12-2
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 12 Configuring Traffic Policies
Class Map and Policy Map Overview
Class Map and Policy Map Overview
You classify inbound network traffic destined to, or passing through, the ACE appliance based on a
series of flow match criteria specified by a class map. Each class map defines a traffic classification; that
is, network traffic that is of interest to you. A policy map defines a series of actions (functions) that you
want applied to a set of classified inbound traffic.
Class maps enable you to classify network traffic based on the following criteria:
• Layer 3 and Layer 4 traffic flow information—Source or destination IP address, source or
destination port, virtual IP address, IP protocol and port, or management protocol
• Layer 7 protocol information—HTTP cookie, HTTP URL, HTTP header, HTTP content, FTP
request commands, RADIUS, RDP, RTSP, Skinny, or SIP
Table 12-1 lists the available policies for the ACE.
The traffic classification process consists of the following three steps:
1. Creating a class map, which comprise a set of match criteria related to Layer 3 and Layer 4 traffic
classifications or Layer 7 protocol classifications.
Table 12-1 Traffic Policies
Policy Map Description
Layer 3/4 Management Traffic
(First-Match)
Layer 3 and Layer 4 policy map for network management traffic received by the
ACE
Layer 3/4 Network Traffic (First-Match) Layer 3 and Layer 4 policy map for traffic passing through the ACE
Layer 7 Command Inspection - FTP
(First-Match)
Layer 7 policy map for inspection of FTP commands
Layer 7 Deep Packet Inspection - HTTP
(All-Match)
Layer 7 policy map for inspection of HTTP packets
Layer 7 Deep Packet Inspection - SIP
(All-Match)
Layer 7 policy map for inspection of SIP packets
Layer 7 Deep Packet Inspection - Skinny Layer 7 policy map for inspection of Skinny Client Control Protocol (SCCP)
Layer 7 HTTP Optimization (First-Match) Layer 7 policy map for optimizing HTTP traffic
Layer 7 Server Load Balancing
(First-Match)
Layer 7 policy map for HTTP server load balancing
Server Load Balancing - Generic
(First-Match)
Generic Layer 7 policy map for server load balancing
Server Load Balancing - HTTPS
1
(First-Match)
1. This option is not available for ACE NPE software image.
Layer 7 policy map for HTTPS server load balancing
Server Load Balancing - RADIUS
(First-Match)
Layer 7 policy map for RADIUS server load balancing
Server Load Balancing - RDP
(First-Match)
Layer 7 policy map for RDP server load balancing
Server Load Balancing - RTSP
(First-Match)
Layer 7 policy map for RTSP server load balancing
Comments to this Manuals