欢迎来到天天文库
浏览记录
ID:52311963
大小:1.04 MB
页数:50页
时间:2020-04-04
《技术学习资料分享MPF2腾科.ppt》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、©2005CiscoSystems,Inc.Allrightsreserved.SNPAv4.0—10-1AdvancedProtocolHandlingNeedforAdvancedProtocolHandlingSomepopularprotocolsorapplicationsbehaveasfollows:TheynegotiateconnectionstodynamicallyassignedsourceanddestinationportsandIPaddresses.Theyembedsourceanddestinationportan
2、dIPaddressinformationabovethenetworklayer.Agoodsecurityappliancehastoinspectpacketsabovethenetworklayeranddothefollowingasrequiredbytheprotocolorapplication:SecurelyopenandclosenegotiatedportsandIPaddressesforlegitimateclient-serverconnectionsthroughthesecurityapplianceUseNAT-r
3、elevantinstancesofIPaddressesinsideapacketUsePAT-relevantinstancesofportsinsideapacketInspectpacketsforsignsofmaliciousapplicationmisuseinspectCommandServerClientControlPort2008DataPort2010DataPort20ControlPort21Port2010Port2010OKDataNOFTPProtocolInspectionTCPS/21-C/2008TCPS/2
4、0-????XServerClientControlPort2008DataPort2010DataPort20ControlPort21Port2010Port2010OKDataFTPProtocolInspectionTCPS/21-C/2008TCPS/20-C/2010SecurityapplianceopensreturnportfordataNoreturnportfordataDefaultTrafficInspectionandPortNumbersfw1(config)#class-mapinspection_defaultf
5、w1(config)#match?default-inspection-trafficMatchdefaultinspectiontraffic:ctiqbe----tcp--2748dns-------udp--53ftp-------tcp--21gtp-------udp--2123,3386h323-h225-tcp--1720h323-ras--udp--1718-1719http------tcp--80icmp------icmpils-------tcp--389mgcp------udp--2427,2727netbios---ud
6、p--137-138rpc-------udp--111rsh-------tcp--514rtsp------tcp--554sip-------tcp--5060sip-------udp--5060skinny----tcp--2000smtp------tcp--25sqlnet----tcp--1521tftp------udp--69xdmcp-----udp--177DefaultProtocolInspectionPolicyclass-mapinspection_defaultmatchdefault-inspection-traf
7、fic!policy-mapglobal_policyclassinspection_defaultinspectdnsmaximumlength512inspectftpinspecth323h225inspecth323rasinspectnetbiosinspectsunrpcinspectrshinspectrtspinspectsipinspectskinnyinspectesmtpinspectsqlnetinspecttftpinspectxdmcp!service-policyglobal_policyglobalClassMapPo
8、licyMapServicePolicyDeleteInspectionforaProtocolDisabl
此文档下载收益归作者所有