Cisco ASA 5505 Configuration Manual page 799

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 37
Configuring Inspection of Basic Internet Protocols
Select FTP Map
The Select FTP Map dialog box is accessible as follows:
Add/Edit Service Policy Rule Wizard > Rule Actions > Protocol Inspection Tab >
Select FTP Map
The Select FTP Map dialog box lets you enable strict FTP application inspection, select an FTP map, or
create a new FTP map. An FTP map lets you change the configuration values used for FTP application
inspection.The Select FTP Map table provides a list of previously configured maps that you can select
for application inspection.
Fields
Modes
The following table shows the modes in which this feature is available:
Firewall Mode
Routed
FTP Class Map
The FTP Class Map dialog box is accessible as follows:Configuration > Global Objects > Class Maps
> FTP
The FTP Class Map pane lets you configure FTP class maps for FTP inspection.
An inspection class map matches application traffic with criteria specific to the application. You then
identify the class map in the inspect map and enable actions. The difference between creating a class
map and defining the traffic match directly in the inspect map is that you can create more complex match
criteria and you can reuse class maps. The applications that support inspection class maps are DNS, FTP,
H.323, HTTP, IM, and SIP.
Fields
OL-20339-01
FTP Strict (prevent web browsers from sending embedded commands in FTP requests)—Enables
strict FTP application inspection, which causes the adaptive security appliance to drop the
connection when an embedded command is included in an FTP request.
Use the default FTP inspection map—Specifies to use the default FTP map.
Select an FTP map for fine control over inspection—Lets you select a defined application inspection
map or add a new one.
Add—Opens the Add Policy Map dialog box for the inspection.
Security Context
Transparent Single
Name—Shows the FTP class map name.
Match Conditions—Shows the type, match criterion, and value in the class map.
Match Type—Shows the match type, which can be a positive or negative match.
Criterion—Shows the criterion of the FTP class map.
Value—Shows the value to match in the FTP class map.
Multiple
Context
System
Cisco ASA 5500 Series Configuration Guide using ASDM
FTP Inspection
37-15

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents