Configuring inspection of basic internet protocols, Dns inspection, C h a p t e r – Cisco ASA 5505 User Manual

Page 877

Advertising
background image

C H A P T E R

43-1

Cisco ASA 5500 Series Configuration Guide using the CLI

43

Configuring Inspection of Basic Internet
Protocols

This chapter describes how to configure application layer protocol inspection. Inspection engines are
required for services that embed IP addressing information in the user data packet or that open secondary
channels on dynamically assigned ports. These protocols require the ASA to do a deep packet inspection
instead of passing the packet through the fast path. As a result, inspection engines can affect overall
throughput.

Several common inspection engines are enabled on the ASA by default, but you might need to enable
others depending on your network.

This chapter includes the following sections:

DNS Inspection, page 43-1

FTP Inspection, page 43-11

HTTP Inspection, page 43-16

ICMP Inspection, page 43-20

ICMP Error Inspection, page 43-21

Instant Messaging Inspection, page 43-21

IP Options Inspection, page 43-24

IPsec Pass Through Inspection, page 43-26

IPv6 Inspection, page 43-27

NetBIOS Inspection, page 43-28

PPTP Inspection, page 43-30

SMTP and Extended SMTP Inspection, page 43-31

TFTP Inspection, page 43-34

DNS Inspection

This section describes DNS application inspection. This section includes the following topics:

How DNS Application Inspection Works, page 43-2

How DNS Rewrite Works, page 43-2

Configuring DNS Rewrite, page 43-3

Advertising