
5-3
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
How Application Inspection Works
FTP Ye s Yes Yes TCP/21 RFC 1123 None.
H.323 PIX Firewal
l Version 6.2
and higher
Yes Yes TCP/1720
UDP/1718
UDP (RAS)
1718-1719
ITU-T H.323,
H.245, H225.0,
Q.931, Q.932
None. Support for Version 3 and 4
introduced with PIX
Firewall
Version 6.3. Does not support
segmented messages.
HTTP Yes Yes Yes TCP/80 RFC 2616 Beware of MTU limitations when
stripping ActiveX and Java.
2
ICMP Yes Yes No — — None.
ILS (LDAP) Yes Yes Yes — — Introduced in PIX Firewall
Version 6.2.
MGCP No No Yes
2427, 2727 RFC2705bis-05
Introduced with PIX Firewall
Version 6.3.
NBDS / UDP
Yes Yes No UDP/138
—
None.
NBNS / UDP
No No No UDP/137
—
No WINS support.
NetBIOS over
IP
3
No No No
— —
None.
PPTP Yes Yes Yes 1723 RFC2637 Introduced with PIX Firewall
Version 6.3.
RSH
Yes Yes Yes TCP/514 Berkeley UNIX None.
RTSP
No No Ye s TCP/554 RFC 2326, RFC
2327, RFC 1889
No handling for HTTP cloaking.
SIP
PIX Firewal
l Version 6.2
or higher
Yes Yes TCP/5060
UDP/5060
RFC 2543 None.
SKINNY
(SCCP)
PIX Firewal
l Version 6.3
Yes Yes TCP/2000
—
Does not handle TFTP uploaded
Cisco IP Phone configurations
under certain circumstances.
SMTP
Yes Yes Yes TCP/25 RFC 821, 1123 None.
SNMP
No No Ye s
UDP 161,
162
RFC 1155, 1157,
1212, 1213, 1215
v.2 RFC 1902-1908; v.3 RFC
2570-2580.
SQL*Net
Yes Yes Yes TCP/1521
(v.1)
—
V.1 and v.2.
Sun RPC
No No No UDP /1 11
TCP/111
—
Payload not NATed.
VDO LIVE
No Yes No TCP/7000
—
None.
Windows
Media
No Yes No TCP/1755
—
Can stream Netshow over HTTP,
TCP or UDP.
XDCMP
No No No UDP/117
—
None.
1. No NAT support is available for name resolution through WINS.
2. If the MTU is too small to allow the Java or ActiveX tag to be included in one packet, stripping may not occur.
3. NetBIOS is supported by performing NAT of the packets for NBNS UDP port 137 and NBDS UDP port 138.
Table 5-1 Application Inspection Functions (continued)
Application PAT? NAT (1-1)? Configure? Default Port Standards Limitations/Comments
Commentaires sur ces manuels