Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


CBAC Advantages

Sep 10,2009 by alperen

image

Understanding CBAC might be made easier if you think of it as reflexive ACLs without the limitations. CBAC adds inspection intelligence to ACL capabilities by reading the entire packet for application status information, which is stored in the state table. Like reflexive ACLS, CBAC watches outbound traffic to determine what packets to let in; but unlike reflexive ACLs, CBAC can make decisions based on how the application behaves, not only the addresses and port number it uses.

CBAC can open any additional inbound channels required for returning data that were negotiated by the outgoing data for a particular application.

When a session times out or ends, the state table and ACL entries are deleted, and the opening closes to additional traffic.

CBAC can be configured to inspect and filter the following IP sessions and application-layer protocols:


366 times read

Related news

» Context-Based Access Control (CBAC)
by alperen posted on Sep 10,2009
» CBAC Process
by alperen posted on Sep 10,2009
» CBAC Configuration
by alperen posted on Sep 20,2009
» CBAC Limitations
by alperen posted on Sep 10,2009
» Using Context-Based Access-Lists
by admin posted on Jul 21,2008
Did you enjoy this article?
Rating: 5.00Rating: 5.00Rating: 5.00Rating: 5.00Rating: 5.00 (total 53 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author