CHAPT ER
50-1
Cisco ASA 5500 Series Configuration Guide using ASDM
50
Configuring Inspection for Management Application Protocols
This chapter describes how to configure application layer protocol inspection. Inspection engines are
required for services that embed IP addressing information in the user data packet or that open secondary
channels on dynamically assigned ports. These protocols require the ASA to do a deep packet inspection
instead of passing the packet through the fast path. As a result, inspection engines can affect overall
throughput.
Several common inspection engines are enabled on the ASA by default, but you might need to enable
others depending on your network.
This chapter includes the following sections:
DCERPC Inspection, page 50-1
GTP Inspection, page 50-5
RADIUS Accounting Inspection, page50-12
RSH Inspection, page 50-16
SNMP Inspection, page 50-16
XDMCP Inspection, page 50-18

DCERPC Inspection

This section describes the DCERPC inspection engine. This section includes the following topics:
DCERPC Overview, page50-1
“Select DCERPC Map” section on page50-2
“DCERPC Inspect Map” section on page50-2
“Add/Edit DCERPC Policy Map” section on page50-4

DCERPC Overview

DCERPC is a protocol widely used by Microsoft distributed client and server applications that allows
software clients to execute programs on a server remotely.