Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
12-11
思科 ASA 系列命令参考,S 命令
第 12 章 show running-config 至 show switch vlan 命令
show service-policy
示例
以下是
show service-policy global 命令的输出示例:
ciscoasa# show service-policy global
Global policy:
Service-policy: inbound_policy
Class-map: ftp-port
Inspect: ftp strict inbound_ftp, packet 0, drop 0, reset-drop 0
以下是
show service-policy priority 命令的输出示例:
ciscoasa# show service-policy priority
Interface outside:
Global policy:
Service-policy: sa_global_fw_policy
Interface outside:
Service-policy: ramap
Class-map: clientmap
Priority:
Interface outside: aggregate drop 0, aggregate transmit 5207048
Class-map: udpmap
Priority:
Interface outside: aggregate drop 0, aggregate transmit 5207048
Class-map: cmap
以下是
show service-policy flow 命令的输出示例:
ciscoasa# show service-policy flow udp host 209.165.200.229 host 209.165.202.158 eq 5060
Global policy:
Service-policy: f1_global_fw_policy
Class-map: inspection_default
Match: default-inspection-traffic
Action:
Input flow: inspect sip
Interface outside:
Service-policy: test
Class-map: test
Match: access-list test
Access rule: permit ip 209.165.200.229 255.255.255.224 209.165.202.158
255.255.255.224
Action:
Input flow: ids inline
Input flow: set connection conn-max 10 embryonic-conn-max 20
以下是
show service-policy inspect http 命令的输出示例: 此示例展示 match-any 类映射中的每个
匹配命令的统计信息。
ciscoasa# show service-policy inspect http
Global policy:
Service-policy: global_policy
Class-map: inspection_default
Inspect: http http, packet 1916, drop 0, reset-drop 0
protocol violations
packet 0
class http_any (match-any)
Match: request method get, 638 packets
Match: request method put, 10 packets
Match: request method post, 0 packets