Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TuncayBAS
Contributor II

DNS tunneling traffic, how we can prevent with IPS.

below snort signatures for software iodine but did not use it on the FortiGate. How to FortiGate need to write these signatures?
 # detects iodine covert tunnels (over DNS), send feedback on rules to merc [at] securitywire.com
 alert udp any any -> any 53 (content:" |01 00 00 01 00 00 00 00 00 01|" ; offset: 2; depth: 10; content:" |00 00 29 10 00 00 00 80 00 00 00|" ;  \
 	  msg: " covert iodine tunnel request" ; threshold: type limit, track by_src, count 1, seconds 300; sid: 5619500; rev: 1;)
 alert udp any 53 -> any any (content: " |84 00 00 01 00 01 00 00 00 00|" ; offset: 2; depth: 10; content:" |00 00 0a 00 01|" ;  \
 	  msg: " covert iodine tunnel response" ; threshold: type limit, track by_src, count 1, seconds 300; sid: 5619501; rev: 1;)
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
5 REPLIES 5
Dave_Hall
Honored Contributor

Iodine is listed in app control as a proxy; I would imagine you can tailor an app sensor to block proxies over DNS traffic.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

I regularily use an AppControl sensor with these DNS misusers: DNS_DNS2TCP DNS_Dynamic.Update DNS_Request.ANY.Record DNS_Zone.Transfer TCP.Over.DNS
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
TuncayBAS
Contributor II

thanks for our answers but i want to ips signatures. app control use.
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
ede_pfau
SuperUser
SuperUser

AppControl is based on the IPS engine. Any reason why you don' t want to use it? CPU load won' t be affected much.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
TuncayBAS
Contributor II

ready to put into place, with the IPS How do I prevent this kind of traffic. I' m doing research. I also know that blocked with application control.
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors