cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1770
Views
5
Helpful
2
Replies

Sourcefire IAB with Custom Application Detectors

Ryan G
Level 1
Level 1

Is it possible to create Intelligent Application Bypass rules that leverage custom application detectors? Is it possible to leverage access policy rules with custom application detectors?

 

When I attempt to do so, they do not show as available applications for selection.

 

I'm trying to detect a URL (and certificate common name) for a particular patch management system and intelligently bypass when elephant flows are rampant. Here is just the URL for now...

 

rule01.PNGrule02.PNG

 

However, it does not show-up as an option in the access rule or IAB add:

rule03.PNGrule04.PNG

Entirely possible I'm doing something wrong... new to the platform.

 

Thanks

-Ryan

1 Accepted Solution

Accepted Solutions

mikael.lahtela
Level 4
Level 4

Hi,

Try creating a custom "Application Protocol" (Add) in the first picture, haven't tried it but looks like you can create a custom and it shows up in the application list in IAB.
I created one for URL and I got a hit in the event list with the custom application name.

Edit: Haven't found a way to delete the Application Protocol once it is created.


br, Micke

View solution in original post

2 Replies 2

mikael.lahtela
Level 4
Level 4

Hi,

Try creating a custom "Application Protocol" (Add) in the first picture, haven't tried it but looks like you can create a custom and it shows up in the application list in IAB.
I created one for URL and I got a hit in the event list with the custom application name.

Edit: Haven't found a way to delete the Application Protocol once it is created.


br, Micke

Thank you much.
Review Cisco Networking for a $25 gift card