Cisco 4700M Configuration Manual page 143

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 3
Configuring Application Protocol Inspection
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
OL-16202-01
Checks the validity of each header parameter in the context of each message
following the syntax rules specified in RFC 3261.
Removes the optional User-Agent and Server header fields to hide the
endpoint software version.
Checks the Max-Forwards header field. If the Max-Forwards value reaches 0
before the request reaches its destination, the ACE rejects the request with a
483 (Too Many Hops) error response.
Validates SIP URIs and URIs present in the SIP header fields.
Handles unknown SIP methods. Because SIP is an evolving protocol, which
includes many extensions, some of the new methods may not be recognized
by the ACE (only the methods defined by RFC 3261 and the extensions listed
above are supported). You can configure how the ACE handles "unknown"
SIP methods.
Permits or denies third-party registrations or deregistrations and specifies
which users are allowed to perform these functions. If this policy is enabled,
REGISTER messages, with mismatched To and From headers and with From
values that do not match any of the privileged user IDs, are dropped.
Protects against buffer overflows as follows:
Enforces the Content-Length and the Content-Type (user configurable)
values:
Allows you to configure the maximum size of a SIP message body. When
a request or response SIP message passes through the ACE appliance, the
message is checked to ensure that it meets the size constraints. If it does
not, the action configured for this policy by the user will be executed.
Cross checks the Content-Length header field value with the actual
message size.
Allows you to select whether a subset of Content-types are permitted
through the ACE appliance. You can specify the Content-type string in
the form of a regular expression, for example, Application/SDP,
text/html. The default behavior is to allow all types.
Enforces SIP or SIPS URI length (user configurable).
Application Protocol Inspection Overview
3-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents