06-13-2019 02:56 PM - edited 02-21-2020 09:13 AM
Hello
Is there a way to write custom SNORT rules (for IPS) and OpenAppID scripts(for a new Protocol or an APP) and use them in FTD or Firepower Services?
Links would be appreciated.
Solved! Go to Solution.
06-14-2019 07:32 AM - edited 06-14-2019 07:33 AM
For custom snort rules you can check the following (The idea is the same, but the locations are a bit different, but mainly you would use the GUI provided editor or upload the custom rules into the FMC and enable them in your Intrusion rules) and syntax wise you can check any snort guide for further information.
http://www.labminutes.com/sec0175_asa_firepower_ips_custom_rule < version 5.X
https://www.youtube.com/watch?v=uN53tw_6bms < version 6.X
And for application detection, check these
http://www.labminutes.com/sec0169_asa_firepower_firepower_custom_application_detector_1
Hope the links help!
06-14-2019 07:32 AM - edited 06-14-2019 07:33 AM
For custom snort rules you can check the following (The idea is the same, but the locations are a bit different, but mainly you would use the GUI provided editor or upload the custom rules into the FMC and enable them in your Intrusion rules) and syntax wise you can check any snort guide for further information.
http://www.labminutes.com/sec0175_asa_firepower_ips_custom_rule < version 5.X
https://www.youtube.com/watch?v=uN53tw_6bms < version 6.X
And for application detection, check these
http://www.labminutes.com/sec0169_asa_firepower_firepower_custom_application_detector_1
Hope the links help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide