Cisco 4700M Configuration Manual page 226

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a Layer 3 and Layer 4 Application Protocol Inspection Traffic Policy
Defining Layer 3 and Layer 4 Application Protocol Inspection Policy Actions
Note
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-102
You can use the inspect command in policy map class configuration mode to
define the Layer 3 and Layer 4 HTTP deep packet inspection, FTP command
inspection, or application protocol inspection policy actions. Application
inspection involves the examination of protocols such as DNS, FTP, HTTP, ICMP,
ILS, RTSP, SCCP, and SIP to verify the protocol behavior and identify unwanted
or malicious traffic that passes through the ACE.
If you intend to perform Layer 7 application inspection of network traffic, first
create a Layer 7 policy as follows:
To perform the deep packet inspection of Layer 7 HTTP application traffic by
the ACE, first create a Layer 7 policy using the policy-map type inspect http
command (see the
Policy Map"
section). You nest the Layer 7 HTTP inspection policy by using
the Layer 3 and Layer 4 inspect http command.
To perform the request inspection of FTP commands, first create a Layer 7
policy by using the policy-map type inspect ftp command (see the
"Configuring a Layer 7 FTP Command Inspection Policy Map"
nest the Layer 7 FTP inspection policy by using the Layer 3 and Layer 4
inspect ftp command.
You associate the Layer 7 policy map within the appropriate Layer 3 and Layer 4
policy map to provide an entry point for the traffic classification. Layer 7 policy
maps are considered to be child policies and can only be associated within a
Layer 3 and Layer 4 policy map. Only a Layer 3 and Layer 4 policy map can be
applied to a VLAN interface or applied globally to all VLAN interfaces in the
same context; a Layer 7 policy map cannot be directly applied on an interface.
If you do not specify a Layer 7 HTTP or FTP policy map, the ACE performs a
general set of Layer 3 and Layer 4 HTTP or FTP protocol fixup actions. For
example, the ACE performs strict HTTP.
The syntax of this command is as follows:
inspect dns [maximum-length bytes]
inspect ftp [strict policy name1 | sec-param conn_parammap_name1]
inspect http [policy name4 | url-logging]
inspect icmp [error]
inspect ils
Chapter 3
Configuring Application Protocol Inspection
"Configuring a Layer 7 HTTP Deep Packet Inspection
section). You
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents