Cisco ACE-4710-K9 Administration Guide - Page 163

Using Parameter Maps in a Layer 3 and Layer 4 Policy Map

Page 163 highlights

Chapter 4 Configuring Class Maps and Policy Maps Configuring a Layer 3 and Layer 4 Policy Map Table 4-9 Layer 3 and Layer 4 Policy Map Actions and Related Documentation (continued) Layer 3 and Layer 4 Policy Map/Actions Connection redundancy Application protocol inspection Static or dynamic NATs IP, TCP, and UDP connection behavior Document Cisco 4700 Series Application Control Engine Appliance Administration Guide (this book) Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide Chapter Chapter 7, Configuring Redundant ACE Appliances Chapter 3, Configuring Application Protocol Inspection Chapter 5, Configuring Network Address Translation Chapter 4, Configuring TCP/IP Normalization and IP Reassembly Parameters Using Parameter Maps in a Layer 3 and Layer 4 Policy Map To combine related actions for TCP, IP, HTTP, or UDP connections in a Layer 3 and Layer 4 policy map, create one or more parameter maps for use with the ACE. The ACE supports the following Layer 3 and Layer 4 parameter map types: • parameter-map type connection map_name-Combines all TCP and IP connection-related parameters pertaining to TCP normalization, termination, and server re-use as well as IP normalization, fragmentation, and reassembly. See the Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide for details. • parameter-map type http-Configures advanced HTTP behavior for HTTP load-balanced connections. See the Cisco 4700 Series Application Control Engine Appliance Server Load-Balancing Configuration Guide for details. • parameter-map type http-Configures advanced HTTP behavior for HTTP deep packet inspection. See the Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide for details. OL-11157-01 Cisco 4700 Series Application Control Engine Appliance Administration Guide 4-49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418

4-49
Cisco 4700 Series Application Control Engine Appliance Administration Guide
OL-11157-01
Chapter 4
Configuring Class Maps and Policy Maps
Configuring a Layer 3 and Layer 4 Policy Map
Using Parameter Maps in a Layer 3 and Layer 4 Policy Map
To combine related actions for TCP, IP, HTTP, or UDP connections in a Layer 3
and Layer 4 policy map, create one or more parameter maps for use with the ACE.
The ACE supports the following Layer 3 and Layer 4 parameter map types:
parameter-map type connection
map_name
—Combines all TCP and IP
connection-related parameters pertaining to TCP normalization, termination,
and server re-use as well as IP normalization, fragmentation, and reassembly.
See the
Cisco 4700 Series Application Control Engine Appliance Security
Configuration Guide
for details.
parameter-map type http
—Configures advanced HTTP behavior for HTTP
load-balanced connections. See the
Cisco 4700 Series Application Control
Engine Appliance Server Load-Balancing Configuration Guide
for details.
parameter-map type http
—Configures advanced HTTP behavior for HTTP
deep packet inspection. See the
Cisco 4700 Series Application Control
Engine Appliance Security Configuration Guide
for details.
Connection
redundancy
Cisco 4700 Series Application
Control Engine Appliance
Administration Guide
(this
book)
Chapter 7, Configuring Redundant ACE
Appliances
Application protocol
inspection
Cisco 4700 Series Application
Control Engine Appliance
Security Configuration Guide
Chapter 3, Configuring Application
Protocol Inspection
Static or dynamic
NATs
Cisco 4700 Series Application
Control Engine Appliance
Security Configuration Guide
Chapter 5, Configuring Network Address
Translation
IP, TCP, and UDP
connection behavior
Cisco 4700 Series Application
Control Engine Appliance
Security Configuration Guide
Chapter 4, Configuring TCP/IP
Normalization and IP Reassembly
Parameters
Table 4-9
Layer 3 and Layer 4 Policy Map Actions and Related Documentation (continued)
Layer 3 and Layer 4
Policy Map/Actions
Document
Chapter