Cisco ASA supports inspection for the Internet Locator Service (ILS) protocol. ILS is based on the Lightweight Directory Access Protocol (LDAP) specification. Numerous applications use ILS for directory services, including the following:

  • Microsoft NetMeeting
  • Microsoft SiteServer
  • Microsoft Active Directory

To enable ILS inspection, use the inspect ils command. This command is disabled by default.

The Cisco ASA ILS inspection engine provides support for the following:

  • Decoding of the LDAP REQUEST/RESPONSE PDUs using the BER decode functions
  • Parsing the LDAP packet
  • Extracting the IP addresses
  • Translating IP addresses as necessary (PAT is not supported)
  • Encoding the PDU with translated addresses using BER encode functions
  • Copying the newly encoded PDU back to the TCP packet
  • Performing incremental TCP checksum and sequence number adjustment

Part I: Product Overview

Introduction to Network Security

Product History

Hardware Overview

Part II: Firewall Solution

Initial Setup and System Maintenance

Network Access Control

IP Routing

Authentication, Authorization, and Accounting (AAA)

Application Inspection

Security Contexts

Transparent Firewalls

Failover and Redundancy

Quality of Service

Part III: Intrusion Prevention System (IPS) Solution

Intrusion Prevention System Integration

Configuring and Troubleshooting Cisco IPS Software via CLI

Part IV: Virtual Private Network (VPN) Solution

Site-to-Site IPSec VPNs

Remote Access VPN

Public Key Infrastructure (PKI)

Part V: Adaptive Security Device Manager

Introduction to ASDM

Firewall Management Using ASDM

IPS Management Using ASDM

VPN Management Using ASDM

Case Studies

Cisco Asa(c) All-in-one Firewall, IPS, And VPN Adaptive Security Appliance
Cisco ASA: All-in-One Firewall, IPS, and VPN Adaptive Security Appliance
ISBN: 1587052091
EAN: 2147483647
Year: 2006
Pages: 231 © 2008-2020.
If you may any questions please contact us: