Configuring Http And Https Management Traffic Services; Creating And Configuring A Class Map; Creating A Layer 3 And Layer 4 Policy Map; Applying A Service Policy Globally To All Vlan Interfaces In The Same Context - Cisco 4700M Administration Manual

Application control engine appliance
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring the XML Interface
host1/Admin# xml-show on
(Optional) Save your configuration changes to Flash memory.
Step 7
host1/Admin# copy running-config startup-config

Configuring HTTP and HTTPS Management Traffic Services

This section describes how to configure HTTP and HTTPS remote management traffic to the ACE
through class maps, policy maps, and service policies. The ACE provides support for remote
management using XML over either HTTP or HTTPS to configure, monitor, and manage software
objects.
The following items summarize the role of each function in configuring HTTP or HTTPS network
management access to the ACE:
HTTP or HTTPS sessions are established to the ACE per context. For details on creating contexts and
users, see the Cisco 4700 Series Application Control Engine Appliance Virtualization Configuration
Guide.
This section contains the following topics:

Creating and Configuring a Class Map

This section describes how to create a Layer 3 and Layer 4 class map to classify the HTTP or HTTPS
management traffic that can be received by the ACE. This process allows network management traffic
by identifying the incoming IP protocols that the ACE can receive and the client source host IP address
and subnet mask as the matching criteria.
A class map of type management defines the allowed network traffic as a form of management security
for protocols such as HTTP or HTTPS. A class map can include multiple match commands. You can
configure class maps to define multiple HTTP or HTTPS management protocol or source IP address
match commands in a group that you then associate with a traffic policy. The match-all and match-any
keywords determine how the ACE evaluates multiple match statements operations when multiple match
criteria exist in a class map.
Cisco 4700 Series Application Control Engine Appliance Administration Guide
8-8
Class map—Provides the remote network traffic match criteria to permit HTTP and HTTPS
management traffic based on HTTP or HTTPS network management protocols or host source IP
addresses.
Policy map—Enables remote network management access for a traffic classification that matches
the criteria listed the class map.
Service policy—Activates the policy map and attaches the traffic policy to an interface or globally
on all interfaces.
Creating and Configuring a Class Map

Creating a Layer 3 and Layer 4 Policy Map

Applying a Service Policy Globally to All VLAN Interfaces in the Same Context

Applying a Service Policy to a Specific VLAN Interface

Chapter 8
Configuring the XML Interface
OL-20823-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents