Modular Policy Framework (MPF)

Lesson 1 of 6

Introduction

In this lesson, we will configure the Modular Policy Framework (MPF) on the ASA firewall to perform granular traffic inspection for FTP connections. This is crucial in a real network as it allows us to control and secure specific commands sent to an FTP server, ensuring that only authorized actions are permitted.

Topology & Device Table

        +-------------------+
        |      Internet     |
        +-------------------+
                |
                |  (Outside)
                |
         +--------------+
         |     ASA1     |
         |  10.1.101.10 |
         +--------------+
         | E0/0         |
         | E0/1         |
         | E0/2         |
         +--------------+
                |
                |  (DMZ)
                |
         +-------------------+
         |      FTP Server   |
         |   10.1.104.20     |
         +-------------------+
                |
                |  (Inside)
                |
         +--------------+
         |      R1      |
         |  10.1.101.1  |
         +--------------+
         | F0/0         |
         +--------------+
                |
                |  (Inside)
                |
         +--------------+
         |      R2      |
         |  10.1.102.2  |
         +--------------+
         | G0/0         |
         +--------------+
                |
                |  (Inside)
                |
         +--------------+
         |      R4      |
         |  10.1.104.4  |
         +--------------+
         | F0/0         |
         +--------------+
DeviceInterfaceIP AddressSubnet MaskRole
ASA1E0/010.1.101.10255.255.255.0Firewall
ASA1E0/110.1.101.10255.255.255.0Firewall
ASA1E0/210.1.104.10255.255.255.0Firewall
R1F0/010.1.101.1255.255.255.0Router
R2G0/010.1.102.2255.255.255.0Router
R4F0/010.1.104.4255.255.255.0Router
FTPN/A10.1.104.20255.255.255.0Server

Subscribe to unlock this lesson

₹7,999/year

Full access to all 6 lessons in this course, plus 74 more lab courses, quizzes, and AI mock interviews. 365 days.

Already have an account? Sign in