08-12-2022 05:24 AM
Dears,
Please help in creating an IPS rule that can drop a specific MD5, SHA hashes
Solved! Go to Solution.
08-12-2022 06:10 AM
Only SHA hashes are supported. You add them to a Custom Detection List (under Objects, Object Management, File List) and then make sure the feature is enabled under your File Policy and the file policy is applied in your Access Control Policy rules. Note you will only be able to detect files which are passing unencrypted through the devices. Normally that does not include anything in an SSL/TLS session (unless you have SSL decryption active for that flow). So... almost all of your web traffic is not normally seen by such a policy
08-12-2022 06:10 AM
Only SHA hashes are supported. You add them to a Custom Detection List (under Objects, Object Management, File List) and then make sure the feature is enabled under your File Policy and the file policy is applied in your Access Control Policy rules. Note you will only be able to detect files which are passing unencrypted through the devices. Normally that does not include anything in an SSL/TLS session (unless you have SSL decryption active for that flow). So... almost all of your web traffic is not normally seen by such a policy
08-14-2022 11:19 PM
Dear Marvin,
Thank you for the solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide