cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

Extreme Analytics Custom Fingerprint - Can you define a port range?

Extreme Analytics Custom Fingerprint - Can you define a port range?

Steve_Ballantyn
Contributor
Perhaps this should be a feature request, but I feel like I am just doing this wrong.

I have an application, GE Centricity, which likes to use a wide range of ports from 6000-6060. Sometimes it is talking directly to one of two servers. Since those two servers only run this one application, I can easily make a Fingerprint based on *address*. However - this application also loves to broadcast (yuck) and since the source IP can be one of a dozen VLAN's on my wireless network, and the destination is going to be *something* ending in 255 ... that leaves me a little lost.

I am trying to define a Fingerprint for a port range but I don't see a way to do that. What is the preferred method to handle this? Should I create 60 different rules, one for each port number, but all with the same application name and application group? Seems like the wrong way to do it.

EDIT: Here are some flow example screenies' ...

ff02b26c5862434bb9e41134687d5dd3_RackMultipart20180104-124096-egy6za-flow1_inline.jpg



ff02b26c5862434bb9e41134687d5dd3_RackMultipart20180104-72029-qoot25-flow2_inline.jpg

5 REPLIES 5

Steve_Ballantyn
Contributor
Thanks Jeff! I think it would be a very useful enhancement.

Hi Jeff,

i got a similar case with around 300 Fingerprints needed.

Can you give us a status on what you are planning to do?

If no changes are planned, is there an option to create custom fingerprints via script/API?

Thank you in advance.

It looks like Jeff put this in for me as a feature request (original case number 01420854). But since then, he has been waiting on engineering to implement the feature. Originally it was going to go into 8.2 or 8.3, but I imagine it was left on the cutting room floor.  šŸ˜‰

 

Hi Steve,

if thats the case, thats disappointing to hear.

Thanks for the quick heads up.

-Patrick

GTM-P2G8KFN