cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
531
Views
0
Helpful
1
Replies

asa application inspection

carl_townshend
Spotlight
Spotlight

Hi all

By default the asa does a default application inspection for certain traffic.

is this inspection only looking for certain port number changes and other embedded ip addresses? I gather it doesnt look for anonimalies etc ?

cheers                  

1 Accepted Solution

Accepted Solutions

The answer depends on the protocol you are looking for. Most of the default-inspections just make the protocol work (FTP, Voice-inspections and so on). But some of them look into the packets to make the connection more secure (ESMTP).

Here is some more info on the application-layer inspections:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/inspect_overview.html#wp1435177

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

View solution in original post

1 Reply 1

The answer depends on the protocol you are looking for. Most of the default-inspections just make the protocol work (FTP, Voice-inspections and so on). But some of them look into the packets to make the connection more secure (ESMTP).

Here is some more info on the application-layer inspections:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/inspect_overview.html#wp1435177

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card