1-9
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 1 Service Policy Using the Modular Policy Framework
Defaults for Service Policies
This limit also includes default class maps of all types, limiting user-configured class maps to
approximately 235. See
Default Class Maps (Traffic Classes), page 1-11
Policy Map Guidelines
See the following guidelines for using policy maps:
•
You can only assign one policy map per interface. However you can create up to 64 policy maps in
the configuration.
•
You can apply the same policy map to multiple interfaces.
•
You can identify up to 63 Layer 3/4 class maps in a Layer 3/4 policy map.
•
For each class map, you can assign multiple actions from one or more feature types, if supported.
See
Incompatibility of Certain Feature Actions, page 1-7
.
Service Policy Guidelines
•
Interface service policies take precedence over the global service policy for a given feature. For
example, if you have a global policy with FTP inspection, and an interface policy with TCP
normalization, then both FTP inspection and TCP normalization are applied to the interface.
However, if you have a global policy with FTP inspection, and an interface policy with FTP
inspection, then only the interface policy FTP inspection is applied to that interface.
•
You can only apply one global policy. For example, you cannot create a global policy that includes
feature set 1, and a separate global policy that includes feature set 2. All features must be included
in a single policy.
•
When you make service policy changes to the configuration, all
new
connections use the new service
policy. Existing connections continue to use the policy that was configured at the time of the
connection establishment. Output for the
show
command will not include data about the old
connections.
For example, if you remove a QoS service policy from an interface, then add a modified version,
then the
show service-policy
command only displays QoS counters associated with new
connections that match the new service policy; existing connections on the old policy no longer
show in the command output.
To ensure that all connections use the new policy, you need to disconnect the current connections so
they can reconnect using the new policy. Use the
clear conn
or
clear local-host
commands.
Defaults for Service Policies
The following topics describe the default settings for service policies and the Modular Policy
Framework:
•
Default Service Policy Configuration, page 1-10
•
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......