Configure synchronization to retain Snort 2 version settings and custom rules when moving to Snort 3, ensuring similar coverage between versions.
This task helps ensure that Snort 2 rule override settings and custom rules are replicated on Snort 3, allowing you to start with similar coverage when transitioning between versions.
To ensure that the Snort 2 version settings and custom rules are retained and carried over to Snort 3, the Firewall Management Center provides the synchronization functionality. Synchronization helps Snort 2 rule override settings and custom rules, which you may have altered and added over the last few months or years, to be replicated on the Snort 3 version. This utility helps to synchronize Snort 2 version policy configuration with Snort 3 version to start with similar coverage.
Snort 2 is not supported on threat defense Version 7.7. For information on Snort 2 features that are supported in versions earlier than 7.7, refer to the Firewall Management Center guide that matches your Firewall Threat Defense version.
If the Firewall Management Center is upgraded from 6.7 or earlier to 7.0 or later version, the system synchronizes the configuration. If the Firewall Management Center is a fresh 7.0 or later version, you can upgrade to a higher version, and the system will not synchronize any content during upgrade.
Before upgrading a device to Snort 3, if changes are made in Snort 2 version, you can use this utility to have the latest synchronization from Snort 2 version to Snort 3 version so that you start with a similar coverage.
When you move to Snort 3, manage the Snort 3 version of the policy independently. Do not use this utility as a regular operation.
Only the Snort 2 rule overrides and custom rules are copied to Snort 3 and not the other way around. You may not find a one-to-one mapping of all the intrusion rules in Snort 2 and Snort 3. Your changes to rule actions for rules that exist in both versions are synchronized when you perform the following procedure.
Synchronization does not migrate the threshold and suppression settings of any custom or system-provided rules from Snort 2 to Snort 3.
Procedure
| 1. | Choose . |
|
| 2. | Ensure the Intrusion Policies tab is selected. |
|
| 3. | Click Show Snort 3 Sync status. |
|
| 4. | Identify the intrusion policy that is out-of-sync. |
|
| 5. | Click the Sync icon Snort out-of-Sync (
|
|
| 6. | Read the summary. Download a copy of the summary if required. |
|
| 7. | Click Re-Sync.
|
What to do next
Deploy configuration changes. See Deploy configuration changes.

