Re: how would i.....signature wizard tcp ports 3127-3199
Signatures 9033 and 9233 were written to detect the MyDoom.C activity. These signature were built using the ATOMIC.TCP engine and cannot have a range attached to them.
If you want a port range the engine STRING.TCP is the one to use. This is the 'tcp stream' portion on the signature wizard. Once you get to the parameter ServicePort you can enter a range like 3127-3199 as a value.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...