1
# SNMP - Simple Network Management Protocol - RFC 1157
2
# Pattern quality: good veryfast
3
# Usually runs on UDP ports 161 (monitoring) and 162 (traps)
5
# These filters match SNMPv1 packets without fail, and are made
6
# as specific as possible not to match any ASN.1 encoded protocols.
7
# However these could still be matched by other protocols that
10
# Contributed by Goli SriSairam <goli_sai AT yahoo.com>
12
# This pattern has been tested and is believed to work well. If it does not
13
# work for you, or you believe it could be improved, please post to
14
# l7-filter-developers@lists.sf.net . This list may be subscribed to at
15
# http://lists.sourceforge.net/lists/listinfo/l7-filter-developers
17
# All SNMPv1 traffic. See snmp-mon.pat and snmp-trap.pat for details.
19
^\x02\x01\x04.+([\xa0-\xa3]\x02[\x01-\x04].?.?.?.?\x02\x01.?\x02\x01.?\x30|\xa4\x06.+\x40\x04.?.?.?.?\x02\x01.?\x02\x01.?\x43)