Interface Using A Service Policy - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 5
Configuring Network Address Translation
Note
Applying the Static NAT and Static Port Redirection Policy Map
to an Interface Using a Service Policy
Note
OL-16202-01
Table 5-5
Well-Known UDP Port Numbers and Keywords (continued)
Keyword
Port Number
wsp-wtp
9201
wsp-wtp-wtls
9203
vlan number—Specifies the interface for the global IP address.
If a packet egresses an interface that you have not configured for NAT, the ACE
transmits the packet untranslated.
The following DNAT static port redirection example specifies the nat static
command as an action for a static NAT policy map:
host1/C1(config)# policy-map multi-action NAT_POLICY
host1/C1(config-pmap)# class NAT_CLASS
host1/C1(config-pmap-c)# nat static 192.168.12.0 255.255.255.0 80
vlan 101
To remove a NAT action from a policy map, enter:
host1/C1(config-pmap-c) no nat static 192.168.12.15 255.255.255.0
vlan 200
You can activate the static NAT and port redirection policy and assign it to an
interface by using the service-policy command in interface configuration mode.
For details about the service-policy command, see the Cisco 4700 Series
Application Control Engine Appliance Administration Guide.
You can configure static NAT as an input service policy only; you cannot
configure it as an output service policy.
The syntax of this command is as follows:
service-policy input policy_name
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring Static NAT and Static Port Redirection
Description
Connection-based WSP
Secure Connection-based WSP
5-39

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents