12-25
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 12 Configuring Traffic Policies
Setting Match Conditions for Class Maps
Setting Match Conditions for Layer 7 HTTP Deep Packet Inspection Class
Maps
The ACE Appliance Device Manager allows you to create Layer 7 class maps and policy maps to be used
for HTTP deep packet inspection by the ACE appliance. When these features are configured, the ACE
appliance performs a stateful deep packet inspection of the HTTP protocol and permits or restricts traffic
based on the actions in the defined policy maps. You can configure the following security features as
part of HTTP deep packet inspection to be performed by ACE appliances:
• Regular expression matching on name in an HTTP header, URL name, or content expressions in an
HTTP entity body
• Content, URL, and HTTP header length checks
• MIME-type message inspection
• Transfer-encoding methods
• Content type verification and filtering
• Port 80 misuse by tunneling protocols
• RFC compliance monitoring and RFC method filtering
Use this procedure to configure a Layer 7 class map for deep packet inspection of HTTP traffic.
Assumption
You have configured a Layer 7 deep packet inspection class map and want to establish match conditions.
Procedure
Step 1 Choose Config > Virtual Contexts > context > Expert > Class Maps. The Class Maps table appears.
Step 2 In the Class Maps table, select the Layer 7 HTTP deep packet inspection class map you want to set match
conditions for. You can select multiple class maps (hold down the Shift key while selecting entries) and
apply common match conditions to them.
Step 3 In the Match Condition table, click Add to add match criteria, or select the match condition you want to
modify, and then click Edit. The Match Condition configuration screen appears.
Step 4 In the Sequence Number field, enter an integer from 2 to 255 as the line number. The number entered
here does not indicate a priority or sequence for the match conditions.
Step 5 In the Match Condition Type field, select the method by which match decisions are to be made and
configure condition-specific attributes as described in Table 12-12.
Comments to this Manuals