CHAPT ER
24-1
Cisco ASDM User Guide
OL-16647-01
24
Configuring Application Layer Protocol Inspection
This chapter describes how to configure application layer protocol inspection. Inspection engines are
required for services that embed IP addressing information in the user data packet or that open secondary
channels on dynamically assigned ports. These protocols require the security appliance to do a deep
packet inspection instead of passing the packet through the fast path. As a result, inspection engines can
affect overall throughput.
Several common inspection engines are enabled on the security appliance by default, but you might need
to enable others depending on your network. This chapter includes the following sections:
Inspection Engine Overview, page 24-2
When to Use Application Protocol Inspection, page 24-2
Inspection Limitations, page 24-3
Default Inspection Policy, page 24-3
Configuring Application Inspection, page 24-4
CTIQBE Inspection, page 24-5
DCERPC Inspection, page 24-6
DNS Inspection, page 24-6
ESMTP Inspection, page 24-8
FTP Inspection, page 24-8
GTP Inspection, page 24-10
H.323 Inspection, page 24-11
HTTP Inspection, page 24-13
Instant Messaging Inspection, page 24-14
ICMP Inspection, page 24-14
ICMP Error Inspection, page 24-14
ILS Inspection, page 24-14
MGCP Inspection, page 24-15
MMP Inspection, page 24-17
NetBIOS Inspection, page 24-18
PPTP Inspection, page 24-19