HTTP Inspection Engine
HTTP or web traffic is one of the most popular types of traffic on networks today. ASA includes the ability to inspect HTTP traffic flows to detect possible network attacks. You can initiate the process to configure the inspection of an HTTP traffic flow under the Service Policy Rules section. This process to initiate the creation of a traffic flow for HTTP inspection is similar to the process to define a traffic flow with Service Policy Rules for IPS inspection as described in the "Intrusion Prevention Service" section earlier in this chapter. The configuration to inspect a certain HTTP traffic flow results in a class-map and policymap statement, similar to the CLI output for the IPS Service Policy Rule configuration.
The HTTP inspection engine allows the ASA to mitigate potential network attacks that are tunneled over TCP port 80, the HTTP port. The HTTP inspection engine also verifies that the network traffic is RFC-compliant and not a series of malformed or handcrafted packets designed to potentially launch a network attack. URL length is also inspected to help detect any handcrafted large URLs that can be designed to create a network attack.
ASDM features an easy-to-use wizard to walk you through the Service Policy Rule definition process. You can configure HTTP inspection globally for all traffic through the ASA, or you can configure protocol inspection for a single interface. In the Add Service Policy Rule Wizard, as shown in Figure 3-14, you can configure a rule to be global, which applies to all interfaces on the ASA.
Figure 3-14. Global Rule to Inspect HTTP
[View full size imagel
The next step is specification of what traffic or ports will be inspected .Figure 3-15 displays an example of how to select the inspection of TCP packets, and Figure 3-16 configures the HTTP/web service to inspect HTTP/WWW, or TCP port 80.
Continue reading here: Figure 331 URL Blocking in Trend Micro Inter Scan
Was this article helpful?