Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TomerDi1987
New Contributor

custom ips signature

Hi,

I want to use IPs engine to block udp traffic that doesn't match specific byte in the payload.

I send udp data between to pc, the data payload in bytes is "74 65 73 74 74 65 73 74"

I want the IPs engine will check if "73" in byte number 3 how can I do it ?

I tried this, but its not working

F-SBID( --name "test"; --protocol udp; --pattern !"|73|"; --data_at 3,relative; --within 1,match;)

 

 

4 REPLIES 4
Anthony_E
Staff
Staff

Hello TomerDi1987,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony
Network Lab engineer.
TomerDi1987

Hi Anthony,

Thanks. I still didn't find the solution for this.

Hope to hear from you soon.

Anthony_E
Staff
Staff

Hello,

 

Count on us to find an answer to your question as soon as possible.

 

Regards,

Anthony
Network Lab engineer.
Anthony_E
Staff
Staff

Hello,

 

I have found this guide:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/f21167b4-200c-11e9-b6f6-f8bc12...

 

Could you please have a look and tell me if you find something interesting ?:)

 

Regards,

Anthony
Network Lab engineer.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors