Cisco PIX 525 Spezifikationen Seite 303

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 302
18-11
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 18 Using Modular Policy Framework
Direction Policies When Applying a Service Policy
Types of Direction Policies
There are three types of policies when considering which traffic direction to classify traffic:
Input (or ingress)
Output (or egress)
Bidirectional (both ingress and egress)
An input policy on an interface means that classification is applied to traffic that enters the security
appliance through an interface. An output policy on an interface means that classification is applied to
traffic that exits the security appliance through an interface. A bidirectional policy means that
classification is applied to traffic that enters or exits the security appliance through the interface.
Implicit Direction Policies
Table 18-6 illustrates the implicit direction policies for each supported action on an interface. Note that
a global service policy applies policy on all interfaces and an interface policy applies policy only on the
interface specified.
Examples
The following Modular Policy Framework examples are provided:
Match Port/Interface Policy Example, page 18-11
Match Access List/Interface Policy Example, page 18-12
Match Port/Global Policy Example, page 18-13
Match Port/Interface Policy Example
In the match port/interface policy example:
Any HTTP connection (TCP traffic on port 80) which enters or exits the security appliance box
through the inside interface is classified for HTTP inspection (bidirectional policy).
Any HTTP connection (TCP traffic on port 80) which exits the security appliance through the inside
interface is classified for priority control (output policy).
Table 18-6 Implicit Direction Policies
Action Global Service Policy Interface Service Policy
inspect Input Bidirectional (input and output)
ips Input Bidirectional (input and output)
set connection Input Bidirectional (input and output)
police Output Output
priority Output Output
Seitenansicht 302
1 2 ... 298 299 300 301 302 303 304 305 306 307 308 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare