Cisco 4700M Configuration Manual page 156

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a Layer 7 FTP Command Inspection Policy
Adding a Layer 7 FTP Inspection Class Map Description
Defining FTP Match Request Methods
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-32
To remove the FTP request inspection class map from the ACE, enter:
host1/Admin(config)#no class-map type ftp inspect match-any
FTP_INSPECT_L7CLASS
You can use the description command to provide a brief summary of the Layer 7
FTP inspection class map.
You must access the class map configuration mode to specify the description
command.
The syntax of this command is as follows:
description text
Use the text argument to enter an unquoted text string with a maximum of
240 alphanumeric characters.
To add a description that the class map is to perform FTP command inspection,
enter:
host1/Admin(config-cmap-ftp-insp)# description FTP command inspection
of incoming traffic
To remove the description from the class map, enter:
host1/Admin(config-cmap-ftp-insp)# no description FTP command
inspection of incoming traffic
You can use the match request-method command to configure the class map to
define FTP command inspection decisions by the ACE. The match command
identifies the FTP commands that you want filtered by the ACE.
You must access the class map configuration mode to specify the match
request-method command.
The syntax of this command is as follows:
match request-method ftp_commands
Chapter 3
Configuring Application Protocol Inspection
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents