Configuring SNMP
•
Creating and Configuring a Layer 3 and Layer 4 Class Map
This section describes how to create a Layer 3 and Layer 4 class map to classify the SNMP management
traffic that can be received by the ACE. This class map allows the ACE to receive the network
management traffic by identifying the incoming IP protocols that the ACE can receive and the client
source host IP address and subnet mask as the matching criteria. The class map also defines the allowed
network traffic as a form of management security for protocols such as SNMP.
A class map can have multiple match commands. You can configure class maps to define multiple
SNMP management protocol and source IP address commands in a group that you then associate with a
traffic policy. The match-all and match-any keywords determine how the ACE evaluates multiple match
statements operations when multiple match criteria exist in a class map.
Detailed Steps
Command
Step 1
config
Example:
host1/Admin# config
host1/Admin#(config)#
Step 2
class-map type management [match-all |
match-any] map_name
Example:
host1/Admin(config)# class-map type
management match-all SNMP-ALLOW_CLASS
host1/Admin(config-cmap-mgmt)#
no class-map type management [match-all |
map_name
match-any]
Example:
host1/Admin(config)# no class-map type
management match-all SNMP-ALLOW_CLASS
Cisco 4700 Series Application Control Engine Appliance Administration Guide
7-48
Applying a Service Policy to a Specific VLAN Interface
Purpose
Enters global configuration mode.
Create a Layer 3 and Layer 4 class map to classify the SNMP
management traffic that can be received by the ACE.
The keywords, arguments, and options are as follows:
match-all | match-any—(Optional) Determines how the
•
ACE evaluates Layer 3 and Layer 4 network traffic when
multiple match criteria exist in a class map. The class map is
considered a match if the match commands meet one of the
following conditions:
match-all —(Default) All of the match criteria listed in
–
the class map match th e network traffic class in the class
map (typically, match commands of the same type).
match-any—Only one of the match criteria listed in the
–
class map matches the network traffic class in the class
map (typically, match commands of different types).
map_name—Name assigned to the class map. Enter an
•
unquoted text string with no spaces and a maximum of 64
alphanumeric characters.
This command enters the class map management configuration
mode.
(Optional) Removes a Layer 3 and Layer 4 SNMP protocol
management class map from the ACE.
Chapter 7
Configuring SNMP
OL-20823-01