Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NATHANJ
New Contributor

IPS on a specific policy

Hi Guys

 

We are trying to create a custom IPS signature to block all ports and just allow a specific port to go through.

Can an IPS signature achieve that?

Here's what we got so far using a specific port 23232

 

F-SBID(--name "TERMINAL"; --protocol tcp; --flow from_client; --dst_port !23232; )

 

Any help would be useful :)

3 REPLIES 3
ronalds_567
New Contributor

Hi Nathanj,

You can do that but you should do it easily using a custom service on your policy.

Hope it helps

Ronald

ronalds567
ronalds567
NATHANJ

Hi Robert 

 

Thanks. But i heard now they want the IPS signature more specific with patterns like:

"msgType"

"chain"

"store"

"terminal"

 

Do you know how we could fit that in, in the signature?

First time writing one :\

 

Labels
Top Kudoed Authors