10-22
User
Guide

for

the

Cisco

Application

Networking

Manager

5.2
OL-26572-01
Chapter
10






Configuring

Parameter

Maps
Configuring
SIP

Parameter

Maps
Max.
Forward

Validation
Option
that

allows

you

to

configure

the

ACE

to

validate

the

value

of

the

Max-Forward

header
fi
eld

.
Specify
how

the

ACE

is

to

handle

the

validation

of

Max-Forward

header

fields.

The

choices
are
as

fo

llows:


N/A—The
ACE

is

not

to

validate

Max-Forward

header

fields.


Drop—The
ACE
is

to

drop

the

SIP

message
if
it

does

not

pass

Max-Forward

header
validation.


Deny—The
ACE

is

to

reset

the

SIP

connection
if
it

does

not

pass

Max-Forward

header
validation.
Log
Max.

Forward
Validation
Event
Check
box

that
instructs
the

ACE

to

log
Max-Forward
validation

events.
Uncheck
the

check

box

to

disable

this

feature.
Mask
UA

Software

Version
Check
box

that

instructs

the

ACE

to

mask

the

user

agent

software

version.

If

the

software
version
of

a

user

agent

is

exposed,

that

user

agent

might

be

vulnerable

to

attacks

from

hackers
who
exploit

the

security

holes

present

in

that

particular

software

version.

This

option

allows
you
to

mask

or

log

the

user

agent

software

version

so

that

it

is

not

exposed.
Uncheck
the

check

box

to

disable

this

feature.
Log
UA

Software

Version
Check
box

that

instructs

the

ACE

to

log

the

user

agent

software

version.
Uncheck
the

check

box

to

disable

this

feature.
Strict
Header

Validation
Action
that

the

ACE

is

to

take

to

handle

header

validation.

You

can

ensure

the

validity

of

SIP
packet
headers

by

configuring

the

ACE

to

check

for

the

presence

of

the

following

mandatory
SIP
header

fields:


From


To


Call-ID


CSeq


Vi
a


Max-Forwards
If
one

of

the

header

fields

is

missing

in

a

SIP

packet,

the

ACE

considers

that

packet

invalid.
The
ACE

also

checks

for

forbidden

header

fields,

according

to

RFC

3261.
Specify
how

the

ACE

is

to

handle

header

validation.

The

choices

are

as

follows:


N/A—The
ACE

does

not
to
perform

header

validation.


Drop—The
ACE

drops

the

SIP

message

if

the

SIP

packet

does

not
pass
header

validation.


Reset—The
ACE

resets

the

connection

if

the

SIP

packet

does

not

pass

header

validation.
Log
Strict

Header

Validation
Check
box

that

instructs

the

ACE

to

log

header

validation

events.
Uncheck
the

check

box

to

disable

this

feature.
Mask
Non

SIP

URI
Check
box

that

instructs

the

ACE

to

mask

non-SIP

URIs

in

SIP

messages.

This

option

and

the
next
enable

the

detection

of

no

n-SIP

URI s

in

SIP

messages.
Uncheck
the

check

box

to

disable

this

feature.
Table
10-9
SIP
Parameter

Map

Attributes

(continued)
Field
Description