17-62
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 17 Managing Firewall Inspection Rules
Configuring Protocols and Maps for Inspection
Type Specifies whether the map includes traffic that matches or does not
match the criterion. For example, if Doesn’t Match is selected on the
string “example.com,” then any traffic that contains “example.com” is
excluded from the map.
Matches—Matches the criterion. For some criteria, this is the only
available option.
Doesn’t Match—Does not match the criterion.
Action
(Policy Map only)
The action you want the device to take for traffic that matches the
defined criteria. The types of action depend on the criterion you select.
Var iab le F iel ds
The following fields vary based on what you select in the Criterion field. This list is a super-set of the
fields you might see.
Field Name The name of the header field to evaluate. You can select one of the
following:
Predefined—The predefined HTTP header fields.
Regular Expression—The regular expression object that defines
the regular expression you want to use for pattern matching. Enter
the name of the object. You can click Select to choose the object
from a list of existing ones or to create a new regular expression
object.
Table17-36 HTTP Class and Policy Maps (ASA 7.2+/PIX 7.2+) Add and Edit Match Condition and
Action Dialog Boxes (Continued)
Element Description