Servicepolicy Applies policy to an interface or globally

© 2005 Cisco Systems, Inc. All rights reserved. SNPA V4.0—10-14

To filter FTP commands, you must follow four steps. First, define in the ftp-map command which FTP commands you want to filter. Second, identify a traffic flow in the class-map command. Third, configure a policy that associates the FTP commands that are to be filtered (the ftp-map command) with the traffic flow that is identified in the class- map. And finally, use a service policy to enable the policy on an interface or on a global basis.

Cisco com

request-command deny Command

1 Uscu.com 1

Client n. r^fc- , 1 ,

FTP

Server

fw1 (config-ftp-map)#

help | mkd | put | rmd | rnfr | rnto | site | stou }

• Defines an FTP map name

• Identifies denied FTP request commands

fw1(config)# ftp-map inbound ftp fw1(config-ftp-map)# request-cmd deny dele rnfr rnto appe

put rmd

© 2005 Cisc

o Systems, Inc. All rights reserved.

SNPA v4.0

—10-15

To use the ftp-map command to define which FTP commands are to be blocked, follow these steps. Enter the ftp-map command and a map name; the system enters FTP map configuration mode. Use the request-cmd deny command to list which FTP request commands should be blocked. In the example in the figure, the inbound_ftp FTP map was defined. The inbound_ftp FTP map identifies six commands to be filtered: dele, rnfr, rnto, appe, put, and rmd. After an FTP map is configured, define a class map and a policy map, then apply the policy with a service policy.

The syntax for the ftp-map command is as follows:

ftp-map [map name]

map_name

The name of the FTP map.

Client

FTP Traffic

Define which FTP request commands to deny Identify traffic flow Define policy map

- Class map: Identify a traffic flow

- Associate FTP command filtering (FTP map) with traffic flow (class map) Apply policy to an interface a FTP Server fw1(config)# ftp-map inbound ftp fw1(config-ftp-map)# request-cmd deny dele rnfr rnto appe put rmd fwl(config)# access-list 101 permit TCP any host 192.168.1.11 eq ftp fwl(config)# class-map inbound ftp traffic fw1(config-ftp-map)# match access-list 101 fw1(config-ftp-map)# exit fw1(config)# policy-map inbound fw1(config-pmap)# class inbound ftp traffic fw1(config-pmap-c)# inspect ftp strict inbound ftp fw1(config-pmap-c)# exit fw1(config-pmap)# exit fw1(config)# service-policy inbound outside

© 2005 Cisco Systems, Inc. All rights reserved. SNPA v4.0—10-16

To deny FTP request commands, you must configure an FTP map, define a class map and a policy map, and apply the policy to an interface. The FTP map defines which FTP request commands should be blocked. The class map identifies a flow of traffic. The policy map associates the FTP map with a defined flow of traffic. The service policy enables the policy globally or on a specific interface. In the example in the figure, the inbound_ftp FTP map identifies six FTP request commands to filter. The inbound_ftp class of traffic matches traffic defined by ACL 101 (FTP traffic between any host and host 192.168.1.11, the FTP server). In the inbound policy map, the FTP command request restrictions defined in the inbound_ftp FTP map are associated with the inbound_ftp_traffic class of traffic. And finally, the inbound policy is enabled on the outside interface.

+1 0

Post a comment