Hello,
Is there any way of viewing the IPS signatures that come with Sophos XG, i.e. so I can learn from them as examples?
This thread was automatically locked due to age.
Hello,
Is there any way of viewing the IPS signatures that come with Sophos XG, i.e. so I can learn from them as examples?
There is a section in the online help to write your own IPS signatures.
__________________________________________________________________________________________________________________
Hi. Thanks for the reply. Yes I saw the patterns but I was more interested in seeing some examples, particular the ones than come as part of the default WAN->LAN setup. Because we've had some seemingly SQL injections that don't seem to have been detected so I was looking to see the default signatures as possible templates for our own.
Hi,
is this server open to the internet via a WAF rule or purely internal? If internal you are using the wrong IPS policy you should be using LAN-WAN policy.
Ian
XG115W - v19.5.1 mr-1 - Home
If a post solves your question please use the 'Verify Answer' button.
Hi,
is this server open to the internet via a WAF rule or purely internal? If internal you are using the wrong IPS policy you should be using LAN-WAN policy.
Ian
XG115W - v19.5.1 mr-1 - Home
If a post solves your question please use the 'Verify Answer' button.
OK so I think I may be able to use https://www.snort.org/downloads/#rule-downloads as a source of some examples.
Thanks for replies.