Cisco PIX 525 Specifikace Strana 186

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 466
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 185
5-10
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Basic Internet Protocols
Application inspection of ESP traffic is disabled by default. To enable this feature, enter the following
command:
fixup protocol esp-ike
When this feature is enabled, PIX Firewall preserves the IKE source port. Support is not provided for
the following:
ESP tunnel serialization
SPI matching
Recording of SPIs for each ESP connection
PPTP
The Point-to-Point Tunneling Protocol (PPTP) is a protocol for tunneling PPP traffic. A PPTP session is
composed of one TCP channel and usually two PPTP GRE tunnels. The TCP channel is the control
channel used for negotiating and managing the PPTP GRE tunnels. The GRE tunnels carries PPP
sessions between the two hosts.
As described in RFC 2637, the PPTP protocol is mainly used for the tunneling of PPP sessions initiated
from a modem bank PAC (PPTP Access Concentrator) to the headend PNS (PPTP Network Server).
When used this way, the PAC is the remote client and the PNS is the server.
However, when used for VPN by Windows, the interaction is inverted. The PNS is a remote single-user
PC that initiates connection to the head-end PAC to gain access to a central network.
PPTP application inspection is disabled by default. You use the fixup command to enable PPTP. The
command syntax is as follows:
[no] fixup protocol pptp 1723
When enabled, PPTP application inspection inspects PPTP protocol packets and dynamically creates the
GRE connections and xlates necessary to permit PPTP traffic. Only Version 1, as defined in RFC 2637,
is supported.
PAT is only performed for the modified version of GRE [RFC 2637] when negotiated over the PPTP TCP
control channel. Port Address Translation is not performed for the unmodified version of GRE [RFC
1701, RFC 1702].
To view the xlates used by PPTP connections, enter the following command:
show xlate
This command includes output for GRE connection. PAT type is shown with the detail option. A string
is shown for each GRE xlate. For example:
GRE PAT from inside:10.2.1.51/1723 to outside:192.150.49.100/0 flags ri
To view the status of GRE connections, enter one of the following commands:
show conn fport 1723
show conn lport 1723
You can use the show local-host command to display both GRE xlate and GRE connection status.
Zobrazit stránku 185
1 2 ... 181 182 183 184 185 186 187 188 189 190 191 ... 465 466

Komentáře k této Příručce

Žádné komentáře