Hi All,
I am using FortiGate-81E-POE v5.6.4,build1575,180425 (GA).
The Fortigate is a pass through for IKE and ESP packets. I am trying to block IPsec Phase 2 pass through messages.
Based on the captures, it is seen that the Phase 2 exchange type Quick mode has the hex of value 20. This is coming at an offset of 64.
Tried the following custom signatures, however this doesn't seem to work.Could someone help me out with this requirement.
F-SBID( --attack_id 6288; --name "Biju-Ike-Test"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --udp[64]=0x20; --flow bi_direction; --default_action drop;)
F-SBID( --attack_id 6288; --name "Biju-Ike-Test"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --within 100,packet; --flow bi_direction; --default_action drop;)
F-SBID( --attack_id 5669; --name "bv-ike-hex"; --protocol UDP; --dst_port 4500; --pattern "|20|"; --flow bi_direction; --default_action drop;)
F-SBID( --attack_id 6288; --name "bv-Ike-Test"; --protocol UDP; --dst_port 4500; --pattern "Quick Mode";)
Regards,
Biju
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.