Scanning Services and Other Firewall Features
Most firewalls are capable of performing scanning services, which means that they scan different types of incoming traffic in an effort to detect problems. For example, firewalls can scan incoming HTTP traffic to look for viruses or spyware, or they can scan email looking for spam. You can often set scanning rules that will prevent users from downloading files over a certain size. On Cisco routers, scanning is administered by the Content Security and Control Security Services Module (CSC-SSM). Two categories of content are typically scanned: mail and web.
Table 15.1 shows some key default scanning settings within CSC-SSM.
Table 15.1 Default scanning settings
Category | Protocol | Function |
SMTP and POP3 | Scans all scannable files in an email | |
SMTP and POP3 | Rejects all messages larger than 15 MB | |
SMTP | Rejects messages addressed to more than 100 recipients | |
SMTP | Cleans emails or attachments containing malware, and... |