data:image/s3,"s3://crabby-images/f921e/f921e13a58cab6050d2d4b6d0d2f3412ca63105a" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 516"
22-100
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
Sun RPC Inspection
•
Verifying and Monitoring Sun RPC Inspection, page 22-102
Sun RPC Inspection Overview
To enable Sun RPC application inspection or to change the ports to which the FWSM listens, use the
inspect sunrpc command
in policy map class configuration mode, which is accessible by using the
class
command within policy map configuration mode. To remove the configuration, use the
no
form of this
command.
The
inspect sunrpc
command enables or disables application inspection for the Sun RPC protocol. Sun
RPC is used by NFS and NIS. Sun RPC services can run on any port. When a client attempts to access
an Sun RPC service on a server, it must learn the port that service is running on. It does this by querying
the port mapper process, usually rpcbind, on the well-known port of 111.
The client sends the Sun RPC program number of the service and the port mapper process responds with
the port number of the service. The client sends its Sun RPC queries to the server, specifying the port
identified by the port mapper process. When the server replies, the FWSM intercepts this packet and
opens both embryonic TCP and UDP connections on that port.
Note
NAT or PAT of Sun RPC payload information is not supported.
Enabling and Configuring Sun RPC Inspection
Sun RPC inspection is enabled by default.
Note
To enable or configure Sun RPC inspection over UDP, you do not have to define a separate traffic class
or a new policy map. You simply add the
inspect sunrpc
command into a policy map whose traffic class
is defined by the default traffic class. An example of this configuration is shown in
Example 22-16 on
page 22-102
.
To enable Sun RPC inspection or change the default port used for receiving Sun RPC traffic using TCP,
perform the following steps:
Step 1
Determine the port or ports that the port mapper process listens to. While this is most often port 111, it
can differ between operating systems and implementations.
Step 2
Create a class map or modify an existing class map to identify Sun RPC traffic. Use the
class-map
command to do so, as follows:
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 3
Use a
match
command to identify traffic sent to the port or ports that you determined in
Step 1
.
If the port mapper process listens to a single port, you can use the
match port
command to identify
traffic sent to that port, as follows:
hostname(config-cmap)#
match port tcp eq
port_number
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......