Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

No class inspection_default on 5505?

I was under the impression that all Cisco ASA firewalls shipped with a default inspection policy.

Example

policy-map global_policy

class inspection_default

  inspect dns preset_dns_map

  inspect ftp

  inspect h323 h225

  inspect h323 ras

  inspect rsh

  inspect rtsp

  inspect esmtp

  inspect sqlnet

  inspect skinny 

  inspect sunrpc

  inspect xdmcp

  inspect sip 

  inspect netbios

  inspect tftp

  inspect ip-options

  inspect http

  inspect ipsec-pass-thru

However, looking at a 5505 I have here, there is NO default inspection policy defined. If I try to add

policy-map global_policy

class inspection_default

It tells me there is no class inspection_default

can I build this myself? Why is it missing (I have two other ASA 5505s here that also do not have it). What would I do to rebuild it?

Everyone's tags (1)
3 REPLIES
New Member

No class inspection_default on 5505?

Ah, nevermind: figured out what the issue was

you need the

class-map inspection_default
 match default-inspection-traffic
Cisco Employee

No class inspection_default on 5505?

Hello Collin,

When there is no inspection default, you can also add "Clear config fixup" and the default policy will appear.

Mike

Mike
New Member

clear config fixup is a nifty

clear config fixup is a nifty trick.

 

Thank you!

1739
Views
0
Helpful
3
Replies