Chapter7 Application Security
HTTP
7-22
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Set maximum URI length inspection Checkbox
Check this box if you want to define a maximum length for Universal Resour ce
Indicators (URIs). Specify the maximum length in bytes, and then use the Permit,
Block, and Alarm controls to specify the action that the router is to take when an
URL that is longer than this value is encountered.
Enable HTTP inspection checkbox
Check this box if you want the router to inspect HTTP traffic. If you want to block
traffic from Java applications, you can specify a Java blocking filter by clicking
the ... button and either specifying an existing ACL, or creating a new ACL for
Java inspection.
Enable HTTPS inspection checkbox
Check this box if you want the router to inspect HTTPS traffic.
Set time out value checkbox
Check this box if you want to set a time out for HTTP sessions, and enter the
number of second in the Time-Out field. Sessions will be dropped that exceed this
amount of time.
Enable audit trail
You can make CBAC audit trail settings for HTTP traffic that will override the
setting in the Global Timeouts and Thresholds window. Default means that the
current global setting will be used. On explicitly enables the CBAC audit trail for
HTTP traffic and for HTTPS traffic if HTTPS inspection is enabled, and overrides
the global audit trail setting. Off explicitly disables the CBAC audit trail for
HTTP traffic and for HTTPS traffic if HTTPS inspection is enabled, and overrides
the global audit trail setting