資源描述:
《技術(shù)學(xué)習(xí)資料分享MPF2騰科》由會員上傳分享,免費(fèi)在線閱讀,更多相關(guān)內(nèi)容在教育資源-天天文庫。
1、?2005CiscoSystems,Inc.Allrightsreserved.SNPAv4.0—10-1AdvancedProtocolHandlingNeedforAdvancedProtocolHandlingSomepopularprotocolsorapplicationsbehaveasfollows:TheynegotiateconnectionstodynamicallyassignedsourceanddestinationportsandIPaddresses.TheyembedsourceanddestinationportandIPad
2、dressinformationabovethenetworklayer.Agoodsecurityappliancehastoinspectpacketsabovethenetworklayeranddothefollowingasrequiredbytheprotocolorapplication:SecurelyopenandclosenegotiatedportsandIPaddressesforlegitimateclient-serverconnectionsthroughthesecurityapplianceUseNAT-relevantins
3、tancesofIPaddressesinsideapacketUsePAT-relevantinstancesofportsinsideapacketInspectpacketsforsignsofmaliciousapplicationmisuseinspectCommandServerClientControlPort2008DataPort2010DataPort20ControlPort21Port2010Port2010OKDataNOFTPProtocolInspectionTCPS/21-C/2008TCPS/20-????XServerCl
4、ientControlPort2008DataPort2010DataPort20ControlPort21Port2010Port2010OKDataFTPProtocolInspectionTCPS/21-C/2008TCPS/20-C/2010SecurityapplianceopensreturnportfordataNoreturnportfordataDefaultTrafficInspectionandPortNumbersfw1(config)#class-mapinspection_defaultfw1(config)#match?def
5、ault-inspection-trafficMatchdefaultinspectiontraffic:ctiqbe----tcp--2748dns-------udp--53ftp-------tcp--21gtp-------udp--2123,3386h323-h225-tcp--1720h323-ras--udp--1718-1719http------tcp--80icmp------icmpils-------tcp--389mgcp------udp--2427,2727netbios---udp--137-138rpc-------udp--
6、111rsh-------tcp--514rtsp------tcp--554sip-------tcp--5060sip-------udp--5060skinny----tcp--2000smtp------tcp--25sqlnet----tcp--1521tftp------udp--69xdmcp-----udp--177DefaultProtocolInspectionPolicyclass-mapinspection_defaultmatchdefault-inspection-traffic!policy-mapglobal_policycla
7、ssinspection_defaultinspectdnsmaximumlength512inspectftpinspecth323h225inspecth323rasinspectnetbiosinspectsunrpcinspectrshinspectrtspinspectsipinspectskinnyinspectesmtpinspectsqlnetinspecttftpinspectxdmcp!service-policyglobal_policyglobalClassMapPolicyMapServicePolicyDeleteInspectio
8、nforaProtocolDisabl