
21-52
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing SMTP and Extended SMTP Inspection
• For unknown commands, the security appliance changes all the characters in the packet to X. In this
case, the server generates an error code to the client. Because of the change in the packed, the TCP
checksum has to be recalculated or adjusted.
• TCP stream editing.
• Command pipelining.
Enabling and Configuring SMTP and Extended SMTP Application Inspection
To enable SMTP and extended SMTP inspection or change the default port used for receiving SMTP
traffic, perform the following steps:
Step 1 Name the traffic class by entering the following command in global configuration mode:
hostname(config)# class-map
class_map_name
Replace class_map_name with the name of the traffic class, for example:
hostname(config)# class-map smtp_port
When you enter the class-map command, the CLI enters the class map configuration mode, and the
prompt changes, as in the following example:
hostname(config-cmap)#
Step 2 In the class map configuration mode, define the match command, as in the following example:
hostname(config-cmap)# match port tcp eq 25
hostname(config-cmap)# exit
hostname(config)#
To assign a range of continuous ports, enter the range keyword, as in the following example:
hostname(config-cmap)# match port tcp range 2025-2030
To assign more than one non-contiguous port for SMTP inspection, enter the access-list command and
define an access control entry to match each port. Then enter the match command to associate the access
lists with the SMTP traffic class.
Step 3 Name the policy map by entering the following command:
hostname(config)# policy-map
policy_map_name
Replace policy_map_name with the name of the policy map, as in the following example:
hostname(config)# policy-map inbound_policy
The CLI enters the policy map configuration mode and the prompt changes accordingly, as follows:
hostname(config-pmap)#
Step 4 Specify the traffic class defined in Step 2 to be included in the policy map by entering the following
command:
hostname(config-pmap)# class
class_map_name
For example, the following command assigns the smtp_port traffic class to the current policy map.
hostname(config-pmap)# class smtp_port
Comentarios a estos manuales