14
Release Notes for the Cisco ASA 5500 Series, Version 8.2(x)
OL-18971-02
New Features
Processing H.323
Endpoints When the
Endpoints Do Not Send
OLCAck
H.323 application inspection has been enhanced to process common H.323 endpoints. The
enhancement affects endpoints using the extendedVideoCapability OLC with the H.239 protocol
identifier. Even when an H.323 endpoint does not send OLCAck after receiving an OLC message
from a peer, the adaptive security appliance propagates OLC media proposal information into the
media array and opens a pinhole for the media channel (extendedVideoCapability).
IPv6 in transparent
firewall mode
Transparent firewall mode now participates in IPv6 routing. Prior to this release, the adaptive
security appliance could not pass IPv6 traffic in transparent mode. You can now configure an IPv6
management address in transparent mode, create IPv6 access lists, and configure other IPv6
features; the adaptive security appliance recognizes and passes IPv6 packets.
All IPv6 functionality is supported unless specifically noted.
Botnet Traffic Filter Malware is malicious software that is installed on an unknowing host. Malware that attempts
network activity such as sending private data (passwords, credit card numbers, key strokes, or
proprietary data) can be detected by the Botnet Traffic Filter when the malware starts a connection
to a known bad IP address. The Botnet Traffic Filter checks incoming and outgoing connections
against a dynamic database of known bad domain names and IP addresses, and then logs any
suspicious activity. You can also supplement the dynamic database with a static database by
entering IP addresses or domain names in a local “blacklist” or “whitelist.”
Note This feature requires the Botnet Traffic Filter license. See the following licensing document
for more information:
http://www.cisco.com/en/US/docs/security/asa/asa82/license/license82.html
The following commands were introduced: dynamic-filter commands (various), and the inspect
dns dynamic-filter-snoop keyword.
AIP SSC card for the
ASA 5505
The AIP SSC offers IPS for the ASA 5505 adaptive security appliance. Note that the AIP SSM does
not support virtual sensors. The following commands were introduced: allow-ssc-mgmt,
hw-module module ip, and hw-module module allow-ip.
IPv6 support for IPS You can now send IPv6 traffic to the AIP SSM or SSC when your traffic class uses the match any
command, and the policy map specifies the ips command.
Management Features
Table 4 New Features for ASA Version 8.2(1) (continued)
Feature Description
Comments to this Manuals