cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1197
Views
0
Helpful
2
Replies

FireSIGHT Application Detector HTTP/SSLv2

Netmart
Level 3
Level 3

Hello,

I was wondering, whether it is possible to create an Application Detector for HTTPs connections including SSLv2 Client Hello Requests.

If not is there any alternative how to capture and eventually block those kind of events with FireSIGHT.

 

Thanks,

 

1 Accepted Solution

Accepted Solutions

yogdhanu
Cisco Employee
Cisco Employee

Hi

 

I am assuming you need to block any connection attempt with SSLv2.

You can do that using intrusion rules. Snort rule(1:38060) POLICY-OTHER SSLv2 Client Hello attempt is available which (if configured to block) would block any client hello packet with SSLv2

 

Hope this helps,

Yogesh

View solution in original post

2 Replies 2

yogdhanu
Cisco Employee
Cisco Employee

Hi

 

I am assuming you need to block any connection attempt with SSLv2.

You can do that using intrusion rules. Snort rule(1:38060) POLICY-OTHER SSLv2 Client Hello attempt is available which (if configured to block) would block any client hello packet with SSLv2

 

Hope this helps,

Yogesh

Thank you very much. Yes, that's what I meant.
Review Cisco Networking for a $25 gift card