List of protocols

  1. Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
    If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all.
  2. Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
  3. Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
  4. DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
    DSL protocols are created by VAS Experts specialists upon client request to Technical Support.

ProtocolIDDPI versionProtocol groupProtocol typeUpdateDescription
mpm-flags4412.2Network servicesBuilt-inAs neededMPM-Flags transmits state triggers for media event-driven automation.
mpm4512.2Network servicesBuilt-inAs neededMPM (Media Policy Management) governs content control and routing in video delivery networks.
mpm-snd4612.2Network servicesBuilt-inAs neededMPM-SND initiates secure media play or alert messages in orchestration workflows.
ni-ftp4712.2Data transferBuilt-inAs neededNI-FTP is National Instruments' variant of FTP supporting secure transfers of measurement data.
auditd4812.2Debugging and measurementBuilt-inAs neededAuditD protocol transmits OS-level audit logs securely to central servers.
tacacs4912.2Network servicesBuilt-inAs neededTerminal Access Controller Access-Control System used for user authentication in networks.
re-mail-ck5012.2E-MailBuilt-inAs neededRe-Mail-CK manages encrypted resending and bounce-handling in complex mail routing environments.
la-maint5112.2Network servicesBuilt-inAs neededA protocol for LA Maintenance, maintaining LA networked systems.
xns-time5212.2Network servicesBuilt-inAs neededTime sync protocol in XNS for distributed system clock alignment.
dns5312.2Network servicesBuilt-inAs neededThe Domain Name System protocol, fundamental for translating domain names to IP addresses on the internet.
xns-ch5412.2Network servicesBuilt-inAs neededClearinghouse directory service used in legacy XNS networks.
isi-gl5512.2Debugging and measurementBuilt-inAs neededISI-GL protocol is used by Isilon systems for global namespace and sync management.
xns-auth5612.2Network servicesBuilt-inAs neededAuthentication protocol for Xerox Network Systems-based services.
xns-mail5812.2E-MailBuilt-inAs neededXNS-Mail is part of the Xerox Network Systems suite for legacy email message delivery.
ni-mail6112.2E-MailBuilt-inAs neededNI-Mail supports National Instruments' measurement data exchange over secured email protocols.
acas6212.2Network servicesBuilt-inAs neededA protocol for ACAS (Access Control and Authentication Service), controlling access.
whois++6312.2Network servicesBuilt-inAs neededEnhanced WHOIS protocol supporting structured queries and object retrieval.
covia6412.2Network servicesBuilt-inAs neededA protocol for Covia, a proprietary or niche network service.
tacacs-ds6512.2Network servicesBuilt-inAs neededTACACS Directory Service handles role/group access control extensions.
sql*net6612.2Data basesBuilt-inAs neededSQL*Net is the older name for Oracle Net, providing client-server encrypted database communication.