Learn how to manage Snort 3 intrusion policies and configure access control rules for effective intrusion detection and prevention.
This chapter provides information on managing Snort 3 intrusion policies and access control rule configurations for intrusion detection and prevention.
Intrusion policies
Describes defined sets of intrusion detection and prevention configurations that inspect traffic for security violations and can block or alter malicious traffic in inline deployments.
Create a custom snort 3 intrusion policy
Configure a custom Snort 3 intrusion policy to define how the system inspects and responds to network intrusions.
Edit Snort 3 Intrusion Policies
Edit and configure Snort 3 intrusion policies.
Change the base policy of an intrusion policy
Configure a different system-provided or custom policy as the base policy for an intrusion policy.
View Snort 2 and Snort 3 base policy mapping
View the Snort 3 to Snort 2 intrusion policy mapping in the management center.
Synchronize Snort 2 rules with Snort 3
Configure synchronization to retain Snort 2 version settings and custom rules when moving to Snort 3, ensuring similar coverage between versions.
Manage intrusion policies
Configure intrusion policies through creation, deletion, editing, export, deployment, and reporting functions on the Intrusion Policy window.
Access control rule configuration to perform intrusion prevention
Describes how access control policies can have multiple access control rules associated with intrusion policies to provide different intrusion inspection profiles for different types of network traffic.
Tune Intrusion Policies using Rules
Describes how to tune intrusion policies using custom rules in Snort 3, including rule actions, event notification filters, converting Snort 2 rules, and adding rule groups to policies.
Recommended rules
Describes the Secure Firewall recommended rules and explains how to generate and apply these rules to enhance security policy effectiveness.
Mitigate threats using MITRE framework in Snort 3 intrusion policies
Describes how to use the MITRE ATT&CK framework within Snort 3 intrusion policies to identify, categorize, and mitigate security threats based on known adversary tactics and techniques.