Cisco PIX 525 Spezifikationen Seite 356

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 355
21-30
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing HTTP Inspection
Managing HTTP Inspection
This section describes how the HTTP inspection engine works and how you can change its configuration.
This section includes the following topics:
HTTP Inspection Overview, page 21-30
Enabling and Configuring Advanced HTTP Inspection, page 21-31
HTTP Inspection Overview
Use the inspect http command to protect against specific attacks and other threats that may be associated
with HTTP traffic. HTTP inspection performs several functions:
Enhanced HTTP inspection
URL screening through N2H2 or Websense
Java and ActiveX filtering
The latter two features are configured in conjunction with the filter command. See theApplying
Filtering” chapter.
Note The no inspect http command also disables the filter url command.
The enhanced HTTP inspection feature, which is also known as an application firewall, verifies that
HTTP messages conform to RFC 2616, use RFC-defined methods, and comply with various other
criteria. This can help prevent attackers from using HTTP messages for circumventing network security
policy. In many cases, you can configure these criteria and the way the system responds when these
criteria are not met. The actions that you can specify for messages that fail the criteria set using the
different configuration commands include allow, reset, or drop. In addition to these actions, you can
specify to log the event or not.
The criteria that you can apply to HTTP messages include the following:
Does not include any method on a configurable list.
Specific transfer encoding method or application type.
HTTP transaction adheres to RFC specification.
Message body size is within configurable limits.
Request and response message header size is within a configurable limit.
URI length is within a configurable limit.
The content-type in the message body matches the header.
The content-type in the response message matches the accept-type field in the request message.
MIME type is included on a predefined list.
Specified keywords are present or absent at specified positions in the message.
To enable enhanced HTTP inspection, enter the inspect http http-map command. The rules that this
applies to HTTP traffic are defined by the specific HTTP map, which you configure by entering the
http-map command and HTTP map configuration mode commands.
Seitenansicht 355
1 2 ... 351 352 353 354 355 356 357 358 359 360 361 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare