This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG v18 Custom IPS signatures - multiple content values

Dear Sophos team and users,

we're actually trying to add multiple content values to a custom IPS signatures rule, like it's indicated in manual, but when we are saving, a warning pops up to say that the rule isn't valid.

example:

content:"manager/text/list";dstport:443;nocase;content:"manager/html";
we have try this one too:

content:"manager/text/list";content:"manager/html";dstport:443;nocase;

could you please explain why?

Thank you ahead.

Joel.



This thread was automatically locked due to age.
Parents
  • Hi,

    when you compare your rule to existing rules how does the format compare?
    ian

  • Hi Ian,

    could you be more accurate please?
    Is there a function for to compare the rules?

    Do you mean compare the custom IPS signatures? 
    I have used since the beginning just one content parameter for every signature.

    I've tried something new because we are receiving lot of scan attempt on our IPS Software on the Machines and we are trying to block these ones directly on the Sophos XG.

    Joel.

Reply
  • Hi Ian,

    could you be more accurate please?
    Is there a function for to compare the rules?

    Do you mean compare the custom IPS signatures? 
    I have used since the beginning just one content parameter for every signature.

    I've tried something new because we are receiving lot of scan attempt on our IPS Software on the Machines and we are trying to block these ones directly on the Sophos XG.

    Joel.

Children