cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
481
Views
0
Helpful
2
Replies

Signature to compare data

avanzaadmin
Level 1
Level 1

Hi folks

I got a question today that left we thinking and no answer.

Can I, on an IPS 7.x, create a rule that compares data in a HTTP flow?

Example: User send a login request in clear text but the server responds with a different account. A custom packet sniffer app would store the data, extract the login, store it as a variable and then compare it with the response. Easy, but can the IPS do that?

Regards

Fredrik

1 Accepted Solution

Accepted Solutions

Scott Fringer
Cisco Employee
Cisco Employee

Fredrik;

  No, the IPS is not designed to store values for later comparison - it only checks the data in the current flow.

Scott

View solution in original post

2 Replies 2

Scott Fringer
Cisco Employee
Cisco Employee

Fredrik;

  No, the IPS is not designed to store values for later comparison - it only checks the data in the current flow.

Scott

Plain and simple, as I suspected. Thank you.

Regards

Fredrik

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card