Nonstandard Application Port Implementation

We have not discussed the use of nonstandard application port numbers. It was common for companies to use port 8080 for HTTP instead of the standard port 80. Other applications allow for the use of nonstandard ports, such as FTP, SMTP, and Telnet.

However, CBAC expects traffic to be on standard application ports, and it does not inspect applications that use nonstandard ports. Obviously, that is not good. The Cisco solution is PAM.

CBAC does not inspect application traffic running on nonstandard application ports unless you use PAM.

Get SECUR Exam Cram™ 2 (Exam 642-501) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.