Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Biju_FTNT
Staff
Staff

Block IPsec phase 2 messages

Hi All,

 

I am using FortiGate-81E-POE v5.6.4,build1575,180425 (GA).

The Fortigate is a pass through for IKE and ESP packets. I am trying to block IPsec Phase 2 pass through messages.

Based on the captures, it is seen that the Phase 2 exchange type Quick mode has the hex of value 20. This is coming at an offset of 64.

Tried the following custom signatures, however this doesn't seem to work.Could someone help me out with this requirement.

F-SBID( --attack_id 6288; --name "Biju-Ike-Test"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --udp[64]=0x20; --flow bi_direction; --default_action drop;)

F-SBID( --attack_id 6288; --name "Biju-Ike-Test"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --within 100,packet; --flow bi_direction; --default_action drop;)

F-SBID( --attack_id 5669; --name "bv-ike-hex"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --flow bi_direction; --default_action drop;)

F-SBID( --attack_id 6288; --name "bv-Ike-Test"; --protocol UDP;  --dst_port 4500; --pattern "Quick Mode";)

 

Regards,

Biju

0 REPLIES 0
Labels
Top Kudoed Authors