CHAPT ER
47-1
Cisco ASA 5500 Series Configuration Guide using ASDM
47
Configuring Inspection of Basic Internet Protocols
This chapter describes how to configure application layer protocol inspection. Inspection engines are
required for services that embed IP addressing information in the user data packet or that open secondary
channels on dynamically assigned ports. These protocols require the ASA to do a deep packet inspection
instead of passing the packet through the fast path. As a result, inspection engines can affect overall
throughput.
Several common inspection engines are enabled on the ASA by default, but you might need to enable
others depending on your network.
This chapter includes the following sections:
DNS Inspection, page47-1
FTP Inspection, page 47-13
HTTP Inspection, page 47-24
ICMP Inspection, page 47-39
ICMP Error Inspection, page 47-39
Instant Messaging Inspection, page 47-39
IP Options Inspection, page 47-41
IPsec Pass Through Inspection, page47-46
IPv6 Inspection, page47-50
NetBIOS Inspection, page47-51
PPTP Inspection, page 47-53
SMTP and Extended SMTP Inspection, page47-54
TFTP Inspection, page47-64

DNS Inspection

This section describes DNS application inspection. This section includes the following topics:
How DNS Application Inspection Works, page47-2
How DNS Rewrite Works, page47-3
Configuring DNS Rewrite, page47-3