Describes how intrusion policies are migrated from Snort 2 to Snort 3. Guides users through enabling Snort 3, converting Snort 2 custom rules, synchronizing rule sets, and deploying configuration changes to leverage Snort 3’s enhanced detection and performance capabilities.
Starting with Version 7.0, Snort 3 is the default inspection engine for new Firewall Threat Defense deployments with Firewall Management Center. Snort 3 is required in Version 7.7+. If you are still using the Snort 2 inspection engine, switch to Snort 3 now for improved detection and performance.
Upgrading Firewall Threat Defense to Version 7.2 through 7.6 also upgrades eligible Snort 2 devices to Snort 3. For devices that are ineligible because they use custom intrusion or network analysis policies, manually upgrade to Snort 3 as described here.
Although you can switch individual devices back, you should not. Upgrading Firewall Threat Defense to Version 7.7+ is blocked for Snort 2 devices.
Snort 3 inspection engine
Describes the default inspection engine for newly registered devices on version 7.0 or later, and the requirements for upgraded devices.
Snort 2 versus Snort 3
Provides architectural and inspection engine capability differences between Snort 2 and Snort 3 versions.
Migrating from Snort 2 to Snort 3
Describes the process of switching the inspection engine of the Firewall Threat Defense device from Snort 2 to Snort 3.
View Snort 2 and Snort 3 base policy mapping
View the Snort 3 to Snort 2 intrusion policy mapping in the management center.
Synchronize Snort 2 rules with Snort 3
Configure synchronization to retain Snort 2 version settings and custom rules when moving to Snort 3, ensuring similar coverage between versions.
Deploy configuration changes
Deploy configuration changes to affected devices after modifying configurations.
Examples for migration
Describes Snort 2 to Snort 3 migration scenarios and examples.