Cisco Cisco ASA 5580 Adaptive Security Appliance Technical Manual

Page of 26
 
13
XML Examples for the Cisco Application Centric Infrastructure Security Device Package, Version 1.2(3)
 
  Static Route
Static Route
This XML example sets up the static route configuration that is associated with an existing interface.
ASA Configuration
route internalIf 10.100.0.0 255.255.0.0 10.6.55.1 1
XML Example
<polUni>
<fvTenant name="tenant1">
  
<vnsAbsGraph name = "WebGraph">
<vnsAbsNode name = "FW1">
<vnsAbsDevCfg>
   <vnsAbsFolder key="Interface" name="internalIf">
<vnsAbsFolder key="StaticRoute" name="InsideRTE1">
<vnsAbsFolder key="route" name="RouteIN1">
<vnsAbsParam key="network" name="network1" value="10.100.0.0"/>
<vnsAbsParam key="netmask" name="netmask1" value="255.255.0.0"/>
<vnsAbsParam key="gateway" name="gateway1" value="10.6.55.1"/>
<vnsAbsParam key="metric" name="metric1" value="1"/>
</vnsAbsFolder>
</vnsAbsFolder>
</vnsAbsFolder>
</vnsAbsDevCfg>
</vnsAbsNode>
  
</vnsAbsGraph>
 </fvTenant>
</polUni>
Basic Threat Detection
This XML example sets up a basic threat detection rate for an ACL drop.
ASA Configuration
threat-detection rate acl-drop rate-interval 600 average-rate 0 burst-rate 0
XML Example
<polUni>
    <fvTenant name="tenant1">
        <vnsLDevVip name="Firewall">
                  <vnsDevFolder key="BasicThreatDetection" name="BasicTD">
                    <vnsDevParam key="basic_threat" name="Basic1" value="enable"/>
                    <vnsDevFolder key="BasicThreatDetectionRateAclDrop" name="BasicTDACL">
                        <vnsDevParam key="rate_interval" name="ri1" value="600"/>
                        <vnsDevParam key="average_rate" name="ar1" value="0"/>
                        <vnsDevParam key="burst_rate" name="br1" value="0"/>
                    </vnsDevFolder>