Skip to main content
learningall555555
New Member
January 31, 2020
Question

Enumerating ports in IPS TCP header options tcp.dst_port,--dst_port like p1,p2,p3,pN.

  • January 31, 2020
  • 0 replies
  • 1303 views

Hi,

i hope that you can help me with one problem.

I installed last stable firmware version (6.0.9 firmware version) on my FG, and currently testing/learning how to use IPS, and how to write custom IPS rules. In first day one problem emerged. Signature don't support   enumerating  ports in one IPS signature.

(testing with syntax  like F-SBID(--name xxxx; --protocol tcp;  --dst_port 2121,137,22,5555;).

 

Is it possible to enumerate more ports in one IPS signature (not range,  larger/smaller then) ?

I would like that  IPS signature with N tcp ports, trigger  when packets with any of tcp port   2121,137,22,5555 appear on interface.

Example rule which i tried don't work:

F-SBID( --attack_id 9999; --name " Scanning.Closed.Ports_enumerating" --default_action quarantine; --protocol tcp;  --dst_port 2121,137,22,5555;).

 

In manual i found syntax for single port, port range, larger then, smaller then.

Why we can't have simple enumerating like:  port1,port2,portx,porty, or i missed something in manual.  

Thanks for answer.

 

 

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!