Skip to main content
TuncayBAS
Explorer
September 28, 2016
Question

How can i convert rule

  • September 28, 2016
  • 0 replies
  • 1645 views

Rule :

alert udp $EXTERNAL_NET any -> $HOME_NET 53 (msg:"Potential NSTX DNS Tunneling"; content:"|01 00|"; offset:2; within:4; content:"cT"; offset:12; depth:3; content:"|00 10 00 01|"; within:255; classtype:badunknown; sid:1000 2;)

 

how can i this rule convert to fortigate ips rule.