このドキュメントでは、統合ロギングの手順を含め、NGFW、URLフィルタリング、AMP、およびIPS/IDSを設定グループ経由で設定する方法について説明します。
フローの可視化とアプリケーションの可視化を実現
ポリシーグループを使用してポリシーを定義している場合(デフォルト)。
レガシー・ポリシーを使用している場合
policy
app-visibility
flow-visibility
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/url-filtering.htmlで説明されている機能の前提条件を満たしていることを確認します。
Note: If you are using the legacy policy along with Configuration groups :
Select Configuration and Click Security
Click Custom Options and select Policies/Profiles and then access these features to enable
このドキュメントでは、ポリシーグループを使用して有効にする機能に焦点を当てています
NGFWを有効にするには、次の手順を実行します。
ロギングを有効にするには、NGFWポリシーを編集してから追加設定を選択し、統合ロギングをオンにします
20.18より前のリリースでURLフィルタリングを有効にするには、次のコマンドを実行します。
リリース20.18以降でURLフィルタリングを有効にするには、次のコマンドを実行します。
Add url filteringを選択し、詳細を入力してsaveをクリックします
20.18より前のリリースでAMPを有効にするには:
リリース20.18以降でAMPを有効にするには、次の手順を実行します。
Advanced Malware Protectionを選択し、Add Advanced Malware Protectionをクリックします
詳細を追加し、[保存]をクリックします
20.18より前のリリースでIPS/IDSを有効にするには、次のコマンドを実行します。
リリース20.18以降でIPS/IDSを有効にするには、次のコマンドを実行します。
Intrusion Preventionを選択し、Add Intrusion Preventionをクリックする
詳細を追加し、[保存]をクリックします
20.18より前のリリースでAIPを有効にするには、次のコマンドを実行します。
リリース20.18以降でAIPを有効にするには、次の手順を実行します。
「拡張検査プロファイル」を選択し、「拡張検査プロファイルの追加」をクリックします
ロギングを行うには、cli add onを使用して設定グループ経由でルータ上の機能を有効にします。
policy
ip visibility features
ulogging enable
parameter-map type inspect-global
log dropped-packets
log flow-export fnf
log flow
!
utd engine standard unified-policy
utd global
flow-logging all
show flow monitor sdwan-flow-monitor cache
IPV4 SOURCE ADDRESS: 10.100.10.75
IPV4 DESTINATION ADDRESS: 10.10.10.25
TRNS SOURCE PORT: 53
TRNS DESTINATION PORT: 34796
IP VPN ID: 10
IP PROTOCOL: 17
tcp flags: 0x00
interface input: Gi2
interface output: Gi3
flow cts source group tag: 0
flow cts destination group tag: 0
counter bytes long: 125
counter packets long: 1
timestamp abs first: 14:59:47.613
timestamp abs last: 14:59:47.613
flow end reason: Not determined
connection initiator: Reverse initiator
interface overlay session id input: 10
interface overlay session id output: 0
connection connection id long: 0x000000000050D9CC
drop cause id: 0
counter bytes drop long: 0
sdwan sla not met : 0
sdwan preferred color not met : 0
sdwan queue id : 2
counter packets drop long: 0
ulogging fw zp id: 4
ulogging fw zone id array: 3 3
ulogging fw class id: 12544961
ulogging fw policy id: 5559936
ulogging fw proto id: 25
ulogging fw action: 2
ulogging fw drop reason id: 0
ulogging fw source ipv4 address translated: 0.0.0.0
ulogging fw destination ipv4 address translated: 0.0.0.0
ulogging fw source port translated: 0
ulogging fw destination port translated: 0
ulogging utd ips pri: 1
ulogging utd ips sid: 57756
ulogging utd ips gid: 1
ulogging utd ips cid: 21
ulogging utd urlf url hash: 00000000000000000000000000000000
ulogging utd urlf url category: 0
ulogging utd urlf url reputation: 0
ulogging utd urlf application name:
ulogging utd amp dispos: 0
ulogging utd amp filename hash: 00000000000000000000000000000000
ulogging utd amp file type: 0
ulogging utd amp file hash: 0000000000000000000000000000000000000000000000000000000000000000
ulogging utd amp malname hash: 00000000000000000000000000000000
ulogging utd drop reason id: 0
ulogging sdvt drop reason id: 0
ulogging utd ips policy id: 1
ulogging utd ips action id: 1
ulogging utd urlf policy id: N/A
ulogging utd urlf action id: N/A
ulogging utd amp policy id: N/A
ulogging utd amp action id: N/A
ulogging utd urlf reason id: 0
ulogging ulogging flow direction: Reverse initiator
ulogging fw user name:
ulogging fw source ipv6 address translated: ::
ulogging fw destination ipv6 address translated: ::
ip dscp: 0x00
application name: port dns
| 改定 | 発行日 | コメント |
|---|---|---|
1.0 |
16-Sep-2026
|
初版 |