Cisco PIX 525 Spezifikationen Seite 369

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 368
21-43
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing SIP Inspection
hostname(config-pmap-c)# inspect rtsp 8554
hostname(config-pmap-c)# exit
hostname(config)# service-policy inbound_policy interface outside
To enable RTSP inspection for all interfaces, enter the global parameter in place of interface outside.
Managing SIP Inspection
This section describes how to enable SIP application inspection and change the default port
configuration. This section includes the following topics:
SIP Inspection Overview, page 21-43
SIP Instant Messaging, page 21-43
Enabling and Configuring SIP Inspection, page 21-44
Configuring SIP Timeout Values, page 21-46
Verifying and Monitoring SIP Inspection, page 21-46
SIP Inspection Overview
SIP, as defined by the IETF, enables call handling sessions, particularly two-party audio conferences, or
“calls.” SIP works with SDP for call signalling. SDP specifies the ports for the media stream. Using SIP,
the security appliance can support any SIP VoIP gateways and VoIP proxy servers. SIP and SDP are
defined in the following RFCs:
SIP: Session Initiation Protocol, RFC 2543
SDP: Session Description Protocol, RFC 2327
To support SIP calls through the security appliance, signaling messages for the media connection
addresses, media ports, and embryonic connections for the media must be inspected, because while the
signaling is sent over a well-known destination port (UDP/TCP 5060), the media streams are
dynamically allocated. Also, SIP embeds IP addresses in the user-data portion of the IP packet. SIP
inspection applies NAT for these embedded IP addresses.
Note If a remote endpoint tries to register with a SIP proxy on a network protected by the security appliance,
the registration will fail under very specific conditions. These conditions are when PAT is configured for
the remote endpoint, the SIP registrar server is on the outside network, and when the port is missing in
the contact field in the REGISTER message sent by the endpoint to the proxy server.
SIP Instant Messaging
Instant Messaging refers to the transfer of messages between users in near real-time. SIP supports the
Chat feature on Windows XP using Windows Messenger RTC Client version 4.7.0105 only. The
MESSAGE/INFO methods and 202 Accept response are used to support IM as defined in the following
RFCs:
Session Initiation Protocol (SIP)-Specific Event Notification, RFC 3265
Session Initiation Protocol (SIP) Extension for Instant Messaging, RFC 3428
Seitenansicht 368
1 2 ... 364 365 366 367 368 369 370 371 372 373 374 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare