Cisco Explorer 4700 Installationsanleitung Seite 423

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 648
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 422
12-3
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 12 Configuring Traffic Policies
Class Map and Policy Map Overview
2. Creating a policy map, which refers to the class maps and identifies a series of actions to perform
based on the traffic match criteria.
3. Activating the policy map and attaching it to a specific VLAN interface or globally to all VLAN
interfaces associated with a context by configuring a virtual context global traffic policy to filter
traffic received by the ACE appliance.
The following overview topics describe the components that define a traffic policy:
Class Maps, page 12-3
Policy Maps, page 12-4
Parameter Maps and Their Use in Layer 3 and Layer 4 Policy Maps, page 12-5
Application Protocol Inspection Overview, page 12-5
Configuring Virtual Context Global Traffic Policies, page 4-28
Class Maps
A class map defines each type of Layer 3 and Layer 4 traffic class and each Layer 7 protocol class. You
create class maps to classify the traffic received and transmitted by the ACE appliance.
Layer 3 and Layer 4 traffic classes contain match criteria that identify the IP network traffic that can
pass through the ACE appliance or network management traffic that can be received by the ACE
appliance.
Layer 7 protocol-specific classes identify server load balancing based on HTTP traffic, deep
inspection of HTTP traffic, or the inspection of FTP commands by the ACE appliance.
A traffic class contains the following components:
Class map name
Class map type
One or more match conditions that define the match criteria for the class map
Instructions on how the ACE appliance evaluates match conditions when you specify more than one
match statement in a traffic class (match-any, match-all)
The ACE supports a system-wide maximum of 8192 class maps.
The individual match conditions specify the criteria for classifying Layer 3 and Layer 4 network traffic
as well as the Layer 7 HTTP server load balancing and application protocol-specific fields. The ACE
appliance evaluates the packets to determine whether they match the specified criteria. If a statement
matches, the ACE appliance considers that packet to be a member of the class and forwards the packet
according to the specifications set in the traffic policy. Packets that fail to meet any of the matching
criteria are classified as members of the default traffic class if one is specified.
The ACE appliance allows you to configure two Layer 7 HTTP load-balancing class maps in a nested
traffic class configuration to create a single traffic class. You can perform Layer 7 class map nesting to
achieve complex logical expressions. The ACE appliance restricts the nesting of class maps to two levels
to prevent you from including one nested class map under a different class map.
Related Topics
Class Map and Policy Map Overview, page 12-2
Policy Maps, page 12-4
Parameter Maps and Their Use in Layer 3 and Layer 4 Policy Maps, page 12-5
Seitenansicht 422
1 2 ... 418 419 420 421 422 423 424 425 426 427 428 ... 647 648

Kommentare zu diesen Handbüchern

Keine Kommentare