0,
Q.931, Q.932
HTTP Yes Yes Yes TCP/80 RFC 2616
ICMP Yes Yes No ??” ??”
ICMP ERROR Yes Yes No ??” ??”
ILS (LDAP) Yes Yes Yes ??” ??”
MGCP Yes Yes Yes 2427, 2727 RFC 2705bis-05
NBDS / UDP Yes Yes No UDP/138 ??”
NBNS / UDP No No No UDP/137 ??”
NetBIOS over IP3 No No No ??” ??”
PPTP Yes Yes Yes 1723 RFC 2637
RSH Yes Yes Yes TCP/514 Berkeley UNIX
RTSP No No Yes TCP/554 RFC 2326, RFC
2327, RFC 1889
SIP Yes Yes Yes TCP/5060
UDP/5060
RFC 2543
SKINNY (SCCP) Yes Yes Yes TCP/2000 ??”
SMTP/ESMTP Yes Yes Yes TCP/25 RFC 821, 1123
SQL*Net Yes Yes Yes TCP/1521 (v.1) ??”
Sun RPC No Yes No UDP/111
TCP/111
??”
Application PAT? NAT
(1-1)?
Ports Can Be
Modified to
Nonstandard?
Default Port Standards
Compliance
XDCMP No No No UDP/177 ??”
The information in Table 6-2 is taken from "Cisco Security Appliance Command Line Configuration
Guide, Version 7.0" at
http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/inspect.html#wp1250375.
Adaptive Security Algorithm Operation
Figure 6-5 illustrates how the stateful-inspection and application intelligence works in the Security Appliance.
Conceptually, three basic operational functions are performed:
Access lists: Controlling network access based on specific networks, hosts, and services (TCP/UDP port
numbers).
Pages:
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264