Defining Tcp/Udp Port Number Or Port Range Match Criteria - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a Layer 3 and Layer 4 Application Protocol Inspection Traffic Policy

Defining TCP/UDP Port Number or Port Range Match Criteria

Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-96
The keywords, arguments, and options are as follows:
line_number—(Optional) Argument that assists you in editing or deleting
individual match commands. Enter an integer from 2 to 255 as the line
number. You can enter no line_number to delete long match commands
instead of entering the entire line. The line numbers do not dictate a priority
or sequence for the match statements.
identifier—Previously created access list identifier. Enter an unquoted text
string with a maximum of 64 characters.
You can enter multiple match access-list commands within a single class map.
You may combine multiple match access-list and match port commands in a
class map.
For example, to specify that the class map is to match on access control list
INBOUND_ACL1, enter:
host1/Admin(config)# class-map match-any DNS_INSPECT_L4CLASS
host1/Admin(config-cmap)# match access-list INBOUND_ACL1
To clear the access control list match criteria from the class map, enter:
host1/Admin(config-cmap)# no match access-list inboundacl1
You can use the match port command to specify a TCP or UDP port number or
port range as the Layer 3 and Layer 4 network traffic matching criteria.
You must access the class map configuration mode to specify the match port
command.
The syntax of this command is as follows:
[line_number] match port {tcp | udp} {any | eq {port_number} | range
port1 port2}
The keywords, arguments, and options are as follows:
line_number—(Optional) Argument that assists you in editing or deleting
individual match commands. Enter an integer from 2 to 255 as the line
number. You can enter no line_number to delete long match commands
instead of entering the entire line. The line numbers do not dictate a priority
or sequence for the match statements.
Chapter 3
Configuring Application Protocol Inspection
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents