List of protocols
- Built-in protocols — updated along with the SSG software version. Installing a new version requires a DPI reboot, which causes traffic interruption.
If needed, they can be supplemented with up-to-date attributes from the VAS Cloud. This is only necessary for complex protocols, but the option is available for all. - Cloud protocols created by VAS Experts — are periodically updated from the VAS Cloud. This ensures that popular applications remain up-to-date as their behavior changes. Description
- Custom (user-defined) protocols — protocols created by users via the GUI using VAS Cloud tools. These have higher priority than those loaded from the VAS Cloud, and within them, IP:PORT takes precedence over IP and CIDR. It is possible to add a protocol based on IP, SNI, or AS. Guide.
- DSL protocols — protocols described in the DSL language and connected to DPI as a separate module, without reinstalling the software or causing traffic interruption. Unlike custom protocols, a DSL protocol is a finite state machine that analyzes the first N packets of a flow against defined conditions (ports, AS numbers, payload bytes, DSL expressions) and determines whether the flow matches the protocol.
DSL protocols are created by VAS Experts specialists upon client request to Technical Support.
| Protocol | ID | DPI version | Protocol group | Protocol type | Update | Description |
|---|---|---|---|---|---|---|
| snmpssh | 5161 | 12.2 | Unknown | Built-in | As needed | snmpssh operates on port 5161 and supports SNMP over SSH for secure network management protocol communication. |
| snmpssh-trap | 5162 | 12.2 | Unknown | Built-in | As needed | snmpssh-trap operates on port 5162 and facilitates SNMP over SSH Trap for secure SNMP trap notifications. |
| ampl-tableproxy | 5196 | 12.2 | Unknown | Built-in | As needed | ampl-tableproxy operates on port 5196 and facilitates proxy communication for AMPL-based data tables in optimization software. |
| anydesk_cloud | 54273 | 12.2 | Remote control | Cloud | As needed | AnyDesk remote desktop cloud service. |
| DoT | 49281 | 12.4 | Tunneling, secure, ssl, pki | Built-in | As needed | DoT (DNS-over-TLS) is a protocol for encrypting DNS traffic using TLS. |
| RTCP | 49282 | 12.4 | RTP | Built-in | As needed | Real-time Transport Control Protocol, used alongside RTP for monitoring transmission quality. |
| LIGHTWAY | 49283 | 12.4 | VPN | Built-in | As needed | A fast and secure VPN protocol developed by ExpressVPN, designed for optimal speed and stability. |
| GOOGLE_MEET | 49284 | 12.4 | Video conference platforms | Built-in | As needed | A communication platform developed by Google for video and audio conferencing. It integrates with Google Workspace (formerly G Suite) |
| 49286 | 12.4 | Instant messengers | Built-in | As needed | A messaging service, social network, payment system, shopping and gaming platform. The protocol does not affect audio and video calls | |
| DTLS | 49287 | 12.4 | Tunneling, secure, ssl, pki | Built-in | As needed | DTLS (Datagram Transport Layer Security) provides TLS-equivalent security for UDP-based applications. |
| LIVEU_LRT | 49289 | 12.4 | RTP | Built-in | As needed | Low-latency, high-reliability transport protocol used by LiveU for video contribution over IP. |
| JITSI | 49285 | 12.4 | Video conference platforms | Built-in | As needed | Jitsi is an open-source platform that provides video conferencing, VoIP, and instant messaging capabilities. |
| DpiTunnel | 49290 | 13.1 | VPN | Built-in | As needed | A VPN designed to bypass deep packet inspection (DPI) filters used by some networks. |
| VK_CDN_VIDEO | 49291 | 13.1 | Video, pictures | Built-in | As needed | VK_CDN_Video is a content delivery protocol used by VK (VKontakte) for encrypted media streaming. |
| quic_unknown | 49293 | 13.1 | Web browsing | Built-in | As needed | QUIC protocol with unidentified or non-standard version or extensions. |
| QUIC_UNKNOWN_MARKED | 49294 | 13.1 | Web browsing | Built-in | As needed | QUIC protocol, unidentified version, with specific marking or flags. |
| LANTERN_WEAK | 49295 | 13.1 | VPN | Built-in | As needed | A version of Lantern designed to handle weak or restricted internet connections. |
| belblock | 54359 | 12.2 | Unknown | Cloud | As needed | belblock operates on port 54359 and handles encrypted communication for BEL Block devices or secure transport modules. |
| HLS VIDEO | 49298 | 13.2-BETA6 | Video, pictures | Built-in | As needed | HLS Video uses HTTP Live Streaming protocol from Apple for encrypted adaptive video delivery. |
| ICMP TUNNEL | 49299 | 13.2-BETA6 | VPN | Built-in | As needed | Uses ICMP (ping) packets for tunneling traffic, often to bypass restrictions where typical VPNs are blocked. |
Was this information helpful?