25-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 25 Configuring Application Layer Protocol Inspection
Inspection Engine Overview
•
RADIUS Accounting Inspection, page 25-60
•
RSH Inspection, page 25-61
•
RTSP Inspection, page 25-61
•
SIP Inspection, page 25-65
•
Skinny (SCCP) Inspection, page 25-71
•
SMTP and Extended SMTP Inspection, page 25-75
•
SNMP Inspection, page 25-76
•
SQL*Net Inspection, page 25-77
•
Sun RPC Inspection, page 25-77
•
TFTP Inspection, page 25-80
•
TLS Proxy for Encrypted Voice Inspection, page 25-80
•
XDMCP Inspection, page 25-90
Inspection Engine Overview
This section includes the following topics:
•
When to Use Application Protocol Inspection, page 25-2
•
Inspection Limitations, page 25-3
•
Default Inspection Policy, page 25-3
When to Use Application Protocol Inspection
When a user establishes a connection, the security appliance checks the packet against access lists,
creates an address translation, and creates an entry for the session in the fast path, so that further packets
can bypass time-consuming checks. However, the fast path relies on predictable port numbers and does
not perform address translations inside a packet.
Many protocols open secondary TCP or UDP ports. The initial session on a well-known port is used to
negotiate dynamically assigned port numbers.
Other applications embed an IP address in the packet that needs to match the source address that is
normally translated when it goes through the security appliance.
If you use applications like these, then you need to enable application inspection.
When you enable application inspection for a service that embeds IP addresses, the security appliance
translates embedded addresses and updates any checksum or other fields that are affected by the
translation.
When you enable application inspection for a service that uses dynamically assigned ports, the security
appliance monitors sessions to identify the dynamic port assignments, and permits data exchange on
these ports for the duration of the specific session.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......