<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why inspect command is disable by default on PIX 7.x in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815746#M979818</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i just wanted to add a note to this thread...&lt;/P&gt;&lt;P&gt;i'm not sure what the difference is between factory shipped v/s default configuration...&lt;/P&gt;&lt;P&gt;'factory shipped' configuration is easy enough to understand, but is that the default configuration?  &lt;/P&gt;&lt;P&gt;if I do a "wr erase" in 7.x and reboot, i have no inpsect commands, so is that the default?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2007 14:46:41 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2007-05-30T14:46:41Z</dc:date>
    <item>
      <title>Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815744#M979816</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question about fixup (PIX 6.x) and inspect (PIX 7.x) command because our customer asked us the following question;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- why inspect command replaced from fixup command is disabled by default on ASA 7.2/PIX 7.x ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Do we have to configure inspect command explicitly even if it is disabled by default ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however I can not clear it. So I posted this question here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In PIX 7.0, the fixup command has been deprecated and replaced with the inspect command under the Modular Policy Framework (MPF) infrastructure. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that In PIX 6.x, fixup command is enabled by default, however In ASA 7.2, inspect and fixup command are  disabled by default. Why I say so is when I configured brand new ASA 5500 version 7.2, I could not find the following MPF commands related to application inspection from the output of show runn command on ASA 7.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map xxxx&lt;/P&gt;&lt;P&gt;policy-map yyyy&lt;/P&gt;&lt;P&gt;class xxxx&lt;/P&gt;&lt;P&gt;inspect "protocol"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that I think that the Firewall service of ASA 7.2 is the same as the one of PIX 7.x.&lt;/P&gt;&lt;P&gt;So I assume that inspect command is disabled by default also on PIX 7.x.&lt;/P&gt;&lt;P&gt;Unfortunately, I can not prepare PIX 7.x and can not confirm whether inspect command is enabled or disabled by default on PIX 7.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think why inspect command replaced from fixup command is disabled by default on ASA 7.2/PIX 7.x is due to the following reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Allows Selective application control based on MPF infrastructure&lt;/P&gt;&lt;P&gt;- Allows to configure Firewall/QoS policy per interface basis whereas fixup command could be configured globally&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I think we should or we have to configure necessary inspect command to do application inspect, though it is disabled by default and it may differ according to the application used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my idea suitable ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your any comment would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815744#M979816</guid>
      <dc:creator>snakayama</dc:creator>
      <dc:date>2019-03-11T10:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815745#M979817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default for 7.x is for a basic global &lt;/P&gt;&lt;P&gt;inspection policy to be turned on.  Although I have seen some Cisco gear shipped with a different config then the normal default.  There is a way to get the actual default config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Backup current config&lt;/P&gt;&lt;P&gt;-write erase&lt;/P&gt;&lt;P&gt;-conf t&lt;/P&gt;&lt;P&gt;-clear config all   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't see any inspection policy configured then it is off.       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Application inspection guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a0080640337.html" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a0080640337.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be the default:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 11:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815745#M979817</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2007-05-30T11:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815746#M979818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i just wanted to add a note to this thread...&lt;/P&gt;&lt;P&gt;i'm not sure what the difference is between factory shipped v/s default configuration...&lt;/P&gt;&lt;P&gt;'factory shipped' configuration is easy enough to understand, but is that the default configuration?  &lt;/P&gt;&lt;P&gt;if I do a "wr erase" in 7.x and reboot, i have no inpsect commands, so is that the default?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 14:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815746#M979818</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-05-30T14:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815747#M979819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the Cisco doc the default includes a global inspection policy.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a0080640337.html#wp1383691" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a0080640337.html#wp1383691&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the last few devices I have bought came with a different config then the actual default.  And when I erased that I had what should be the default.    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a test pix running 7.x and I will see what that has as the default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 15:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815747#M979819</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2007-05-30T15:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815748#M979820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did a wr erase.  Rebooted and said no to the automated prompts.  I attached the default config which includes the default global inspection policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2007 11:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815748#M979820</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2007-05-31T11:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815749#M979821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your reply and lab work.&lt;/P&gt;&lt;P&gt;I have also tested in my lab with PIX 7.2.2 and ASA 7.2.2. And I got the same result on PIX and ASA as you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I executed "write erase" command on PIX 7.2.2 and ASA 7.2.2 to get them backed to default configuration and then rebooted them. The following is the result of "sh runn" command after rebooted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next I executed "clear config all" at configuration mode on both and then confirmed whether inspect command enabled (appeared) from "sh runn" command.&lt;/P&gt;&lt;P&gt;The result was the same as above, because "clear config all" command get running-config backed to factory shipped configuration not startup-config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However brand new ASA 7.2.2 does not enable inspect command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not know why factory shipped configuration (brand-new configuration) and default configuration are different about the inspect command, however I could understand what kind of case make the inspect command enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2007 03:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815749#M979821</guid>
      <dc:creator>snakayama</dc:creator>
      <dc:date>2007-06-01T03:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why inspect command is disable by default on PIX 7.x</title>
      <link>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815750#M979822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command "clear configure fixup" will bring back the FPM. Try that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 03:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-inspect-command-is-disable-by-default-on-pix-7-x/m-p/815750#M979822</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2010-05-29T03:11:34Z</dc:date>
    </item>
  </channel>
</rss>

