Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Revert from Snort 3.0 for FDM-Managed device

Want to summarize with AI?

Log in

Learn how to revert an FDM-managed device from Snort 3 to Snort 2 in Security Cloud Control Firewall Management and monitor the reversion process.


Some intrusion rules in Snort 2.0 might not exist in Snort 3.0. If you downgrade to 2.0, any custom intrusion policies that you created are converted to the base policy used in the custom policy. As far as possible, rule action overrides are retained. If more than one custom policy uses the same base policy, the overrides of the custom policy that is used in the most access control policies are retained, and the overrides for the other custom policies are lost. Access control rules that used these"duplicate"policies will now use the base policy created from your most-used custom policy. All custom policies are deleted.

Before you opt to revert from Snort 3.0, read Managing Intrusion Policies (Snort2) of the Firepower Device Manager Configuration Guide and find out how switching snort engine versions will affect your current rules and policies.

Note

Reverting to version 2 does not uninstall the Firepower software version.


Revert From Snort 3.0

If you change the Snort version,the system will perform an automatic deployment to implement the change. Note that you can only revert individual devices from Snort 3.0 to version 2.

Use the following procedure to revert the intrusion prevention engine:

Procedure

1.

In the navigation pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and and click the device you want to revert.

4.

In the Device Actions pane located to the right, click Upgrade.

5.

Set the upgrade toggle to Intrusion Prevention Engine.

6.

In Step 1, confirm you want to revert from Snort version 3, and click Revert to Snort Engine 2.

7.

From the Security Devices page, devices that are upgrading have a "Upgrade in Progress" configuration status.