Generate Secure Firewall Recommendations in Snort 3: Upgrade Scenarios

Starting or stopping the use of Secure Firewall recommendations may take several minutes. It depends on the size of your network and intrusion rule set.

Generate the Secure Firewall recommendations for the intrusion policy. Follow the steps for the upgrade scenarios described in the procedure.

Before you begin

Secure Firewall recommendations have the following requirements:

  • Firewall Threat Defense License—Threat

  • Classic License—Protection

  • User Roles—Admin or Intrusion Admin

  • Ensure that hosts are present in the system to generate recommendations.

  • Protected networks configured for recommendations should map to the hosts present in the system

Procedure

1

Upgrade from 6.5+ to 7.1.


 

We assume there are no changes in 7.0.

  1. Generate Snort 3 Recommendations in 7.1 using existing Snort 2 recommendation configurations.

2

Displays the Snort 2 to Snort 3 Sync summary details:

  • Recommendations generated for Snort 3 version of the following Intrusion policy.

  • Same base policy and inspection mode are updated to Snort 3 policy.

You can also download the summary details.
3

Considering an Upgrade Scenario 2: Upgrade from 6.5+ to 7.0 to 7.1 - First upgrading to 7.0:

4

Choose Policies > Intrusion and identify the intrusion policy that is out-of-sync.

5

Click the Sync icon (snort versions out-of-sync).


 

If the Snort 2 and the Snort 3 versions of the intrusion policy are synchronized, then the Sync icon is in green (snort versions in-sync) ).

During upgrade from pre-7.0 to 7.0, any existing Snort 2 recommendations will be synched to Snort 3. However, if you have generated Snort 2 recommendations after upgrade to 7.0, then you can sync all these recommendations to Snort 3 version.

6

Read through the summary and download a copy of the summary if required.

7

Considering there are no recommendations in 7.0 and Snort 2 recommendations are migrated as the rule overrides in 7.0.

8

Displays the Migrated Overrides details:

  • This policy had Snort 2 recommendations that are migrated as overrides, in previous upgrade. Select Snort 3 version to generate recommendations for Snort 3.

    Prior to generating Snort 3 recommendations, click View to view the overrides or click Remove to remove the overrides or click Ignore and Generate to ignore the overrides and generate the recommendations.

  • Same base policy and inspection mode are updated to Snort 3 policy.

You can also download the summary details.
9

Upgrade from 7.0 to 7.1:

10

For a 7.0 Firewall Management Center with Snort 2 Rule Recommendations, after upgrade to 7.1, you will be notified with a sync summary message.

What to do next

Deploy configuration changes; see Deploy Configuration Changes.