Cisco 4700M manuals
4700M
Table of contents
4700M
Table of contents
- configuration guide
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- how to use this guide
- related documentation
- C H A P T E R 1 Configuring Security Access Control Lists
- ACL Types and Uses
- ACL Implicit Deny
- Configuring ACLs
- Configuring Comments in an Extended ACL
- Configuring an EtherType ACL
- Resequencing Entries
- Simplifying Access Control Lists with Object Groups
- Configuring Network Object Groups
- Creating a Network Object Group
- Configuring a Network IP Address for a Network Object Group
- Configuring Service Object Groups
- Adding a Description to a Service Object Group
- Defining Protocol Parameters for a Service Object Group
- Using Object Groups in an ACL
- Example of Configuring the Equivalent Extended ACL Using Object Groups
- Entries
- Applying an ACL to an Interface
- Applying an ACL Globally to All Interfaces in a Context
- Filtering Traffic with an ACL
- Inbound and Outbound ACLs
- IP Addresses for ACLs with NAT
- Examples of EtherType ACLs
- Displaying ACL Configuration Information and Statistics
- Displaying the ACL Merge Tree Node Usage
- C H A P T E R 2 Configuring Authentication and Accounting Services
- Local Database and Remote Server Support
- Local Database
- RADIUS Server
- Authentication Overview
- Accounting Overview
- Configuring the AAA Server
- Configuring Accounting Settings on the TACACS+ Server
- Defining Private Attributes for Virtualization Support in a TACACS Server
- Configuring a RADIUS Server
- Configuring Accounting Settings on the RADIUS Server
- Defining Private Attributes for Virtualization Support in a RADIUS Server
- Configuring an LDAP Server
- Defining Private Attributes for Virtualization Support in an LDAP Server
- Creating User Accounts
- Configuring the ACE as a Client of a RADIUS, TACACS+, or LDAP Server
- Configuring RADIUS on the ACE
- Configuring the RADIUS NAS-IP-Address Attribute
- Configuring the Global RADIUS Server Dead-Time Interval
- Setting the Global RADIUS Server Number of Retransmissions
- Setting the Global RADIUS Server Timeout Value
- Setting the TACACS+ Server Parameters
- Setting the Global Preshared Key
- Setting the Global TACACS+ Server Dead-Time Interval
- Setting the Global TACACS+ Server Timeout Value
- Setting the LDAP Server Parameters
- Setting the Global LDAP Server Port Setting
- Setting the Global LDAP Server Timeout Value
- Creating a TACACS+, RADIUS, or LDAP Server Group
- Setting the Dead-Time Interval for a TACACS+ Server Group
- Setting the Dead-Time Interval for a RADIUS Server Group
- Configuring the User Profile Attribute Type for an LDAP Server Group
- Configuring the Base DN for an LDAP Server Group
- Configuring the Search Filter for an LDAP Server Group
- Defining the Login Authentication Method
- Defining the Default Accounting Method
- Viewing AAA Status and Statistics
- Displaying TACACS+ Server Configuration Information
- Displaying LDAP Server Configuration Information
- Displaying Accounting Log Information
- Displaying Authentication Configuration Information
- C H A P T E R 3 Configuring Application Protocol Inspection
- Application Inspection Protocol Overview
- FTP Inspection
- HTTP Deep Packet Inspection
- ILS Inspection
- RTSP Inspection
- SCCP Inspection
- SIP Inspection
- Application Protocol Inspection Configuration Quick Start Procedures
- Configuring a Layer 7 FTP Command Inspection Policy
- Configuring an FTP Inspection Class Map
- Adding a Layer 7 FTP Inspection Class Map Description
- Configuring a Layer 7 FTP Command Inspection Policy Map
- Creating a Layer 7 FTP Command Inspection Policy Map
- Policy Map
- Traffic Policy
- Specifying the Layer 7 FTP Command Inspection Policy Actions
- Configuring a Layer 7 HTTP Deep Inspection Policy
- Configuring a Layer 7 HTTP Deep Inspection Class Map
- Description
- Defining HTTP Content Match Criteria
- Defining the Length of the HTTP Content for Inspection
- Defining a Secondary Cookie for HTTP Inspection
- Defining an HTTP Header for Inspection
- Defining the HTTP Maximum Header Length for Inspection
- Defining a Header MIME-Type Messages for Inspection
- Defining an HTTP Traffic Restricted Category
- Defining HTTP Request Methods and Extension Methods
- Defining an HTTP Transfer Encoding Type
- Defining an HTTP URL for Inspection
- Defining an HTTP Maximum URL Length for Inspection
- Configuring a Layer 7 HTTP Deep Packet Inspection Policy Map
- Including Inline Match Statements in a Layer 7 HTTP Deep Packet Inspection Policy Map
- Policy
- Specifying the Layer 7 HTTP Deep Packet Policy Actions
- Configuring a Layer 7 SCCP Inspection Policy
- Adding a Description to the Layer 7 SCCP Inspection Policy Map
- Specifying the Layer 7 SCCP Inspection Policy Map Action
- Configuring a Layer 7 SIP Inspection Policy
- Creating a Layer 7 SIP Inspection Class Map
- Adding a Layer 7 Class Map Description for SIP Inspection
- Defining the Calling Party in the SIP From Header
- Defining SIP Content Checks
- Defining the SIP Instant Messaging Subscriber
- Defining the Message Path Taken by SIP Messages
- Defining the SIP Request Methods
- Defining the SIP Party Registration Entities
- Defining SIP URI Checks
- Configuring a Layer 7 SIP Inspection Policy Map
- Creating a Layer 7 SIP Policy Map
- Specifying the Layer 7 SIP Inspection Policy Map Actions
- Configuration Guidelines for Inspection Traffic Policies
- Configuring a Layer 3 and Layer 4 Class Map
- Adding a Layer 3 and Layer 4 Class Map Description
- Defining Access-List Match Criteria
- Defining TCP/UDP Port Number or Port Range Match Criteria
- Configuring a Layer 3 and Layer 4 Policy Map
- Adding a Layer 3 and Layer 4 Policy Map Description
- Defining Layer 3 and Layer 4 Application Protocol Inspection Policy Actions
- Configuring a DNS Parameter Map
- Configuring a DNS Query Timeout
- Configuring an HTTP Parameter Map
- Disabling Case-Sensitivity Matching
- Setting the Maximum Number of Bytes to Parse in HTTP Content
- Configuring an SCCP Parameter Map
- SCCP Inspection Configuration Considerations
- Enabling Registration Enforcement
- Setting the Minimum and Maximum SCCP Prefix Length
- Configuring a SIP Parameter Map
- SIP Inspection Configuration Considerations
- Configuring a Timeout for a SIP Media Secure Port
- Enabling Maximum Forward Field Validation
- Configuring User Agent Software Version Options
- Enabling Non-SIP URI Detection in SIP Messages
- Applying a Service Policy
- Examples of Application Protocol Inspection Configurations
- Layer 7 FTP Command Inspection
- Layer 3 and Layer 4 Application Protocol Inspection for DNS Inspection
- Viewing Application Protocol Inspection Statistics and Service Policy Information
- Displaying Service Policy Configuration Information
- TCP Normalization Overview
- C H A P T E R 4 Configuring TCP/IP Normalization and IP Reassembly Parameters
- Configuring a Connection Parameter Map for TCP/IP Normalization and Termination
- Creating a Connection Parameter Map for TCP/IP, UDP, and ICMP
- Configuring Rate Limits for a Policy Map
- Setting the Maximum Receive or Transmit Buffer Share
- Setting a Range for the Maximum Segment Size
- Configuring ACE Behavior for a Segment That Exceeds the Maximum Segment Size
- Enabling Nagle's Algorithm
- Configuring How the ACE Handles Reserved Bits
- Configuring the Timeout for a Half-Closed Connection
- Configuring the Connection Inactivity Timeout
- Setting the Window Scale Factor
- Enabling the TCP Slow Start Algorithm
- Data
- Setting the Urgent Pointer Policy
- Setting the Type of Service
- Configuring a Traffic Policy for TCP/IP Normalization and Termination
- Defining a Class Map Description
- Specifying IP Address Match Criteria
- Defining a TCP or UDP Port Number or Port Range Match Criteria
- Associating a Layer 3 and Layer 4 Class Map with a Policy Map
- Associating a Connection Parameter Map with a Policy Map
- Associating a Layer 3 and Layer 4 Policy Map with a Service Policy
- Disabling TCP Normalization on an Interface
- Disabling the ICMP Security Checks on an Interface
- Configuring SYN-Cookie Denial-of-Service Protection
- Configuration and Operational Considerations
- Configuring SYN Cookie DoS Protection on an Interface
- Configuring How the ACE Handles IP Options
- Setting the IP Packet TTL
- Configuring IP Fragment Reassembly Parameters
- Configuring the MTU for an Interface
- Configuring the Minimum Fragment Size for Reassembly
- Example of a TCP/IP Normalization and IP Reassembly Configuration
- Reassembly, and SYN Cookie
- Displaying a Connection Parameter Map
- Displaying TCP/IP and UDP Connection Statistics
- Displaying Global Context Connection Statistics
- Displaying IP Statistics
- Displaying IP Fragmentation and Reassembly Statistics
- Displaying TCP Statistics
- Displaying UDP Statistics
- Displaying Service Policy Statistics
- Displaying SYN Cookie Statistics
- Clearing TCP/IP and UDP Connections and Statistics
- Clearing Connection Statistics
- Clearing TCP Statistics
- Clearing IP Fragmentation and Reassembly Statistics
- configuring network address
- C H A P T E R 5 Configuring Network Address Translation
- Dynamic NAT
- Dynamic PAT
- Server Farm-Based Dynamic NAT
- Static Port Redirection
- Global Address Guidelines
- Configuring Dynamic NAT and PAT
- Configuring an ACL
- Configuring a Class Map
- Configuring a Class Map for Passive FTP
- Action
- Applying the Dynamic NAT and PAT Policy Map to an Interface Using a Service Policy
- Configuring Server Farm-Based Dynamic NAT
- Configuring an ACL for Server Farm-Based Dynamic NAT
- Configuring Real Servers and a Server Farm
- Configuring Server Farm-Based Dynamic NAT as a Layer 7 Policy Action
- Configuring Static NAT and Static Port Redirection
- Configuring an ACL for Static NAT and Static Port Redirection
- Configuring a Policy Map
- Configuring Static NAT and Static Port Redirection as a Policy Action
- Interface Using a Service Policy
- Displaying NAT Configurations and Statistics
- Dynamic NAT Example
- Dynamic PAT Example
- Clearing Xlates
- NAT Configuration Examples
- Server Farm-Based Dynamic NAT (SNAT) Configuration Example
- Static Port Redirection (DNAT) Configuration Example
- SNAT with Cookie Load Balancing Example
4700M
Table of contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- how to use this guide
- related documentation
- setting up the ace
- Chapter 1 Setting Up the ACE
- Setting Up the ACE
- Using the Setup Script to Enable Connectivity to the Device Manager
- Connecting and Logging In to the ACE
- Changing or Resetting the Administrative Password
- Changing the Administrative Password
- Resetting the Administrator Account Password
- Assigning a Name to the ACE
- Configuring an ACE Inactivity Timeout
- Configuring a Message-of-the-Day Banner
- Configuring the Date and Time
- Configuring the Time Zone
- Adjusting for Daylight Saving Time
- Synchronizing the ACE with an NTP Server
- Configuring Terminal Settings
- Configuring Virtual Terminal Line Settings
- Modifying the Boot Configuration
- Setting the BOOT Environment Variable
- Configuring the ACE to Bypass the Startup Configuration File During the Boot Process
- Restarting the ACE
- Using the GRUB Boot Loader to Specify the System Boot Image During a Reload
- Shutting Down the ACE
- Displaying Other ACE Setup Configuration Information
- Clearing NTP Statistics
- enabling remote access to the ace
- Chapter 2 Enabling Remote Acces to the ACE
- Enabling Remote Access to the ACE
- Configuring Remote Network Management Traffic Services
- Creating and Configuring a Remote Management Class Map
- Creating a Layer 3 and Layer 4 Remote Access Policy Map
- Applying a Service Policy Globally to All VLAN Interfaces in the Same Context
- Applying a Service Policy to a Specific VLAN Interface
- Configuring the Maximum Number of Telnet Management Sessions
- Configuring SSH Management Session Parameters
- Generating SSH Host Key Pairs
- Terminating an Active User Session
- Enabling ICMP Messages to the ACE
- Directly Accessing a User Context Through SSH
- Displaying Remote Access Session Information
- Displaying Telnet Session Information
- Displaying Other Remote Access Session Information
- Configuration Example for Enabling Remote Access to the ACE
- Information about ACE Licenses
- Chapter 3 Managing ACE Software License
- Guidelines and Limitations
- Managing ACE Appliance Software Licenses
- Installing a New or Upgrade License File
- Replacing a Demo License with a Permanent License
- Removing a License
- Removing a Virtual Context License
- Backing Up an ACE License File
- Displaying ACE License Configurations and Statistics
- Saving Configuration Files
- Chapter 4 Managing the ACE Software
- Copying the Configuration File to the disk0: File System
- Merging the Startup-Configuration File with the Running-Configuration File
- Clearing the Startup-Configuration File
- Copying Configuration Files from a Remote Server
- Using the File System on the ACE
- Copying Files to Another Directory on the ACE
- Copying a Packet Capture Buffer
- Copying Files from a Remote Server
- Uncompressing Files in the disk0: File System
- Untarring Files in the disk0: File System
- Creating a New Directory
- Deleting Files
- Displaying Files Residing On the ACE
- Saving show Command Output to a File
- Managing Core Dump Files
- Clearing the Core Directory
- Deleting a Core Dump File
- Enabling the Packet Capture Function
- Copying Packet Capture Buffer Information
- Displaying or Clearing Packet Information
- Clearing Capture Buffer Information
- Deleting a Configuration Checkpoint
- Rolling Back a Running Configuration
- Reformatting the Flash Memory
- C H A P T E R 5 Displaying ACE Hardware and Software System Information
- Displaying Installed Software Information
- displaying system processes and memory resources limits
- Displaying System Processes and Memory Resources Limits
- displaying system information
- Displaying System Information
- displaying or clearing icmp statistics
- Displaying or Clearing ICMP Statistics
- Displaying General System Process Information
- Displaying or Collecting Technical Information for Reporting Problems
- Information About Redundancy
- Chapter 6 Configuring Redundant ACE
- Stateful Failover
- Configuration Synchronization
- Redundancy State for Software Upgrade or Downgrade
- Default Settings
- Configuring Redundant ACEs
- Configuring Redundancy
- Configuring an Alias IP Address
- Configuring an FT Peer
- Configuring an FT Group
- Modifying an FT Group
- Specifying the MAC Address Banks for a Shared VLAN
- Forcing a Failover
- Synchronizing Redundant Configurations
- Configuring Tracking and Failure Detection
- Configuring Tracking and Failure Detection for a Host or Gateway
- Configuring Tracking and Failure Detection for an Interface
- Displaying or Clearing Redundancy Information
- Displaying Redundancy Information
- Displaying FT Group Information
- Displaying the Redundancy Internal Software History
- Displaying Peer Information
- Displaying FT Statistics
- Displaying FT Tracking Information
- Clearing Redundancy Statistics
- Clearing Heartbeat Statistics
- Configuration Example of Redundancy
- Information About SNMP
- Chapter 7 Configuring SNMP
- SNMP Traps and Informs
- CLI and SNMP User Synchronization
- Supported MIBs and Notifications
- Default Settings for SNMP
- Configuring SNMP
- Configuring SNMP Users
- Defining SNMP Communities
- Configuring an SNMP Contact
- Configuring an SNMP Location
- Configuring SNMP Notifications
- Enabling SNMP Notifications
- Enabling the IETF Standard for SNMP linkUp and linkDown Traps
- Unmasking the SNMP Community Name and Community Security Name OIDs
- Assigning a Trap-Source Interface for SNMP Traps
- Accessing ACE User Context Data Through the Admin Context IP Address
- Accessing User Context Data When Using SNMPv3
- Configuring SNMP Management Traffic Services
- Creating and Configuring a Layer 3 and Layer 4 Class Map
- Creating a Layer 3 and Layer 4 Policy Map
- Displaying or Clearing SNMP and Service Policy Statistics
- Displaying SNMP Service Policy Statistics
- Clearing SNMP Service Policy Statistics
- Information About XML
- Chapter 8 Configuring the XML Interface
- HTTP Return Codes
- Document Type Definition
- Configuring the XML Interface
- Configuring HTTP and HTTPS Management Traffic Services
- Enabling the Display of Raw XML Request show Command Output in XML Format
- Accessing the ACE DTD File
- Displaying or Clearing XML Service Policy Statistics
- Example of ACE CLI Command and the XML Equivalent
- Overview of Upgrading ACE Software
- A P P E N D I X A Upgrading or Downgrading Your ACE Software
- Updating Your Application Protocol Inspection Configurations
- Performing Software Upgrades and Downgrades
- Task Flow for Downgrading the ACE Software
- Copying the Software Upgrade Image to the ACE
- Configuring the ACE to Autoboot the Software Image
- Reloading the ACE
- Displaying the Boot Variable and Configuration Register