Cisco 4700M Configuration Manual page 165

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 3
Configuring Application Protocol Inspection
Adding a Layer 7 HTTP Deep Packet Inspection Class Map Description
OL-16202-01
match request-method—See the
Extension Methods"
match transfer-encoding—See the
Type"
match url—See the
match url length—See the
Inspection"
section.
You may include multiple match commands in the class map.
For example, to specify HTTP_INSPECT_L7CLASS as the name of a class map
and identify that at least one command in the Layer 7 HTTP application
inspection class map must be satisfied for the ACE to indicate a match, enter:
host1/Admin(config)# class-map type http inspect match-any
HTTP_INSPECT_L7CLASS
host1/Admin(config-cmap-http-insp)# match header length request eq 200
host1/Admin(config-cmap-http-insp)# match header Host header-value
.*mycompanyexample.com
host1/Admin(config-cmap-http-insp)# match url length eq 10000
host1/Admin(config-cmap-http-insp)# match url .*.gif
To remove the HTTP application inspection class map from the ACE, enter:
host1/Admin(config)#no class-map type http inspect match-any
HTTP_INSPECT_L7CLASS
You can use the description command to provide a brief description of the
Layer 7 HTTP deep packet inspection class map.
You must access the class map configuration mode to specify the description
command.
The syntax of this command is as follows:
description text
Use the text argument to enter an unquoted text string with a maximum of
240 alphanumeric characters.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring a Layer 7 HTTP Deep Inspection Policy
"Defining HTTP Request Methods and
section.
"Defining an HTTP Transfer Encoding
"Defining an HTTP URL for Inspection"
"Defining an HTTP Maximum URL Length for
section.
3-41

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents