Cisco PIX: Advanced Features and Attack Guards

This sample chapter from Cisco Secure PIX Firewalls introduces the concepts and configuration elements of the Cisco Secure PIX Firewall features necessary to securely handle multichannel TCP applications. You will learn about advanced protocol handling, multimedia support, and attack guards.

Cisco Secure PIX Firewalls

This section summarizes the key points in this chapter.

  • The PIX offers an application-aware feature called a fixup protocol to enable the PIX to respond to the needs of complex mutlichannel applications by monitoring their control channels and dynamically opening and closing ports as needed by the protocol being monitored.

  • The PIX is able to securely handle the popular RTSP and H.323 multimedia protocols.

  • The PIX also features attack guards to mitigate threats to e-mail servers, DNS responses, fragmentation attacks, and certain types of DoS attacks.

