List of protocols

  1. Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
    If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all.
  2. Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
  3. Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
  4. DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
    DSL protocols are created by VAS Experts specialists upon client request to Technical Support.

ProtocolIDDPI versionProtocol groupProtocol typeUpdateDescription
netsc-dev15512.2Network servicesBuilt-inAs neededNetSC-Dev provides secure API access to development-stage smart card services.
sqlsrv15612.2Data basesBuilt-inAs neededSQLSRV is Microsoft's SQL Server protocol for encrypted client-server database communication.
knet-cmp15712.2Remote controlBuilt-inAs needed related to Kerberos network management.
pcmail-srv15812.2E-MailBuilt-inAs neededPCMail-Srv supports an early LAN-based email protocol suite for PC-based messaging.
nss-routing15912.2Network servicesBuilt-inAs neededNSS-Routing handles secure routing and message delivery over NSS-managed sessions.
sgmp-traps16012.2Debugging and measurementBuilt-inAs neededSGMP-Traps is the trap notification protocol for the Simple Gateway Monitoring Protocol (SGMP), used in legacy network devices.
snmp16112.2Debugging and measurementBuilt-inAs neededSNMP (Simple Network Management Protocol) enables monitoring and management of networked devices.
snmptrap16212.2Debugging and measurementBuilt-inAs neededSNMPTrap delivers unsolicited notifications (traps) from SNMP-managed devices to management systems.
cmip-man16312.2Application serversBuilt-inAs neededCMIP-MAN is part of the Common Management Information Protocol, used in network device management.
cmip-agent16412.2Application serversBuilt-inAs neededCMIP-Agent provides management data from devices using the Common Management Information Protocol.
xns-courier16512.2Application serversBuilt-inAs neededXNS-Courier is a transport protocol from the Xerox Network Systems suite, used in early networking environments.
s-net16612.2Network servicesBuilt-inAs neededS-NET protocol transmits real-time control data in fieldbus and industrial automation.
namp16712.2Network servicesBuilt-inAs neededNode Access Management Protocol authenticates device-level access in automation.
rsvd16812.2Network servicesBuilt-inAs neededRemote Storage Volume Daemon manages access and sync for virtual storage pools.
send16912.2Network servicesBuilt-inAs neededSecure Neighbor Discovery extension provides signed ICMPv6 messages for address validation.
print-srv17012.2PrintingBuilt-inAs neededA print server service used to manage print queues and jobs on a network.
multiplex17112.2Network servicesBuilt-inAs neededMultiplexes multiple application sessions over a single secure connection.
cl/117212.2Network servicesBuilt-inAs neededA protocol for CL/1 (Command Line 1), managing command line operations.
xyplex-mux17312.2Network servicesBuilt-inAs neededMultiplexer protocol for terminal servers and concentrators by Xyplex.
mailq17412.2E-MailBuilt-inAs neededMailQ protocol checks the mail delivery queue and manages retry logic securely.