Cisco PIX 525 Spécifications Page 148

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 147
3-36
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 3 Controlling Network Access and Use
Filtering Outbound Connections
Filtering Long URLs
PIX Firewall Version 6.1 and earlier versions do not support filtering URLs longer than 1159 bytes.
PIX
Firewall Versions 6.2 and higher support filtering URLs up to 4 KB for the Websense filtering
server. PIX
Firewall Versions 6.2 and higher support a maximum URL length of 1159 bytes for the N2H2
filtering server.
In addition, PIX Firewall Version 6.2 introduces the longurl-truncate and cgi-truncate commands to
allow handling of URL requests longer than the maximum permitted size. The format for these options
is as follows:
filter url [http | port[-port] local_ip local_mask foreign_ip foreign_mask] [allow]
[proxy-block] [longurl-truncate | longurl-deny] [cgi-truncate]
PIX Firewall Versions 6.2 and higher support a maximum URL length of 1159 bytes for the N2H2
filtering server. Filtering of URLs up to 4 KB is supported for the Websense filtering server. If a URL is
longer than the maximum, and you do not enable the longurl-truncate or longurl-deny options, the
firewall drops the packet.
The longurl-truncate option causes the PIX Firewall to send only the host name or IP address portion
of the URL for evaluation to the filtering server when the URL is longer than the maximum length
permitted. Use the longurl-deny option to deny outbound URL traffic if the URL is longer than the
maximum permitted.
Use the cgi-truncate option to truncate CGI URLs to include only the CGI script location and the script
name without any parameters. Many long HTTP requests are CGI requests. If the parameters list is very
long, waiting and sending the complete CGI request including the parameter list can use up memory
resources and affect firewall performance.
Viewing Filtering Statistics and Configuration
Use the commands in this section to view URL filtering information:
To show information about the filtering server, enter the following command:
show url-server
The following is sample output from this command:
url-server (outside) vendor n2h2 host 128.107.254.202 port 4005 timeout 5 protocol TCP
To show the URL statistics, enter the following command:
show url-server stats
The following is sample output from this command:
URL Server Statistics:
----------------------
Vendor websense
URLs total/allowed/denied 0/0/0
HTTPSs total/allowed/denied 0/0/0
FTPs total/allowed/denied 0/0/0
Vue de la page 147
1 2 ... 143 144 145 146 147 148 149 150 151 152 153 ... 465 466

Commentaires sur ces manuels

Pas de commentaire