10-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 10 Inspection for Management Application Protocols
GTP Inspection
Defaults for GTP Inspection
GTP inspection is not enabled by default. However, if you enable it without specifying your own
inspection map, a default map is used which provides the following processing. You need to configure a
map only if you want different values.
•
Errors are not permitted.
•
The maximum number of requests is 200.
•
The maximum number of tunnels is 500.
•
The GSN timeout is 30 minutes.
•
The PDP context timeout is 30 minutes.
•
The request timeout is 1 minute.
•
The signaling timeout is 30 minutes.
•
The tunneling timeout is 1 hour.
•
The T3 response timeout is 20 seconds.
•
Unknown message IDs are dropped and logged.
Configure GTP Inspection
GTP inspection is not enabled by default. You must configure it if you want GTP inspection.
Procedure
Step 1
Configure a GTP Inspection Policy Map, page 10-6
.
Step 2
Configure the GTP Inspection Service Policy, page 10-9
.
Step 3
(Optional) Configure RADIUS accounting inspection to protect against over-billing attacks. See
RADIUS Accounting Inspection, page 10-11
Configure a GTP Inspection Policy Map
If you want to enforce additional parameters on GTP traffic, and the default map does not meet your
needs, create and configure a GTP map.
Before You Begin
Some traffic matching options use regular expressions for matching purposes. If you intend to use one
of those techniques, first create the regular expression or regular expression class map.
Procedure
Step 1
Create a GTP inspection policy map:
hostname(config)#
policy-map type inspect gtp
policy_map_name
hostname(config-pmap)#
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......