Cisco 4700M Configuration Manual page 127

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 3
Configuring Application Protocol Inspection
Application Protocol Inspection Overview
You may require the ACE to perform application inspection of Domain Name
System (DNS), FTP (File Transfer Protocol), HTTP, Internet Control Message
Protocol (ICMP), Internet Locator Service (ILS), Real-Time Streaming Protocol
(RTSP), Skinny Client Control Protocol (SCCP), and Session Initiation Protocol
(SIP) as a first step before passing the packets to the destination server. For HTTP,
the ACE performs deep packet inspection to statefully monitor the HTTP protocol
and permit or deny traffic based on user-defined traffic policies. HTTP deep
packet inspection focuses mainly on HTTP attributes such as the HTTP header,
the URL, and the payload. For FTP, the ACE performs FTP command inspection
for FTP sessions, allowing you to restrict specific commands by the ACE.
Application inspection helps you to identify the location of the embedded IP
addressing information in the TCP or UDP flow. This inspection allows the ACE
to translate embedded IP addresses and to update any checksum or other fields
that are affected by the translation.
Translating IP addresses embedded in the payload of protocols is especially
important for NAT (explicitly configured by the user) and server load balancing
(an implicit NAT).
Application inspection also monitors TCP or UDP sessions to determine the port
numbers for secondary channels. Some protocols open secondary TCP or UDP
ports to improve performance. The initial session on a well-known port is used to
negotiate dynamically assigned port numbers. The application protocol inspection
function monitors these sessions, identifies the dynamic port assignments, and
permits data exchange on these ports for the duration of the session.
Table 3-1
describes the application inspection protocols supported by the ACE,
the default TCP or UDP protocol and port, and whether the protocol is compatible
with Network Address Translation (NAT) and Port Address Translation (PAT).
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-3
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents