11-4
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 11 Service Policy Using the Modular Policy Framework
About Service Policies
Features Configured with Service Policies
The following table lists the features you configure using service policies.
Feature Directionality
Actions are applied to traffic bidirectionally or unidirectionally depending on the feature. For features
that are applied bidirectionally, all traffic that enters or exits the interface to which you apply the policy
map is affected if the traffic matches the class map for both directions.
Note
When you use a global policy, all features are unidirectional; features that are normally bidirectional
when applied to a single interface only apply to the ingress of each interface when applied globally.
Because the policy is applied to all interfaces, the policy will be applied in both directions so
bidirectionality in this case is redundant.
Table 11-1
Features Configured with Service Policies
Feature
For Through
Traffic?
For Management
Traffic?
See:
Application inspection (multiple
types)
All
except
RADIUS
accounting
RADIUS
accounting
only
•
Chapter 12, “Getting Started with Application
Layer Protocol Inspection.”
•
Chapter 13, “Inspection of Basic Internet
Protocols.”
•
Chapter 14, “Inspection for Voice and Video
Protocols.”
•
Chapter 15, “Inspection of Database, Directory,
and Management Protocols.”
•
Chapter 8, “ASA and Cisco Cloud Web Security.”
ASA IPS
Yes
No
See the ASA IPS quick start guide.
ASA CX
Yes
No
See the ASA CX quick start guide.
ASA FirePOWER (ASA SFR)
Yes
No
Chapter 7, “ASA FirePOWER Module.”
NetFlow Secure Event Logging
filtering
Yes
Yes
See the general operations configuration guide.
QoS input and output policing
Yes
No
Chapter 17, “Quality of Service.”
QoS standard priority queue
Yes
No
Chapter 17, “Quality of Service.”
TCP and UDP connection limits
and timeouts, and TCP sequence
number randomization
Yes
Yes
Chapter 16, “Connection Settings.”
TCP normalization
Yes
No
Chapter 16, “Connection Settings.”
TCP state bypass
Yes
No
Chapter 16, “Connection Settings.”
User statistics for Identity
Firewall
Yes
Yes
See the
user-statistics
command in the command
reference.
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......