Cisco ASA Series Firewall ASDM Configuration Guide
Chapter 11 Configuring Inspection of Basic Internet Protocols
FTP Inspection
• FTP Strict (prevent web browsers from sending embedded commands in FTP requests)—Enables
strict FTP application inspection, which causes the ASA to drop the connection when an embedded
command is included in an FTP request.
• Use the default FTP inspection map—Specifies to use the default FTP map.
• Select an FTP map for fine control over inspection—Lets you select a defined application inspection
map or add a new one.
• Add—Opens the Add Policy Map dialog box for the inspection.
FTP Class Map
The FTP Class Map dialog box is accessible as follows:
Configuration > Global Objects > Class Maps > FTP
The FTP Class Map pane lets you configure FTP class maps for FTP inspection.
An inspection class map matches application traffic with criteria specific to the application. You then
identify the class map in the inspect map and enable actions. The difference between creating a class
map and defining the traffic match directly in the inspect map is that you can create more complex match
criteria and you can reuse class maps. The applications that support inspection class maps are DNS, FTP,
H.323, HTTP, IM, and SIP.
• Name—Shows the FTP class map name.
• Match Conditions—Shows the type, match criterion, and value in the class map.
Match Type—Shows the match type, which can be a positive or negative match.
Criterion—Shows the criterion of the FTP class map.
Value—Shows the value to match in the FTP class map.
• Description—Shows the description of the class map.
• Add—Adds an FTP class map.
• Edit—Edits an FTP class map.
• Delete—Deletes an FTP class map.
Add/Edit FTP Traffic Class Map
The Add/Edit FTP Traffic Class Map dialog box is accessible as follows:
Configuration > Global Objects > Class Maps > FTP > Add/Edit FTP Traffic Class Map
The Add/Edit FTP Traffic Class Map dialog box lets you define a FTP class map.
• Name—Enter the name of the FTP class map, up to 40 characters in length.
• Description—Enter the description of the FTP class map.
• Add—Adds an FTP class map.
• Edit—Edits an FTP class map.