47-15
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter47 Configuring Inspection of Basic Internet Protocol s
FTP Inspection
Select FTP Map
The Select FTP Map dialog box is accessible as follows:
Add/Edit Service PolicyRule Wizard > Rule Actions > Protocol Inspection Tab >
Select FTP Map
The Select FTP Map dialog box lets you enable strict FTP application inspection, select an FTP map, or
create a new FTP map. An FTP map lets you change the configuration values used for FTP application
inspection.The Select FTP Map table provides a list of previously configured maps that you can select
for application inspection.
Fields
FTP Strict (prevent web browsers from sending embedded commands in FTP requests)Enables
strict FTP application inspection, which causes the ASA to drop the connection when an embedded
command is included in an FTP request.
Use the default FTP inspection map—Specifies to use the default FTP map.
Select an FTP map for fine control over inspectionLets you select a defined application inspection
map or add a new one.
Add—Opens the Add Policy Map dialog box for the inspection.
Modes
The following table shows the modes in which this feature is available:
FTP Class Map
The FTP Class Map dialog box is accessible as follows:
Configuration> Global Objects > Class Maps > FTP
The FTP Class Map pane lets you configure FTP class maps for FTP inspection.
An inspection class map matches application traffic with criteria specific to the application. You then
identify the class map in the inspect map and enable actions. The difference between creating a class
map and defining the traffic match directly in the inspect map is that you can create more complex match
criteria and you can reuse class maps. The applications that support inspection class maps are DNS, FTP,
H.323, HTTP, IM, and SIP.
Fields
Name—Shows the FTP class map name.
Match Conditions—Shows the type, match criterion, and value in the class map.
Match Type—Shows the match type, which can be a positive or negative match.
Criterion—Shows the criterion of the FTP class map.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
••••