Cisco Application (port) Inspection

Sample of default default global policy:

class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
service-policy global_policy global

Disable default global inspection for sip application:

ASA5520(config)#policy-map global_policy
ASA5520(config-pmap)#class inspection_default
ASA5520(config-pmap-c)#no inspect sip         (for tun on back: #inspect sip)
pASA5520(config-pmap-c)#wr (save config)


