
21-8
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Applying Application Inspection to Selected Traffic
Step 5 To return to global configuration mode, enter the following command:
hostname(config-cmap)# exit
hostname(config)#
Using an Application Inspection Map
Some application inspection engines have configurable parameters that are used to control application
inspection. The default value of these parameters may work without modification, but if you need to fine
tune control of the application inspection engine, use an application inspection map. The following
procedure provides the general steps required to create an application inspection map.
To use an application inspection map, perform the following steps:
Step 1 Create an application inspection map by entering the following command:
hostname(config)#
application
-map
application_map_name
Replace application with the type of application inspection. Replace application_map_name with the
name of the application inspection map, for example:
hostname(config)# http-map inbound_http
This example causes the system to enter HTTP map configuration mode and the CLI prompt changes as
follows:
hostname(config-http-map)#
Step 2 Define the configuration of the application inspection map by entering any of the supported commands.
To display a list of the supported commands, type a question mark (?) from within the application.
hostname(config-http-map)# ?
Http-map configuration commands:
content-length Content length range inspection
content-type-verification Content type inspection
max-header-length Maximum header size inspection
max-uri-length Maximum URI size inspection
no Negate a command or set its defaults
port-misuse Application inspection
request-method Request method inspection
strict-http Strict HTTP inspection
transfer-encoding Transfer encoding inspection
rtsp tcp 554
sip tcp, udp 5060
skinny tcp 2000
smtp tcp 25
sqlnet tcp 1521
tftp udp 69
xdmcp udp 177
Table 21-2 Default Port Assignments (continued)
Protocol Name Protocol Port
Comentarios a estos manuales