Set intrusion rule action

Set intrusion rule actions to control how the system responds to detected threats, allowing you to configure rules to alert on or block specific intrusion attempts.

Intrusion rule actions are policy-specific.

Procedure


Step 1

Choose Policies > Security policies > Intrusion.

Step 2

Click Snort 3 Version next to the policy you want to edit.

Tip
This page shows the total number of:
  • disabled rules

  • enabled rules set to Alert

  • enabled rules set to Block

  • overridden rules

Step 3

Choose the rule or rules where you want to set the rule action.

Step 4

Choose one of the rule actions from the Rule Action drop-down list. See Edit Snort 3 Intrusion Policies for more information about the different rule actions.

Step 5

Click Save.


What to do next

Deploy configuration changes. See Deploy configuration changes.