Chapter9 Firewall Policy
Edit Firewall Policy
9-24
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
For example, to create a new policy map for Instant Messaging, check the box
next to IM, click the button next to the IM field, and choose Create. Then, create
the policy map in the Configure Deep Packet Inspection dialog.
URL Filter
Add an URL filter by choosing an existing URL filter from the URL Filter Name
list, or by clicking Create New and making a new URL filter in the dialogs
displayed. the settings for the URL filter that you chose or created are summarized
in this dialog.
Quality of Service
You can drop traffic that exceeds a specified rate per second, the police rate, and
drop traffic that exceeds a specified burst value. The police rate can be a value
between 8,000 and 2,000,000,000 bits per second. The bur st rate can be a value
between 1,000 and 512,000,000 bytes.
Inspect Parameter
Specify an existing parameter map in the Inspect Parameter window by choosing
a parameter map in the Inspect Parameter Map list, or click Create New to create
a new parameter map to apply to the rule for the policy you a re modifying. The
details of the parameter map that you specify are displayed i n the Preview box.
To learn about parameter maps, click Timeouts and Thresholds for Inspect
Parameter Maps and CBAC.
Select Traffic
Select a class map that specifies the traffic that you want to add to the policy. To
view more information about a particular class map, select the class map and click
View Details.
When you click OK, the Add a New Rule dialog is displayed, with the
information in the class map that you chose. You can make additional changes to
the class map or leave it unchanged. If you do make changes, you can change the
name of the class map if you do not want your changes to ap ply to other policies
that use the original class map.