Snort 3 inspection engine

Snort 3 is a network inspection engine that

  • serves as the default inspection engine for newly registered Firewall Threat Defense devices on version 7.0 or later,

  • requires explicit enablement after upgrading Firewall Threat Defense devices to version 7.0 or later, and

  • activates the Snort 3 version of the intrusion policy, which is applied through access control policies, for all traffic passing through the device.

For Firewall Threat Defense devices on version 6.x or earlier, Snort 2 is the default inspection engine.

Version switching and rule mapping

You can switch Snort versions when required. Snort 2 and Snort 3 intrusion rules are mapped and the mapping is system-provided. However, you may not find a one-to-one mapping of all the intrusion rules in Snort 2 and Snort 3. If you change the rule action for one rule in Snort 2, that change will not be retained if you switch to Snort 3 without first synchronizing Snort 2 with Snort 3. For more information on synchronization, see Synchronize Snort 2 rules with Snort 3.