Multi-layer inspection

The multi-layer inspection feature in Snort 3 enables you to inspect traffic across multiple protocol layers within the same session.

Snort 3 can simultaneously inspect the following layers:

  • Network layer (L3): IP addresses, fragmentation

  • Transport layer (L4): TCP or UDP ports, flags, session tracking

  • Application layer (L7): HTTP, DNS, SMTP, TLS, SIP, and others.

  • File and payload layer: File extraction, malware signatures, embedded content

Snort 3 supports decoding for a wide range of protocols. It inspects encapsulated protocols and evaluates packet headers to determine policy actions during advanced threat inspection.