Quick Start
Create a Layer 3 and Layer 4 policy map and associate the Layer 7 FTP
command inspection policy map to activate the operation. Specify the
actions that you want to apply to the Layer 3 and Layer 4 user-defined class
map and, if appropriate, to the default class map.
host1/Admin(config)# policy-map multi-match FTP_INSPECT_L4POLICY
host1/Admin(config-pmap)# class FTP_INSPECT_L4CLASS
host1/Admin(config-pmap-c) inspect ftp strict policy
FTP_INSPECT_L7POLICY
host1/Admin(config-pmap-c)# exit
host1/Admin(config)#
Attach the Layer 3 and Layer 4 traffic policy to a single VLAN interface or
globally to all VLAN interfaces, and specify the direction in which the
policy should be applied. For example, to specify a VLAN interface and
apply multiple service policies to the VLAN, enter:
host1/Admin(config)# interface vlan 50
host1/Admin(config-if)# ip address 172.16.1.100 255.255.255.0
host1/Admin(config-if)# service-policy input FTP_INSPECT_L4POLICY
(Optional) Save your configuration changes to flash memory.
host1/Admin(config)# exit
host1/Admin# copy running-config startup-config
3-23

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents