En este documento se describe la configuración de NGFW, filtrado de URL, AMP e IPS/IDS mediante grupos de configuración, incluidas instrucciones para el registro unificado.
Habilitar visibilidad del flujo y de las aplicaciones
Si utiliza grupos de directivas para definir directivas:
Si utiliza la política heredada
policy
app-visibility
flow-visibility
Asegúrese de cumplir los requisitos previos para las funciones que se indican aquí https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/url-filtering.html
Note: If you are using the legacy policy along with Configuration groups :
Select Configuration and Click Security
Click Custom Options and select Policies/Profiles and then access these features to enable
Este documento se centra en las funciones que se deben habilitar mediante los grupos de políticas
Para activar NGFW, siga los pasos que se indican a continuación:
Para habilitar el desregistro, edite la política de NGFW, seleccione Parámetros adicionales y active el registro unificado
Para activar el filtrado de URL para versiones anteriores a 20.18:
Para habilitar el filtrado de url para las versiones 20.18 y posteriores:
Seleccione agregar filtrado de URL, introduzca los detalles y haga clic en guardar
Para activar AMP para versiones anteriores a 20.18:
Para habilitar AMP para las versiones 20.18 y posteriores:
Seleccione Protección frente a malware avanzado y haga clic en Agregar protección frente a malware avanzado
Agregue los detalles y haga clic en Guardar
Para activar IPS/IDS para versiones anteriores a 20.18:
Para activar IPS/IDS para las versiones 20.18 y posteriores:
Seleccione Prevención de intrusiones y haga clic en Agregar prevención de intrusiones
Agregue los detalles y haga clic en Guardar
Para activar AIP para versiones anteriores a 20.18:
Para habilitar AIP para las versiones 20.18 y posteriores:
Seleccione Perfil de inspección avanzado y haga clic en Agregar perfil de inspección avanzado
Para la desconexión , habilite la función en el router a través del grupo de configuración mediante cli add on
policy
ip visibility features
ulogging enable
parameter-map type inspect-global
log dropped-packets
log flow-export fnf
log flow
!
utd engine standard unified-policy
utd global
flow-logging all
show flow monitor sdwan-flow-monitor cache
IPV4 SOURCE ADDRESS: 10.100.10.75
IPV4 DESTINATION ADDRESS: 10.10.10.25
TRNS SOURCE PORT: 53
TRNS DESTINATION PORT: 34796
IP VPN ID: 10
IP PROTOCOL: 17
tcp flags: 0x00
interface input: Gi2
interface output: Gi3
flow cts source group tag: 0
flow cts destination group tag: 0
counter bytes long: 125
counter packets long: 1
timestamp abs first: 14:59:47.613
timestamp abs last: 14:59:47.613
flow end reason: Not determined
connection initiator: Reverse initiator
interface overlay session id input: 10
interface overlay session id output: 0
connection connection id long: 0x000000000050D9CC
drop cause id: 0
counter bytes drop long: 0
sdwan sla not met : 0
sdwan preferred color not met : 0
sdwan queue id : 2
counter packets drop long: 0
ulogging fw zp id: 4
ulogging fw zone id array: 3 3
ulogging fw class id: 12544961
ulogging fw policy id: 5559936
ulogging fw proto id: 25
ulogging fw action: 2
ulogging fw drop reason id: 0
ulogging fw source ipv4 address translated: 0.0.0.0
ulogging fw destination ipv4 address translated: 0.0.0.0
ulogging fw source port translated: 0
ulogging fw destination port translated: 0
ulogging utd ips pri: 1
ulogging utd ips sid: 57756
ulogging utd ips gid: 1
ulogging utd ips cid: 21
ulogging utd urlf url hash: 00000000000000000000000000000000
ulogging utd urlf url category: 0
ulogging utd urlf url reputation: 0
ulogging utd urlf application name:
ulogging utd amp dispos: 0
ulogging utd amp filename hash: 00000000000000000000000000000000
ulogging utd amp file type: 0
ulogging utd amp file hash: 0000000000000000000000000000000000000000000000000000000000000000
ulogging utd amp malname hash: 00000000000000000000000000000000
ulogging utd drop reason id: 0
ulogging sdvt drop reason id: 0
ulogging utd ips policy id: 1
ulogging utd ips action id: 1
ulogging utd urlf policy id: N/A
ulogging utd urlf action id: N/A
ulogging utd amp policy id: N/A
ulogging utd amp action id: N/A
ulogging utd urlf reason id: 0
ulogging ulogging flow direction: Reverse initiator
ulogging fw user name:
ulogging fw source ipv6 address translated: ::
ulogging fw destination ipv6 address translated: ::
ip dscp: 0x00
application name: port dns
| Revisión | Fecha de publicación | Comentarios |
|---|---|---|
1.0 |
16-Sep-2026
|
Versión inicial |