Cisco Cisco ASA 5555-X Adaptive Security Appliance - No Payload Encryption 기술 매뉴얼

다운로드
페이지 32
 
8
XML Examples for the Cisco Application Centric Infrastructure Security Device Package, Version 1.2(7)
 
  Interfaces
XML Example 
Define the port channel members, graph, then attach them to the tenant.
<polUni>
    <fvTenant dn="uni/tn-tenant1" name="tenant1">
      <vnsLDevVip name="Firewall" funcType="GoTo" devtype="PHYSICAL">
        <vnsRsMDevAtt tDn="uni/infra/mDev-CISCO-ASA-{dp_version}"/>
         <vnsRsALDevToPhysDomP tDn="uni/phys-phys"/>
          <vnsCMgmt name="devMgmt" host="10.122.202.33" port="443" />
            <vnsCCred name="username" value="management-user"/>
            <vnsCCredSecret name="password"  value="cisco"/>
        <vnsDevFolder key="PortChannelMember" name="PC1a">
          <vnsDevParam key="port_channel_id" name="PC1a" value="1"/>
          <vnsDevParam key="interface" name="PC1a" value="Gig0/1"/>
        </vnsDevFolder>
        <vnsDevFolder key="PortChannelMember" name="PC2a">
          <vnsDevParam key="port_channel_id" name="PC2a" value="2"/>
          <vnsDevParam key="interface" name="PC2a" value="Gig0/0"/>
        </vnsDevFolder>
        </vnsLDevVip>
        <vnsLDevCtx ctrctNameOrLbl="webCtrct" graphNameOrLbl="WebGraph" nodeNameOrLbl="FW1">
            <vnsRsLDevCtxToLDev tDn="uni/tn-tenant1/lDevVip-Firewall"/>
            <vnsLIfCtx connNameOrLbl="internal">
                <vnsRsLIfCtxToBD tDn= "uni/tn-tenant1/BD-tenant1BD1"/>
                <vnsRsLIfCtxToLIf tDn="uni/tn-tenant1/lDevVip-Firewall/lIf-internalPC"/>
            </vnsLIfCtx>
            <vnsLIfCtx connNameOrLbl="external">
               <vnsRsLIfCtxToLIf tDn="uni/tn-tenant1/lDevVip-Firewall/lIf-externalPC"/>
                <vnsRsLIfCtxToBD tDn= "uni/tn-tenant1/BD-tenant1BD2"/>
            </vnsLIfCtx>
        </vnsLDevCtx>
    </fvTenant>
</polUni>
<polUni>
    <fvTenant name="tenant1">
    <vnsAbsGraph name = "WebGraph">
    <vnsAbsTermNodeCon name = "Input1">
        <vnsAbsTermConn name = "C1">
        </vnsAbsTermConn>
    </vnsAbsTermNodeCon>
    <!-- FW1 Provides FW functionality -->
    <vnsAbsNode name = "FW1">
        <vnsRsDefaultScopeToTerm tDn="uni/tn-tenant1/AbsGraph-WebGraph/AbsTermNodeProv-Output1/outtmnl"/>
        <vnsAbsFuncConn name = "external" attNotify="yes">
            <vnsRsMConnAtt tDn="uni/infra/mDev-CISCO-ASA-{dp_version}/mFunc-Firewall/mConn-external" />
        </vnsAbsFuncConn>
        <vnsAbsFuncConn name = "internal" attNotify="yes">
            <vnsRsMConnAtt tDn="uni/infra/mDev-CISCO-ASA-{dp_version}/mFunc-Firewall/mConn-internal" />
        </vnsAbsFuncConn>
        
        <vnsAbsDevCfg>
           <vnsAbsFolder key="Interface" name="internalIf">
            <vnsAbsFolder key="InterfaceConfig" name="internalIfCfg">
                <vnsAbsFolder key="IPv4Address" name="internalIfIP">
                    <vnsAbsParam key="ipv4_address" name="ipv4_internal" value="10.10.10.10/255.255.255.0"/>