Configuration examples for the asa cx module – Cisco ASA 5505 User Manual

Page 1267

Advertising
background image

59-21

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 59 Configuring the ASA CX Module

Configuration Examples for the ASA CX Module

src ip/id=0.0.0.0, mask=0.0.0.0, port=0

dst ip/id=192.168.0.100, mask=255.255.255.255, port=2000, dscp=0x0

input_ifc=inside, output_ifc=identity

3.

In the packet captures, the redirect request should be going to destination port 2000.

Configuration Examples for the ASA CX Module

The following example diverts all HTTP traffic to the ASA CX module, and blocks all HTTP traffic if
the ASA CX module card fails for any reason:

hostname(config)# access-list ASACX permit tcp any any eq port 80

hostname(config)# class-map my-cx-class

hostname(config-cmap)# match access-list ASACX

hostname(config-cmap)# policy-map my-cx-policy

hostname(config-pmap)# class my-cx-class

hostname(config-pmap-c)# cxsc fail-close auth-proxy

hostname(config-pmap-c)# service-policy my-cx-policy global

The following example diverts all IP traffic destined for the 10.1.1.0 network and the 10.2.1.0 network
to the ASA CX module, and allows all traffic through if the ASA CX module fails for any reason.

hostname(config)# access-list my-cx-acl permit ip any 10.1.1.0 255.255.255.0

hostname(config)# access-list my-cx-acl2 permit ip any 10.2.1.0 255.255.255.0

hostname(config)# class-map my-cx-class

hostname(config-cmap)# match access-list my-cx-acl

hostname(config)# class-map my-cx-class2

hostname(config-cmap)# match access-list my-cx-acl2

hostname(config-cmap)# policy-map my-cx-policy

hostname(config-pmap)# class my-cx-class

hostname(config-pmap-c)# cxsc fail-open auth-proxy

hostname(config-pmap)# class my-cx-class2

hostname(config-pmap-c)# cxsc fail-open auth-proxy

hostname(config-pmap-c)# service-policy my-cx-policy interface outside

Advertising