
21-19
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 21 Applying Application Layer Protocol Inspection
Managing GTP Inspection
• The username, source IP address, destination IP address, NAT address, and the file operation are
logged.
• Audit record 201005 is generated if the secondary dynamic channel preparation failed due to
memory shortage.
In conjunction with NAT, the FTP application inspection translates the IP address within the application
payload. This is described in detail in RFC 959.
Managing GTP Inspection
This section describes how the GTP inspection engine works and how you can change its configuration.
This section includes the following topics:
• GTP Inspection Overview, page 21-19
• Enabling and Configuring GTP Inspection, page 21-20
• Verifying and Monitoring GTP Inspection, page 21-23
Note GTP inspection requires a special license. If you enter GTP-related commands on a security appliance
without the required license, the security appliance displays an error message.
GTP Inspection Overview
GPRS provides uninterrupted connectivity for mobile subscribers between GSM networks and corporate
networks or the Internet. The GGSN is the interface between the GPRS wireless data network and other
networks. The SGSN performs mobility, data session management, and data compression (See
Figure 21-2).
Figure 21-2 GPRS Tunneling Protocol
119935
Internet
Corporate
network 2
Corporate
network 1
Home PLMN
Gn
Gp
GRX
Roaming partner
(visited PLMN)
MS
SGSN GGSN
Gi
Komentarze do niniejszej Instrukcji