17-29
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter17 Managing Firewall Inspection Rules
Configuring Protocols and Maps for Inspection
Navigation Path
Select Manage > Policy Objects, then select Maps > Policy Maps > Inspect > DNS from the Object
Type selector. Right-click inside the work area, then select New Object or right-click a row and select
Edit Object.
Related Topics
Understanding Map Objects, page 6-72
Configuring Protocols and Maps for Inspection, page 17-21
Configuring Class Maps for Inspection Policies, page 17-26
Field Reference
Table17-13 Add and Edit DNS Map Dialog Boxes
Element Description
Name The name of the policy object. A maximum of 40 characters is allowed.
Description A description of the policy object. A maximum of 200 characters is
allowed.
Protocol Conformance Tab
Defines DNS security settings and actions. For a description of the options on this tab, see DNS Map
Protocol Conformance Tab, page17-30.
Filtering Tab
Defines the filtering settings for DNS. For a description of the options on this tab, see DNS Map
Filtering Tab, page17-30.
Mismatch Rate Tab
The Log When DNS ID Mismatch Rate Exceeds option determines whether you want to report
excessive instances of DNS identifier mismatches based on the following criteria:
Threshold—The maximum number of mismatch instances before a system message log is sent.
Values are 0 to 4294967295.
Time Interval—The time period to monitor (in seconds). Values are 1 to 31536000.
Match Condition and Action Tab
The Match All table lists the criteria included in the policy map. Each row indicates whether the
inspection is looking for traffic that matches or does not match each criterion, the criterion and value
that is inspected, and the action to be taken for traffic that satisfies the conditions.
To add a criterion, click the Add button and fill in the Match Condition and Action dialog box (see
DNS Class and Policy Maps Add or Edit Match Condition (and Action) Dialog Boxes,
page 17-31).
To edit a criterion, select it and click the Edit button.
To delete a criterion, select it and click the Delete button.
Category The category assigned to the object. Categories help you organize and
identify rules and objects. See Using Category Objects, page 6-12.