Limiting pattern matching for intrusions
Limit pattern matching for intrusions to optimize system performance by controlling how many pattern states are analyzed per packet and managing content inspection before and after stream reassembly.
Pattern matching limits help balance security effectiveness with system performance. When processing high volumes of traffic, limiting the number of pattern states analyzed per packet can prevent performance degradation while maintaining essential intrusion detection capabilities.
Before you begin
Follow these steps to limit pattern matching for intrusions:
Procedure
Step 1 | In the access control policy editor, click Advanced (, click Edit and then click Advanced Settings). In the new UI, select Advanced Settings from the drop-down arrow at the end of the packet flow line. | ||
Step 2 | Click Edit ( If View ( | ||
Step 3 | Click Pattern Matching Limits in the Performance Settings pop-up window. | ||
Step 4 | Enter a value for the maximum number of events to queue in the Maximum Pattern States to Analyze Per Packet field. | ||
Step 5 | To disable the inspection of packets that will be rebuilt into larger streams of data before and after stream reassembly in Snort 2, check the Disable Content Checks on Traffic Subject to Future Reassembly check box. Inspection before and after reassembly requires more processing overhead and may decrease performance.
| ||
Step 6 | Click OK. | ||
Step 7 | Click Save to save the policy. |
What to do next
-
Deploy configuration changes.
