Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TomerDi1987
New Contributor

custom ips signature

Hi,

I want to use IPs engine to block udp traffic that doesn't match specific byte in the payload.

I send udp data between to pc, the data payload in bytes is "74 65 73 74 74 65 73 74"

I want the IPs engine will check if "73" in byte number 3 how can I do it ?

I tried this, but its not working

F-SBID( --name "test"; --protocol udp; --pattern !"|73|"; --data_at 3,relative; --within 1,match;)

 

 

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello TomerDi1987,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
TomerDi1987

Hi Anthony,

Thanks. I still didn't find the solution for this.

Hope to hear from you soon.

Anthony_E
Community Manager
Community Manager

Hello,

 

Count on us to find an answer to your question as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

I have found this guide:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/f21167b4-200c-11e9-b6f6-f8bc12...

 

Could you please have a look and tell me if you find something interesting ?:)

 

Regards,

Anthony-Fortinet Community Team.
Labels
Top Kudoed Authors