Parameter Maps

A parameter map allows you to specify parameters that control the behavior of actions and match criteria specified under a policy map and a class map, respectively.

The four current types of parameter maps are as follows:

■ Inspect parameter map: An inspect parameter map is optional. If you do not configure a parameter map, the software uses default parameters. Parameters associated with the inspect action apply to all nested actions (if any). If parameters are specified in both the top and lower levels, those in the lower levels override those in the top levels.

■ URL filter parameter map: A parameter map is required for URL filtering (via the URL filter action in a Layer 3 or Layer 4 policy map and the URL filter parameter map).

■ Mitigation parameter map: A parameter map is required for an instant messaging (IM) application (Layer 7) policy map.

■ TMS (TIDP Based Mitigation Services ) parameter map: The TMS type parameter map is a container for TMS protocol-specific configuration parameters.

After you enter the parameter-map type inspect command, you can enter the following subcommands:

■ alert {on | off}: Turns on Cisco IOS stateful packet inspection alert messages

■ audit-trail {on | off}: Turns audit trail messages on or off

■ dns-timeout seconds: Specifies the DNS idle timeout

■ icmp idle-timeout seconds: Configures the timeout for ICMP sessions

■ max-incomplete {low number-of-connections | high number-of-connections}: Defines the number of existing half-open sessions that will cause the software to start and stop deleting half-open sessions

© 2007 Cisco Systems, Inc. Adaptive Threat Defense 5-113

■ one-minute {low number-of-connections | high number-of-connections}: Defines the number of new unestablished sessions that will cause the system to start deleting half-open sessions and stop deleting half-open sessions

■ tcp finwait-time seconds: Specifies how long a TCP session will be managed after the Cisco IOS Firewall detects a FIN exchange

■ tcp idle-time seconds: Configures the timeout for TCP sessions

■ tcp max-incomplete host threshold [block-time minutes}: Specifies the threshold and blocking time values for TCP host-specific DoS detection and prevention

■ tcp synwait-time seconds: Specifies how long the software will wait for a TCP session to reach the established state before dropping the session

■ udp idle-time seconds: Configures the timeout of UDP sessions going through the firewall

5-114 Securing Networks with Cisco Routers and Switches (SNRS) v2.0

Continue reading here: Verifying Cisco IOS Zone Based Policy Firewall

Was this article helpful?

0 -1