Cisco 4700M Configuration Manual page 158

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a Layer 7 FTP Command Inspection Policy
Creating a Layer 7 FTP Command Inspection Policy Map
Adding a Layer 7 FTP Inspection Policy Map Description
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-34
You can use the policy-map type inspect ftp command in configuration mode to
name the traffic policy and initiate FTP command inspection.
The syntax of this command is as follows:
policy-map type inspect ftp first-match map_name
The keywords and arguments are as follows:
ftp first-match—Specifies a Layer 7 policy map that defines the inspection
of FTP commands by the ACE. The first-match keyword defines the
execution for the Layer 7 FTP command inspection policy map. The ACE
executes only the action specified against the first-matching classification.
map_name—Name assigned to the policy map. Enter an unquoted text string
with no spaces and a maximum of 64 alphanumeric characters.
For example, to create a Layer 7 FTP command inspection policy map, enter:
host/Admin(config)# policy-map type inspect ftp first-match
FTP_INSPECT_L7POLICY
host/Admin(config-pmap-ftp-ins)#
The CLI displays the policy map configuration mode.
To remove a Layer 7 command inspection policy map from the ACE, enter:
host1/Admin(config)# no policy-map type inspect ftp first-match
FTP_INSPECT_L7POLICY
You can use the description command to provide a brief summary of the Layer 7
FTP inspection policy map.
You must access the policy map FTP inspection configuration mode to specify the
description command.
The syntax of this command is as follows:
description text
Use the text argument to enter an unquoted text string with a maximum of
240 alphanumeric characters.
Chapter 3
Configuring Application Protocol Inspection
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents