Use the SNORT Rules tab to import a SNORT rules file, to add SNORT rules, and to configure these rules for the network.
Navigating in IPS Local Management Interface: Secure Protection Settings > Advanced IPS > SNORT Configuration and Rules
Navigating in SiteProtector™ Management: select the SNORT Configuration and Rules policy
Option | Description |
---|---|
Enabled | Enables the SNORT rule. |
SID | Displays the SNORT-assigned identification of the rule. Note: A
SNORT rule must have a SID or the appliance identifies the rule as
invalid.
|
File | Displays the SNORT rules file from which the SNORT rule was imported. |
Message | Displays the SNORT-assigned description of the rule. |
Rule String | Lists the string version of the SNORT rule. |
Comment | Specifies an optional description of the SNORT rule. |
Severity | Specifies a severity level for the rule: low, medium, or
high. Note: This setting is useful for statistical and filtering purposes.
Use it to manipulate data on log pages (such as the Security
Alerts page) and in graphs (such as the Attacks
by Severity graph).
|
Display | Specifies how to display the SNORT event in the SiteProtector Management console:
|
Log Evidence | Determines the type of packet to capture
when suspicious traffic triggers events. The appliance logs files
to the /var/iss/ directory. You can retrieve
log evidence files from Review Analysis and
Diagnostics > Downloads > Logs
and Packet Captures > Log Evidence.
Note: Connection, Interface,
and All Interfaces are not available for the
SNORT feature.
|
User Overridden | Identifies modified imported rules and rules created on the appliance. This setting is read-only and is useful for grouping. |
Responses |
Tip: If you do not receive responses for SNORT activity,
see if the setting Send alert messages to syslog is
enabled on the SNORT Execution tab. When this
setting is enabled, the SNORT system does not send responses for SNORT
activity.
If a response is not in the drop down lists, you can configure the responses in Secure Protection Settings > Response Tuning > Responses. |
Apply policy settings after configuring this tab. Apply is at the bottom of the page. Applying settings sets the system to check for errors. See Troubleshooting SNORT errors for information about system behavior when it encounters an error.