Assigning a Class Map Name
System Engineers To configure a class map:
Name a class
Define matching attributes
Executives
Internet
Internet
System Engineers To configure a class map:
Headquarters
Site C
Site to Site
Site B
Headquarters
Executives
Site to Site
Assign a name to the class of traffic pix1(config)# class-map se pix1(config)# class-map exec pix1(config)# class-map s2s_voice pix1(config)# class-map internet
© 2005 Cisco Systems, Ii
The class-map command is used to classify a set of traffic with which security actions may be associated. Configuring a class map is a two-step process, naming the class of traffic and defining the attributes of the traffic. A name is assigned to each individual class of traffic. In the example in the figure, four traffic classes are named. The class-map se command identifies the remote VPN traffic to the system engineers. The class-map s2s_voice command identifies the site-to-site VPN traffic. The class-map internet command identifies traffic from the Internet.
The syntax of the class-map commands is as follows:
class-map class_map_name
System Engineers To configure a class map: • Name a class
Internet
Headquarters
Executives
Site C
Define matching attributes
Define a class of traffic by matching:
• default-inspection-traffic—Match inspection commands
• dscp—Match IP differentiated services code point
• flow—Match the destination IP address
• precedence—Match IP precedence
• rtp—Match RTP port numbers
• tunnel-group—Match a VPN tunnel group
© 2005 Cisco Systems, Inc. All rights reserved.
Internet
Headquarters
Executives
Site C
Site B
Site B
After a class of traffic is named, the characteristics of the traffic flow are identified. To be considered part of a named class, a traffic flow must match a defined set of attributes. There are various types of matchable criteria in a class map.
The following is the class matching criteria:
■ access-list—Keyword specifies to match an entry in an access-list.
■ any—Keyword specifies that all traffic is to be matched. match any is used in the 'inspection_default' class-map; it means match any packet.
■ dscp—Keyword specifies to match the Internet Engineering Task Force (IETF)-defined differentiated services code point (DSCP) value in the IP header. This criterion allows the user to define classes based on the DSCP values that are defined within the type of service (ToS) byte in the IP header.
■ flow—Keyword pair specifies to match the destination IP address (within a tunnel group). This match command must be used in conjunction with the match tunnel-group command.
■ port—Keyword specifies to match traffic using the TCP or User Datagram Protocol (UDP) destination port.
■ precedence—Keyword specifies to match the precedence value represented by the ToS byte in the IP header. This criterion allows the user to define classes based on the precedence defined within the ToS byte in the IP header.
■ rtp—Keyword specifies to match Real-Time Transport Protocol (RTP) destination port. This criterion allows the user to match on a UDP port number within the specified range. The allowed range is targeted at capturing applications that are likely to be using RTP. The packet matches the defined class only if the UDP port falls within the specified range, inclusive, and the port number is an even number.
■ tunnel-group—Keyword specifies to match tunnel traffic.
class-map <classmap name>
description <text> match any match access-list <acl name>
match port tcp | udp {eq <n> | range <n1> <n2>}
match precedence <precedence value>
match dscp <dscp value>
match rtp <starting port> <range>
match tunnel-group <tunnel group id>
match flow ip destination-address match default-inspection-traffic
|
classmap_name |
Name for the class map; up to 40 characters. "inspection_default" is a reserved name for default class. It always exists and it can't be configured or removed via CLI. When used in a policy map, a default class means "all other traffic." The actual syntax of a default class is: class-map inspection_default match any The name space for a class map is local to a security context. The same name may be used in different security contexts. The maximum number of class maps per security context is 255. |
|
description |
A subcommand that is used to specify a description for the class map. |
|
<text> |
The description; up to 200 characters are allowed. |
|
match |
A subcommand that is used to specify a match criterion. |
|
access-list |
Keyword that specifies that an ACL is to be used as a match criterion. When a packet matches no entry in an ACL, the match result is a no-match. When a packet matches an entry in an ACL and it is a "permit" entry, the match result is a match. If it is a "deny" entry, the match result is a no-match. |
|
<acl_name> |
Name of the ACL to be used as a match criteria. |
|
any |
Keyword that specifies that all traffic is to be matched. match any is used in the inspection_default class map. |
|
none |
Keyword that specifies that no traffic will be matched. When a class map is created with no match command in the class map, a match none is automatically created in the class map. Note that match none cannot be configured. |
|
port |
Keyword that specifies to match traffic using the TCP or UDP destination port. |
|
tcp |
Keyword that specifies to match traffic using a TCP destination port. |
|
udp |
Keyword that specifies to match traffic using a UDP destination port. |
|
<port_name> | <n> |
Specifies a port name, such as HTTP, or a port number (from 1 through-65535. |
|
precedence |
Keyword that specifies to match the precedence value represented by the ToS byte in the IP header. |
|
precedence_value |
Specifies the precedence value (0-7). |
|
dscp |
Keyword that specifies to match the IETF-defined DSCP value in the IP header. |
|
dscp_value |
Specifies the DSCP value (0-63). |
|
rtp |
Keyword that specifies to match RTP ports (even UDP port numbers between starting_port and starting_port+range). |
|
starting_port |
Specifies the lower bound of UDP destination port. |
|
range |
Specifies the range of RTP ports. |
|
default-inspection-traffic |
Keyword that specifies to match default traffic for individual inspect commands. Following are the rules of using this match criteria: This match applies only to the inspect command as such; when the class map that contains this match command is used in a policy map, the class map cannot be associated with any action command other than the inspect command. The matched traffic depends on the individual inspect command. See the following table for what default-inspection-traffic means to each |
inspect command.
This match can be used in conjunction with one other match command, typically an ACL in the form of permit ip src-ip dst-ip. The two match commands are merged to produce match rules for inspect commands. The merge rule is to use the protocol and port information from the match default-inspect-traffic command and use the nonprotocol and nonport information (such as IP addresses) from the other match command. So any protocol or port information in the other match command is ignored with respect to inspect commands. For example, in this configuration, port 65535 is ignored.
match default-inspection-traffic match port 65535
or access-list foo permit ip host 192.168.1.1 any eq 65535
match default-inspection-traffic match access-list foo default traffic for individual inspection:
|
Protocol Name |
Protocol |
Source Port |
Destination Port |
||||||||||||
|
tcp |
N/A |
2748 |
|||||||||||||
|
dns |
udp |
53 |
53 |
||||||||||||
|
ftp |
tcp |
N/A |
21 |
||||||||||||
|
gtp |
udp |
2123,3386 |
2123,3386 |
||||||||||||
|
h323 h225 |
tcp |
N/A |
1720 |
||||||||||||
|
h323 ras |
udp |
N/A |
1718-1719 |
||||||||||||
|
http |
tcp |
N/A |
80 |
||||||||||||
|
icmp |
icmp |
N/A |
N/A |
||||||||||||
|
ils |
tcp |
N/A |
389 |
||||||||||||
|
mgcp |
udp |
2427,2727 |
2427,2727 |
||||||||||||
|
netbios |
udp |
137-138 |
N/A |
||||||||||||
|
rpc |
udp |
111 |
111 |
||||||||||||
|
rsh |
tcp |
N/A |
514 |
||||||||||||
|
rtsp |
tcp |
N/A |
554 |
||||||||||||
|
sip |
tcp,udp |
N/A |
5060 |
||||||||||||
|
skinny |
tcp |
N/A |
2000 |
||||||||||||
|
smtp |
tcp |
N/A |
25 |
||||||||||||
|
sqlnet |
tcp |
N/A |
1521 |
||||||||||||
|
tftp |
udp |
N/A |
69 |
||||||||||||
|
xdmcp |
udp |
177 |
Keyword that specifies to match tunnel traffic.
|
Continue reading here: Show run service policy Command
Was this article helpful?