8-15
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 8 Inspection for Voice and Video Protocols
MGCP Inspection
•
command-queue
command_limit
—Sets the maximum number of commands allowed in the MGCP
command queue, from 1 to 2147483647. The default is 200.
Example
The following example shows how to define an MGCP map:
hostname(config)#
policy-map type inspect mgcp sample_map
hostname(config-pmap)#
parameters
hostname(config-pmap-p)#
call-agent 10.10.11.5 101
hostname(config-pmap-p)#
call-agent 10.10.11.6 101
hostname(config-pmap-p)#
call-agent 10.10.11.7 102
hostname(config-pmap-p)#
call-agent 10.10.11.8 102
hostname(config-pmap-p)#
gateway 10.10.10.115 101
hostname(config-pmap-p)#
gateway 10.10.10.116 102
hostname(config-pmap-p)#
gateway 10.10.10.117 102
hostname(config-pmap-p)#
command-queue 150
Configure the MGCP Inspection Service Policy
MGCP inspection is not enabled in the default inspection policy, so you must enable it if you need this
inspection. However, the default inspect class does include the default MGCP ports, so you can simply
edit the default global inspection policy to add MGCP inspection. You can alternatively create a new
service policy as desired, for example, an interface-specific policy.
Procedure
Step 1
If necessary, create an L3/L4 class map to identify the traffic for which you want to apply the inspection.
class-map
name
match
parameter
Example:
hostname(config)# class-map mgcp_class_map
hostname(config-cmap)# match access-list mgcp
In the default global policy, the inspection_default class map is a special class map that includes default
ports for all inspection types (
match default-inspection-traffic
). If you are using this class map in
either the default policy or for a new service policy, you can skip this step.
For information on matching statements, see
Identify Traffic (Layer 3/4 Class Maps), page 1-13
Step 2
Add or edit a policy map that sets the actions to take with the class map traffic.
policy-map
name
Example:
hostname(config)# policy-map global_policy
In the default configuration, the global_policy policy map is assigned globally to all interfaces. If you
want to edit the global_policy, enter global_policy as the policy name.
Step 3
Identify the L3/L4 class map you are using for MGCP inspection.
class
name
Example:
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......