Generate new Secure Firewall recommendations in Snort 3
Generate Secure Firewall recommendations to create new recommended rule settings in Snort 3.
Generate the Secure Firewall recommendations for the intrusion policy and then follow the steps that are listed here to create new recommended rule settings in Snort 3. Rule overheads are interpreted as security levels based on the threshold policies you select in Snort 3. The recommended action depends on the selected security level. If it is higher than the base policy, the recommendation includes actions beyond only generating events.
Prior to setting the Secure Firewall recommendations you should ask which of the three points listed below closely matches the goal:
-
Increased Protection —Enable additional rules based on vulnerabilities found in the host database and do not automatically disable any rules. This will likely result in a larger rule set.
-
Focused Protection—Enable additional rules and disable existing rules based on vulnerabilities found in the host database. This can increase or decrease the number of rules depending on vulnerabilities discovered.
-
Higher Efficiency—Use the currently enabled rule set and disable any rules for vulnerabilities not found in the host database. This will likely result in a smaller enabled rule set.
Based on the response, these are the recommended actions:
-
Set recommendations to the next highest security level, and clear the option to disable rules.
-
Set recommendations to the next highest security level, and select the option to disable rules.
-
Set recommendations to the current security level, and select the option to disable rules.
Before you begin
Secure Firewall recommendations have the following requirements:
-
Ensure that hosts are present in the system to generate recommendations.
-
Protected networks configured for recommendations should map to the hosts present in the system
Follow these steps to generate new Secure Firewall recommendations in Snort 3:
Procedure
Step 1 | Choose . | ||||
Step 2 | Click the Snort 3 Version button of the intrusion policy. | ||||
Step 3 | Click the Recommendations (Not in Use) layer to configure the rule recommendations. Click Start. In the Secure Firewall Rule Recommendations window you can set the following:
| ||||
Step 4 | Generate and apply recommendations:
Recommendations are generated successfully. A new recommendation tab appears with all the recommended rules with their corresponding recommended actions. Rule action preset filters are also available for this tab, in addition with new recommendations. | ||||
Step 5 | You can verify the recommendations and choose to apply them.
Under All Rules, there is a Recommended Rules section which displays the recommended rules.
|
What to do next
Deploy configuration changes. See Deploy configuration changes.