Cisco PIX 525 Spezifikationen Seite 210

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 466
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 209
5-34
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Management Protocols
Internet Control Message Protocol
The ICMP payload is scanned to retrieve the five-tuple from the original packet. ICMP inspection
supports both one-to-one NAT and PAT. Using the retrieved five-tuple, a lookup is performed to
determine the original address of the client. ICMP inspection makes the following changes to the ICMP
packet:
In the IP Header, the NAT IP is changed to Client IP (Destination Address) and the IP checksum is
modified.
In ICMP Header, the ICMP checksum is modified due to the changes in the ICMP packet.
In the Payload, the following changes are made:
Original packet NAT IP is changed to Client IP
Original packet NAT port is changed to Client Port
Original packet IP checksum is updated
Remote Shell
You can use the fixup command to change the default port assignment for the Remote Shell protocol
(RSH). The command syntax is as follows.
fixup protocol rsh [514]
The RSH protocol uses a TCP connection from the RSH client to the RSH server on TCP port 514. The
client and server negotiate the TCP port number where the client will listen for the STDERR output
stream. RSH inspection supports NAT of the negotiated port number if necessary.
X Display Manager Control Protocol
The port assignment for the X Display Manager Control Protocol (XDMCP) is not configurable.
XDMCP is a protocol that uses UDP port 177 to negotiate X sessions, which use TCP when established.
For successful negotiation and start of an Xwindows session, the PIX Firewall must allow the TCP back
connection from the Xhosted computer. To permit the back connection use the established command on
the PIX
Firewall. Once XDMCP negotiates the port to send the display, The established command is
consulted to verify if this back connection should be permitted.
During the X Windows session, the manager talks to the display's Xserver on the well-known port 6000
+ n. Each display has a separate connection to the Xserver, as a result of the following terminal setting.
setenv DISPLAY Xserver:n
where n is the display number.
When XDMCP is used, the display is negotiated using IP addresses, which the PIX Firewall can NAT if
needed. XDCMP inspection does not support PAT.
Simple Network Management Protocol Fixup
SNMP fixup enables packet traffic monitoring between network devices. Using the fixup protocol
snmp command, the PIX Firewall can be configured to deny traffic based on packet version.
Seitenansicht 209
1 2 ... 205 206 207 208 209 210 211 212 213 214 215 ... 465 466

Kommentare zu diesen Handbüchern

Keine Kommentare