Assigning a Class Map Name

System Engineers To configure a class map:

Name a class

Define matching attributes

Executives

Internet

Internet

System Engineers To configure a class map:

Headquarters

Site C

Site to Site

Site B

Headquarters

Executives

Site to Site

Assign a name to the class of traffic pix1(config)# class-map se pix1(config)# class-map exec pix1(config)# class-map s2s_voice pix1(config)# class-map internet

© 2005 Cisco Systems, Ii

The class-map command is used to classify a set of traffic with which security actions may be associated. Configuring a class map is a two-step process, naming the class of traffic and defining the attributes of the traffic. A name is assigned to each individual class of traffic. In the example in the figure, four traffic classes are named. The class-map se command identifies the remote VPN traffic to the system engineers. The class-map s2s_voice command identifies the site-to-site VPN traffic. The class-map internet command identifies traffic from the Internet.

The syntax of the class-map commands is as follows:

class-map class_map_name

System Engineers To configure a class map: • Name a class

Internet

Headquarters

Executives

Site C

Define matching attributes

Define a class of traffic by matching:

• default-inspection-traffic—Match inspection commands

• dscp—Match IP differentiated services code point

• flow—Match the destination IP address

• precedence—Match IP precedence

• rtp—Match RTP port numbers

• tunnel-group—Match a VPN tunnel group

© 2005 Cisco Systems, Inc. All rights reserved.

Internet

Headquarters

Executives

Site C

Site B

Site B

After a class of traffic is named, the characteristics of the traffic flow are identified. To be considered part of a named class, a traffic flow must match a defined set of attributes. There are various types of matchable criteria in a class map.

The following is the class matching criteria:

■ access-list—Keyword specifies to match an entry in an access-list.

■ any—Keyword specifies that all traffic is to be matched. match any is used in the 'inspection_default' class-map; it means match any packet.

■ dscp—Keyword specifies to match the Internet Engineering Task Force (IETF)-defined differentiated services code point (DSCP) value in the IP header. This criterion allows the user to define classes based on the DSCP values that are defined within the type of service (ToS) byte in the IP header.

■ flow—Keyword pair specifies to match the destination IP address (within a tunnel group). This match command must be used in conjunction with the match tunnel-group command.

■ port—Keyword specifies to match traffic using the TCP or User Datagram Protocol (UDP) destination port.

■ precedence—Keyword specifies to match the precedence value represented by the ToS byte in the IP header. This criterion allows the user to define classes based on the precedence defined within the ToS byte in the IP header.

■ rtp—Keyword specifies to match Real-Time Transport Protocol (RTP) destination port. This criterion allows the user to match on a UDP port number within the specified range. The allowed range is targeted at capturing applications that are likely to be using RTP. The packet matches the defined class only if the UDP port falls within the specified range, inclusive, and the port number is an even number.

■ tunnel-group—Keyword specifies to match tunnel traffic.

class-map <classmap name>

description <text> match any match access-list <acl name>

match port tcp | udp {eq <n> | range <n1> <n2>}

match precedence <precedence value>

match dscp <dscp value>

match rtp <starting port> <range>

match tunnel-group <tunnel group id>

match flow ip destination-address match default-inspection-traffic

classmap_name

Name for the class map; up to 40 characters.

"inspection_default" is a reserved name for default class. It always exists and it can't be configured or removed via CLI. When used in a policy map, a default class means "all other traffic." The actual syntax of a default class is:

class-map inspection_default match any

The name space for a class map is local to a security context. The same name may be used in different security contexts.

The maximum number of class maps per security context is 255.

description

A subcommand that is used to specify a description for the class map.

<text>

The description; up to 200 characters are allowed.

match

A subcommand that is used to specify a match criterion.

access-list

Keyword that specifies that an ACL is to be used as a match criterion. When a packet matches no entry in an ACL, the match result is a no-match. When a packet matches an entry in an ACL and it is a "permit" entry, the match result is a match. If it is a "deny" entry, the match result is a no-match.

<acl_name>

Name of the ACL to be used as a match criteria.

any

Keyword that specifies that all traffic is to be matched. match any is used in the inspection_default class map.

none

Keyword that specifies that no traffic will be matched. When a class map is created with no match command in the class map, a match none is automatically created in the class map. Note that match none cannot be configured.

port

Keyword that specifies to match traffic using the TCP or UDP destination port.

tcp

Keyword that specifies to match traffic using a TCP destination port.

udp

Keyword that specifies to match traffic using a UDP destination port.

<port_name> | <n>

Specifies a port name, such as HTTP, or a port number (from 1 through-65535.

precedence

Keyword that specifies to match the precedence value represented by the ToS byte in the IP header.

precedence_value

Specifies the precedence value (0-7).

dscp

Keyword that specifies to match the IETF-defined DSCP value in the IP header.

dscp_value

Specifies the DSCP value (0-63).

rtp

Keyword that specifies to match RTP ports (even UDP port numbers between starting_port and starting_port+range).

starting_port

Specifies the lower bound of UDP destination port.

range

Specifies the range of RTP ports.

default-inspection-traffic

Keyword that specifies to match default traffic for individual inspect commands. Following are the rules of using this match criteria:

This match applies only to the inspect command as such; when the class map that contains this match command is used in a policy map, the class map cannot be associated with any action command other than the inspect command.

The matched traffic depends on the individual inspect command. See the following table for what default-inspection-traffic means to each

inspect command.

This match can be used in conjunction with one other match command, typically an ACL in the form of permit ip src-ip dst-ip. The two match commands are merged to produce match rules for inspect commands. The merge rule is to use the protocol and port information from the match default-inspect-traffic command and use the nonprotocol and nonport information (such as IP addresses) from the other match command. So any protocol or port information in the other match command is ignored with respect to inspect commands. For example, in this configuration, port 65535 is ignored.

match default-inspection-traffic match port 65535

or access-list foo permit ip host 192.168.1.1 any eq 65535

match default-inspection-traffic match access-list foo default traffic for individual inspection:

Protocol Name

Protocol

Source Port

Destination Port

ctiqbe

tcp

N/A

2748

dns

udp

53

53

ftp

tcp

N/A

21

gtp

udp

2123,3386

2123,3386

h323 h225

tcp

N/A

1720

h323 ras

udp

N/A

1718-1719

http

tcp

N/A

80

icmp

icmp

N/A

N/A

ils

tcp

N/A

389

mgcp

udp

2427,2727

2427,2727

netbios

udp

137-138

N/A

rpc

udp

111

111

rsh

tcp

N/A

514

rtsp

tcp

N/A

554

sip

tcp,udp

N/A

5060

skinny

tcp

N/A

2000

smtp

tcp

N/A

25

sqlnet

tcp

N/A

1521

tftp

udp

N/A

69

xdmcp

udp

177

Keyword that specifies to match tunnel traffic.

<tunnel_group>

Specifies a configured tunnel-group.

flow ip

Keyword pair that specifies to match destination IP address within a flow. This match command must be used in conjunction with the match tunnel-group command.

<destination-address>

Destination address.

classmap_name

Name for the class map; up to 40 characters.

"inspection_default" is a reserved name for default class. It always exists, and it can't be configured or removed via CLI. When used in a policy map, a default class means "all other traffic." The actual syntax of a default class is:

class-map inspection_default match any

The name space for the class map is local to a security context. So the same name may be used in different security contexts.

The maximum number of class maps per security context is 255.

description

A subcommand that is used to specify a description for the class map.

<text>

Text for the description; up to 200 characters are allowed.

Continue reading here: Show run service policy Command

Was this article helpful?

0 0