Contents
xvii
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Configuring DNS Rewrite with Three NAT Zones 25-19
Verifying and Monitoring DNS Inspection 25-20
Configuring a DNS Inspection Policy Map for Additional Inspection Control 25-20
ESMTP Inspection 25-24
Configuring an ESMTP Inspection Policy Map for Additional Inspection Control 25-24
FTP Inspection 25-25
FTP Inspection Overview 25-26
Using the strict Option 25-26
Configuring an FTP Inspection Policy Map for Additional Inspection Control 25-27
Verifying and Monitoring FTP Inspection 25-30
GTP Inspection 25-31
GTP Inspection Overview 25-31
Configuring a GTP Inspection Policy Map for Additional Inspection Control 25-32
Verifying and Monitoring GTP Inspection 25-36
H.323 Inspection 25-37
H.323 Inspection Overview 25-37
How H.323 Works 25-37
Limitations and Restrictions 25-38
Configuring an H.323 Inspection Policy Map for Additional Inspection Control 25-38
Configuring H.323 and H.225 Timeout Values 25-41
Verifying and Monitoring H.323 Inspection 25-41
Monitoring H.225 Sessions 25-41
Monitoring H.245 Sessions 25-42
Monitoring H.323 RAS Sessions 25-43
HTTP Inspection 25-43
HTTP Inspection Overview 25-43
Configuring an HTTP Inspection Policy Map for Additional Inspection Control 25-44
Instant Messaging Inspection 25-47
IM Inspection Overview 25-48
Configuring an Instant Messaging Inspection Policy Map for Additional Inspection Control 25-48
ICMP Inspection 25-51
ICMP Error Inspection 25-51
ILS Inspection 25-51
MGCP Inspection 25-52
MGCP Inspection Overview 25-53
Configuring an MGCP Inspection Policy Map for Additional Inspection Control 25-54
Configuring MGCP Timeout Values 25-56
Verifying and Monitoring MGCP Inspection 25-56