15-22
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 15 Inspection of Database, Directory, and Management Protocols
VXLAN Inspection
When XDMCP is used, the display is negotiated using IP addresses, which the ASA can NAT if needed.
XDCMP inspection does not support PAT.
For information on enabling XDMCP inspection, see
Configure Application Layer Protocol Inspection,
VXLAN Inspection
Virtual Extensible Local Area Network (VXLAN) inspection works on VXLAN encapsulated traffic that
passes through the ASA. It ensures that the VXLAN header format conforms to standards, dropping any
malformed packets. VXLAN inspection is not done on traffic for which the ASA acts as a VXLAN
Tunnel End Point (VTEP) or a VXLAN gateway, as those checks are done as a normal part of
decapsulating VXLAN packets.
VXLAN packets are UDP, normally on port 4789. This port is part of the default-inspection-traffic class,
so you can simply add VXLAN inspection to the inspection_default service policy rule. Alternatively,
you can create a class for it using port or ACL matching.
History for Database, Directory, and Management Protocol
Inspection
Feature Name
Releases
Feature Information
DCERPC inspection support for
ISystemMapper UUID message
RemoteGetClassObject opnum3.
9.4(1)
The ASA started supporting non-EPM DCERPC messages
in release 8.3, supporting the ISystemMapper UUID
message RemoteCreateInstance opnum4. This change
extends support to the RemoteGetClassObject opnum3
message.
We did not modify any commands.
VXLAN packet inspection
9.4(1)
The ASA can inspect the VXLAN header to enforce
compliance with the standard format.
We introduced the following command:
inspect vxlan
.
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......