Chapter9 Firewall Policy
Edit Firewall Policy
9-18
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Expanding and Collapsing the Display of a Policy
Adding a New Rule to a Policy
Adding a New Zone Policy
Reordering Rules Within a Policy
Copying and Pasting a Rule
Displaying the Rule Flow Diagram
Applying Your Changes
Discarding Your Changes
Things You Must do Before Viewing Information in this Window
This window is empty if no zone, zone-pairs, or policy maps have been
configured. Create a basic configuration containing these elements by going to
Configure > Firewall and ACL > Create Firewall and completing the Advanced
Firewall wizard. After you have done this, you can create additional zones, zone
pairs and policies as needed by going to Configure > Additional Tasks > Zo nes
to configure zones, and to Additional Task s > Zone Pairs to configure additional
zone pairs.
To create the policy maps that the zone pairs are to use, go to Configure >
Additional Task s > C3PL. Click the Policy Map branch to displ ay additional
branches which enable you to create policy maps and the class maps that define
traffic for the policy maps.
Expanding and Collapsing the Display of a Policy
When the display of a policy is collapsed, only the policy name and the source and
destination zones are displayed. To expand the display of the policy to show the
rules that make up the policy, click the + button to the left of the policy name. An
expanded view of a firewall policy might look similar to the following:
Traffic Classification Action Rule Options
ID Source Destination Service
clients-servers-policy (clients to servers)
1 any any tcp Permit Firewall