Provides an overview of the Snort inspection engine, and the network analysis and intrusion policies. It provides an insight into system-provided and custom network analysis and intrusion poliies, their requirements and prerequisites for these policies.
The Snort inspection engine is an integral part of the Firewall Threat Defense. In most cases, the system-provided policies are all you need. For advanced users with specific needs, you can create custom rules.
To configure custom Snort 2 rules, see Custom Snort 2 Intrusion Policies for Access Control.
Intrusion prevention
Describes the intrusion detection and prevention feature that uses network analysis and intrusion policies to monitor, analyze, and protect against network threats.
Snort inspection engine
Describes a traffic analysis component that provides real-time deep packet inspection capabilities.
Snort 3
Describes the latest version of the Snort inspection engine. This version includes improvements over prior versions.
Multi-layer inspection
Provides an overview of the multi-layer inspection feature in Snort 3
Guidelines and limitations for network analysis and intrusion policies
Consider the feature limitations of Snort 3 for Firewall Management Center-managed Firewall Threat Defense devices when planning your network security deployment.
Prerequisites for network analysis and intrusion policies
Provides the prerequisites for enabling network analysis and management of intrusion policies.
How policies examine traffic for intrusions
Describes how the system analyzes traffic through network analysis and intrusion prevention phases in access control deployments.
System-provided and custom network analysis and intrusion policies
Describes how system-provided and custom network analysis and intrusion policies work together in access control policies to examine and process network traffic for security threats.