Configure a custom Snort 3 intrusion policy to define how the system inspects and responds to network intrusions.
Create a custom Snort 3 intrusion policy to tailor intrusion detection and prevention settings to your network security requirements.
Snort 3 intrusion policies define how the system inspects traffic and responds to potential threats. You can create custom policies based on existing system-provided policies or other custom policies to meet specific security needs.
Before you begin
Follow these steps to create a custom Snort 3 intrusion policy:
Procedure
| 1. | Choose . |
|
| 2. | Click Create Policy. |
|
| 3. | Enter a unique Name and, optionally, a Description. |
|
| 4. | Choose the Inspection Mode. The selected action determines whether intrusion rules block and alert (Prevention mode) or only alert (Detection mode).
|
|
| 5. | Choose the Base Policy. You can use either a system-provided policy or an existing policy as your base policy. |
|
| 6. | Click Save. The new policy has the same settings as its base policy. |
What to do next
To customize the policy, see Edit Snort 3 Intrusion Policies.