Chapter 3
Configuring Application Protocol Inspection
Creating a Layer 7 SIP Policy Map
Adding a Layer 7 SIP Inspection Policy Map Description
OL-16202-01
You can create a Layer 7 SIP policy map by using the policy-map type inspect
sip command in configuration mode.
The syntax of this command is as follows:
policy-map type inspect sip all-match map_name
The keywords and arguments are as follows:
sip all-match—Specifies the policy map that initiates the inspection of the
•
SIP protocol packets by the ACE. The ACE attempts to match all specified
conditions against the matching classification and executes the actions of all
matching classes until it encounters a deny for a match request.
map_name—Name assigned to the policy map. Enter an unquoted text string
•
with no spaces and a maximum of 64 alphanumeric characters.
For example, to create a Layer 7 SIP inspection policy map, enter:
host1/Admin(config)# policy-map type inspect sip all-match
SIP_INSPECT_L7POLICY
host1/Admin(config-pmap-ins-sip)#
To remove the SIP inspection policy map from the configuration, enter:
host1/Admin(config)# no policy-map type inspect sip all-match
SIP_INSPECT_L7POLICY
You can configure a description for the Layer 7 SIP inspection policy map by
using the description command in policy map inspection SIP configuration
mode.
The syntax of this command is as follows:
description
For example, to add a description for a Layer 7 SIP inspection policy map, enter:
host1/Admin(config-pmap-ins-sip)# description layer 7 sip inspection
policy
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring a Layer 7 SIP Inspection Policy
3-87