Set Suppression for an Intrusion Rule in Snort 3
You can set one or more suppressions for a rule in your intrusion policy.
Before you begin
Ensure you create the required network objects to be added for source or destination suppression.
Procedure
1 |
Choose . |
2 |
Click Snort 3 All Rules tab. |
3 |
Click the None link in the intrusion rule’s Alert Configuration column,. |
4 |
Click Edit ( |
5 |
From the Suppressions tab, click the add icon Add (
|
6 |
Select any of the preset networks in the Network drop-down list. |
7 |
Click Save. |
8 |
(Optional) Repeat the last three steps if required. |
9 |
Click Save in the Alert Configuration window. |
What to do next
Deploy configuration changes; see Deploy Configuration Changes.