7-24
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 7 Managing FlexConfigs
Configuring FlexConfig Policies and Policy Objects
Configuring FlexConfig Policies and Policy Objects
You create and manage FlexConfig policy objects in the same way that you create other policy objects.
The following topics describe how to create FlexConfig policies and policy objects. For information on
other tasks you can perform with FlexConfig policy objects (such as deleting them), see Working with
Policy Objects—Basic Procedures, page 6-9.
• A FlexConfig Creation Scenario, page 7-24
• Creating FlexConfig Policy Objects, page 7-27
• Editing FlexConfig Policies, page 7-34
A FlexConfig Creation Scenario
This scenario takes you through the steps to set up Media Gateway Control Protocol (MGCP) for an ASA
device using one of the predefined FlexConfig policy objects that are shipped with Security Manager.
MGCP is used by the call agent application to control media gateways (devices that convert telephone
circuit audio to data packets). Security Manager does not support MGCP configuration, but you can use
a FlexConfig policy object to provide a configuration. This illustrates how FlexConfigs enable you to
customize, for your network, what is not otherwise supported in Security Manager.
In this scenario, you do the following:
1. Create a policy object by duplicating an existing policy object.
2. Assign the policy object to a device.
ROUTER_interface_prevent_dos _attacks Prevents denial-of-service (DOS) attacks on all device
interfaces.
This FlexConfig policy object uses the list of interface
names from the SYS_INTERFACE_NAME_LIST
system variable.
ROUTER_OSPF_no_router_Id Removes the router OSPF ID for each OSPF process.
This FlexConfig policy uses the list of OSPF IDs from the
SYS_ROUTER_OSPF_PROCESS_IDS_LIST system
variable.
ROUTER_QoS_Class_Map _description Sets QoS class map descriptions.
This FlexConfig policy object uses the list of router QoS
class names from the
SYS_ROUTER_QOS_CLASS_MAP_LIST system
variable.
ROUTER_QoS_Policy_Map _description Sets QoS policy descriptions.
This FlexConfig policy object uses the list of router QoS
policy names from the
SYS_ROUTER_QOS_POLICY_MAP_LIST system
variable.
Table 7-10 Predefined Router FlexConfig Policy Objects (Continued)
Name Description