17-32
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 17 Managing Firewall Inspection Rules
Configuring Protocols and Maps for Inspection
When creating a DNS policy map, in the Policy Object Manager, from the Match Condition and Action
tab on the Add and Edit DNS Map dialog boxes, right-click inside the table, then select Add Row or
right-click a row, then select Edit Row. See Configuring DNS Maps, page 17-28.
Related Topics
Understanding Map Objects, page 6-72
Configuring Protocols and Maps for Inspection, page 17-21
Field Reference
Table17-16 DNS Class and Policy Maps Add and Edit Match Condition and Action Dialog Boxes
Element Description
Match Type
Class Name
(Policy Map only)
Enables you to use an existing DNS class map or define a new DNS
class map.
Use Specified Values—You want to define the class map on this
dialog box.
Use Values in Class Map—You want to select an existing DNS
class map policy object. Enter the name of the DNS class map in
the Class Name field. Click Select to select the map from a list or
to create a new class map object.
Criterion Specifies which criterion of traffic to match:
DNS Class—Matches a DNS query or resource record class.
DNS Type—Matches a DNS query or resource record type.
Domain Name—Matches a domain name from a DNS query or
resource record.
Header Flag—Matches a DNS flag in the header.
Question—Matches a DNS question.
Resource Record—Matches a DNS resource record.
Type Specifies whether the map includes traffic that matches or does not
match the criterion. For example, if Doesn’t Match is selected on the
string “example.com,” then any traffic that contains “example.com” is
excluded from the map.
Matches—Matches the criterion.
Doesn’t Match—Does not match the criterion.
Action
(Policy Map only)
The action you want the device to take for traffic that matches the
defined criteria.
Var iab le F iel ds
The following fields vary based on what you select in the Criterion field. This list is a super-set of the
fields you might see.
Val ue
(for DNS Class criterion)
The DNS class you want to inspect:
Internet—Matches the Internet DNS class.
DNS Class Field Value—Matches the specified number.
DNS Class Field Range—Matches the specified range of numbers.