EasyManuals Logo

Cisco ASA Series User Manual

Cisco ASA Series
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1107 background imageLoading...
Page #1107 background image
CHAPTER
1-1
Cisco ASA Series CLI Configuration Guide
1
Configuring Inspection of Basic Internet
Protocols
This chapter describes how to configure application layer protocol inspection. Inspection engines are
required for services that embed IP addressing information in the user data packet or that open secondary
channels on dynamically assigned ports. These protocols require the ASA to do a deep packet inspection
instead of passing the packet through the fast path. As a result, inspection engines can affect overall
throughput.
Several common inspection engines are enabled on the ASA by default, but you might need to enable
others depending on your network.
This chapter includes the following sections:
• DNS Inspection, page 1-1
• FTP Inspection, page 1-10
• HTTP Inspection, page 1-15
• ICMP Inspection, page 1-20
• ICMP Error Inspection, page 1-20
• Instant Messaging Inspection, page 1-20
• IP Options Inspection, page 1-24
• IPsec Pass Through Inspection, page 1-25
• IPv6 Inspection, page 1-26
• NetBIOS Inspection, page 1-30
• PPTP Inspection, page 1-32
• SMTP and Extended SMTP Inspection, page 1-32
• TFTP Inspection, page 1-35
DNS Inspection
This section describes DNS application inspection. This section includes the following topics:
• Information About DNS Inspection, page 1-2
• Default Settings for DNS Inspection, page 1-2
• (Optional) Configuring a DNS Inspection Policy Map and Class Map, page 1-3

Table of Contents

Other manuals for Cisco ASA Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA Series and is the answer not in the manual?

Cisco ASA Series Specifications

General IconGeneral
ModelASA 5505
InterfacesVaries by model (Fast Ethernet, Gigabit Ethernet, 10 Gigabit Ethernet, etc.)
High AvailabilityActive/Standby or Active/Active (varies by model)
Power SupplyVaries by model
Form FactorVaries by model
Operating SystemCisco ASA Software
IPsec VPNSupported
SSL VPNSupported
IPS ThroughputVaries by model

Related product manuals