Cisco Cisco ASA for Nexus 1000V Series Switch 기술 매뉴얼

다운로드
페이지 30
 
13
XML Examples for the Cisco Application Centric Infrastructure Security Device Package, Version 1.2(5)
 
  Static Route
Static Route
This XML example sets up the static route configuration that is associated with an existing interface.
ASA Configuration
route internalIf 10.100.0.0 255.255.0.0 10.6.55.1 1
XML Example
<polUni>
<fvTenant name="tenant1">
  
<vnsAbsGraph name = "WebGraph">
<vnsAbsNode name = "FW1">
<vnsAbsDevCfg>
   <vnsAbsFolder key="Interface" name="internalIf">
<vnsAbsFolder key="StaticRoute" name="InsideRTE1">
<vnsAbsFolder key="route" name="RouteIN1">
<vnsAbsParam key="network" name="network1" value="10.100.0.0"/>
<vnsAbsParam key="netmask" name="netmask1" value="255.255.0.0"/>
<vnsAbsParam key="gateway" name="gateway1" value="10.6.55.1"/>
<vnsAbsParam key="metric" name="metric1" value="1"/>
</vnsAbsFolder>
</vnsAbsFolder>
</vnsAbsFolder>
</vnsAbsDevCfg>
</vnsAbsNode>
  
</vnsAbsGraph>
 </fvTenant>
</polUni>
Basic Threat Detection
This XML example sets up a basic threat detection rate for an ACL drop.
ASA Configuration
threat-detection rate acl-drop rate-interval 600 average-rate 0 burst-rate 0
XML Example
<polUni>
    <fvTenant name="tenant1">
        <vnsLDevVip name="Firewall">
                  <vnsDevFolder key="BasicThreatDetection" name="BasicTD">
                    <vnsDevParam key="basic_threat" name="Basic1" value="enable"/>
                    <vnsDevFolder key="BasicThreatDetectionRateAclDrop" name="BasicTDACL">
                        <vnsDevParam key="rate_interval" name="ri1" value="600"/>
                        <vnsDevParam key="average_rate" name="ar1" value="0"/>
                        <vnsDevParam key="burst_rate" name="br1" value="0"/>
                    </vnsDevFolder>