
5-4
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Using the fixup Command
Using the fixup Command
You can use the fixup command to change the default port assignments or to enable or disable
application inspection for the following protocols and applications:
• CTIQBE (disabled by default)
• DNS
• ESP-IKE (disabled by default)
• FTP
• H.323
• HTTP
• ILS
• MGCP (disabled by default)
• PPTP (disabled by default)
• RSH
• RTSP
• SIP
• SKINNY (SCCP)
• SMTP
• SNMP
• SQL*Net
• TFTP
The basic syntax for the fixup command is as follows:
[no] fixup protocol [protocol] [port]
To change the default port assignment, identify the protocol and the new port number to assign. Use the
no fixup protocol command to reset the application inspection entries to the default configuration.
Note Disabling or modifying application inspection only affects connections that are initiated after the
command is processed. Disabling application inspection for a specific port or application does not affect
existing connections. If you want the change to take effect immediately, enter the clear xlate command
to remove all existing application inspection entries. If there are no xlates, such as nat 0 access-list, use
clear local-host instead of clear xlate to disable or modify application inspection.
The following is the detailed syntax of the fixup command showing the syntax for each configurable
application:
fixup protocol ctiqbe 2748 | dns [maximum-length max-len] | esp-ike | ftp [strict] [port] |
http [port[-port]] | h323 h225 | ras [port[-port]] | ils [port[-port]] | mgcp
[port[-port]| pptp 1723 | rsh
[514] | rtsp [port] | sip udp [port] | skinny [port] | smtp
[port[-port]]
| sqlnet [port[-port]]
Komentarze do niniejszej Instrukcji