parameter-map type urlfpolicy local Test
allow-mode on------------其余所有allow,也可以通过配置allow特定url
block-page message "yeslab-test-message"-----block时显示给客户的信息
parameter-map type urlf-glob BAD-DOMAINS
pattern *cisco.com------任何cisco.com结尾的域名
parameter-map type urlf-glob BAD-KEYWORDS
pattern exec
!
class-map type urlfilter match-any BAD-KEYWORDS-CLASS
match url-keyword urlf-glob BAD-KEYWORDS----匹配关键字
class-map type urlfilter match-any BAD-DOMAINS-CLASS
match server-domain urlf-glob BAD-DOMAINS-----匹配域名
!
class-map type inspect match-all Inside-to-Outside-HTTP-Class
match protocol http
!
policy-map type inspect urlfilter URL-POLICY
parameter type urlfpolicy local Test-----调用urlfpolicy的参数map
class type urlfilter BAD-DOMAINS-CLASS
reset
log
class type urlfilter BAD-KEYWORDS-CLASS
reset
log
policy-map type inspect Inside-to-Outside-Policy
class type inspect Inside-to-Outside-HTTP-Class
inspect
service-policy urlfilter URL-POLICY
class class-default
drop log