Hi guys,
How to write custom IPS signatures for blocking applications? I have found a few VPNs which are not on the application control list and I would like to block them.
Regards
This thread was automatically locked due to age.
Hi guys,
How to write custom IPS signatures for blocking applications? I have found a few VPNs which are not on the application control list and I would like to block them.
Regards
Hello Vineeth Penugonda,
Thank you for reaching out to the community, you can refer the following useful KBAs:
1.) Custom IPS signatures: https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/IntrusionPrevention/CustomIPSSignatures/index.html
2.) Add a custom IPS signature: https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/tasks/IpsCustomSignatureEdit.html
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Global Support & Services
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello Vineeth Penugonda,
Thank you for reaching out to the community, you can refer the following useful KBAs:
1.) Custom IPS signatures: https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/IntrusionPrevention/CustomIPSSignatures/index.html
2.) Add a custom IPS signature: https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/tasks/IpsCustomSignatureEdit.html
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Global Support & Services
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Thanks for the Custom IPS signature syntax link. Is there any tutorial for making a custom IPS signature for an "example application"? I am confused what to put in "content, rawbytes, offset, uricontent, byte_test" keywords.