
21-4
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Application Inspection Engines
Table 21-1 Application Inspection Engines
Application PAT? NAT (1-1)?
Configure
Port? Default Port Standards Comments
CTIQBE Yes Yes Yes TCP/2748 — —
DNS
1
1. No NAT support is available for name resolution through WINS.
Yes Yes No UDP/53 RFC 1123 Only forward NAT. No PTR
records are changed.
FTP Yes Yes Yes TCP/21 RFC 959 —
GTP Yes Yes Yes UDP/3386
UDP/2123
— Requires a special license.
H.323 Yes Yes Yes TCP/1720
UDP/1718
UDP (RAS)
1718-1719
ITU-T H.323,
H.245, H225.0,
Q.931, Q.932
HTTP Yes Yes Yes TCP/80 RFC 2616 Beware of MTU limitations
when stripping ActiveX and
Java.
2
2. If the MTU is too small to allow the Java or ActiveX tag to be included in one packet, stripping may not occur.
ICMP Yes Yes No — — —
ICMP ERROR Yes Yes No — — —
ILS (LDAP) Yes Yes Yes — — —
MGCP Yes Yes Yes 2427, 2727 RFC2705bis-05 —
NBDS / UDP Yes Yes No UDP/138 — —
NBNS / UDP No No No UDP/137 — No WINS support.
NetBIOS over
IP
3
3. NetBIOS is supported by performing NAT of the packets for NBNS UDP port 137 and NBDS UDP port 138.
No No No — — —
PPTP Yes Yes Yes 1723 RFC2637 —
RSH Yes Yes Yes TCP/514 Berkeley UNIX —
RTSP No No Yes TCP/554 RFC 2326, RFC
2327, RFC 1889
No handling for HTTP cloaking.
SIP Yes Yes Yes TCP/5060
UDP/5060
RFC 2543 —
SKINNY
(SCCP)
Yes Yes Yes TCP/2000 — Does not handle TFTP uploaded
Cisco IP Phone configurations
under certain circumstances.
SMTP/ESMTP Yes Yes Yes TCP/25 RFC 821, 1123 —
SQL*Net Yes Yes Yes TCP/1521
(v.1)
— V.1 and v.2.
Sun RPC No No No UDP/111
T C P/1 1 1
— Payload not NATed.
XDCMP No No No UDP/177 — —
Kommentare zu diesen Handbüchern