<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for your help. Mike in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588678#M205908</link>
    <description>&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Fri, 17 Oct 2014 17:51:19 GMT</pubDate>
    <dc:creator>burleyman</dc:creator>
    <dc:date>2014-10-17T17:51:19Z</dc:date>
    <item>
      <title>Help setting up Service policy for CX module</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588672#M205902</link>
      <description>&lt;P&gt;I want to setup a service policy rule to send traffic to the CX module. What would be the best setup for that? What interfaces? etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588672#M205902</guid>
      <dc:creator>burleyman</dc:creator>
      <dc:date>2019-03-12T04:56:55Z</dc:date>
    </item>
    <item>
      <title>Best practice is to redirect</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588673#M205903</link>
      <description>&lt;P&gt;Best practice is to redirect traffic to the CX via your global policy (class class-default).&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2014 20:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588673#M205903</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-16T20:00:20Z</dc:date>
    </item>
    <item>
      <title>Do I send all traffic through</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588674#M205904</link>
      <description>&lt;P&gt;Do I send all traffic through the CX or just some?&lt;/P&gt;&lt;P&gt;Which direction or both?&lt;/P&gt;&lt;P&gt;I did try to use the global policy and I had some issues with that. I will try again as maybe I missed something.&lt;/P&gt;&lt;P&gt;Also I need to make sure the ASA is not inspecting the HTTP traffic, correct?&lt;/P&gt;&lt;P&gt;Is there any other traffic that I should make sure the ASA does not inspect?&lt;/P&gt;&lt;P&gt;Will setting this up disrupt traffic?&lt;/P&gt;&lt;P&gt;Are there any step by steps for this? I could not seem to find any this about setting up the service policy specific to the traffic going to the CX module.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 14:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588674#M205904</guid>
      <dc:creator>burleyman</dc:creator>
      <dc:date>2014-10-17T14:53:28Z</dc:date>
    </item>
    <item>
      <title>The Quick Start Guide covers</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588675#M205905</link>
      <description>&lt;P&gt;The &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/cx/cx_qsg.html#wp49644"&gt;Quick Start Guide&lt;/A&gt; covers it briefly. The &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asacx/9-3/user/guide/b_User_Guide_for_ASA_CX_and_PRSM_9_3/prsm-ug-prep.html#task_9FB7BF809DCE491689756325F6DBD8E6"&gt;User&amp;nbsp;Guide&lt;/A&gt; goes into more detail and includes cli steps.&lt;/P&gt;&lt;P&gt;Ideally you'd send all traffic - that's part of the value of AVC, giving you visibility into and control over what's going on at the application level.&lt;/P&gt;&lt;P&gt;No, you should not inspect http&amp;nbsp;on the base ASA. Any other inspections should be OK to keep.&lt;/P&gt;&lt;P&gt;With a default policy set there should not be any traffic disruption. Based on what policy you may have configured, you may get the blocks, warnings, etc. the product is designed to offer.&lt;/P&gt;&lt;P&gt;Even so we always recommend testing in a lab environment first and introducing any such significant change as part of a coordinated and approved maintenance window so that the possibility of service-affecting outage is taken into account.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 15:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588675#M205905</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-17T15:29:45Z</dc:date>
    </item>
    <item>
      <title>Thank you for your help...so</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588676#M205906</link>
      <description>&lt;P&gt;Thank you for your help...so based on all this see if this is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current Config&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;********************************&lt;BR /&gt;Make these changes&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class class-default&lt;BR /&gt;cxsc fail-open&lt;/P&gt;&lt;P&gt;*****************************&lt;/P&gt;&lt;P&gt;Result&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; cxsc fail-open&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's it? I actually had found that but it seemed to easy so I did not think that was it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 16:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588676#M205906</guid>
      <dc:creator>burleyman</dc:creator>
      <dc:date>2014-10-17T16:03:25Z</dc:date>
    </item>
    <item>
      <title>Yes, that's all it takes to</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588677#M205907</link>
      <description>&lt;P&gt;Yes, that's all it takes to redirect the flows through the ASA into the CX module.&lt;/P&gt;&lt;P&gt;When you modify the policy-map the parser will actually put the class-default at the end of that configuration section instead of in the beginning as you showed in your reply.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 17:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588677#M205907</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-17T17:14:27Z</dc:date>
    </item>
    <item>
      <title>Thanks for your help. Mike</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588678#M205908</link>
      <description>&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 17:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588678#M205908</guid>
      <dc:creator>burleyman</dc:creator>
      <dc:date>2014-10-17T17:51:19Z</dc:date>
    </item>
    <item>
      <title>You're welcome. Thanks for</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588679#M205909</link>
      <description>&lt;P&gt;You're welcome. Thanks for the ratings.&lt;/P&gt;&lt;P&gt;I was thinking about&amp;nbsp;your question about impact. If you don't have a lab to work in ahead of time you can selectively choose to redirect only a single host or subnet to the CX module by defining it with an ACL and then trying out only that subset of your traffic in the CX policy regime.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 18:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588679#M205909</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-10-17T18:45:40Z</dc:date>
    </item>
    <item>
      <title>Thanks for the info. I am</title>
      <link>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588680#M205912</link>
      <description>&lt;P&gt;Thanks for the info. I am going to do it on site early so I should be good to test and roll back as needed.&lt;/P&gt;&lt;P&gt;Thanks and have a great weekend.&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 19:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-setting-up-service-policy-for-cx-module/m-p/2588680#M205912</guid>
      <dc:creator>burleyman</dc:creator>
      <dc:date>2014-10-17T19:13:29Z</dc:date>
    </item>
  </channel>
</rss>

