14-7
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter 14 Configuring Inspection for Management Application Protocols
GTP Inspection
• Default Level—Sets the security level back to the default.
IMSI Prefix Filtering
Configuration > Global Objects > Inspect Maps > GTP > IMSI Prefix Filtering
The IMSI Prefix tab lets you define the IMSI prefix to allow within GTP requests.
Fields
• Mobile Country Code—Defines the non-zero, three-digit value identifying the mobile country code.
One or two-digit entries will be prepended by 0 to create a three-digit value.
• Mobile Network Code—Defines the two or three-digit value identifying the network code.
• Add—Add the specified country code and network code to the IMSI Prefix table.
• Delete—Deletes the specified country code and network code from the IMSI Prefix table.
Add/Edit GTP Policy Map (Security Level)
Configuration > Global Objects > Inspect Maps > GTP > GTP Inspect Map > Basic View
The Add/Edit GTP Policy Map pane lets you configure the security level and additional settings for GTP
application inspection maps.
Fields
• Name—When adding a GTP map, enter the name of the GTP map. When editing a GTP map, the
name of the previously configured GTP map is shown.
• Description—Enter the description of the GTP map, up to 200 characters in length.
• Security Level—Security level low only.
Do not Permit Errors
Maximum Number of Tunnels: 500
GSN timeout: 00:30:00
Pdp-Context timeout: 00:30:00
Request timeout: 00:01:00
Signaling timeout: 00:30:00.
Tunnel timeout: 01:00:00.
T3-response timeout: 00:00:20.
Drop and log unknown message IDs.
–
IMSI Prefix Filtering—Opens the IMSI Prefix Filtering dialog box to configure IMSI prefix
filters.
–
Default Level—Sets the security level back to the default.
• Details—Shows the Parameters, IMSI Prefix Filtering, and Inspections tabs to configure additional
settings.