By default, the global policy used on a Cisco ASA firewall enables FTP inspection for all traffic passing through the appliance. Before discussing the usage of ftp inspection, let’s see how ftp works: In Active FTP (which is the default mode), we need two ports for communication. Port 21 is used for Command and Control […]
Archives for December 2008
5 Reasons to Buy a Cisco ASA 5505 from Amazon
For advanced home users or for SOHO and Branch offices, the Cisco ASA 5505 Firewall appliance is an excellent choice to use for network protection. Its Adaptive Security software is the same used for the whole range of the ASA series, so you can be assured that the 5505 will offer you also top-class security […]
Cisco ASA QoS for VoIP Traffic
One of the new additions in the Cisco ASA 7.x and 8.x software image is the ability to configure Quality of Service for VoIP traffic, something that was found only on IOS routers in the past. The ASA supports now Low Latency Queuing (LLQ priority queuing) which lets you prioritize certain traffic flows (such as […]
Antivirus and Antispam protection with CSC SSM
The CSC-SSM module of the Cisco ASA 5500 Firewall offers content security inspection for FTP, HTTP, POP3, and SMTP traffic, thus protecting the network from viruses, spyware, worms, spam and phishing, and controls unwanted mail and Web content. In more detail, the capabilities of the CSC-SSM module include the following: Antivirus and Antispyware protection using the Trend […]
IP Phones behind a Cisco ASA 5505 Firewall
The Cisco ASA 5505 firewall is an excellent device for small branch office locations since it can offer several network services in one box. It can provide firewall security, IPSEC VPN lan-to-lan connectivity with a central office, and even power-over-ethernet connectivity for local IP phones (two of its network interfaces are power-over-ethernet ports). A common […]
Cisco IDS/IPS Module for Cisco ASA Firewalls (AIP-SSM)
The Cisco ASA 5500 security appliance is not just a plain firewall. With an add-on security module (AIP-SSM), you can transform the ASA 5500 into an IDS/IPS sensor as well. The AIP-SSM (Advanced Inspection and Prevention – Security Services Module) is a full-blown IDS/IPS sensor with the same software and functionality like the external standalone […]