Modular Policy Framework Configuration Overview - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Information About Modular Policy Framework

Modular Policy Framework Configuration Overview

Configuring Modular Policy Framework consists of the following tasks:
1.
2.
3.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
20-2
Identify the traffic on which you want to perform Modular Policy Framework actions by creating
Layer 3/4 class maps. For example, you might want to perform actions on all traffic that passes
through the FWSM; or you might only want to perform certain actions on traffic from 10.1.1.0/24
to any destination address.
Layer 3/4 Class Map
See the
"Identifying Traffic (Layer 3/4 Class Map)" section on page
If one of the actions you want to perform is application inspection, and you want to perform
additional actions on some inspection traffic, then create an inspection policy map. The inspection
policy map identifies the traffic and specifies what to do with it. For example, you might want to
drop all HTTP requests with a body length greater than 1000 bytes.
Inspection Policy Map Actions
Inspection Class Map/
Match Commands
You can create a self-contained inspection policy map that identifies the traffic directly with match
commands, or you can create an inspection class map for reuse or for more complicated matching.
See the
"Defining Actions in an Inspection Policy Map" section on page 20-7
Traffic in an Inspection Class Map" section on page
If you want to match text with a regular expression within inspected packets, you can create a regular
expression or a group of regular expressions (a regular expression class map). Then, when you
define the traffic to match for the inspection policy map, you can call on an existing regular
expression. For example, you might want to drop all HTTP requests with a URL including the text
"example.com."
Inspection Class Map/
Match Commands
Regular Expression Statement/
Regular Expression Class Map
Layer 3/4 Class Map
20-10.
Inspection Policy Map Actions
Chapter 20
Using Modular Policy Framework
20-4.
and the
"Identifying
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents