Archive for June, 2011

Application Inspection of CCIE Security


A stateful Cisco CCIE firewall can easily examine the source and destination parameters of packets passing through it. Many applications use protocols that also embed address or port information inside the packet, requiring special handling for examination.
Application inspection allows a firewall to dig inside the packets used by certain applications. The firewall can find and [...]

Defining CCIE Security Policies in a Modular Policy Framework


Traditionally, Cisco firewalls have supported CCIE security policies that are applied to all traffic passing through them. Although that does offer a common level of security to all the protected networks and hosts, it doesn't offer a way to fine-tune or vary the policies according to differing requirements.
Beginning with PIX 7.0, a Cisco firewall can [...]