cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
373
Views
0
Helpful
2
Replies

how to create a custom IPS rule to drop specific MD5, SHA, hashes

 

Dears,

Please help in creating an IPS rule that can drop a specific MD5, SHA hashes

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Only SHA hashes are supported. You add them to a Custom Detection List (under Objects, Object Management, File List) and then make sure the feature is enabled under your File Policy and the file policy is applied in your Access Control Policy rules. Note you will only be able to detect files which are passing unencrypted through the devices. Normally that does not include anything in an SSL/TLS session (unless you have SSL decryption active for that flow). So... almost all of your web traffic is not normally seen by such a policy

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/network-malware-protection.html#ID-2193-00000296

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Only SHA hashes are supported. You add them to a Custom Detection List (under Objects, Object Management, File List) and then make sure the feature is enabled under your File Policy and the file policy is applied in your Access Control Policy rules. Note you will only be able to detect files which are passing unencrypted through the devices. Normally that does not include anything in an SSL/TLS session (unless you have SSL decryption active for that flow). So... almost all of your web traffic is not normally seen by such a policy

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/network-malware-protection.html#ID-2193-00000296

 

Dear Marvin,

Thank you for the solution.

Review Cisco Networking products for a $25 gift card