Cisco PIX 525 Spécifications Page 206

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 205
5-30
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Database and Directory Support
RTSP applications use the well-known port 554 with TCP (rarely UDP) as a control channel.
PIX
Firewall only supports TCP, in conformity with RFC 2326.
This TCP control channel will be used to negotiate the data channels that will be used to transmit
audio/video traffic, depending on the transport mode that is configured on the client.
The supported RDT transports are: rtp/avp, rtp/avp/udp, x-real-rdt, x-real-rdt/udp, and x-pn-tng/udp.
The PIX Firewall parses Setup response messages with a status code of 200. If the response message is
travelling inbound, the server is outside relative to the PIX
Firewall and dynamic channels need to be
opened for connections coming inbound from the server. If the response message is outbound, then the
PIX
Firewall does not need to open dynamic channels.
Because RFC 2326 does not require that the client and server ports must be in the SETUP response
message, the PIX
Firewall will need to keep state and remember the client ports in the SETUP message.
QuickTime places the client ports in the SETUP message and then the server responds with only the
server ports.
RTSP inspection does not support PAT or dual-NAT. Also, PIX Firewall cannot recognize HTTP
cloaking where RTSP messages are hidden in the HTTP messages.
VDO LIVE
VDO LIVE is a streaming multimedia service that allows users to receive audio and video streams from
across the Internet.
There are two connections, TCP for control messages and UDP for streams. TCP session uses a fixed
port of 7000; while the UDP source port is always 7001. The UDP stream uses a destination port
provided by the client over the control connection.
PIX Firewall monitors the VDO Live TCP control session and allows only the VDO live server system
to communicate with the client via the solicited UDP port with source port 7001. During this time, the
TCP channel should be active. When one goes down, PIX
Firewall tears down the other connection.
PIX Firewall bypasses the data channel by opening up the port that was negotiated in the control channel.
The application inspection scans the control channel and opens up the negotiated ports.
When NAT is involved, the negotiated IP address and the port number is NAT translated, which means
that the payload has to be modified.
Database and Directory Support
This section describes how to allow access to database or directory services through the PIX Firewall. It
includes the following topics:
ILS and LDAP, page 5-31
Network File System and Sun RPC, page 5-32
Oracle SQL*Net (V1/V2), page 5-33
Vue de la page 205
1 2 ... 201 202 203 204 205 206 207 208 209 210 211 ... 465 466

Commentaires sur ces manuels

Pas de commentaire