EasyManuals Logo

Cisco ASA Series User Manual

Cisco ASA Series
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1417 background imageLoading...
Page #1417 background image
1-11
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the Botnet Traffic Filter
Configuring the Botnet Traffic Filter
Default DNS Inspection Configuration and Recommended Configuration
The default configuration for DNS inspection inspects all UDP DNS traffic on all interfaces, and does
not have DNS snooping enabled.
We suggest that you enable DNS snooping only on interfaces where external DNS requests are going.
Enabling DNS snooping on all UDP DNS traffic, including that going to an internal DNS server, creates
unnecessary load on the ASA.
For example, if the DNS server is on the outside interface, you should enable DNS inspection with
snooping for all UDP DNS traffic on the outside interface. See the “Examples” section for the
recommended commands for this configuration.
Detailed Steps
Command Purpose
Step 1
class-map name
Example:
hostname(config)# class-map
dynamic-filter_snoop_class
Creates a class map to identify the traffic for which you want to
inspect DNS.
Step 2
match parameters
Example:
hostname(config-cmap)# match port udp eq
domain
Specifies traffic for the class map. See the “Identifying Traffic
(Layer 3/4 Class Maps)” section on page 35-12 for more
information about available parameters. For example, you can
specify an access list for DNS traffic to and from certain
addresses, or you can specify all UDP DNS traffic.
Step 3
policy-map name
Example:
hostname(config)# policy-map
dynamic-filter_snoop_policy
Adds or edits a policy map so you can set the actions to take with
the class map traffic.
Step 4
class name
Example:
hostname(config-pmap)# class
dynamic-filter_snoop_class
Identifies the class map you created in Step 1.

Table of Contents

Other manuals for Cisco ASA Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA Series and is the answer not in the manual?

Cisco ASA Series Specifications

General IconGeneral
ModelASA 5505
InterfacesVaries by model (Fast Ethernet, Gigabit Ethernet, 10 Gigabit Ethernet, etc.)
High AvailabilityActive/Standby or Active/Active (varies by model)
Power SupplyVaries by model
Form FactorVaries by model
Operating SystemCisco ASA Software
IPsec VPNSupported
SSL VPNSupported
IPS ThroughputVaries by model

Related product manuals