Configuring the Application and Application Set (NSM Procedure)
You can define application protocols for the stateful
firewall and Network Address Translation (NAT) services to use in
match condition rules. An application protocol, or application layer
gateway (ALG), defines application parameters using information from
network Layer 3 and above. You can configure properties of an application
and whether to include it in an application set using the application
option. You can configure one or more applications to include in an
application set using the application set option.
To configure an application set in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Applications.
- Add or modify settings as specified in Table 1.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
 |
Note:
Application and application set are configurable, only
if the device is in the in-device policy mode.
|
Table 1: Applications Configuration
Details
| Task |
Your Action |
Configure properties of an application and whether to
include it in an application set.
|
- Click Application next to Applications.
- Click Add new entry next to Application.
- In the Name box, enter the identifier
of the application.
- In the Comment box, enter the comment.
- From the Application Protocol list,
select the name of the protocol.
- From the Protocol list, select the
networking protocol type.
- From the Source Port list, select
the identifier for the port.
- From the Destination Port list, select
the Identifier for the port.
- From the Snmp Command list, select
the SNMP command format.
- From the Icmp Type list, select the
ICMP packet type value.
- From the Icmp Code list, select the
Internet Control Message Protocol (ICMP) code value.
- From the Ttl Threshold list, select
the TTL threshold value.
- In the Rpc Program number box, enter
the Remote procedure call (RPC) or Distributed Computing Environment
(DCE) value.
Range: 100,000 through 400,000
- In the Uuid box, enter the Universal
Unique Identifier (UUID) for DCE RPC objects.
- From the Inactivity Timeout list,
select the length of time the application is inactive before it times
out.
- Select the Learn Sip Register check
box to activate SIP register to accept potential incoming SIP calls.
- From the Sip Call Hold Timeout list
select the length of time the application holds a SIP call open before
it times out.
Default: 7200 seconds
Range: 0 through 36,000 seconds (10 hours)
- Select one of the following:
- do-not-translate-AAAA-query-to-A-query—To control the translation of AAAA query to A query.
- do-not-translate-A-query-to-AAAA—To
control the translation of A query to AAAA query.
|
Configuring application sets.
|
- Click Application Set next to Applications.
- Click Add new entry next to Application
Set.
- Expand application-set.
- In the Name box, enter the identifier
of an application set.
- In the Comment box, enter the comment.
- Click Application next to application-set.
- Click Add new entry next to Application.
- From the Name list, select the identifier
of the application.
- In the Comment box, enter the comment.
|
Published: 2009-08-23