Cisco 7604 Configuration Guide - Page 485
Configuring MGCP Timeout Values, Verifying and Monitoring MGCP Inspection
View all Cisco 7604 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 485 highlights
Chapter 22 Applying Application Layer Protocol Inspection MGCP Inspection hostname(config-pmap-c)# service-policy policy_map_name [global | interface interface_ID] hostname(config)# where policy_map_name is the policy map you configured in Step 5. If you want to apply the policy map to traffic on all the interfaces, use the global option. If you want to apply the policy map to traffic on a specific interface, use the interface interface_ID option, where interface_ID is the name assigned to the interface with the nameif command. The FWSM begins inspecting MGCP traffic, as specified. Example 22-10 shows how to identify MGCP traffic, define a MGCP map, define a policy, and apply the policy to the outside interface. This creates a class map to match MGCP traffic on the default ports (2427 and 2727). This configuration allows call agents 10.10.11.5 and 10.10.11.6 to control gateway 10.10.10.115, and allows call agents 10.10.11.7 and 10.10.11.8 to control both gateways 10.10.10.116 and 10.10.10.117. The maximum number of MGCP commands that can be queued is 150. The service policy is then applied to the outside interface. Example 22-10 Enabling and Configuring MGCP Inspection hostname(config)# access-list mgcp_acl permit udp any any eq 2427 hostname(config)# access-list mgcp_acl permit udp any any eq 2727 hostname(config)# class-map mgcp-traffic hostname(config-cmap)# match access-list mgcp_acl hostname(config-cmap)# mgcp-map sample_map hostname(config-mgcp-map)# call-agent 10.10.11.5 101 hostname(config-mgcp-map)# call-agent 10.10.11.6 101 hostname(config-mgcp-map)# call-agent 10.10.11.7 102 hostname(config-mgcp-map)# call-agent 10.10.11.8 102 hostname(config-mgcp-map)# gateway 10.10.10.115 101 hostname(config-mgcp-map)# gateway 10.10.10.116 102 hostname(config-mgcp-map)# gateway 10.10.10.117 102 hostname(config-mgcp-map)# command-queue 150 hostname(config-mgcp-map)# policy-map sample_policy hostname(config-pmap)# class mgcp_port hostname(config-pmap-c)# inspect mgcp sample_map hostname(config-pmap-c)# service-policy sample_policy interface outside Configuring MGCP Timeout Values The timeout mgcp command lets you set the interval for inactivity after which an MGCP media connection is closed. The default is five minutes. The timeout mgcp-pat command lets you set the timeout for PAT xlates. Because MGCP does not have a keepalive mechanism, if you use non-Cisco MGCP gateways (call agents), the PAT xlates are torn down after the default timeout interval, which is 30 seconds. Verifying and Monitoring MGCP Inspection The show mgcp commands command lists the number of MGCP commands in the command queue. The show mgcp sessions command lists the number of existing MGCP sessions. The detail option includes additional information about each command (or session) in the output. The following is sample output from the show mgcp commands command. OL-20748-01 Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM 22-69