Cisco 4700M Configuration Manual page 248

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Applying a Service Policy
For example, to specify a VLAN interface and apply multiple service policies to
a VLAN, enter:
host1/Admin(config)# interface vlan 50
host1/Admin(config-if)# ip address 172.16.1.100 255.255.255.0
host1/Admin(config-if)# service-policy input FTP_INSPECT_L4POLICY
host1/Admin(config-if)# service-policy input HTTP_INSPECT_L4POLICY
host1/Admin(config-if)# service-policy input DNS_INSPECT_L4POLICY
For example, to globally apply multiple service policies to all of the VLANs
associated with a context, enter:
host1/Admin(config)# service-policy input FTP_INSPECT_L4POLICY
host1/Admin(config)# service-policy input HTTP_INSPECT_L4POLICY
host1/Admin(config)# service-policy input DNS_INSPECT_L4POLICY
To detach a traffic policy from a VLAN interface, enter:
host1/Admin(config-if)# no service-policy input DNS_INSPECT_L4POLICY
To globally detach a traffic policy from all VLANs associated with a context,
enter:
host1/Admin(config)# no service-policy input DNS_INSPECT_L4POLICY
When you detach a traffic policy either individually from the last VLAN interface
on which you applied the service policy or globally from all VLAN interfaces in
the same context, the ACE automatically resets the associated service policy
statistics. The ACE performs this action to provide a new starting point for the
service policy statistics the next time that you attach a traffic policy to a specific
VLAN interface or globally to all VLAN interfaces in the same context.
Follow these guidelines when creating a service policy:
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-124
Policy maps, applied globally in a context, are internally applied on all
interfaces existing in the context.
A policy activated on a VLAN interface overwrites any specified global
policies for overlapping classification and actions.
The ACE allows only one policy of a specific feature type to be activated on
a given interface.
Chapter 3
Configuring Application Protocol Inspection
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents