
22-5
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
Inspection Engine Overview
ESMTP
TCP/25
—
RFC 821, 1123
—
FTP
TCP/21
—
RFC 959
Default FTP inspection does not
enforce compliance with RFC
standards. To do so, configure the
inspect ftp
command with the
strict
keyword.
GTP
UDP/3386
(V0)
UDP/2123
(V1)
No NAT or PAT.
—
Requires a special license.
H.323
TCP/1720
UDP/1718
UDP (RAS)
1718-1719
No NAT on same security
interfaces.
No static PAT.
ITU-T H.323,
H.245, H225.0,
Q.931, Q.932
By default, both RAS and H.225
inspection are enabled.
HTTP
TCP/80
—
RFC 2616
Beware of MTU limitations stripping
ActiveX and Java. If the MTU is too
small to allow the Java or ActiveX tag to
be included in one packet, stripping
may not occur.
ICMP
—
—
—
All ICMP traffic is matched in the
default class map.
ICMP ERROR
—
—
—
All ICMP traffic is matched in the
default class map.
ILS (LDAP)
TCP/389
No PAT.
—
—
MGCP
UDP/2427,
2727
—
RFC 2705bis-05
—
NetBIOS
Datagram
Service / UDP
UDP/138
—
—
NetBIOS Name
Service / UDP
UDP/137
No NAT
No PAT
—
No WINS support.
PPTP
TCP/1723
—
RFC 2637
—
RSH
TCP/514
No PAT
Berkeley UNIX
—
RTSP
TCP/554
No PAT.
No outside NAT.
RFC 2326, 2327,
1889
No handling for HTTP cloaking.
SIP
TCP/5060
UDP/5060
No outside NAT.
No NAT on same security
interfaces.
RFC 3261
—
SKINNY
(SCCP)
TCP/2000
No outside NAT.
No NAT on same security
interfaces.
—
Does not handle TFTP uploaded Cisco
IP Phone configurations under certain
circumstances.
SMTP
TCP/25
—
RFC 821, 1123
—
Table 22-1
Supported Application Inspection Engines (continued)
Application
1
Default Port NAT Limitations
Standards
2
Comments
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......