Delete Rule Groups

Before you begin

Exclude the rule group you want to delete from all intrusion policies where you have included it. For steps on excluding a rule group from an intrusion policy, see Edit Snort 3 Intrusion Policies.

Procedure


Step 1

Choose Objects > Intrusion Rules.

Step 2

Click Snort 3 All Rules tab.

Step 3

Expand Local Rules in the left pane.

Step 4

Select the rule group to be deleted.

Step 5

Ensure the rule action for all the rules in the group is set to Disable before proceeding.

If the rule action for any of the rules is anything other than Disable, then you cannot delete the rule group. If required, follow the steps below to disable the rule action for all the rules:

  1. Check the check box below the Rule Actions drop-down list to select all the rules in the group.

  2. From the Rule Actions drop-down box, select Per Intrusion Policy.

  3. Select All Policies radio button.

  4. Select Disable from the Select Override state drop-down list.

  5. Click Save.

Step 6

Click the Delete (delete icon) next to the rule group.

Step 7

Click OK in the Delete Rule Group pop-up window.


What to do next

Deploy configuration changes; see Deploy Configuration Changes.