Configuring the POP Preprocessor
|
This section applies to Snort 2 preprocessors. For information on Snort 3 inspectors, see https://www.cisco.com/go/snort3-inspectors. |
Procedure
1 |
Choose Network Analysis Policy or , and then click Network Analysis Policies. , and then click
|
||
2 |
Click Snort 2 Version next to the policy you want to edit. |
||
3 |
Click Edit ( If View ( |
||
4 |
Click Settings in the navigation panel. |
||
5 |
If POP Configuration under Application Layer Preprocessors is disabled, click Enabled. |
||
6 |
Click Edit ( |
||
7 |
Modify the settings described in POP Preprocessor Options. |
||
8 |
To save changes you made in this policy since the last policy commit, click Policy Information, then click Commit Changes. If you leave the policy without committing changes, cached changes since the last commit are discarded if you edit a different policy. |
What to do next
-
If you want to enable intrusion events, enable POP preprocessor rules (GID 142). For more information, see Setting Intrusion Rule States.
-
Deploy configuration changes.