Manage custom rules in Snort 3
This task enables uploaded custom rules in intrusion policies to enforce rule monitoring on network traffic.
Custom rules that are uploaded in the system have to be added to an intrusion policy and enabled to enforce those rules on the traffic. You can enable the uploaded custom rules across all policies or selectively on individual policies.
Before you begin
Follow these steps to enable custom rules in one or many intrusion policies:
Procedure
Step 1 | Choose . |
Step 2 | Click Snort 3 All Rules tab. |
Step 3 | Expand Local Rules. |
Step 4 | Select the required rule group. |
Step 5 | Select the rules by checking the check boxes next to them. |
Step 6 | Select Per Intrusion Policy from the Rule Actions drop-down list. |
Step 7 | Choose:
|
Step 8 | Set the rule actions:
|
Step 9 | Optionally, add a comment in the Comments text box. |
Step 10 | Click Save. |
What to do next
Deploy configuration changes. See Deploy configuration changes.