Custom-defined packet grep protocols section is where you can view the list of custom-defined packet grep protocols and also create new ones. Custom-defined packet grep protocols can be used when creating a Native Trellix IPS Format custom attack with Text in Custom Application template.
- — Add a new packet grep protocol instance.
.png)
— Delete a created instance.Note
You cannot modify a default custom-defined packet grep protocol.
Custom-defined Packet Grep Protocols window.png)
When you add a packet grep protocol, you need to specify the transport layer protocol and the identifying port(s) for locating those attacks that use an application protocol unknown to Trellix IPS.
The interface fields and options are as follows:
Name — Name displayed during selection. For example, type "Custom-Adobe-Flash" for the Name.
Transport Protocol — Specify the transport protocol that will be used by the application whose protocol details that you are defining.
TCP
UDP
Ports — Target ports that have been added for the current custom protocol. Type the number in this field, and then click Add to add a port that can be used to identify the unknown traffic.
Note
Do not enter any standard port number.