1-9
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Inspection of Basic Internet Protocols
DNS Inspection
Examples
The following example shows a how to use a new inspection policy map in the global default
configuration:
policy-map global_policy
class inspection_default
no inspect dns preset_dns_map
inspect dns new_dns_map
service-policy global_policy global
Monitoring DNS Inspection
To view information about the current DNS connections, enter the following command:
hostname#
show conn
Step 3
policy-map
name
Example:
hostname(config)# policy-map global_policy
Adds or edits a policy map that sets the actions to take with the
class map traffic.
In the default configuration, the global_policy policy map is
assigned globally to all interfaces. If you want to edit the
global_policy, enter global_policy as the policy name.
Step 4
class
name
Example:
hostname(config-pmap)# class
inspection_default
Identifies the class map created in
To edit the default policy, or to use the special inspection_default
class map in a new policy, specify
inspection_default
for the
name
.
Step 5
inspect dns
[
dns_policy_map
]
[
dynamic-filter-snoop
]
Example:
hostname(config-class)# no inspect dns
hostname(config-class)# inspect dns
dns-map
Configures DNS inspection. Specify the inspection policy map
you created in the
“(Optional) Configuring a DNS Inspection
Policy Map and Class Map” section on page 1-3
.
For information about the Botnet Traffic Filter
dynamic-filter-snoop
keyword, see the
Snooping” section on page 26-11
.
Note
If you are editing the default global policy (or any in-use
policy) to use a different DNS inspection policy map from
the default preset_dns_map, you must remove the DNS
inspection with the
no inspect dns
command, and then
re-add it with the new DNS inspection policy map name.
Step 6
service-policy
policymap_name
{
global
|
interface
interface_name
}
Example:
hostname(config)# service-policy
global_policy global
Activates the policy map on one or more interfaces.
global
applies
the policy map to all interfaces, and
interface
applies the policy
to one interface. Only one global policy is allowed. You can
override the global policy on an interface by applying a service
policy to that interface. You can only apply one policy map to
each interface.
The default configuration includes a global policy called
global_policy. If you are editing that policy, you can skip this step.
Command
Purpose
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......