48-33
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter48 Configuring Inspection for Voice and Video Protocols
SIP Inspection
Add/Edit SIP Policy Map (Details)
Configuration> Global Objects > Inspect Maps > SIP > SIP Inspect Map > Advanced View
The Add/Edit SIP Policy Map pane lets you configure the security level and additional settings for SIP
application inspection maps.
Fields
Name—When adding a SIP, enter the name of the SIP map. When editing a SIP map, the name of
the previously configured SIP map is shown.
Description—Enter the description of the SIP map, up to 200 characters in length.
Security Level—Shows the security level settings to configure
Filtering—Tab that lets you configure the filtering settings for SIP.
Enable SIP instant messaging (IM) extensions—Enables Instant Messaging extensions. Default
is enabled.
Permit non-SIP traffic on SIP port—Permits non-SIP traffic on SIP port. Permitted by default.
IP Address Privacy—Tab that lets you configure the IP address privacy settings for SIP.
Hide server’s and endpoint’s IP addresses—Enables IP address privacy. Disabled by default.
Hop Count—Tab that lets you configure the hop count settings for SIP.
Ensure that number of hops to destination is greater than 0—Enables check for the value of
Max-Forwards header is zero.
Action—Drop packet, Drop Connection, Reset, Log.
Log—Enable or Disable.
RTP Conformance—Tab that lets you configure the RTP conformance settings for SIP.
Check RTP packets for protocol conformance—Checks RTP/RTCP packets flowing on the
pinholes for protocol conformance.
Limit payload to audio or video, based on the signaling exchange—Enforces payload type to be
audio/video based on the signaling exchange.
SIP Conformance—Tab that lets you configure the SIP conformance settings for SIP.
Enable state transition checking—Enables SIP state checking.
Action—Drop packet, Drop Connection, Reset, Log.
Log—Enable or Disable.
Enable strict validation of header fields—Enables validation of SIP header fields.
Action—Drop packet, Drop Connection, Reset, Log.
Log—Enable or Disable.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
••••