Snort 3 inspection engine
Snort 3 is a network inspection engine that
-
serves as the default inspection engine for newly registered Firewall Threat Defense devices on version 7.0 or later,
-
requires explicit enablement after upgrading Firewall Threat Defense devices to version 7.0 or later, and
-
activates the Snort 3 version of the intrusion policy, which is applied through access control policies, for all traffic passing through the device.
For Firewall Threat Defense devices on version 6.x or earlier, Snort 2 is the default inspection engine.
Version switching and rule mapping
You can switch Snort versions when required. Snort 2 and Snort 3 intrusion rules are mapped and the mapping is system-provided. However, you may not find a one-to-one mapping of all the intrusion rules in Snort 2 and Snort 3. If you change the rule action for one rule in Snort 2, that change will not be retained if you switch to Snort 3 without first synchronizing Snort 2 with Snort 3. For more information on synchronization, see Synchronize Snort 2 rules with Snort 3.


Feedback