Configuring A Layer 7 Ftp Command Inspection Policy Map; Creating A Layer 7 Ftp Command Inspection Policy Map; Adding A Layer 7 Ftp Inspection Policy Map Description - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 3
Configuring Application Protocol Inspection

Configuring a Layer 7 FTP Command Inspection Policy Map

OL-16202-01
The ftp_commands argument is the FTP command in the class map to be subjected
to FTP inspection by the ACE. The possible ftp_commands are appe, cd, cdup,
dele, get, help, mkd, put, rmd, rnfr, rnto, site, stou, and syst.
You can specify multiple match request-methods commands within a class map.
For example, to specify FTP_INSPECT_L7CLASS as the name of a class map
and identify that at least one FTP inspection command in the class map must be
satisfied for the ACE to indicate a match, enter:
host1/Admin(config)# class-map type ftp inspect match-any
FTP_INSPECT_L7CLASS
host1/Admin(config-cmap-ftp-insp)# match request-method cdup
host1/Admin(config-cmap-ftp-insp)# match request-method mkdir
host1/Admin(config-cmap-ftp-insp)# match request-method get
host1/Admin(config-cmap-ftp-insp)# match request-method stou
host1/Admin(config-cmap-ftp-insp)# match request-method put
Use the no form of the command to clear the FTP inspection request method from
the class map:
host1/Admin(config-cmap-ftp-insp)# no match request-method cdup
This section outlines how to configure a Layer 7 FTP command inspection policy
map. The Layer 7 policy map configures the applicable FTP command inspection
actions executed on the network traffic that matches the classifications defined in
a class map. You then associate the completed Layer 7 FTP command inspection
policy with a Layer 3 and Layer 4 policy map to activate the operation on a VLAN
interface (see the
"Defining Layer 3 and Layer 4 Application Protocol Inspection
Policy Actions"
section).
This section contains the following topics:

Creating a Layer 7 FTP Command Inspection Policy Map

Adding a Layer 7 FTP Inspection Policy Map Description

Including Inline Match Statements in a Layer 7 FTP Command Inspection
Policy Map
Associating a Layer 7 FTP Command Inspection Traffic Class with the
Traffic Policy
Specifying the Layer 7 FTP Command Inspection Policy Actions
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring a Layer 7 FTP Command Inspection Policy
3-33

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents