<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/124096/sophos-xg-v18-custom-ips-signatures---multiple-content-values</link><description>Dear Sophos team and users, 
 
 we&amp;#39;re actually trying to add multiple content values to a custom IPS signatures rule, like it&amp;#39;s indicated in manual, but when we are saving, a warning pops up to say that the rule isn&amp;#39;t valid. 
 example: 
 content:&amp;quot;manager</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/thread/452847?ContentTypeID=1</link><pubDate>Tue, 17 Nov 2020 10:43:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f896a818-562f-4e10-b683-37da2134028f</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Sure you can, see:&amp;nbsp;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/concepts/IPSCustomSignatures.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/concepts/IPSCustomSignatures.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;But again, Port is not part of content.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/thread/452835?ContentTypeID=1</link><pubDate>Tue, 17 Nov 2020 07:00:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9114bd79-0616-4b7e-9f56-757cf41ea6cf</guid><dc:creator>JoelTimm</dc:creator><description>&lt;p&gt;Hi Toni,&lt;/p&gt;
&lt;p&gt;I have other IPS custom signatures and they&amp;#39;re working without any problem. I just ask if we can put more than one &amp;quot;content&amp;quot; parameter in the custom signature as it&amp;#39;s written in the manual and how. the fact is: IPS custom signature with 1 &amp;quot;content&amp;quot; parameter -&amp;gt; it works and it&amp;#39;s written in my reports, when the xg&amp;nbsp;is using my custom signature, but when the IPS custom signature with 2 or more &amp;quot;content&amp;quot; -&amp;gt; invalid error.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Joel Timm&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/thread/452713?ContentTypeID=1</link><pubDate>Mon, 16 Nov 2020 10:57:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fa904785-4dfb-4c04-9d58-e46b0677a804</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;First question, not related to IPS in specific, but more likely to this rule, are you decrypting HTTPS? Because you try to scan contant within HTTPs, which is not possible without decryption.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Your rule is likely invalid, as the content part covers the packet content, and not the Port.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For example:&amp;nbsp;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/tasks/IPSCustomSignatureAdd.html"&gt;https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/tasks/IPSCustomSignatureAdd.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/thread/452712?ContentTypeID=1</link><pubDate>Mon, 16 Nov 2020 10:43:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:796452fe-e129-424c-9481-5caae76c8d38</guid><dc:creator>JoelTimm</dc:creator><description>&lt;p&gt;Hi Ian,&lt;/p&gt;
&lt;p&gt;could you be more accurate please?&lt;br /&gt;Is there a function for to compare the rules?&lt;/p&gt;
&lt;p&gt;Do you&amp;nbsp;mean&amp;nbsp;compare the custom IPS signatures?&amp;nbsp;&lt;br /&gt;I have used since the beginning just one content parameter for every signature.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve tried something new because we are receiving lot of scan attempt on our IPS Software on the Machines and we are trying to block these ones directly on the Sophos XG.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Joel.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos XG v18 Custom IPS signatures - multiple content values</title><link>https://community.sophos.com/thread/452710?ContentTypeID=1</link><pubDate>Mon, 16 Nov 2020 10:03:38 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1cd2bb65-9244-4517-80d2-8fa53d7ab877</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;when you compare your rule to existing rules how does the format compare?&lt;br /&gt;ian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>