1-12
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 1 Service Policy Using the Modular Policy Framework
Configure Service Policies
If one of the actions you want to perform is application inspection, and you want to perform additional
actions on some inspection traffic, then create an inspection policy map. The inspection policy map
identifies the traffic and specifies what to do with it.
For example, you might want to drop all HTTP requests with a body length greater than 1000 bytes.
You can create a self-contained inspection policy map that identifies the traffic directly with
match
commands, or you can create an inspection class map for reuse or for more complicated matching. For
example, you could match text within a inspected packets using a regular expression or a group of regular
expressions (a regular expression class map), and target actions based on narrower criteria. For example,
you might want to drop all HTTP requests with a URL including the text “example.com.”
See
Defining Actions in an Inspection Policy Map, page 2-4
Identifying Traffic in an Inspection
.
Step 3
Define the actions you want to perform on each Layer 3/4 class map by creating a Layer 3/4 policy map,
as described in
Define Actions (Layer 3/4 Policy Map), page 1-16
.
Inspection Class Map/
Match Commands
Inspection Policy Map Actions
241507
Regular Expression Statement/
Regular Expression Class Map
Inspection Class Map/
Match Commands
Inspection Policy Map Actions
241509
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......