06-19-2013 11:13 PM - edited 03-10-2019 05:59 AM
Hello Experts,
I want to create a custom-signature to block all TELNET traffic going across my IOS IPS. I tried alot but it didnt work for me. i created a sig with String-Tcp engine > added regex and telnet port=23 but it does not work.
can any one help me, plz ?
06-20-2013 02:27 AM
Hope that this suites you.
Post something if you have some doubts.
Best Regards
Hugo Rodrigues
06-20-2013 10:26 AM
What you have posted is blocking telnet through normal router ios . but my question was how to block telnet through IOS IPS.
06-20-2013 02:24 PM
Try using Atomic IP engine, for any packet using TCP/23 drop the packet.
There's also some signatures which detect Telnet over non-standard ports which you might consider turning on.
06-22-2013 09:07 AM
I used Atomic ip engine aswell, but that is also not working. i tried droping all packets for TCP/23 but it is not blocking telnet traffic. but on other hand if i try blocking the whole ip then telnet will be blocked. but if i try blocking only port tcp/23 it does not get any effect
any help, this is a ccie lab question and i have to work it out asap
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide