1-10
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA CSC Module
Configuring the CSC SSM
What to Do Next
See the
“Diverting Traffic to the CSC SSM” section on page 1-10
Diverting Traffic to the CSC SSM
You use Modular Policy Framework commands to configure the ASA to divert traffic to the CSC SSM.
Prerequisites
Before configuring the ASA to divert traffic to the CSC SSM, see
Chapter 1, “Configuring a Service
Policy Using the Modular Policy Framework,”
which introduces Modular Policy Framework concepts
and common commands.
To configure the ASA to divert traffic to the CSC SSM, perform the following steps:
Detailed Steps
Command
Purpose
Step 1
access-list extended
Example:
hostname(config)# access-list extended
Creates an access list that matches the traffic you
want scanned by the CSC SSM. Create as many
ACEs as are needed to match all the traffic. For
example, to specify FTP, HTTP/HTTPS, POP3, and
SMTP traffic, you need four ACEs. For guidance on
identifying the traffic that you want to scan, see the
“Determining What Traffic to Scan” section on
page 1-3
Step 2
class-map
class_map_name
Example:
hostname(config)#
class-map
class_map_name
Creates a class map to identify the traffic that should
be diverted to the CSC SSM. The
class_map_name
argument is the name of the traffic class. When you
enter the
class-map
command, the CLI enters class
map configuration mode.
Step 3
match access-list
acl-name
Example:
hostname(config-cmap)# match access-list
acl-name
Identifies the traffic to be scanned with the access list
that you created in Step 1. The
acl-name
argument is
the name of the access list.
Step 4
policy-map
policy_map_name
Example:
hostname(config-cmap)# policy-map
policy_map_name
Creates a policy map or modify an existing policy
map that you want to use to send traffic to the CSC
SSM. The
policy_map_name
argument is the name
of the policy map. When you enter the
policy-map
command, the CLI enters policy map configuration
mode.
Step 5
class
class_map_name
Example:
hostname(config-pmap)# class
class_map_name
Specifies the class map, created in Step 2, that
identifies the traffic to be scanned. The
class_map_name
argument is the name of the class
map that you created in Step 2. The CLI enters the
policy map class configuration mode.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......