You are here
SEC0175 - ASA FirePower IPS Custom Rule
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video shows you how to create a custom intrusion rule on Cisco ASA FirePower. We will generate a special HTTP request to simulate malicious traffic and build an intrusion rule to match the content of the request and drop it. You will learn available parameters that you can use on FireSight web interface Rule Editor to define attack signature.
Topic:
- Intrusion Rule Editor
- Custom Intrusion Rule
- Intrusion Rule Content Matching
- Custom HTTP Request
- Wireshark Packet Capture
2 comments
Except HTTP URI
How can i except an HTTP URI?
I want to except a path with /admin content, but only a website.
Thanks
Except HTTP URI
You can do a whitelist of the URL as part of Security Intelligence.