32-10
Cisco ASA Series Firewall CLI Configuration Guide
Chapter32 Configuring the ASA CSC Module
Configuring the CSC SSM
What to Do Next
See the “Diverting Traffic to the CSC SSM” section on page32-10.
Diverting Traffic to the CSC SSM
You use Modular Policy Framework commands to configure the ASA to divert traffic to the CSC SSM.
Prerequisites
Before configuring the ASA to divert traffic to the CSC SSM, see Chapter1, “Configuring a Service
Policy Using the Modular Policy Framework,” which introduces Modular Policy Framework concepts
and common commands.
To configure the ASA to divert traffic to the CSC SSM, perform the following steps:
Detailed Steps
Command Purpose
Step1 access-list extended
Example:
ciscoasa(config)# access-list extended
Creates an ACL that matches the traffic you want
scanned by the CSC SSM. Create as many ACEs as
are needed to match all the traffic. For example, to
specify FTP, HTTP/HTTPS, POP3, and SMTP
traffic, you need four ACEs. For guidance on
identifying the traffic that you want to scan, see the
“Determining What Traffic to Scan” section on
page 32-3.
Step2 class-map class_map_name
Example:
ciscoasa(config)# class-map class_map_name
Creates a class map to identify the traffic that should
be diverted to the CSC SSM. The class_map_name
argument is the name of the traffic class. When you
enter the class-map command, the CLI enters class
map configuration mode.
Step3 match access-list acl-name
Example:
ciscoasa(config-cmap)# match access-list acl-name
Identifies the traffic to be scanned with the ACL that
you created in Step 1. The acl-name argument is the
name of the ACL.
Step4 policy-map policy_map_name
Example:
ciscoasa(config-cmap)# policy-map policy_map_name
Creates a policy map or modify an existing policy
map that you want to use to send traffic to the CSC
SSM. The policy_map_name argument is the name
of the policy map. When you enter the policy-map
command, the CLI enters policy map configuration
mode.
Step5 class class_map_name
Example:
ciscoasa(config-pmap)# class class_map_name
Specifies the class map, created in Step 2, that
identifies the traffic to be scanned. The
class_map_name argument is the name of the class
map that you created in Step 2. The CLI enters the
policy map class configuration mode.