CCIE Security: Cisco ASA HTTP Inspection and OSI Layer for IM and P2P Filtering

Layer of the OSI Model for Cisco ASA HTTP Inspection

Prev Question Next Question

Question

Which layer of the OSI model is referenced when utilizing http inspection on the Cisco ASA to filter Instant Messaging or Peer to Peer networks with the Modular Policy Framework?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

The OSI (Open Systems Interconnection) model is a conceptual framework used to describe the communication process between computer systems. The model is divided into seven layers, with each layer responsible for specific functions.

When utilizing http inspection on the Cisco ASA (Adaptive Security Appliance) to filter Instant Messaging or Peer to Peer networks with the Modular Policy Framework, the layer of the OSI model that is referenced is the application layer.

The application layer is the topmost layer of the OSI model and is responsible for providing services to end-user applications. It is the layer where the communication between the end-user and the network occurs. The application layer includes protocols like HTTP (HyperText Transfer Protocol), FTP (File Transfer Protocol), SMTP (Simple Mail Transfer Protocol), etc.

The http inspection feature on the Cisco ASA allows the administrator to inspect HTTP traffic in real-time and apply rules to filter out specific traffic based on content. The Modular Policy Framework (MPF) provides a flexible and powerful way to define security policies in the Cisco ASA.

When using http inspection with the MPF to filter Instant Messaging or Peer to Peer networks, the ASA inspects the HTTP traffic at the application layer. This allows the ASA to identify specific content within the HTTP traffic, such as Instant Messaging or Peer to Peer network traffic. Once the content is identified, the ASA can then apply the appropriate security policy to filter out the traffic.

In conclusion, the layer of the OSI model that is referenced when utilizing http inspection on the Cisco ASA to filter Instant Messaging or Peer to Peer networks with the Modular Policy Framework is the application layer.