Ils Inspection - Cisco ASA Series Configuration Manual

Firewall cli, asa services module, and the adaptive security virtual appliance
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

ILS Inspection

ILS Inspection
The ILS inspection engine provides NAT support for Microsoft NetMeeting, SiteServer, and Active
Directory products that use LDAP to exchange directory information with an ILS server.
The ASA supports NAT for ILS, which is used to register and locate endpoints in the ILS or SiteServer
Directory. PAT cannot be supported because only IP addresses are stored by an LDAP database.
For search responses, when the LDAP server is located outside, NAT should be considered to allow
internal peers to communicate locally while registered to external LDAP servers. For such search
responses, xlates are searched first, and then DNAT entries to obtain the correct address. If both of these
searches fail, then the address is not changed. For sites using NAT 0 (no NAT) and not expecting DNAT
interaction, we recommend that the inspection engine be turned off to provide better performance.
Additional configuration may be necessary when the ILS server is located inside the ASA border. This
would require a hole for outside clients to access the LDAP server on the specified port, typically TCP
389.
Because ILS traffic (H225 call signaling) only occurs on the secondary UDP channel, the TCP
Note
connection is disconnected after the TCP inactivity interval. By default, this interval is 60 minutes and
can be adjusted using the TCP timeout command. In ASDM, this is on the Configuration > Firewall >
Advanced > Global Timeouts pane.
ILS/LDAP follows a client/server model with sessions handled over a single TCP connection.
Depending on the client's actions, several of these sessions may be created.
During connection negotiation time, a BIND PDU is sent from the client to the server. Once a successful
BIND RESPONSE from the server is received, other operational messages may be exchanged (such as
ADD, DEL, SEARCH, or MODIFY) to perform operations on the ILS Directory. The ADD REQUEST
and SEARCH RESPONSE PDUs may contain IP addresses of NetMeeting peers, used by H.323 (SETUP
and CONNECT messages) to establish the NetMeeting sessions. Microsoft NetMeeting v2.X and v3.X
provides ILS support.
The ILS inspection performs the following operations:
ILS inspection has the following limitations:
For information on enabling ILS inspection, see
page
Cisco ASA Series Firewall CLI Configuration Guide
15-12
Decodes the LDAP REQUEST/RESPONSE PDUs using the BER decode functions.
Parses the LDAP packet.
Extracts IP addresses.
Translates IP addresses as necessary.
Encodes the PDU with translated addresses using BER encode functions.
Copies the newly encoded PDU back to the TCP packet.
Performs incremental TCP checksum and sequence number adjustment.
Referral requests and responses are not supported.
Users in multiple directories are not unified.
Single users having multiple identities in multiple directories cannot be recognized by NAT.
12-9.
Chapter 15
Inspection of Database, Directory, and Management Protocols
Configure Application Layer Protocol Inspection,

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents