Configuring the Modbus Preprocessor
Note | This section applies to Snort 2 preprocessors. For information on Snort 3 inspectors, see https://www.cisco.com/go/snort3-inspectors. |
You should not enable this preprocessor in a network analysis policy that you apply to traffic if your network does not contain any Modbus-enabled devices.
Procedure
Step 1 | Choose Network Analysis Policy or , then click Network Analysis Policies. , then click
| ||
Step 2 | Click Snort 2 Version next to the policy you want to edit. | ||
Step 3 | Click Edit ( If View ( | ||
Step 4 | Click Settings in the navigation panel. | ||
Step 5 | If Modbus Configuration under SCADA Preprocessors is disabled, click Enabled. | ||
Step 6 | Click Edit ( | ||
Step 7 | Enter a value in the Ports field. Separate multiple values with commas. | ||
Step 8 | To save changes you made in this policy since the last policy commit, click Policy Information, then click Commit Changes. If you leave the policy without committing changes, cached changes since the last commit are discarded if you edit a different policy. |
What to do next
-
If you want to generate events and, in an inline deployment, drop offending packets, enable Modbus preprocessor rules (GID 144). For more information, see Setting Intrusion Rule States and Modbus Preprocessor Rules.
-
Deploy configuration changes.