cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1072
Views
0
Helpful
2
Replies

FireSIGHT Application Detector HTTP/SSLv2

Netmart
Level 1
Level 1

Hello,

I was wondering, whether it is possible to create an Application Detector for HTTPs connections including SSLv2 Client Hello Requests.

If not is there any alternative how to capture and eventually block those kind of events with FireSIGHT.

 

Thanks,

 

1 Accepted Solution

Accepted Solutions

yogdhanu
Cisco Employee
Cisco Employee

Hi

 

I am assuming you need to block any connection attempt with SSLv2.

You can do that using intrusion rules. Snort rule(1:38060) POLICY-OTHER SSLv2 Client Hello attempt is available which (if configured to block) would block any client hello packet with SSLv2

 

Hope this helps,

Yogesh

View solution in original post

2 Replies 2

yogdhanu
Cisco Employee
Cisco Employee

Hi

 

I am assuming you need to block any connection attempt with SSLv2.

You can do that using intrusion rules. Snort rule(1:38060) POLICY-OTHER SSLv2 Client Hello attempt is available which (if configured to block) would block any client hello packet with SSLv2

 

Hope this helps,

Yogesh

Thank you very much. Yes, that's what I meant.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card