PAM

With PAM, you can define the nonstandard ports that are used by your applications so that CBAC can inspect those applications. Not every application can be mapped to a different port with PAM. In actuality, only a few applications can benefit from PAM, such as FTP, HTTP, RTSP, Session Initiation Protocol (SIP), SMTP, Telnet, and TFTP, to name a few.

Configuring Port Mappings

The syntax to define a nonstandard application port is

Router(config)# ip port-map appl_name port port_num
						

Commonly, some departments use standard ports, but other departments use nonstandard ports. Instead of globally enabling nonstandard ports throughout your organization, you can use an ACL to select exactly which devices use nonstandard ports. The syntax to do so ...

Get SECUR Exam Cram™ 2 (Exam 642-501) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.