7-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 7 Configuring Interface Parameters
Configuring Interface Parameters
•
Inspection engines—Some application inspection engines are dependent on the security level. For
same security interfaces, inspection engines apply to traffic in either direction.
–
NetBIOS inspection engine—Applied only for outbound connections.
–
SQL*Net inspection engine—If a control connection for the SQL*Net (formerly OraServ) port
exists between a pair of hosts, then only an inbound data connection is permitted through the
security appliance.
•
Filtering—HTTP(S) and FTP filtering applies only for outbound connections (from a higher level
to a lower level).
For same security interfaces, you can filter traffic in either direction.
•
NAT control—When you enable NAT control, you must configure NAT for hosts on a higher security
interface (inside) when they access hosts on a lower security interface (outside).
Without NAT control, or for same security interfaces, you can choose to use NAT between any
interface, or you can choose not to use NAT. Keep in mind that configuring NAT for an outside
interface might require a special keyword.
•
established
command—This command allows return connections from a lower security host to a
higher security host if there is already an established connection from the higher level host to the
lower level host.
For same security interfaces, you can configure
established
commands for both directions.
Configuring Interface Parameters
Before you can complete your configuration and allow traffic through the security appliance, you need
to configure an interface name, and for routed mode, an IP address.
Note
If you are using failover, do not use this procedure to name interfaces that you are reserving for failover
and Stateful Failover communications. See
Chapter 14, “Configuring Failover.”
to configure the failover
and state links.
This section includes the following topics:
•
Interface Parameters Overview, page 7-2
•
Configuring the Interface, page 7-3
Interface Parameters Overview
This section describes interface parameters and includes the following topics:
•
Default State of Interfaces, page 7-3
•
Default Security Level, page 7-3
•
Multiple Context Mode Guidelines, page 7-3
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......