8
Release Notes for the Cisco ASA 5500 Series, Version 8.2(x)
OL-18971-02
New Features
Inspection for
IP Options
You can now control which IP packets with specific IP options should be allowed through the
adaptive security appliance. You can also clear IP options from an IP packet, and then allow it
through the adaptive security appliance. Previously, all IP options were denied by default, except
for some special cases.
Note This inspection is enabled by default. The following command is added to the default global
service policy: inspect ip-options. Therefore, the adaptive security appliance allows RSVP
traffic that contains packets with the Router Alert option (option 20) when the adaptive
security appliance is in routed mode.
The following commands were introduced: policy-map type inspect ip-options, inspect
ip-options, eool, nop.
Enabling Call Set up
Between H.323
Endpoints
You can enable call setup between H.323 endpoints when the Gatekeeper is inside the network. The
adaptive security appliance includes options to open pinholes for calls based on the
RegistrationRequest/RegistrationConfirm (RRQ/RCF) messages.
Because these RRQ/RCF messages are sent to and from the Gatekeeper, the calling endpoint IP
address is unknown and the adaptive security appliance opens a pinhole through source IP
address/port 0/0. By default, this option is disabled.
The following command was introduced: ras-rcf-pinholes enable (under the policy-map type
inspect h323 > parameters commands).
Also available in Version 8.0(5).
Unified Communication Features
Mobility Proxy
application no longer
requires Unified
Communications Proxy
license
The Mobility Proxy no longer requires the UC Proxy license.
Interface Features
In multiple context
mode, auto-generated
MAC addresses now use
a user-configurable
prefix, and other
enhancements
The MAC address format was changed to allow use of a prefix, to use a fixed starting value (A2),
and to use a different scheme for the primary and secondary unit MAC addresses in a failover pair.
The MAC addresess are also now persistent accross reloads.
The command parser now checks if auto-generation is enabled; if you want to also manually assign
a MAC address, you cannot start the manual MAC address with A2.
The following command was modified: mac-address auto prefix prefix.
Also available in Version 8.0(5).
Support for Pause
Frames for Flow Control
on the ASA 5580 10
Gigabit Ethernet
Interfaces
You can now enable pause (XOFF) frames for flow control.
The following command was introduced: flowcontrol.
Firewall Features
Table 3 New Features for ASA Version 8.2(2) (continued)
Feature Description
Comments to this Manuals