47-44
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter47 Configuring Inspection of Basic Internet Protocols
IP Options Inspection
Step7 Click Finish.
Select IP Options Inspect Map
The Select IP Options Inspect Map dialog box is accessible as follows:
Add/Edit Service PolicyRule Wizard > Rule Actions > Protocol Inspection Tab > Select IM Map
The Select IP-Options Inspect Map dialog box lets you select or create a new IP Options inspection map.
Use this inspection map to control whether the ASA drops, passes, or clears IP packets containing the
following IP options—End of Options List, No Operations, and Router Alert.
Fields
Use the default IP-Options inspection map—Specifies to use the default IP Options map. The default
map drops packets containing all the inspected IP options, namely End of Options List (EOOL), No
Operation (NOP), and Router Alert (RTRALT).
Select an IP-Options map for fine control over inspectionLets you select a defined application
inspection map or add a new one.
Add—Opens the Add IP Options Inspect Map dialog box for the inspection.
Modes
The following table shows the modes in which this feature is available:
IP Options Inspect Map
The IP Options Inspect Maps pane lets you view previously configured IP Options inspection maps. An
IP Options inspection map lets you change the default configuration values used for IP Option
inspection.
You can configure IP Options inspection to control which IP packets with specific IP options are allowed
through the security appliance. Configuring this inspection instructs the security appliance to allow a
packet to pass or to clear the specified IP options and then allow the packet to pass.
In particular, you can control whether the security appliance drops, clears, or passes packets containing
the Router Alert (RTRALT) option. Dropping RSVP packets containing the Router Alert option can
cause problems in VoIP implementations. Therefore, you can create IP Options inspection maps to pass
packets containing the RTRALT option.
Fields
IP Options Inspect Maps—Table that lists the defined IP Options inspect maps.
Add—Configures a new IP Options inspect map.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
••••