Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
24-40
Cisco ASDM User Guide
OL-16647-01
Chapter 24 Configuring Application Layer Protocol Inspection
Class Map Field Descriptions
Add/Edit DNS Traffic Class Map
The Add/Edit DNS Traffic Class Map dialog box lets you define a DNS class map.
Fields
Name—Enter the name of the DNS class map, up to 40 characters in length.
Description—Enter the description of the DNS class map.
Add—Adds a DNS class map.
Edit—Edits a DNS class map.
Delete—Deletes a DNS class map.
Modes
The following table shows the modes in which this feature is available:
Add/Edit DNS Match Criterion
The Add/Edit DNS Match Criterion dialog box lets you define the match criterion and value for the DNS
class map.
Fields
Match Type—Specifies whether the class map includes traffic that matches the criterion, or traffic
that does not match the criterion.
For example, if No Match is selected on the string “example.com,” then any traffic that contains
“example.com” is excluded from the class map.
Criterion—Specifies which criterion of DNS traffic to match.
Header Flag—Match a DNS flag in the header.
Type—Match a DNS query or resource record type.
Class—Match a DNS query or resource record class.
Question—Match a DNS question.
Resource Record—Match a DNS resource record.
Domain Name—Match a domain name from a DNS query or resource record.
Header Flag Criterion Values—Specifies the value details for the DNS header flag match.
Match Option—Specifies either an exact match or match all bits (bit mask match).
Match Value—Specifies to match either the header flag name or the header flag value.
Header Flag Name—Lets you select one or more header flag names to match, including AA
(authoritative answer), QR (query), RA (recursion available), RD (recursion denied), TC
(truncation) flag bits.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
• • • •