List of protocols

  1. Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
    If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all.
  2. Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
  3. Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
  4. DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
    DSL protocols are created by VAS Experts specialists upon client request to Technical Support.

ProtocolIDDPI versionProtocol groupProtocol typeUpdateDescription
IDPR-CMTP6506212.2UnknownBuilt-inAs neededidpr-cmtp operates on port 65062 and supports control messaging for Inter-Domain Policy Routing extensions.
TP++6506312.2UnknownBuilt-inAs neededtp++ operates on port 65063 and supports communication in advanced transaction processing systems, enabling high-performance data exchange in distributed environments.
IL6506412.2UnknownBuilt-inAs neededil operates on port 65064 and refers to the IL protocol developed at Bell Labs for communication in Plan 9 operating systems.
IPv6-Encap6506512.2UnknownBuilt-inAs neededipv6-encap operates on port 65065 and supports encapsulation of packets using IPv6 tunneling techniques for interoperability across networks.
SDRP6506612.2UnknownBuilt-inAs neededsdrp operates on port 65066 and facilitates Source Demand Routing Protocol for source-initiated routing.
IPv6-Route6506712.2UnknownBuilt-inAs neededipv6-route operates on port 65067 and is associated with IPv6 routing headers used to direct packets through intermediate nodes.
IPv6-Frag6506812.2UnknownBuilt-inAs neededipv6-frag operates on port 65068 and handles IPv6 fragment header processing for packet reassembly.
IDRP6506912.2UnknownBuilt-inAs neededidrp operates on port 65069 and supports routing protocol functionality in Inter-Domain Routing Protocol environments.
RSVP6507012.2UnknownBuilt-inAs neededrsvp-e2e-ignore and rsvp operate on ports 65070–65158 and provide signaling for reservation of resources in IP networks using the Resource Reservation Protocol.
DSR6507212.2UnknownBuilt-inAs neededdsr operates on port 65072 and enables dynamic source routing protocol communication in ad hoc networks.
BNA6507312.2UnknownBuilt-inAs neededBrocade Network Advisor protocol used in SAN or LAN fabric management.
ESP6507412.2UnknownBuilt-inAs neededesp operates on port 65074 and supports Encapsulating Security Payload for secure IP packet encryption.
AH6507512.2UnknownBuilt-inAs neededAuthentication Header (AH) protocol used in IPsec for packet-level integrity and authentication.
I-NLSP6507612.2UnknownBuilt-inAs neededi-nlsp operates on port 65076 and refers to extended NLSP (NetWare Link Services Protocol) in internetworking environments.
SWIPE6507712.2UnknownBuilt-inAs neededswipe operates on port 65077 and supports IP-layer encryption and authentication via the Simple Web IP Security Protocol (SWIPE).
NARP6507812.2UnknownBuilt-inAs needednarp operates on port 65078 and supports Next-Hop Address Resolution Protocol in non-broadcast multi-access networks.
MOBILE6507912.2UnknownBuilt-inAs neededmobile operates on port 65079 and refers to generic or internal protocol used for mobile connectivity or synchronization.
TLSP6508012.2UnknownBuilt-inAs neededtlsp operates on port 65080 and refers to a transport layer security protocol with limited public documentation, used in secure network systems.
SKIP6508112.2UnknownBuilt-inAs neededskip operates on port 65081 and supports Simple Key Management for Internet Protocol (SKIP) for IPsec key exchange.
IPv6-ICMP6508212.2Network servicesBuilt-inAs neededA protocol for IPv6 ICMP (Internet Control Message Protocol), managing IPv6 control.