24-79
Cisco ASDM User Guide
OL-16647-01
Chapter 24 Configuring Application Layer Protocol Inspection
Inspect Map Field Descriptions
FTP Inspect Map
The FTP pane lets you view previously configured FTP application inspection maps. An FTP map lets
you change the default configuration values used for FTP application inspection.
FTP command filtering and security checks are provided using strict FTP inspection for improved
security and control. Protocol conformance includes packet length checks, delimiters and packet format
checks, command terminator checks, and command validation.
Blocking FTP based on user values is also supported so that it is possible for FTP sites to post files for
download, but restrict access to certain users. You can block FTP connections based on file type, server
name, and other attributes. System message logs are generated if an FTP connection is denied after
inspection.
Fields
FTP Inspect Maps—Table that lists the defined FTP inspect maps.
Add—Configures a new FTP inspect map. To edit an FTP inspect map, select the FTP entry in the
FTP Inspect Maps table and click Customize.
Delete—Deletes the inspect map selected in the FTP Inspect Maps table.
Security Level—Select the security level (medium or low).
Low
Mask Banner Disabled
Mask Reply Disabled
Medium—Default.
Mask Banner Enabled
Mask Reply Enabled
File Type Filtering—Opens the Type Filtering dialog box to configure file type filters.
Customize—Opens the Add/Edit FTP Policy Map dialog box for additional settings.
Default Level—Sets the security level back to the default level of Medium.
Modes
The following table shows the modes in which this feature is available:
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
• • • •
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
• • • •