Custom Snort 3 Intrusion Policies for Access Control

PDF

Custom Snort 3 Intrusion Policies for Access Control

Limiting intrusion events generated per packet

Want to summarize with AI?

Log in

Configure the intrusion event logging limits to control the number of intrusion events generated per packet.


This task allows you to control the number of intrusion events generated per packet by configuring intrusion event logging limits in the access control policy performance settings.

Use this task when you need to manage intrusion detection system performance by limiting the number of events generated for each packet processed by the firewall.

Procedure

1.

In the access control policy editor, click Advanced.

In the new UI, select Advanced Settings from the drop-down arrow at the end of the packet flow line.

2.

Click Edit (edit icon) next to Performance Settings.

If View (View button) appears instead, settings are inherited from an ancestor policy, or you do not have permission to modify the settings. If the configuration is unlocked, uncheck Inherit from base policy to enable editing.

3.

Click Intrusion Event Logging Limits in the Performance Settings pop-up window.

4.

You can modify any of the options in Per packet intrusion event generation limits.

5.

Click OK.

6.

Click Save to save the policy.

What to do next

  • Deploy configuration changes.