Cisco PIX-515-RPS - PIX 515-R - Firewall Manual de usuario Pagina 14

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 28
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 13
14
Cisco PIX Security Appliance Release Notes Version 7.2
OL-10104-01
New Features
Other Enhancements
This section includes the following topics:
RTP/RTCP Inspection, page 14
Generic Input Rate Limiting, page 14
URL Filtering Enhancements for Secure Computing (N2H2), page 14
Resource Management for Security Contexts, page 15
Authentication for Through Traffic and Management Access Supports All Servers Previously
Supported for VPN Clients, page 15
Auto Update, page 15
Dead Connection Detection (DCD), page 15
Configurable Prompt, page 15
Save All Context Configurations from the System, page 16
Intra-Interface Communication for Clear Traffic, page 16
Modular Policy Framework Support for Management Traffic, page 16
RTP/RTCP Inspection
This feature NATs embedded IP addresses and opens pinholes for RTP and RTCP traffic. This feature
ensures that only RTP packets flow on the pinholes opened by Inspects SIP, Skinny, and H.323.
To prevent a malicious application from sending UDP traffic to make use of the pinholes created on the
security appliance, this feature allows you to monitor RTP and RTCP traffic and to enforce the validity
of RTP and RTCP packets.
For more information, see the Cisco Security Appliance Command Line Configuration Guide. For a
complete description of the command syntax, see the Cisco Security Appliance Command Reference.
Generic Input Rate Limiting
This feature prevents denial of service (DoS) attacks on a security appliance or on certain inspection
engines on a firewall. The 7.0 release supports egress rate-limiting (police) functionality and in this release,
input rate-limiting functionality extends the current egress policing functionality.
The police command is extended for this functionality.
For a complete description of the command syntax, see the Cisco Security Appliance Command
Reference.
URL Filtering Enhancements for Secure Computing (N2H2)
This feature allows you to enable long URL, HTTPS, and FTP filtering by using both Websense (the
current vendor) and N2H2 (a vendor that has been purchased by Secure Computing). Previously, the
code only enabled the vendor Websense to provide this type of filtering. The url-block, url-server, and
filter commands provide support for this feature.
For more information, see the “Applying Filtering Services” chapter in the Cisco Security Appliance
Command Line Configuration Guide. For a complete description of the command syntax, see the Cisco
Security Appliance Command Reference.
Vista de pagina 13
1 2 ... 9 10 11 12 13 14 15 16 17 18 19 ... 27 28

Comentarios a estos manuales

Sin comentarios