12-43
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 12 Configuring Traffic Policies
Configuring Rules and Actions for Policy Maps
Table 12-18 Policy Map Application Inspection Options
Inspection Option Description
DNS Indicates that Domain Name System (DNS) query inspection is to be implemented. DNS requires
application inspection so that DNS queries will not be subject to the generic UDP handling based on
activity timeouts. Instead, the UDP connections associated with DNS queries and responses are torn
down as soon as a reply to a DNS query has been received. The ACE appliance performs the
reassembly of DNS packets to verify that the packet length is less than the configured maximum
length.
In the DNS Max. Length field, enter the maximum length of a DNS reply in bytes. Valid entries are
integers from 512 to 65535.
FTP Indicates that FTP inspection is to be implemented. The ACE appliance inspects FTP packets,
translates the address and port embedded in the payload, and opens up secondary channel for data.
1. In the Parameter Map field, specify a previously created parameter map used to define parameters
for FTP inspection.
2. In the FTP Strict field, indicate whether the ACE appliance is to check for protocol RFC
compliance and prevent Web browsers from sending embedded commands in FTP requests:
–
N/A—Indicates that this attribute is not set.
–
False—Indicates that the ACE appliance is not to check for RFC compliance or prevent Web
browsers from sending embedded commands in FTP requests.
–
True—Indicates that the ACE appliance is to check for RFC compliance and prevent Web
browsers from sending embedded commands in FTP requests.
3. If you select True, in the FTP Inspect Policy field, select the Layer 7 FTP command inspection
policy to be implemented for this rule.
HTTP Indicates that enhanced Hypertext Transfer Protocol (HTTP) inspection is to be performed on HTTP
traffic. The inspection checks are based on configured parameters in an existing Layer 7 policy map
and internal RFC compliance checks performed by the ACE appliance. By default, the ACE appliance
allows all request methods.
1. In the HTTP Inspect Policy field, select the HTTP inspection policy map to be implemented for
this rule. If you do not specify a Layer 7 policy map, the ACE appliance performs a general set of
Layer 3 and Layer 4 protocol fixup actions and internal RFC compliance checks.
2. In the URL Logging field, indicate whether Layer 3 and Layer 4 traffic is to be monitored:
–
N/A—Indicates that this attribute is not set.
–
False—Indicates that Layer 3 and Layer 4 traffic is not to be monitored.
–
True—Indicates that Layer 3 and Layer 4 traffic is to be monitored. When enabled, this
function logs every URL request that is sent in the specified class of traffic, including the
source or destination IP address and the URL that is accessed.
Comments to this Manuals