Add a custom IPS signature

  1. Go to Intrusion prevention > Custom IPS signatures and click Add.
  2. Type a name.
  3. Select a protocol.
  4. Specify a custom rule.
    keyword:"credit score"
    content:"www.facebook.com"
    srcport:443
  5. Select the severity.
  6. Select the recommended action to take when the firewall finds matching traffic.
    OptionDescription
    Allow packet Allow packet.
    Drop packet Drop packet.
    Drop session Terminate session. Use this setting to prevent an attack.
    Reset Reset session and send TCP reset packet to the originator.
    Bypass session Allow traffic and do not scan traffic for the rest of the session. Use this setting to allow certain types of traffic.
  7. Select Save.

Add the signature to a policy rule.