Contents
ix
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
OL-6392-01
Simplifying Access Control Lists with Object Grouping 10-18
How Object Grouping Works 10-18
Adding Object Groups 10-19
Adding a Protocol Object Group 10-19
Adding a Network Object Group 10-20
Adding a Service Object Group 10-20
Adding an ICMP Type Object Group 10-21
Nesting Object Groups 10-22
Using Object Groups with an Access Control List 10-23
Displaying Object Groups 10-24
Removing Object Groups 10-24
Manually Committing Access Control Lists and Rules 10-24
Adding Remarks to Access Control Lists 10-25
Logging Extended Access Control List Activity 10-26
Access Control List Logging Overview 10-26
Configuring Logging for an Access Control Entry 10-27
Managing Deny Flows 10-28
CHAPTER
11 Allowing Remote Management 11-1
Allowing Telnet 11-1
Allowing SSH 11-2
Configuring SSH Access 11-3
Using an SSH Client 11-4
Allowing HTTPS for PDM 11-4
Allowing a VPN Management Connection 11-5
Configuring Basic Settings for All Tunnels 11-5
Configuring VPN Client Access 11-7
Configuring a Site-to-Site Tunnel 11-9
Allowing ICMP to and from the FWSM 11-10
CHAPTER
12 Configuring AAA 12-1
AAA Overview 12-1
AAA Performance 12-2
About Authentication 12-2
About Authorization 12-2
About Accounting 12-3
AAA Server and Local Database Support 12-4
Configuring the Local Database 12-6