data:image/s3,"s3://crabby-images/13b10/13b1049baf779d8297733629570d41be857f06fd" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 448"
22-32
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
FTP Inspection
Configuring FTP Inspection
FTP application inspection is enabled default, so you only need to perform the procedures in this section
if you want to change the default FTP configuration, in any of the following ways:
•
Enable the
strict
option.
•
Identify specific FTP commands that are not permitted to pass through the FWSM.
•
Change the default port number.
To configure FTP inspection, perform the following steps:
Step 1
Determine the ports to which FTP servers behind your FWSM listen. The default FTP port is TCP port
21; however, alternate ports are often used as a simple means to thwart attacks. To ensure that all FTP
traffic is inspected, check your FTP servers for use of ports other than TCP port 21.
Step 2
Create a class map or modify an existing class map to identify FTP traffic. Use the
class-map
command
to do so, as follows.
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
where
class_map_name
is the name of the traffic class. When you enter the
class-map
command, the
CLI enters class map configuration mode.
Step 3
Identify traffic sent to the FTP ports you determined in
Step 1
. To do so, use a
match port
or
match
access-list
command.
If you need to identify two or more non-contiguous ports, create an access list with the
access-list
extended
command, add an ACE to match each port, and then use the
match access-list
command. The
following commands show how to use an access list to identify multiple TCP ports with an access list.
hostname(config)#
access-list
acl-name
any any tcp eq
port_number_1
hostname(config)#
access-list
acl-name
any any tcp eq
port_number_2
hostname(config)#
class-map
class_map_name
hostname(config-cmap)#
match access-list
acl-name
If you need to identify a single port, use the
match port
command, as follows:
hostname(config-cmap)#
match port tcp
port_number
where
port_number
is the only TCP port listened to by FTP servers behind the FWSM.
If you need to identify a range of contiguous ports for a single protocol, use
match port
command with
the
range
keyword, as follows:
hostname(config-cmap)#
match port tcp range
begin_port_number
end_port_number
rmd
Disallows the command that deletes a directory on the server.
rnfr
Disallows the command that specifies rename-from filename.
rnto
Disallows the command that specifies rename-to filename.
site
Disallows the command that are specific to the server system.
Usually used for remote administration.
stou
Disallows the command that stores a file using a unique filename.
Table 22-3
FTP Map request-command deny Options (continued)
request-command deny Option
Purpose
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......