Best Practices for Migrating from Snort 2 to Snort 3
-
Back up your intrusion policy before performing the migration. See the Export Configurations task in the Cisco Secure Firewall Management Center Administration Guide.
-
Before upgrading a device to Snort 3, if changes are made in Snort 2, use the synchronize utility to include the latest synchronization from Snort 2 to Snort 3 so that you can start with a similar coverage. See Synchronize Snort 2 Rules with Snort 3.
-
Snort 2 custom rules are not automatically converted to Snort 3 and must be manually migrated. See Convert Snort 2 Custom IPS Rules to Snort 3.
-
Synchronization does not migrate Snort 2 rules with thresholds or suppressions. These rules must be created again in Snort 3.