Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
24-10
Cisco ASDM User Guide
OL-16647-01
Chapter 24 Configuring Application Layer Protocol Inspection
GTP Inspection
The security appliance replaces the FTP server response to the SYST command with a series of Xs.
to prevent the server from revealing its system type to FTP clients. To override this default behavior,
use the Low setting in the FTP map.
Verifying and Monitoring FTP Inspection
FTP application inspection generates the following log messages:
An Audit record 302002 is generated for each file that is retrieved or uploaded.
The FTP command is checked to see if it is RETR or STOR and the retrieve and store commands
are logged.
The username is obtained by looking up a table providing the IP address.
The username, source IP address, destination IP address, NAT address, and the file operation are
logged.
Audit record 201005 is generated if the secondary dynamic channel preparation failed due to
memory shortage.
In conjunction with NAT, the FTP application inspection translates the IP address within the application
payload. This is described in detail in RFC 959.
GTP Inspection
Note GTP inspection requires a special license.
GPRS provides uninterrupted connectivity for mobile subscribers between GSM networks and corporate
networks or the Internet. The GGSN is the interface between the GPRS wireless data network and other
networks. The SGSN performs mobility, data session management, and data compression (See
Figure 24-2).