cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

451
Views
5
Helpful
3
Replies
Highlighted
Beginner

Video Games regex or similar

Hi guys,

Does Cisco have any pre-defined application inspection regexes for video games such as World of Warcraft, Steam, PlayStation Network, etc…

Or is there a community site where these could be obtained?

Thank you.

Everyone's tags (7)
3 REPLIES 3
Highlighted
Cisco Employee

Re: Video Games regex or similar

Hello,

Unfortunately there are no pre-defined regexes that would help here. You would have to do some digging into the traffic itself to find out if there is anything you can reasonably filter on. Instead, you might be better off with the approach of blocking the specific ports used by the games. This might not work 100% successfully, but it would be a start. Here are a couple of links that might be helpful:

World of Warcraft Port Numbers:

http://us.blizzard.com/support/article.xml?locale=en_US&articleId=21015&rhtml=true

List of commonly used ports for various games/applications (including Steam and PSN):

http://portforward.com/cports.htm

Hope that helps.

-Mike

Highlighted
Beginner

Re: Video Games regex or similar

We are actually looking in permitting the games, but it is difficult to make the actual connections secure since majority of the ports that need to be open for games can be abused for p2p.

To make things even worst WoW uses torrent to update itself.

Other vendors such as SonicWall offer built-in signatures for that, but since we are running Cisco environment we would prefer to stay with Cisco.

Highlighted
Cisco Employee

Re: Video Games regex or similar

I know this is not exactly what you're looking for, but you could allow the ports and then use regex to block the P2P traffic. We do have some pre-built regexes for this type of thing:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml

If you scroll down to the "List of built-in regular expressions" section you'll see what I'm referring to.

By any chance do you have an IDS? You might have better luck doing this type of filtering there than with the ASA's functionality.

-Mike