
18-12
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 18 Using Modular Policy Framework
Direction Policies When Applying a Service Policy
Using Figure 18-1, where Host A is located on outside and Host B is located on inside, all HTTP
connections initiated from Host A and destined to Host B will be classified for HTTP inspection and
priority queueing. However, all HTTP connections initiated from Host B and destined to Host A will be
classified for HTTP inspection only.
Figure 18-1 Match Port/Interface Policy Topology
See the following commands for this example:
hostname(config)# class-map http
hostname(config-cmap)# match port tcp eq 80
hostname(config)# policy-map http
hostname(config-pmap)# class http
hostname(config-pmap-c)# inspect http
hostname(config-pmap-c)# priority
hostname(config)# service-policy http interface inside
Match Access List/Interface Policy Example
In the match access list/interface policy example:
• An HTTP connection from Host A to Host SERVER_B is classified for HTTP inspection using
http_map_server and connection limit checking.
• An HTTP connection from Host CLIENT_D to Host C is classified for HTTP inspection using
http_map_client and police.
126991
policy http
outside inside
A
Host A
Host B
A B/80 inspection (output rule of bi-directional policy)
priority (output policy)
B A/80 inspection (input rule of bi-directional policy)
Security
appliance
Comentarios a estos manuales