Generate the Secure Firewall recommendations for the intrusion policy and then follow the steps that are listed here to create new recommended rule settings in Snort 3. Rule overheads are interpreted as security levels based on the threshold policies you select in Snort 3. The recommended action depends on the selected security level. If it is higher than the base policy, the recommendation includes actions beyond only generating events.
Prior to setting the Secure Firewall recommendations you should ask which of the three points listed below closely matches the goal:
-
Increased Protection —Enable additional rules based on vulnerabilities found in the host database and do not automatically disable any rules. This will likely result in a larger rule set.
-
Focused Protection—Enable additional rules and disable existing rules based on vulnerabilities found in the host database. This can increase or decrease the number of rules depending on vulnerabilities discovered.
-
Higher Efficiency—Use the currently enabled rule set and disable any rules for vulnerabilities not found in the host database. This will likely result in a smaller enabled rule set.
Based on the response, these are the recommended actions:
-
Set recommendations to the next highest security level, and clear the option to disable rules.
-
Set recommendations to the next highest security level, and select the option to disable rules.
-
Set recommendations to the current security level, and select the option to disable rules.
What to do next
Deploy configuration changes. See Deploy configuration changes.