List of protocols

  1. Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
    If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all.
  2. Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
  3. Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
  4. DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
    DSL protocols are created by VAS Experts specialists upon client request to Technical Support.

ProtocolIDDPI versionProtocol groupProtocol typeUpdateDescription
systat1112.2Debugging and measurementBuilt-inAs neededSystat protocol provides legacy system statistics like uptime and load averages.
daytime1312.2Debugging and measurementBuilt-inAs neededDaytime is a diagnostic time protocol returning current server time in plaintext (legacy).
qotd1712.2Debugging and measurementBuilt-inAs neededQOTD (Quote of the Day) is a legacy protocol returning a quote string for diagnostics.
msp1812.2Remote controlBuilt-inAs neededManaged service provider system.
chargen1912.2Debugging and measurementBuilt-inAs neededChargen (Character Generator) protocol sends a continuous stream of characters, used for testing.
ftp-data2012.2Data transferBuilt-inAs neededFTP-DATA carries the actual file contents in an FTP transfer session, often over port 20.
ftp2112.2Data transferBuilt-inAs neededFTP (File Transfer Protocol) is a legacy file transfer protocol with optional TLS/SSL encryption.
ssh2212.2Remote controlBuilt-inAs neededSecure Shell protocol for encrypted remote access.
telnet2312.2Remote controlBuilt-inAs neededStandard remote terminal access protocol.
smtp2512.2E-MailBuilt-inAs neededSMTP (Simple Mail Transfer Protocol) handles outbound mail delivery with optional TLS.
nsw-fe2712.2Debugging and measurementBuilt-inAs neededNSW-FE protocol provides secure access to front-end services in Novell's legacy workstation tools.
msg-icp2912.2Debugging and measurementBuilt-inAs neededMsg-ICP is a messaging control protocol used in internal content distribution systems.
msg-auth3112.2Debugging and measurementBuilt-inAs neededMsg-Auth manages secure authentication and session binding in messaging platforms.
dsp3312.2Debugging and measurementBuilt-inAs neededDSP (Domain Specific Protocol) refers to a custom application protocol with a narrow scope of encrypted data exchange.
time3712.2Debugging and measurementBuilt-inAs neededTime protocol returns current system time as a 32-bit value, used in early time sync implementations.
rap3812.2Network servicesBuilt-inAs neededRouting Access Protocol enables dynamic service advertisement and queries.
rlp3912.2Network servicesBuilt-inAs neededReliable Link Protocol manages robust link-layer transmission in wireless networks.
graphics4112.2Debugging and measurementBuilt-inAs neededGraphics protocol delivers remote graphical output for thin clients or display managers.
nameserver4212.2Network servicesBuilt-inAs neededProvides hostname-to-address mapping in early distributed systems.
nicname4312.2Network servicesBuilt-inAs neededLegacy protocol used for domain whois queries and registry lookups.