Cisco 4700M Configuration Manual page 128

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Application Protocol Inspection Overview
Table 3-1
Application Inspection Support
Application
Transport
Protocol
Protocol
DNS
UDP
FTP
TCP
FTP strict
TCP
HTTP
TCP
ICMP
ICMP
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-4
NAT/PAT
Port
Support
Src—Any
NAT
Dest—53
Src—Any
Both
Dest—21
Src—Any
Both
Dest—21
Src—Any
Both
Dest—80
Src—N/A
Both
Dest—N/A
Chapter 3
Configuring Application Protocol Inspection
Enabled
by
1
Default
Standards
No
RFC 1123
No
RFC 959
No
RFC 959
No
RFC 2616
No
Comments/Limitations
Inspects DNS packets
destined to port 53. You
can specify the maximum
length of the DNS packet
to be inspected. See the
"DNS Inspection"
section
for more information.
Inspects FTP packets,
translates address and port
embedded in the payload,
and opens up a secondary
channel for data. See the
"FTP Inspection"
section
for more information.
The inspect ftp strict
command allows the ACE
to track each FTP
command and response
sequence and also
prevents an FTP client
from determining valid
usernames that are
supported on an FTP
server. See the
"FTP
Inspection"
section for
more information.
Inspects HTTP packets.
See the
"HTTP Deep
Packet Inspection"
section
for more information.
See the
"ICMP
Inspection"
section for
more information.
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents