FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 197874
Article
Description Bittorent custom IPS signature
Components
  • FortiOS 2.8 and 3.0.
Steps or Commands

To add a custom IPS signature, go to IPS>Signature>Custom and select Create New.

Bittorent_TCP

F-SBID( --name "Bittorent_TCP"; --attack_id 3630; --protocol tcp; --flow from_client; --default_action drop; --content "|69 74 54 6f 72 72 65 6e 74 20 70 72 6f 74 6f 63 6f 6c 65 78|")

Bittorrent_TCP_2

F-SBID( --name "Bittorrent_TCP_2"; --attack_id 9500; --protocol tcp; --flow from_client; --default_action drop; --content "announce?info_hash=")

Bittorrent_TCP_3

F-SBID( --attack_id 9501; --name "Bittorrent_TCP_3"; --protocol tcp; --flow from_client; --default_action drop; --content "info_hash=")

Bittorrent_UDP

F-SBID( --name "Bittorrent_UDP"; --attack_id 3754; --protocol udp; --default_action drop; --content "|64 31 3a 61 64 32 3a|")

Bittorrent_UDP_2

>F-SBID( --name "Bittorrent_UDP_2"; --attack_id 2795; --protocol udp; --default_action drop; --content "|1c b7 1d e0 e2 c9|")

Bittorrent_UDP_3

F-SBID( --name "Bittorrent_UDP_3"; --attack_id 2796; --protocol udp; --default_action drop; --content "|22 77 ea 3a 3d|")