36-14
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter36 Configuring a Service Policy
Managing the Order of Service Policy Rules
Specify the address and subnet mask using prefix/length notation, such as 10.1.1.0/24. If you
enter an IP address without a mask, it is considered to be a host address, even if it ends with a 0.
Enter any to specify any destination address.
Separate multiple addresses by a comma.
d. In the Service field, enter an IP service name or number for the destination service, or click the
... button to choose a service.
If you want to specify a TCP or UDP port number, or an ICMP service number, enter
protocol/port. For example, enter TCP/8080.
By default, the service is IP.
Separate multiple services by a comma.
e. (Optional) Enter a description in the Description field.
f. (Optional) To specify a source service for TCP or UDP, click the More Options area open, and
enter a TCP or UDP service in the Source Service field.
The destination service and source service must be the same. Copy and paste the destination
Service field to the Source Service field.
g. (Optional) To make the rule inactive, click the More Options area open, and uncheck Enable
Rule.
This setting might be useful if you do not want to remove the rule, but want to turn it off.
h. (Optional) To set a time range for the rule, click the More Options area open, and from the Time
Range drop-down list, choose a time range.
To add a new time range, click the ... button. See the “Configuring Time Ranges” section on
page 20-15 for more information.
This setting might be useful if you only want the rule to be active at predefined times.
Destination Port—Click TCP or UDP.
In the Service field, enter a port number or name, or click ... to choose one already defined in ASDM.
Step8 Click Next.
The Add Management Service Policy Rule - Rule Actions dialog box appears.
Step9 To configure RADIUS accounting inspection, choose an inspect map from the RADIUS Accounting
Map drop-down list, or click Configure to add a map.
See the “Supported Features for Management Traffic” section on page36-2 for more information.
Step10 To configure connection settings, see the “Configuring Connection Settings” section on page57-8.
Step11 Click Finish.
Managing the Order of Service Policy Rules
The order of service policy rules on an interface or in the global policy affects how actions are applied
to traffic. See the following guidelines for how a packet matches rules in a service policy:
A packet can match only one rule in a service policy for each feature type.
When the packet matches a rule that includes actions for a feature type, the ASA does not attempt
to match it to any subsequent rules including that feature type.