Custom Snort 3 Intrusion Policies for Access Control

PDF

Custom Snort 3 Intrusion Policies for Access Control

Access control rule configuration to perform intrusion prevention

Want to summarize with AI?

Log in

Describes how access control policies can have multiple access control rules associated with intrusion policies to provide different intrusion inspection profiles for different types of network traffic.


An access control rule configuration to perform intrusion prevention is a security mechanism that

  • enables multiple access control rules within an access control policy to be associated with intrusion policies,

  • permits intrusion inspection for Allow or Interactive Block access control rules to match different intrusion inspection profiles against different types of traffic, and

  • evaluates traffic before it reaches its final destination on the network.

Whenever the system uses an intrusion policy to evaluate traffic, it uses an associated variable set. Variables in a set represent values commonly used in intrusion rules to identify source and destination IP addresses and ports. You can also use variables in intrusion policies to represent IP addresses in rule suppressions and dynamic rule states.

System-provided and custom intrusion policies

Cisco delivers several intrusion policies with the system. By using system-provided intrusion policies, you can take advantage of the experience of the Cisco Talos Intelligence Group (Talos). For these policies, Talos sets intrusion and preprocessor rule states, as well as provides the initial configurations for advanced settings. You can use system-provided policies as-is, or you can use them as the base for custom policies. Building custom policies can improve the performance of the system in your environment and provide a focused view of the malicious traffic and policy violations occurring on your network.

Connection and intrusion event logging

When an intrusion policy invoked by an access control rule detects an intrusion and generates an intrusion event, it saves that event to the Management Center. The system also automatically logs the end of the connection where the intrusion occurred to the Management Center database, regardless of the logging configuration of the access control rule.


Access control rule configuration and intrusion policies

The number of unique intrusion policies you can use in a single access control policy depends on the model of the target devices; more powerful devices can handle more. Every unique pair of intrusion policy and variable set counts as one policy. Although you can associate a different intrusion policy-variable set pair with each Allow and Interactive Block rule (as well as with the default action), you cannot deploy an access control policy if the target devices have insufficient resources to perform inspection as configured.


Configure an access control rule to perform intrusion prevention

Configure an access control rule to enable intrusion prevention inspection on network traffic, allowing you to detect and prevent malicious activities based on intrusion signatures and policies.

You must be an Admin, Access Admin, or Network Admin to perform this task.

Follow these steps to configure an access control rule to perform intrusion prevention:

Procedure

1.

In the access control policy editor, create a new rule or edit an existing rule; see the Access Control Rule Components topic in the latest version of the Cisco Secure Firewall Management Center Configuration Guide.

2.

Ensure the rule action is set to Allow, Interactive Block, or Interactive Block with reset.

3.

Click Inspection.

4.

Choose a system-provided or a custom intrusion policy, or choose None to disable intrusion inspection for traffic that matches the access control rule.

5.

If you want to change the variable set associated with the intrusion policy, choose a value from the Variable Set drop-down list.

6.

Click Save to save the rule.

7.

Click Save to save the policy.

What to do next

Deploy configuration changes. See Deploy configuration changes.