Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

AIP-SSM outside inside dmz

hi

I'm reviewing the situation next three traffic zones outside, inside, DMZ,

service-policy xxxx-policy interface outside

service-policy xxxx-policy interface inside

service-policy xxxx-policy interface dmz_stgo

and I need to lower the level of examination but only in one area, which is the area inside,

such outside high-DMZ

DMZ-outside high

inside low-DMZ

2 REPLIES
Gold

Re: AIP-SSM outside inside dmz

Please give us some additional detail on whatyou mean by "lower the level of examination" on one of your interfaces. Did you want to apply a subset of the signatures? (then you'd go down the virtual sensor path) Or, did you want to filter the IP addresses/port reaching the sensor on that interface? (then you'd adjust the class-map ACL)

New Member

Re: AIP-SSM outside inside dmz

ok I have a situation where some companies want to change but the signatures are applied only to traffic from inside to DMZ

and the class-map

access-list xxxx permit ip any any

148
Views
0
Helpful
2
Replies