cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
773
Views
4
Helpful
1
Replies

Custom Sig for detecting SSH on different ports

jnlawrence76
Level 1
Level 1

I was wondering if anyone has created or is aware of a custom IPS signature that detects someone using SSH on ports other than 22?

Thanks in Advance

1 Reply 1

Dustin Ralich
Cisco Employee
Cisco Employee

There are multiple built-in (Cisco-provided) signatures for this:

11233.0 - SSH Over Non-standard Ports (SSH Over Web Ports)

11233.1 - SSH Over Non-standard Ports (SSH Over HTTP Proxy)

11233.2 - SSH Over Non-standard Ports (SSH Over Socks)

11233.3 - SSH Over Non-standard Ports (SSH Over Non-SSH Ports)

The latter (11233.3) appears to most closely match what you describe.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card