21-34
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 21 Managing Zone-based Firewall Rules
Configuring Inspection Maps for Zone-based Firewall Policies
Related Topics
Understanding Map Objects, page 6-72
Configuring Inspection Maps for Zone-based Firewall Policies, page21-15
Configuring Content Filtering Maps for Zone-based Firewall Policies, page21-35
Understanding the Zone-based Firewall Rules, page 21-3
Field Reference
Add or Edit Match Condition and Action Dialog Boxes for Zone-Based Firewall and Web Filter Policies
Use the Add or Edit Match Condition and Action dialog boxes for zone-based firewall and web filter
policies to select the class maps for inspection and to define the action to take for traffic that matches
the class. This dialog box is used for the following types of policy maps: H.323 (IOS), HTTP (Zone
based IOS), IM (Zone based IOS), IMAP, P2P, POP3, SIP (IOS), SMTP, Sun RPC, Web Filter.
The fields on this dialog box differ slightly depending on the type of policy map you are defining.
Navigation Path
From the Add or Edit Policy Maps dialog boxes for Zone-Based Firewall Policies, right-click inside the
match table and select Add Row or right-click a row and select Edit Row. See Configuring Policy Maps
for Zone-Based Firewall Policies, page 21-33.
Table21-11 Add or Edit Policy Maps Dialog Boxes for Zone-Based Firewall Policies
Element Description
Name The name of the policy object. A maximum of 40 characters is allowed.
Description A description of the policy object. A maximum of 200 characters is
allowed.
Match All table The Match All table lists class maps included in the policy map, and the
action to take for traffic that matches the class. For traffic to match this
class, all criteria defined in the selected class maps must be met.
To add a criterion, click the Add button and fill in the Match
Condition and Action dialog box (see Add or Edit Match Condition
and Action Dialog Boxes for Zone-Based Firewall and Web Filter
Policies, page 21-34).
To edit a criterion, select it and click the Edit button.
To delete a criterion, select it and click the Delete button.
Category The category assigned to the object. Categories help you organize and
identify rules and objects. See Using Category Objects, page 6-12.
Allow Value Override per
Device
Overrides
Edit button
Whether to allow the object definition to be changed at the device level.
For more information, see Allowing a Policy Object to Be Overridden,
page 6-18 and Understanding Policy Object Overrides for Individual
Devices, page 6-17.
If you allow device overrides, you can click the Edit button to create,
edit, and view the overrides. The Overrides field indicates the number
of devices that have overrides for this object.